sbom-nexus/workplans/SBOM-WP-0002-production-cutover.md
tegwick 280da08455
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m9s
feat: add repository projection synchronization
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
2026-08-22 16:52:47 +02:00

4.3 KiB

id type title domain repo status owner topic_slug created updated quality_dor quality_dor_at quality_dor_by quality_dor_note parent_workplan related state_hub_workstream_id
SBOM-WP-0002 workplan Deploy and cut over SBOM Nexus production authority infotech sbom-nexus active codex infotech 2026-08-22 2026-08-22 DoR-Ok 2026-08-22 codex Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history. CUST-WP-0062
SBOM-WP-0001
CUST-WP-0062
ACTIVITY-WP-0030
STATE-WP-0079
RMGR-WP-0008
7729a4bd-c1c4-50b9-a3b6-1faa51fff97d

Deploy and cut over SBOM Nexus production authority

Goal

Deploy SBOM Nexus with managed PostgreSQL, import and reconcile State Hub history, move callers through reversible compatibility stages, and prove the bounded daily catch-up before retiring State Hub SBOM ownership.

Deploy dark with managed PostgreSQL

id: SBOM-WP-0002-T01
status: progress
priority: high
needs_human: true
intervention_note: "Warden requires an attended founder act for the first platform-pg-2 OpenBao database connection, SBOM Nexus dynamic roles/policies, and renewable External Secrets parent token. The database owner must also repair the governed backup credential/policy after a live S3 HeadBucket 403."
state_hub_task_id: "95a520d4-30c2-5c87-8054-6bfe549c2686"

Provision database credentials through the governed route, migrate schema, deploy the API without callers, and capture health plus backup/restore evidence. Image publication, package rendering, family validation, and server-side dry-run are complete; see docs/evidence/SBOM-WP-0002-T01-dark-deployment-preflight-2026-08-22.md. The overflow cell is now 1/1 Ready, but continuous archiving and its first base backup fail closed on an S3 HeadBucket 403. Database-owner work is tracked by RAPP-POSTGRES-WP-0005; no caller or Nexus runtime has been enabled.

Synchronize repository projections

id: SBOM-WP-0002-T02
status: progress
priority: high
state_hub_task_id: "22cbb75f-d82f-5b47-9fef-27bde3b410d5"

Populate active repository identity and host checkout paths from Repo Manager. Verify fleet totals and catch-up ordering without performing ingest.

The projection-only synchronizer and reconciliation contract are implemented. Its dry-run never contacts the Nexus target and no code path calls an SBOM ingest route. Production apply and catch-up ordering proof wait for the dark runtime from T01. The isolated rehearsal reconciled all 120 source projections and selected exactly the oldest three of 116 active repositories; see docs/evidence/SBOM-WP-0002-T02-repository-projection-rehearsal-2026-08-22.md.

Import and reconcile State Hub history

id: SBOM-WP-0002-T03
status: wait
priority: high
state_hub_task_id: "49bd74a5-d806-5d8e-9d75-0d465b380171"

Depends on T01/T02. Back up the empty target, run the idempotent importer, and retain an exact reconciliation report before any caller switch.

Cut over State Hub compatibility façade

id: SBOM-WP-0002-T04
status: wait
priority: high
state_hub_task_id: "e7681dce-e3b6-52d1-bf13-92595b082b09"

Depends on T03 and the State Hub child change. Move reads then writes behind reversible flags; retarget dashboard, MCP, CLI, summary, DoI, and onboarding.

Retarget Repo Manager scanner interface

id: SBOM-WP-0002-T05
status: wait
priority: medium
state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"

Depends on dark deployment. Preserve CLI usability while removing competing SBOM product authority and pinning the Nexus contract.

Enable bounded Activity Core ingest

id: SBOM-WP-0002-T06
status: wait
priority: high
state_hub_task_id: "dad4577d-5dcf-5452-b65e-d72299f432be"

Depends on T03/T04 and ACTIVITY-WP-0030. Enable no more than N ingests/skips per fire with zero spawned catch-up tasks.

Stabilize and retire legacy ownership

id: SBOM-WP-0002-T07
status: wait
priority: medium
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"

Capture two successful daily fires and a zero-flood Monday window. Record the retention decision, then retire State Hub SBOM ownership after the stabilization window without deleting historical data implicitly.