--- id: SBOM-WP-0002 type: workplan title: "Deploy and cut over SBOM Nexus production authority" domain: infotech repo: sbom-nexus status: ready owner: codex topic_slug: infotech created: "2026-08-22" updated: "2026-08-22" parent_workplan: CUST-WP-0062 related: - SBOM-WP-0001 - CUST-WP-0062 - ACTIVITY-WP-0030 - STATE-WP-0079 - RMGR-WP-0008 --- # Deploy and cut over SBOM Nexus production authority ## Goal Deploy SBOM Nexus with managed PostgreSQL, import and reconcile State Hub history, move callers through reversible compatibility stages, and prove the bounded daily catch-up before retiring State Hub SBOM ownership. ## Deploy dark with managed PostgreSQL ```task id: SBOM-WP-0002-T01 status: todo priority: high ``` Provision database credentials through the governed route, migrate schema, deploy the API without callers, and capture health plus backup/restore evidence. ## Synchronize repository projections ```task id: SBOM-WP-0002-T02 status: todo priority: high ``` Populate active repository identity and host checkout paths from Repo Manager. Verify fleet totals and catch-up ordering without performing ingest. ## Import and reconcile State Hub history ```task id: SBOM-WP-0002-T03 status: wait priority: high ``` Depends on T01/T02. Back up the empty target, run the idempotent importer, and retain an exact reconciliation report before any caller switch. ## Cut over State Hub compatibility façade ```task id: SBOM-WP-0002-T04 status: wait priority: high ``` Depends on T03 and the State Hub child change. Move reads then writes behind reversible flags; retarget dashboard, MCP, CLI, summary, DoI, and onboarding. ## Retarget Repo Manager scanner interface ```task id: SBOM-WP-0002-T05 status: wait priority: medium ``` Depends on dark deployment. Preserve CLI usability while removing competing SBOM product authority and pinning the Nexus contract. ## Enable bounded Activity Core ingest ```task id: SBOM-WP-0002-T06 status: wait priority: high ``` Depends on T03/T04 and `ACTIVITY-WP-0030`. Enable no more than N ingests/skips per fire with zero spawned catch-up tasks. ## Stabilize and retire legacy ownership ```task id: SBOM-WP-0002-T07 status: wait priority: medium ``` Capture two successful daily fires and a zero-flood Monday window. Record the retention decision, then retire State Hub SBOM ownership after the stabilization window without deleting historical data implicitly.