Retire SBOM Nexus production cutover
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
parent
11a07a697b
commit
0b14e0d0b2
2 changed files with 64 additions and 2 deletions
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
# SBOM-WP-0002-T07 retirement decision
|
||||
|
||||
Date: 2026-08-22
|
||||
|
||||
Decision authority: repository owner, in-session direction: “retire it after
|
||||
you added an entry to hall-of-helix.”
|
||||
|
||||
## Decision
|
||||
|
||||
SBOM-WP-0002 and the extraction/cutover session are retired. SBOM Nexus remains
|
||||
the production authority. State Hub remains a compatibility façade with its
|
||||
read and write flags pointing to Nexus; Repo Manager remains a deprecated Nexus
|
||||
client; Activity Core remains the bounded scheduler.
|
||||
|
||||
The scheduled Monday observation was explicitly waived by the retirement
|
||||
direction. It is not represented as completed evidence. Evidence that does
|
||||
exist is retained:
|
||||
|
||||
- two full production catch-up fires;
|
||||
- three distinct repositories processed per fire;
|
||||
- six terminal `no-checkout` outcomes;
|
||||
- zero tasks spawned by either fire;
|
||||
- queue fairness advanced from 101 to 98 never-attempted repositories;
|
||||
- `daily-sbom-catchup` enabled and active;
|
||||
- `weekly-sbom-staleness` disabled and paused;
|
||||
- clean Activity Core verification: 409 passed, 1 conditional skip.
|
||||
|
||||
## Retention
|
||||
|
||||
Retain State Hub's 22 historical SBOM snapshots and the compatibility façade as
|
||||
read-only rollback evidence. No historical rows, snapshots, migrations,
|
||||
feature flags, or façade code are deleted by this decision. New authoritative
|
||||
SBOM reads and writes continue through Nexus.
|
||||
|
||||
The remaining operational limitation is also retained honestly: the deployed
|
||||
Nexus pod cannot access workstation host checkout paths, so bounded automation
|
||||
records `no-checkout` until a controlled scan-input topology is designed. That
|
||||
future capability does not reopen this extraction workplan.
|
||||
|
||||
## Hall record
|
||||
|
||||
The completed session is recorded in Hall of Helix commit `9eb42a1`:
|
||||
|
||||
- `entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md`
|
||||
- `visuals/codex-20260822-sbom-ledger-found-room.png`
|
||||
Loading…
Add table
Add a link
Reference in a new issue