railiance-platform/workplans/RPF-WP-0048-activity-core-gitops-adoption.md
codex d49906d59a Record activity-core adoption and track digest retention readiness
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
2026-09-27 15:49:29 +02:00

3.8 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
RPF-WP-0048 workplan Adopt activity-core application runtime into railiance01 GitOps financials railiance-platform active codex railiance 2026-09-27 2026-09-27 b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54

User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the frontend-patterns reporting exception. This explicitly authorizes this adoption; it does not widen the earlier one-time exception to unrelated workloads. Authority: CONSTRUCT @ activity-core and railiance-platform; ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap; activation=APPROVED. Existing 24-hour observation requirement remains in force.

Bootstrap a namespace-scoped project and adopt nine runtime resources

id: RPF-WP-0048-T01
status: done
priority: high
state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370"

New project permits only activity-core source, activity-core destination, and ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal, llm-connect, edge relay, storage or cluster-scoped resources enter this Application. Application source is activity-core k8s/gitops at a pinned reviewed commit; no finalizer, automated sync or pruning initially. Root sync must name this child only; unrelated pending applications must not be changed. Verify ArgoCD's diff, health, resource inventory, schedules and original deployment generations.

Observe adoption and enforce bounded promotion readiness

id: RPF-WP-0048-T02
status: wait
priority: high
state_hub_task_id: "63b44949-39f8-52fd-ab63-e618b67ef992"

Keep automated sync off for at least 24 hours after successful adoption. Record start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication, source validation and the promotion/rollback guard. Root-wide automation is outside this workplan. No unattended merge credential or release executor is assumed just because the Application exists. Confirm the scoped identity and checks before activating bounded routine promotion. Destructive pruning remains disabled.

Make registry retention aware of digest-pinned releases

id: RPF-WP-0048-T03
status: todo
priority: high

The package retention parser currently recognizes tags only; digest references must resolve to protected registry versions before routine digest promotion can be unattended. Cover live and rollback digests, preserve fail-closed behavior on incomplete registry/export coverage, and test the resulting deletion plan without deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is implemented, release evidence must include protected tag aliases for each digest.

Immediate mitigation verified: all three activity-core baseline tags are present in the additive live-image union and recognized by the existing owner parser. No retention deletion was run. Future releases must not assume a digest line alone provides package protection.

Adoption evidence — 2026-09-27

AppProject bootstrapped; root selectively synced only activity-core. Initial nine-resource adoption changed tracking metadata only. Then the child pinned 12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled frontend reporting smoke completed; all three recurring definitions stay enabled.

See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to healthy observation. T02 stays waiting for this window and authenticated narrowly bound release-identity/rollback proof. Automation and pruning remain disabled. Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.