Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
152 lines
7.5 KiB
Markdown
152 lines
7.5 KiB
Markdown
---
|
|
id: RTEL-WP-0002
|
|
type: workplan
|
|
title: "Provide the Q2 receiving contract and prove signal delivery"
|
|
domain: financials
|
|
repo: railiance-telemetry
|
|
status: blocked
|
|
flavor: implementation
|
|
owner: codex
|
|
created: "2026-09-06"
|
|
updated: "2026-09-28"
|
|
related:
|
|
- RTELE-WP-0001
|
|
- RPF-WP-0036
|
|
state_hub_workstream_id: "08a5db92-7293-50d3-b589-55287b9850b3"
|
|
---
|
|
|
|
Bounded initial Q2 reference implementation for platform assurance. Producer
|
|
meaning stays in S3; deployable monitoring packaging stays with a selected
|
|
package owner. No public listener, credential custody or incident workflow.
|
|
|
|
## Define metadata-only receiving and retention contract
|
|
|
|
```task
|
|
id: RTEL-WP-0002-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "ac73553d-5bd4-5dff-8307-95a29bffe474"
|
|
```
|
|
|
|
Implemented `docs/signal-contract.md` and a pinned platform stream contract.
|
|
Exact identities/signals, finite states, payload limit, freshness, replay,
|
|
proposed retention and local recipient semantics are explicit. Live acceptance
|
|
of the proposed budgets and recipient remains T04, not implied by this schema.
|
|
|
|
## Implement durable receipt and operator inbox reference
|
|
|
|
```task
|
|
id: RTEL-WP-0002-T02
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "dacc9e2d-9321-5d39-afc4-88326f5c6930"
|
|
```
|
|
|
|
SQLite acceptance and notices commit together; strict rejection, duplicate
|
|
idempotence, explicit acknowledgments and bounded retention are tested. This
|
|
is a local private CLI implementation; acceptance says local-inbox-only.
|
|
|
|
## Prove platform adaptation and absent-emission semantics locally
|
|
|
|
```task
|
|
id: RTEL-WP-0002-T03
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "a8ed3588-4240-5278-b03f-04c3237a52f9"
|
|
```
|
|
|
|
Adapter preserves producer evaluation time and classifications. Tests prove
|
|
failure survives receiver restart, inbox addressing/acknowledgment, never-seen
|
|
and stopped-producer detection, replay refusal, wrong-scope rejection and
|
|
retention of unacknowledged evidence. Local simulated-time tests establish
|
|
implementation behavior, not actual scheduled notification delivery.
|
|
|
|
## Accept private runtime and controlled end-to-end delivery
|
|
|
|
```task
|
|
id: RTEL-WP-0002-T04
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "ceb14fdc-b3fd-5a22-870d-d835a9d52055"
|
|
```
|
|
|
|
Choose package/runtime execution owner with cluster/activity-core; confirm the
|
|
operator recipient, producer/watchdog cadence, retention/storage/backup and
|
|
private authenticated access. Install only through accepted authority. Prove a
|
|
controlled failure and stopped producer reach and are acknowledged by the named
|
|
operator, and receiver/scheduler failure is independently detectable. Preserve
|
|
receipts across restart; demonstrate capacity/retention handling. Only these
|
|
receipts can satisfy RPF-WP-0036-T04. No package repo name or deployment grant is
|
|
invented here. This live task holds the residual explicitly.
|
|
|
|
T04 implementation follow-up, September 6: added deterministic runtime jobs,
|
|
restart-stable report ingestion, an independently invocable watchdog-age probe,
|
|
and verified SQLite snapshots preserving pending notices. Added disabled domain
|
|
activity definitions and executor task contracts following activity-core's
|
|
recurring-automations playbook. Native parser accepts both; 14 tests pass.
|
|
Recipient/channel clarification is pending. Runtime/profile and failure-domain
|
|
binding, off-host custody and actual notification acknowledgment remain unproven;
|
|
T04 remains wait, with no live schedule enabled.
