Retire SBOM Nexus production cutover

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
tegwick 2026-08-22 21:37:44 +02:00
parent 11a07a697b
commit 0b14e0d0b2
2 changed files with 64 additions and 2 deletions

View file

@ -0,0 +1,45 @@
# SBOM-WP-0002-T07 retirement decision
Date: 2026-08-22
Decision authority: repository owner, in-session direction: “retire it after
you added an entry to hall-of-helix.”
## Decision
SBOM-WP-0002 and the extraction/cutover session are retired. SBOM Nexus remains
the production authority. State Hub remains a compatibility façade with its
read and write flags pointing to Nexus; Repo Manager remains a deprecated Nexus
client; Activity Core remains the bounded scheduler.
The scheduled Monday observation was explicitly waived by the retirement
direction. It is not represented as completed evidence. Evidence that does
exist is retained:
- two full production catch-up fires;
- three distinct repositories processed per fire;
- six terminal `no-checkout` outcomes;
- zero tasks spawned by either fire;
- queue fairness advanced from 101 to 98 never-attempted repositories;
- `daily-sbom-catchup` enabled and active;
- `weekly-sbom-staleness` disabled and paused;
- clean Activity Core verification: 409 passed, 1 conditional skip.
## Retention
Retain State Hub's 22 historical SBOM snapshots and the compatibility façade as
read-only rollback evidence. No historical rows, snapshots, migrations,
feature flags, or façade code are deleted by this decision. New authoritative
SBOM reads and writes continue through Nexus.
The remaining operational limitation is also retained honestly: the deployed
Nexus pod cannot access workstation host checkout paths, so bounded automation
records `no-checkout` until a controlled scan-input topology is designed. That
future capability does not reopen this extraction workplan.
## Hall record
The completed session is recorded in Hall of Helix commit `9eb42a1`:
- `entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md`
- `visuals/codex-20260822-sbom-ledger-found-room.png`

View file

@ -4,7 +4,7 @@ type: workplan
title: "Deploy and cut over SBOM Nexus production authority"
domain: infotech
repo: sbom-nexus
status: active
status: finished
owner: codex
topic_slug: infotech
created: "2026-08-22"
@ -13,6 +13,10 @@ quality_dor: DoR-Ok
quality_dor_at: "2026-08-22"
quality_dor_by: codex
quality_dor_note: "Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history."
quality_dod: DoD-Ok
quality_dod_at: "2026-08-22"
quality_dod_by: codex
quality_dod_note: "Production authority, migration reconciliation, reversible caller cutovers, scanner handoff, bounded automation, retention decision, clean verification, evidence, and owner-directed retirement were reviewed. The scheduled Monday observation was explicitly waived rather than claimed; legacy history remains retained and no destructive cleanup was performed."
parent_workplan: CUST-WP-0062
related:
- SBOM-WP-0001
@ -157,7 +161,7 @@ disabled and paused. See
```task
id: SBOM-WP-0002-T07
status: wait
status: done
priority: medium
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
```
@ -165,3 +169,16 @@ state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
Capture two successful daily fires and a zero-flood Monday window. Record the
retention decision, then retire State Hub SBOM ownership after the stabilization
window without deleting historical data implicitly.
Retired by explicit owner direction on 2026-08-22 after the Hall of Helix entry
was published. The already-proven conditions are recorded exactly: two bounded
production fires, six distinct terminal outcomes, zero spawned tasks, an active
daily schedule, and the legacy weekly schedule disabled and paused. The owner
waived waiting for the next Monday observation; this record does not claim that
window occurred.
Retention decision: keep State Hub's 22 historical snapshots and compatibility
surface read-only as rollback evidence. New reads and writes remain owned by
SBOM Nexus. Do not delete the retained rows, remove rollback flags, or tear out
the façade as part of this retirement. See
`docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md`.