state-hub/docs/retirement-cutover-slice-plan.md
tegwick ccf691042d docs: complete retirement inbox parity gate and track reader cutover
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
2026-09-05 11:27:21 +02:00

91 lines
9.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# State Hub retirement — cutover slice plan
**Execution owner:** STATE-WP-0079-T04/T05
**Re-baselined:** 2026-09-05
**Inventory:** SHR-INV-0001, original 425-item inventory in
`prj-state-hub-retirement/inventory/`. Counts below identify historical slices;
current owner contracts take precedence over the original owner assignments.
This checklist replaces the obsolete August 1920 readiness snapshot. That
snapshot and the original off/dual/owner proposal remain in Git history.
`RM_SLICE_*` names were proposed controls, not proof of deployed flags. Do not
execute the old workstation dual-run instructions against the cluster service:
ADR-002 forbids central services from mutating workstation checkouts.
## Evidence required to switch a slice
For each route family, identify the current caller and destination endpoint,
compare representative identities/content/counts in a read-only parity run,
record the exact deployment/source revisions, exercise rollback, and retain the
switch receipt. An owner workplan marked finished or an imported Python router
proves neither deployed endpoint availability nor data migration. Production
writer changes require a concrete recoverable cutover, within user authorization.
No new permanent receiving authority belongs in State Hub during retirement.
## Current route-family checklist
| Slice / historical items | Receiver and contract evidence | Caller / route-switch evidence | Remaining gate and rollback |
| --- | --- | --- | --- |
| A1 registry / 27 | Repo Manager observation/scaffolding; STATE-WP-0081 and 0086 establish forge-derived projection | `rmgr sync` verified pushed commit `74a3b22` on primary/railiance01 in the preceding session | Inventory remaining registry callers per endpoint. Keep current projection while proving the owner read; do not restore checkout mutation in central |
| A2 work records / 59 | RMGR-WP-0008 implements file-backed workplan, intake, decision, dependency and task mutations; RMGR-WP-0005 identifiers finished | Repository files + `rmgr sync` are the current write convention. Two ad-hoc task-filter callers identified and guidance corrected in this review | Work-record caller inventory and per-kind writer receipts still required. Revert source commit and reconcile for a reviewed rollback; no second file authority |
| A3 registers / 49 | RMGR-WP-0008 register spine; **SBOM Nexus** is the current SBOM product owner | Live State Hub config uses Nexus for both SBOM reads/writes. Direct Nexus licence and snapshot reads return 200. Two more compatibility interfaces retired in the meter September 5 | Other registers need individual caller/parity receipts. Preserve SBOM history; remaining `/sbom/` traffic and retained compatibility handlers prevent deleting the whole router |
| A4 work/repo UI / 22 | hub-core projection + UI clients; RMGR-ADR-003 excludes a Repo Manager dashboard | No complete State Hub UI redirect receipt established | First prove backing reads; rollback redirects to the retained UI |
| A5 topic spine / 8 | Published Repo Manager classification contract, accepted by HUB-WP-0004 | No complete State Hub caller-switch receipt established | Prove deployed consumer contract and parity; retain source-backed classification projection |
| B1 catalogs / 34 | HUB-WP-0004/0005 receiving architecture and `/api/v2` absorption | Completion covers the Core Hub route groups, not every State Hub capability/registry route | Map each State Hub catalog to a deployed endpoint and migration receipt |
| B2 messaging/interface log / 22 | Native `/ports/messaging/messages` uses a distinct envelope; new authenticated `/ports/projections/statehub-inbox` preserves bounded State Hub history | T08 complete: 20-row import, six parity cases, private transport and disable/re-enable proof; no production reader switched | T09 / HUB-WP-0011: freshness, caller credentials and aliases before one reader switch. Interface log and writer cutover remain separate |
| B3 telemetry / 32 | Native `/ports/events/progress` exists; token/software catalogs need separate mappings | Literal `/progress` and `/token-events` absence does not imply no native receiving contract | Map native semantics and historical identity/count parity; writer exclusivity and rollback receipts remain necessary |
| B4 projection/policy / 20 | HUB-WP-0004/0005; policy publication belongs to policy-nexus | State Hub still serves its projection routes; no full family receipt established | Map individual projections and policy publication; retain source/runtime boundaries and current reads |
| B5 hub UI / 17 | Hub Core runtime/console exists | Core Hub absorption does not establish replacement of State Hub dashboard pages | Prove A4/B1B4 data contracts before redirect; retain UI rollback |