|
|
|
|
Production package established September 6 at user direction: rapp-telemetry,
|
|
owned by this Q2 repo and declared against Master's normative schema. Selected
|
|
Prometheus/Alertmanager/Grafana via pinned kube-prometheus-stack; planned runtime
|
|
railiance01, Grafana telemetry.coulomb.social. RAPP-TELEMETRY-WP-0001-T03/T04 owns
|
|
package install, readiness and authenticated exposure. This T04 retains Q2's
|
|
exporter/rule mapping and actual delivery/absence acceptance. Existing SQLite
|
|
runtime and disabled activities are reference work, not the production service.
|
|
No package activation or Q2 delivery acceptance is claimed by repo creation.
|
|
|
|
September 28 loose-end review: completed the local Prometheus text exporter and
|
|
native-tested failure/absence rules under this task. A separate dated contract
|
|
includes platform's added `eso.token-renewal` signal without silently migrating
|
|
existing SQLite bindings. Source classifications and evaluation time survive
|
|
export; stale/future reports fail. Nineteen Python tests, seven native Prometheus
|
|
rule scenarios and metric lint pass. See `docs/prometheus-mapping.md` and
|
|
`history/2026-09-28-loose-end-review.md`.
|
|
|
|
Package T03 is already done (private installation and attended restore proof).
|
|
T04 remains `wait` and this workplan is now `blocked`: rapp-telemetry T04 still
|
|
owes accepted scrape/executor binding, a confirmed recipient/channel, actual
|
|
failure/absence acknowledgments, an outside-node watchdog and recurring backup
|
|
ownership. The founder, Bernd Worsch, supplies recipient/admission decisions;
|
|
rapp-telemetry and platform own runtime/custody integration. No additional task
|
|
or workplan was opened, and no live schedule or notification was enabled.
|
|
|
|
September 28 recipient decision: Bernd Worsch confirmed email to
|
|
`bernd.worsch@gmail.com`, requested the `railiance-admin` role for that user,
|
|
explicit link-based confirmation and acknowledgment records in audit-core, and
|
|
authorized controlled failure/absence drills. Recipient/channel choice is no
|
|
longer a blocker. The native directory group membership is now applied; the updated KeyCape
|
|
issuer is deployed. A real signed-role login remains unproved.
|
|
|
|
Implemented the bounded acknowledgment component, email link template and audit
|
|
outbox/transport under this same T04. A GET never acknowledges; authenticated
|
|
human role, fresh policy decision, Origin and CSRF checks precede POST. The first
|
|
acknowledgment and audit envelope commit together; retries retain the same event.
|
|
Actual audit-core receiver code accepts then deduplicates after a lost reply and
|
|
process reopen. See `docs/alert-acknowledgment.md` for the concrete owner bindings.
|
|
|
|
OIDC code/PKCE sessions, a native Flex Auth decision adapter, a background audit
|
|
worker and the package-owned container/manifests are now implemented. The native
|
|
policy evaluator and signed issuer fixtures pass. KeyCape 1164f65 is published
|
|
and deployed; the native directory role grant preserves existing memberships.
|
|
|
|
T04 stays wait/blocked: the founder selected From `platform@coulomb.social` and
|
|
subsequently created the mailbox; password custody remains pending. Dedicated SMTP/webhook/audit custody, OIDC
|
|
client and enforced PDP caller admission, application rollout, signed identity,
|
|
real email/acknowledgment and independent audit readback remain. Outside-node
|
|
watchdog and recurring backup gates remain. No new task/workplan was created.
|
|
|
|
September 28 custody follow-up: founder reports SMTP_PASSWORD added to the
|
|
OpenBao entry. Exact SMTP ESO ServiceAccount/ClusterSecretStore/ExternalSecret
|
|
installed after server dry-run/diff; OpenBao reader admission still needs the
|
|
attended helper. Ten custody tests pass. SMTP authentication is not yet verified
|
|
and the live alert route remains disabled. No task/workplan added.
|
|
|
|
SMTP custody gate now passed: attended verification of KV version 2 and IONOS
|
|
authentication; exact reader admitted, ESO Ready, password preserved. Scoped
|
|
egress installed after the first transport test exposed namespace isolation.
|
|
The corrected native test Job completed and SMTP accepted the test email.
|
|
Recipient inbox receipt and actual alert acknowledgment remain distinct pending
|
|
evidence, along with browser client/PDP/audit admission and other T04 gates.
|