Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
7.7 KiB
| id | type | title | domain | repo | status | flavor | owner | created | updated | related | state_hub_workstream_id | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RTEL-WP-0002 | workplan | Provide the Q2 receiving contract and prove signal delivery | financials | railiance-telemetry | blocked | implementation | codex | 2026-09-06 | 2026-09-28 |
|
08a5db92-7293-50d3-b589-55287b9850b3 |
Bounded initial Q2 reference implementation for platform assurance. Producer meaning stays in S3; deployable monitoring packaging stays with a selected package owner. No public listener, credential custody or incident workflow.
Define metadata-only receiving and retention contract
id: RTEL-WP-0002-T01
status: done
priority: high
state_hub_task_id: "ac73553d-5bd4-5dff-8307-95a29bffe474"
Implemented docs/signal-contract.md and a pinned platform stream contract.
Exact identities/signals, finite states, payload limit, freshness, replay,
proposed retention and local recipient semantics are explicit. Live acceptance
of the proposed budgets and recipient remains T04, not implied by this schema.
Implement durable receipt and operator inbox reference
id: RTEL-WP-0002-T02
status: done
priority: high
state_hub_task_id: "dacc9e2d-9321-5d39-afc4-88326f5c6930"
SQLite acceptance and notices commit together; strict rejection, duplicate idempotence, explicit acknowledgments and bounded retention are tested. This is a local private CLI implementation; acceptance says local-inbox-only.
Prove platform adaptation and absent-emission semantics locally
id: RTEL-WP-0002-T03
status: done
priority: high
state_hub_task_id: "a8ed3588-4240-5278-b03f-04c3237a52f9"
Adapter preserves producer evaluation time and classifications. Tests prove failure survives receiver restart, inbox addressing/acknowledgment, never-seen and stopped-producer detection, replay refusal, wrong-scope rejection and retention of unacknowledged evidence. Local simulated-time tests establish implementation behavior, not actual scheduled notification delivery.
Accept private runtime and controlled end-to-end delivery
id: RTEL-WP-0002-T04
status: wait
priority: high
state_hub_task_id: "ceb14fdc-b3fd-5a22-870d-d835a9d52055"
Choose package/runtime execution owner with cluster/activity-core; confirm the operator recipient, producer/watchdog cadence, retention/storage/backup and private authenticated access. Install only through accepted authority. Prove a controlled failure and stopped producer reach and are acknowledged by the named operator, and receiver/scheduler failure is independently detectable. Preserve receipts across restart; demonstrate capacity/retention handling. Only these receipts can satisfy RPF-WP-0036-T04. No package repo name or deployment grant is invented here. This live task holds the residual explicitly.
T04 implementation follow-up, September 6: added deterministic runtime jobs, restart-stable report ingestion, an independently invocable watchdog-age probe, and verified SQLite snapshots preserving pending notices. Added disabled domain activity definitions and executor task contracts following activity-core's recurring-automations playbook. Native parser accepts both; 14 tests pass. Recipient/channel clarification is pending. Runtime/profile and failure-domain binding, off-host custody and actual notification acknowledgment remain unproven; T04 remains wait, with no live schedule enabled.
Production package established September 6 at user direction: rapp-telemetry, owned by this Q2 repo and declared against Master's normative schema. Selected Prometheus/Alertmanager/Grafana via pinned kube-prometheus-stack; planned runtime railiance01, Grafana telemetry.coulomb.social. RAPP-TELEMETRY-WP-0001-T03/T04 owns package install, readiness and authenticated exposure. This T04 retains Q2's exporter/rule mapping and actual delivery/absence acceptance. Existing SQLite runtime and disabled activities are reference work, not the production service. No package activation or Q2 delivery acceptance is claimed by repo creation.
September 28 loose-end review: completed the local Prometheus text exporter and
native-tested failure/absence rules under this task. A separate dated contract
includes platform's added eso.token-renewal signal without silently migrating
existing SQLite bindings. Source classifications and evaluation time survive
export; stale/future reports fail. Nineteen Python tests, seven native Prometheus
rule scenarios and metric lint pass. See docs/prometheus-mapping.md and
history/2026-09-28-loose-end-review.md.
Package T03 is already done (private installation and attended restore proof).
T04 remains wait and this workplan is now blocked: rapp-telemetry T04 still
owes accepted scrape/executor binding, a confirmed recipient/channel, actual
failure/absence acknowledgments, an outside-node watchdog and recurring backup
ownership. The founder, Bernd Worsch, supplies recipient/admission decisions;
rapp-telemetry and platform own runtime/custody integration. No additional task
or workplan was opened, and no live schedule or notification was enabled.
September 28 recipient decision: Bernd Worsch confirmed email to
bernd.worsch@gmail.com, requested the railiance-admin role for that user,
explicit link-based confirmation and acknowledgment records in audit-core, and
authorized controlled failure/absence drills. Recipient/channel choice is no
longer a blocker. The native directory group membership is now applied; the updated KeyCape
issuer is deployed. A real signed-role login remains unproved.
Implemented the bounded acknowledgment component, email link template and audit
outbox/transport under this same T04. A GET never acknowledges; authenticated
human role, fresh policy decision, Origin and CSRF checks precede POST. The first
acknowledgment and audit envelope commit together; retries retain the same event.
Actual audit-core receiver code accepts then deduplicates after a lost reply and
process reopen. See docs/alert-acknowledgment.md for the concrete owner bindings.
OIDC code/PKCE sessions, a native Flex Auth decision adapter, a background audit worker and the package-owned container/manifests are now implemented. The native policy evaluator and signed issuer fixtures pass. KeyCape 1164f65 is published and deployed; the native directory role grant preserves existing memberships.
T04 stays wait/blocked: the founder selected From platform@coulomb.social and
subsequently created the mailbox; password custody remains pending. Dedicated SMTP/webhook/audit custody, OIDC
client and enforced PDP caller admission, application rollout, signed identity,
real email/acknowledgment and independent audit readback remain. Outside-node
watchdog and recurring backup gates remain. No new task/workplan was created.
September 28 custody follow-up: founder reports SMTP_PASSWORD added to the OpenBao entry. Exact SMTP ESO ServiceAccount/ClusterSecretStore/ExternalSecret installed after server dry-run/diff; OpenBao reader admission still needs the attended helper. Ten custody tests pass. SMTP authentication is not yet verified and the live alert route remains disabled. No task/workplan added.
SMTP custody gate now passed: attended verification of KV version 2 and IONOS authentication; exact reader admitted, ESO Ready, password preserved. Scoped egress installed after the first transport test exposed namespace isolation. The corrected native test Job completed and SMTP accepted the test email. Recipient inbox receipt and actual alert acknowledgment remain distinct pending evidence, along with browser client/PDP/audit admission and other T04 gates.
Bernd Worsch confirmed the transport-test email arrived in his inbox. SMTP credential custody, projection, authentication and recipient delivery now pass. This is a transport-test receipt, not an audit-core alert acknowledgment.