| C1 execution / 13 | ACTIVITY-WP-0029 finished; Activity Core owns scheduling/ops_run | STATE-WP-0079 records launch-request rejection (410), replacement semantics, and corrected unconsumed requests | Verify every remaining execution caller uses the owner contract. Do not revive the obsolete launch queue for rollback |
| C2 jobs / 5 | ACTIVITY-WP-0029 finished; scheduler is Activity Core, reconciliation engine is Repo Manager | Receiving/sweep handoffs recorded in owner workplan | Attach remaining per-job deployment and caller receipts; keep scheduler ownership distinct from work-record authority |
| D1 service catalog / 11 | OPS-WP-0003 finished; reviewed packages and `/api/v2` conformance gate | Owner contract completion established; State Hub family-switch receipt still missing | Compare catalog identities and UI bindings; preserve current reads until switched |
| D2 Fabric / 10 | **railiance-fabric** authority, FIN-WP-0003 consumer gate | August 31 dual-read import: 131 nodes/117 edges; green hash/count/provenance checks, rollback and roll-forward exercised | Hosted runtime/persistence/auth/freshness remains RAIL-FAB-WP-0028 (`proposed`). Keep retained import rollback; do not claim the local authority is a hosted production receiver |
| D3 kaizen / 2 | the-custodian, original two-tool disposition | No fresh removal/delegation receipt collected in this review | Locate current tools/consumers and owner contract before removal |
| E1 suggestions / 17 | Archived history in the-custodian | STATE-WP-0079 records eight read routes at 410, six MCP tools removed, dashboard removed | Completed surface removal; tables retained for final dump |
| E2 legacy workplans / 13 | Preferred `/workplans` routes and `workplan_id` parameters | Workstream REST handlers return 410 and meter rejected calls. Task query alias still accepted | Seven legacy meter records remain after today's two SBOM retirements; observe volume-scaled quiet periods and complete T07 attribution |
| E3 UI feedback / 1 | State Hub until cutover | Feedback still needed during transition | T06 zero-normal-traffic gate; do not confuse it with retired suggestions |
| E4 meter / 9 | State Hub until all other retirement evidence complete | Eight retired / seven legacy interfaces, zero current candidates after September 5 action | Retire last, after the remaining interfaces and final evidence are closed |
## What today's probes establish
- Central health identifies `primary/railiance01`.
- The live State Hub configuration has `SBOM_NEXUS_READ_MODE=nexus` and
`SBOM_NEXUS_WRITE_MODE=nexus`, using the cluster SBOM Nexus service.
- Direct Nexus `/sbom/report/licences/` and `/sbom/snapshots/` returned 200 from
the State Hub pod. Their State Hub meter entries are now retired. This does
**not** delete the compatibility handlers or historical data.
- The earlier literal-prefix probe missed existing native messaging, event and
projection ports. The bounded inbox projection now has live parity evidence.
Scoped NetworkPolicy admission resolved State Hub-to-candidate transport;
unauthenticated requests from the source pod now reach the 401 boundary.
- Session trace identifies ad-hoc legacy task reads in fluid-telegram and
ops-warden. Their corrected canonical queries return 200 with 8 and 5 tasks.
No evidence identifies the other historical callers yet.
Evidence: `docs/evidence/STATE-WP-0079-sbom-retirement-20260905.json` and
`docs/evidence/STATE-WP-0079-caller-and-receiver-review-20260905.md`.
## Next executable work
1. T07: observe the remaining legacy readers with component attribution. The
known caller repositories and bundled State Hub skill now prescribe canonical
reads. Preserve the quiet clocks; do not exercise legacy URLs to test them.
2. T09 / HUB-WP-0011: establish monotonic freshness and stale-source behavior,
caller-specific credentials and canonical/alias scope before one production
inbox reader switch. T08's frozen snapshot parity and rollback are complete;
see `docs/evidence/statehub-inbox-pilot-20260905.md` and JSON receipt.
3. RAIL-FAB-WP-0028-T01 remains the owner decision for runtime, persistent store,
auth, backup/restore and deployment repository. Its T02T04 deliver deployment,
freshness and final direct-consumer receipts; no new Fabric authority here.
4. Re-evaluate eligible interfaces from a fresh seven-day meter capture. The
quiet ladder is 7 days for 199 historical calls, 30 for 1009,999, and 60 for
10,000+. A new call restarts the relevant clock, including rejected requests.
## Freeze and infrastructure boundary
T06 remains blocked until move/replace families and legacy retirement complete,
followed by a fresh zero-normal-read/write window. Final dump, restore proof,
service stop and repository archive then form one separately reviewable
operation. The original schema-history/keep items and nine infrastructure
couplings (database, scheduler, connectivity) remain explicit final-window
checks; they are not route flags. Ops Bridge connectivity survives retirement.