railiance-platform/history/2026-09-06-WP-0036-closure-gates.md
codex 31386c8e63
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Validate OpenBao snapshot evidence and record assurance closure gates
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 15:24:58 +02:00

37 lines
2.5 KiB
Markdown

# WP-0036 closure review — 2026-09-06
Result: not eligible for completion. T01/T02/T05/T07 are done; T03/T04/T06
retain unmet acceptance criteria. No task criteria were relaxed or moved into
new plans to create an apparent closure.
| Task | Verified local result | Remaining acceptance |
| --- | --- | --- |
| T03 | Native apps-pg/forgejo-db adapters; archive receipt producers; encrypted off-host OpenBao snapshot adapter | Fresh isolated recovery for all supported services, independently available recovery custody, approved installed cadence with execution receipts and operator delivery |
| T04 | Bounded metadata capture and local validation | Q2 receiving contract, named recipient, controlled failure delivery and missing-emission detection |
| T06 | Exact compatibility inventory and dated retention through October 5 | Scoped legacy alias repair and generated brief matching source; retain compatibility until owner acceptance or the recorded retention decision is reviewed |
New source checks:
- `railiance-telemetry/README.md` explicitly says seeded, no implementation;
its only local workplan is proposed RTELE-WP-0001. A receiving contract/runtime
is not available in that checkout. S3 must not build a replacement Q2 plane
merely to satisfy this plan. Owner response is needed for any newer service.
- `rapp-postgres/docs/evidence/backup-restore-20260813T111651Z-remote.json`
explicitly identifies same-node scratch MinIO, not the governed off-host
target. Its successful drill cannot satisfy the current production recovery
acceptance criterion.
- The August 22 OpenBao snapshot receipt is encrypted, hash-verified and copied
off-host. Added its exact SHA-256 to the recovery index and a narrow adapter
that validates source identity and custody flags. It reports the original
creation time and therefore stale, never healthy by rereading. It does not
establish isolated restore or current independent quorum access.
The prepared requests in `docs/platform-ownership-handoffs.md` remain ready for
telemetry, repo-manager/State Hub and compatibility owners. Authorization to
send them was requested separately; no message was sent during this review.
Sending a request alone would not fulfill the receiving owner's acceptance.
Next closure sequence: obtain the Q2 contract and accepted execution/recipient
binding; run fresh owner-authorized recovery and cadence proofs; verify failure
and missing-emission delivery; reconcile aliases and regenerate orientation.
Existing WP-0015 outage exercises remain separate, with their own prerequisites.