railiance-platform/history/2026-09-06-blocked-workplan-progress.md
codex 445f1361dc
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Advance blocked assurance and operator callback work
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 14:16:49 +02:00

42 lines
2.8 KiB
Markdown

# Blocked workplan progress — 2026-09-06
Prior work was clean at a3ca4b708f224de23292c30966b7fa1e52957cd5. Repo-manager
confirmed origin/main synchronized and primary railiance01 applied that exact
commit. Reviewed the six blocked plans against current source and recovery
receipts; no whole-plan closure gate is fully satisfied.
- **WP-0036 / T03:** implemented hash-pinned native Scaleway recovery adapters
for apps-pg and forgejo-db, preserving actual completion times. Invalid,
changed, future, incomplete-cleanup and wrong-provider receipts cannot pass.
Corrected stale Forgejo coverage records. Fresh capture/evaluation is persisted
in `docs/evidence/RPF-WP-0036-assurance-2026-09-06.json`: 16 healthy signals,
six missing recovery signals, one stale ESO refresh aggregate. Capture's
oldest refresh was 09:13:29Z, near the one-hour diagnostic boundary; subsequent
read-only inspection found all 27 ExternalSecrets Ready with newer refreshes.
This is not proof of an ESO outage. Accepted cadence/grace and Q2 failure/
absence delivery still need resolution. Archive receipts without completion
timestamps remain manual evidence, and essentials never attest full recovery.
- **WP-0025 / T03:** replaced whole-role hardcoded callback writes with a silent
preserving update, idempotence, observed-drift refusal and full readback checks.
Existing settings and callbacks survive. No CAS exists, so concurrent role
administration remains a limitation. No live role update was attempted;
attended loopback UI login still gates listener retraction.
- **WP-0035:** refreshed dependency assessment: secrets-engine implemented its
local claim/validation join; external approval-engine/access-engine serving
endpoints remain unavailable in its September 6 source. Service issuer and
operator group/tenant acceptance remain necessary. Signing T04 is complete.
- **WP-0027:** incident closure still needs predecessor disposition and canonical
custody acceptance. Do not reconstruct the unavailable predecessor secret.
- **WP-0029:** new Backup account recovery is proven; old Bernd share invalidation
evidence is still missing. Repeating backup drills would not close this gate.
- **WP-0015:** disruptive load/reboot exercises need fresh execution windows,
named abort operator and recovery prerequisites; earlier NO-GO is terminal.
WP-0038 remains active: scheduled primary/full and Nextcloud/essentials cutover
and retention execution are not established by one-off recovery proofs. Source
ownership and stale hub alias acceptance remain outstanding in WP-0036-T06.
No external owner acceptance or message delivery was asserted.
Validation: 28 focused tests passed (assurance evaluator/collector, recovery
receipt rejection/expiry, callback preservation/drift/silence). Live capture
completed, and a read-only ExternalSecret metadata query confirmed 27 Ready.