Retire SBOM Nexus production cutover
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
parent
11a07a697b
commit
0b14e0d0b2
2 changed files with 64 additions and 2 deletions
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
# SBOM-WP-0002-T07 retirement decision
|
||||
|
||||
Date: 2026-08-22
|
||||
|
||||
Decision authority: repository owner, in-session direction: “retire it after
|
||||
you added an entry to hall-of-helix.”
|
||||
|
||||
## Decision
|
||||
|
||||
SBOM-WP-0002 and the extraction/cutover session are retired. SBOM Nexus remains
|
||||
the production authority. State Hub remains a compatibility façade with its
|
||||
read and write flags pointing to Nexus; Repo Manager remains a deprecated Nexus
|
||||
client; Activity Core remains the bounded scheduler.
|
||||
|
||||
The scheduled Monday observation was explicitly waived by the retirement
|
||||
direction. It is not represented as completed evidence. Evidence that does
|
||||
exist is retained:
|
||||
|
||||
- two full production catch-up fires;
|
||||
- three distinct repositories processed per fire;
|
||||
- six terminal `no-checkout` outcomes;
|
||||
- zero tasks spawned by either fire;
|
||||
- queue fairness advanced from 101 to 98 never-attempted repositories;
|
||||
- `daily-sbom-catchup` enabled and active;
|
||||
- `weekly-sbom-staleness` disabled and paused;
|
||||
- clean Activity Core verification: 409 passed, 1 conditional skip.
|
||||
|
||||
## Retention
|
||||
|
||||
Retain State Hub's 22 historical SBOM snapshots and the compatibility façade as
|
||||
read-only rollback evidence. No historical rows, snapshots, migrations,
|
||||
feature flags, or façade code are deleted by this decision. New authoritative
|
||||
SBOM reads and writes continue through Nexus.
|
||||
|
||||
The remaining operational limitation is also retained honestly: the deployed
|
||||
Nexus pod cannot access workstation host checkout paths, so bounded automation
|
||||
records `no-checkout` until a controlled scan-input topology is designed. That
|
||||
future capability does not reopen this extraction workplan.
|
||||
|
||||
## Hall record
|
||||
|
||||
The completed session is recorded in Hall of Helix commit `9eb42a1`:
|
||||
|
||||
- `entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md`
|
||||
- `visuals/codex-20260822-sbom-ledger-found-room.png`
|
||||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Deploy and cut over SBOM Nexus production authority"
|
||||
domain: infotech
|
||||
repo: sbom-nexus
|
||||
status: active
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
created: "2026-08-22"
|
||||
|
|
@ -13,6 +13,10 @@ quality_dor: DoR-Ok
|
|||
quality_dor_at: "2026-08-22"
|
||||
quality_dor_by: codex
|
||||
quality_dor_note: "Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history."
|
||||
quality_dod: DoD-Ok
|
||||
quality_dod_at: "2026-08-22"
|
||||
quality_dod_by: codex
|
||||
quality_dod_note: "Production authority, migration reconciliation, reversible caller cutovers, scanner handoff, bounded automation, retention decision, clean verification, evidence, and owner-directed retirement were reviewed. The scheduled Monday observation was explicitly waived rather than claimed; legacy history remains retained and no destructive cleanup was performed."
|
||||
parent_workplan: CUST-WP-0062
|
||||
related:
|
||||
- SBOM-WP-0001
|
||||
|
|
@ -157,7 +161,7 @@ disabled and paused. See
|
|||
|
||||
```task
|
||||
id: SBOM-WP-0002-T07
|
||||
status: wait
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
|
||||
```
|
||||
|
|
@ -165,3 +169,16 @@ state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
|
|||
Capture two successful daily fires and a zero-flood Monday window. Record the
|
||||
retention decision, then retire State Hub SBOM ownership after the stabilization
|
||||
window without deleting historical data implicitly.
|
||||
|
||||
Retired by explicit owner direction on 2026-08-22 after the Hall of Helix entry
|
||||
was published. The already-proven conditions are recorded exactly: two bounded
|
||||
production fires, six distinct terminal outcomes, zero spawned tasks, an active
|
||||
daily schedule, and the legacy weekly schedule disabled and paused. The owner
|
||||
waived waiting for the next Monday observation; this record does not claim that
|
||||
window occurred.
|
||||
|
||||
Retention decision: keep State Hub's 22 historical snapshots and compatibility
|
||||
surface read-only as rollback evidence. New reads and writes remain owned by
|
||||
SBOM Nexus. Do not delete the retained rows, remove rollback flags, or tear out
|
||||
the façade as part of this retirement. See
|
||||
`docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue