Retire SBOM Nexus production cutover
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
parent
11a07a697b
commit
0b14e0d0b2
2 changed files with 64 additions and 2 deletions
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
45
docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md
Normal file
|
|
@ -0,0 +1,45 @@
|
||||||
|
# SBOM-WP-0002-T07 retirement decision
|
||||||
|
|
||||||
|
Date: 2026-08-22
|
||||||
|
|
||||||
|
Decision authority: repository owner, in-session direction: “retire it after
|
||||||
|
you added an entry to hall-of-helix.”
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
SBOM-WP-0002 and the extraction/cutover session are retired. SBOM Nexus remains
|
||||||
|
the production authority. State Hub remains a compatibility façade with its
|
||||||
|
read and write flags pointing to Nexus; Repo Manager remains a deprecated Nexus
|
||||||
|
client; Activity Core remains the bounded scheduler.
|
||||||
|
|
||||||
|
The scheduled Monday observation was explicitly waived by the retirement
|
||||||
|
direction. It is not represented as completed evidence. Evidence that does
|
||||||
|
exist is retained:
|
||||||
|
|
||||||
|
- two full production catch-up fires;
|
||||||
|
- three distinct repositories processed per fire;
|
||||||
|
- six terminal `no-checkout` outcomes;
|
||||||
|
- zero tasks spawned by either fire;
|
||||||
|
- queue fairness advanced from 101 to 98 never-attempted repositories;
|
||||||
|
- `daily-sbom-catchup` enabled and active;
|
||||||
|
- `weekly-sbom-staleness` disabled and paused;
|
||||||
|
- clean Activity Core verification: 409 passed, 1 conditional skip.
|
||||||
|
|
||||||
|
## Retention
|
||||||
|
|
||||||
|
Retain State Hub's 22 historical SBOM snapshots and the compatibility façade as
|
||||||
|
read-only rollback evidence. No historical rows, snapshots, migrations,
|
||||||
|
feature flags, or façade code are deleted by this decision. New authoritative
|
||||||
|
SBOM reads and writes continue through Nexus.
|
||||||
|
|
||||||
|
The remaining operational limitation is also retained honestly: the deployed
|
||||||
|
Nexus pod cannot access workstation host checkout paths, so bounded automation
|
||||||
|
records `no-checkout` until a controlled scan-input topology is designed. That
|
||||||
|
future capability does not reopen this extraction workplan.
|
||||||
|
|
||||||
|
## Hall record
|
||||||
|
|
||||||
|
The completed session is recorded in Hall of Helix commit `9eb42a1`:
|
||||||
|
|
||||||
|
- `entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md`
|
||||||
|
- `visuals/codex-20260822-sbom-ledger-found-room.png`
|
||||||
|
|
@ -4,7 +4,7 @@ type: workplan
|
||||||
title: "Deploy and cut over SBOM Nexus production authority"
|
title: "Deploy and cut over SBOM Nexus production authority"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: sbom-nexus
|
repo: sbom-nexus
|
||||||
status: active
|
status: finished
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: infotech
|
topic_slug: infotech
|
||||||
created: "2026-08-22"
|
created: "2026-08-22"
|
||||||
|
|
@ -13,6 +13,10 @@ quality_dor: DoR-Ok
|
||||||
quality_dor_at: "2026-08-22"
|
quality_dor_at: "2026-08-22"
|
||||||
quality_dor_by: codex
|
quality_dor_by: codex
|
||||||
quality_dor_note: "Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history."
|
quality_dor_note: "Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history."
|
||||||
|
quality_dod: DoD-Ok
|
||||||
|
quality_dod_at: "2026-08-22"
|
||||||
|
quality_dod_by: codex
|
||||||
|
quality_dod_note: "Production authority, migration reconciliation, reversible caller cutovers, scanner handoff, bounded automation, retention decision, clean verification, evidence, and owner-directed retirement were reviewed. The scheduled Monday observation was explicitly waived rather than claimed; legacy history remains retained and no destructive cleanup was performed."
|
||||||
parent_workplan: CUST-WP-0062
|
parent_workplan: CUST-WP-0062
|
||||||
related:
|
related:
|
||||||
- SBOM-WP-0001
|
- SBOM-WP-0001
|
||||||
|
|
@ -157,7 +161,7 @@ disabled and paused. See
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: SBOM-WP-0002-T07
|
id: SBOM-WP-0002-T07
|
||||||
status: wait
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
|
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
|
||||||
```
|
```
|
||||||
|
|
@ -165,3 +169,16 @@ state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
|
||||||
Capture two successful daily fires and a zero-flood Monday window. Record the
|
Capture two successful daily fires and a zero-flood Monday window. Record the
|
||||||
retention decision, then retire State Hub SBOM ownership after the stabilization
|
retention decision, then retire State Hub SBOM ownership after the stabilization
|
||||||
window without deleting historical data implicitly.
|
window without deleting historical data implicitly.
|
||||||
|
|
||||||
|
Retired by explicit owner direction on 2026-08-22 after the Hall of Helix entry
|
||||||
|
was published. The already-proven conditions are recorded exactly: two bounded
|
||||||
|
production fires, six distinct terminal outcomes, zero spawned tasks, an active
|
||||||
|
daily schedule, and the legacy weekly schedule disabled and paused. The owner
|
||||||
|
waived waiting for the next Monday observation; this record does not claim that
|
||||||
|
window occurred.
|
||||||
|
|
||||||
|
Retention decision: keep State Hub's 22 historical snapshots and compatibility
|
||||||
|
surface read-only as rollback evidence. New reads and writes remain owned by
|
||||||
|
SBOM Nexus. Do not delete the retained rows, remove rollback flags, or tear out
|
||||||
|
the façade as part of this retirement. See
|
||||||
|
`docs/evidence/SBOM-WP-0002-T07-retirement-2026-08-22.md`.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue