Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
5.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | quality_dor | quality_dor_at | quality_dor_by | quality_dor_note | parent_workplan | related | state_hub_workstream_id | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SBOM-WP-0002 | workplan | Deploy and cut over SBOM Nexus production authority | infotech | sbom-nexus | active | codex | infotech | 2026-08-22 | 2026-08-22 | DoR-Ok | 2026-08-22 | codex | Goal, ownership boundaries, staged dependencies, production safety gates, reconciliation evidence, rollback paths, and cross-repository handoffs were reviewed against the implemented Nexus contract and current State Hub history. | CUST-WP-0062 |
|
7729a4bd-c1c4-50b9-a3b6-1faa51fff97d |
Deploy and cut over SBOM Nexus production authority
Goal
Deploy SBOM Nexus with managed PostgreSQL, import and reconcile State Hub history, move callers through reversible compatibility stages, and prove the bounded daily catch-up before retiring State Hub SBOM ownership.
Deploy dark with managed PostgreSQL
id: SBOM-WP-0002-T01
status: done
priority: high
state_hub_task_id: "95a520d4-30c2-5c87-8054-6bfe549c2686"
Provision database credentials through the governed route, migrate schema,
deploy the API without callers, and capture health plus backup/restore evidence.
Image publication, package rendering, family validation, and server-side dry-run
are complete; see
docs/evidence/SBOM-WP-0002-T01-dark-deployment-preflight-2026-08-22.md.
The overflow cell initially failed closed on an S3 HeadBucket 403. The
database owner repaired that path under RAPP-POSTGRES-WP-0005; no caller was
enabled while the gate was open.
Completed with the private runtime healthy on PostgreSQL at migration head,
dynamic runtime/migration credentials synchronized, a successful governed
backup, 51-second scratch restore, runtime DDL denial, and immutable image
verification. See
docs/evidence/SBOM-WP-0002-T03-production-history-import-2026-08-22.md.
Synchronize repository projections
id: SBOM-WP-0002-T02
status: done
priority: high
state_hub_task_id: "22cbb75f-d82f-5b47-9fef-27bde3b410d5"
Populate active repository identity and host checkout paths from Repo Manager. Verify fleet totals and catch-up ordering without performing ingest.
The projection-only synchronizer and reconciliation contract are implemented.
Its dry-run never contacts the Nexus target and no code path calls an SBOM
ingest route. Production apply and catch-up ordering proof wait for the dark
runtime from T01. The isolated rehearsal reconciled all 120 source projections
and selected exactly the oldest three of 116 active repositories; see
docs/evidence/SBOM-WP-0002-T02-repository-projection-rehearsal-2026-08-22.md.
Completed in production with 120/120 projections reconciled and zero snapshots created by the projection operation.
Import and reconcile State Hub history
id: SBOM-WP-0002-T03
status: done
priority: high
state_hub_task_id: "49bd74a5-d806-5d8e-9d75-0d465b380171"
Depends on T01/T02. Back up the empty target, run the idempotent importer, and retain an exact reconciliation report before any caller switch.
Completed in production: 22 snapshots, 18 repositories, and 3,123 entries
reconciled exactly; licence groups and direct copyleft count matched; the second
run returned already_present=22. No caller was switched.
Cut over State Hub compatibility façade
id: SBOM-WP-0002-T04
status: done
priority: high
state_hub_task_id: "e7681dce-e3b6-52d1-bf13-92595b082b09"
Depends on T03 and the State Hub child change. Move reads then writes behind reversible flags; retarget dashboard, MCP, CLI, summary, DoI, and onboarding.
Completed in production with independent SBOM_NEXUS_READ_MODE and
SBOM_NEXUS_WRITE_MODE flags set to nexus. The State Hub façade preserves
legacy response models and repository UUIDs, projects Nexus last_attempt_at
as last_sbom_at, routes future ingest only to Nexus, and sources dashboard
and summary SBOM metrics from Nexus. Helm ConfigMap checksums make one-value
read or write rollback trigger a real pod rollout. See
docs/evidence/SBOM-WP-0002-T04-state-hub-facade-cutover-2026-08-22.md.
Retarget Repo Manager scanner interface
id: SBOM-WP-0002-T05
status: todo
priority: medium
state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"
Depends on dark deployment. Preserve CLI usability while removing competing SBOM product authority and pinning the Nexus contract.
Enable bounded Activity Core ingest
id: SBOM-WP-0002-T06
status: wait
priority: high
state_hub_task_id: "dad4577d-5dcf-5452-b65e-d72299f432be"
Depends on T03/T04 and ACTIVITY-WP-0030. Enable no more than N ingests/skips
per fire with zero spawned catch-up tasks.
Stabilize and retire legacy ownership
id: SBOM-WP-0002-T07
status: wait
priority: medium
state_hub_task_id: "bb1ff087-f204-5fd0-9295-3bd10bf0d38a"
Capture two successful daily fires and a zero-flood Monday window. Record the retention decision, then retire State Hub SBOM ownership after the stabilization window without deleting historical data implicitly.