diff --git a/docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md b/docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md new file mode 100644 index 0000000..7685bc9 --- /dev/null +++ b/docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md @@ -0,0 +1,45 @@ +# SBOM-WP-0002-T07 retirement decision + +Date: 2026-08-22 + +Decision authority: repository owner, in-session direction: “retire it after +you added an entry to hall-of-helix.” + +## Decision + +SBOM-WP-0002 and the extraction/cutover session are retired. SBOM Nexus remains +the production authority. State Hub remains a compatibility façade with its +read and write flags pointing to Nexus; Repo Manager remains a deprecated Nexus +client; Activity Core remains the bounded scheduler. + +The scheduled Monday observation was explicitly waived by the retirement +direction. It is not represented as completed evidence. Evidence that does +exist is retained: + +- two full production catch-up fires; +- three distinct repositories processed per fire; +- six terminal `no-checkout` outcomes; +- zero tasks spawned by either fire; +- queue fairness advanced from 101 to 98 never-attempted repositories; +- `daily-sbom-catchup` enabled and active; +- `weekly-sbom-staleness` disabled and paused; +- clean Activity Core verification: 409 passed, 1 conditional skip. + +## Retention + +Retain State Hub's 22 historical SBOM snapshots and the compatibility façade as +read-only rollback evidence. No historical rows, snapshots, migrations, +feature flags, or façade code are deleted by this decision. New authoritative +SBOM reads and writes continue through Nexus. + +The remaining operational limitation is also retained honestly: the deployed +Nexus pod cannot access workstation host checkout paths, so bounded automation +records `no-checkout` until a controlled scan-input topology is designed. That +future capability does not reopen this extraction workplan. + +## Hall record + +The completed session is recorded in Hall of Helix commit `9eb42a1`: + +- `entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md` +- `visuals/codex-20260822-sbom-ledger-found-room.png` diff --git a/workplans/SBOM-WP-0002-production-cutover.md b/workplans/SBOM-WP-0002-production-cutover.md index 82383c5..b7c53da 100644 --- a/workplans/SBOM-WP-0002-production-cutover.md +++ b/workplans/SBOM-WP-0002-production-cutover.md @@ -4,7 +4,7 @@ type: workplan title: "Deploy and cut over SBOM Nexus production authority" domain: infotech repo: sbom-nexus -status: active +status: finished owner: codex topic_slug: infotech created: "2026-08-22" @@ -13,6 +13,10 @@ quality_dor: DoR-Ok quality_dor_at: "2026-08-22" quality_dor_by: codex quality_dor_note: "Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history." +quality_dod: DoD-Ok +quality_dod_at: "2026-08-22" +quality_dod_by: codex +quality_dod_note: "Production authority, migration reconciliation, reversible caller cutovers, scanner handoff, bounded automation, retention decision, clean verification, evidence, and owner-directed retirement were reviewed. The scheduled Monday observation was explicitly waived rather than claimed; legacy history remains retained and no destructive cleanup was performed." parent_workplan: CUST-WP-0062 related: - SBOM-WP-0001 @@ -157,7 +161,7 @@ disabled and paused. See ```task id: SBOM-WP-0002-T07 -status: wait +status: done priority: medium state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a" ``` @@ -165,3 +169,16 @@ state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a" Capture two successful daily fires and a zero-flood Monday window. Record the retention decision, then retire State Hub SBOM ownership after the stabilization window without deleting historical data implicitly. + +Retired by explicit owner direction on 2026-08-22 after the Hall of Helix entry +was published. The already-proven conditions are recorded exactly: two bounded +production fires, six distinct terminal outcomes, zero spawned tasks, an active +daily schedule, and the legacy weekly schedule disabled and paused. The owner +waived waiting for the next Monday observation; this record does not claim that +window occurred. + +Retention decision: keep State Hub's 22 historical snapshots and compatibility +surface read-only as rollback evidence. New reads and writes remain owned by +SBOM Nexus. Do not delete the retained rows, remove rollback flags, or tear out +the façade as part of this retirement. See +`docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md`.