state-hub/docs/retirement-cutover-slice-plan.md
tegwick ccf691042d docs: complete retirement inbox parity gate and track reader cutover
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
2026-09-05 11:27:21 +02:00

9.6 KiB
Raw Blame History

State Hub retirement — cutover slice plan

Execution owner: STATE-WP-0079-T04/T05 Re-baselined: 2026-09-05 Inventory: SHR-INV-0001, original 425-item inventory in prj-state-hub-retirement/inventory/. Counts below identify historical slices; current owner contracts take precedence over the original owner assignments.

This checklist replaces the obsolete August 1920 readiness snapshot. That snapshot and the original off/dual/owner proposal remain in Git history. RM_SLICE_* names were proposed controls, not proof of deployed flags. Do not execute the old workstation dual-run instructions against the cluster service: ADR-002 forbids central services from mutating workstation checkouts.

Evidence required to switch a slice

For each route family, identify the current caller and destination endpoint, compare representative identities/content/counts in a read-only parity run, record the exact deployment/source revisions, exercise rollback, and retain the switch receipt. An owner workplan marked finished or an imported Python router proves neither deployed endpoint availability nor data migration. Production writer changes require a concrete recoverable cutover, within user authorization. No new permanent receiving authority belongs in State Hub during retirement.

Current route-family checklist

Slice / historical items Receiver and contract evidence Caller / route-switch evidence Remaining gate and rollback
A1 registry / 27 Repo Manager observation/scaffolding; STATE-WP-0081 and 0086 establish forge-derived projection rmgr sync verified pushed commit 74a3b22 on primary/railiance01 in the preceding session Inventory remaining registry callers per endpoint. Keep current projection while proving the owner read; do not restore checkout mutation in central
A2 work records / 59 RMGR-WP-0008 implements file-backed workplan, intake, decision, dependency and task mutations; RMGR-WP-0005 identifiers finished Repository files + rmgr sync are the current write convention. Two ad-hoc task-filter callers identified and guidance corrected in this review Work-record caller inventory and per-kind writer receipts still required. Revert source commit and reconcile for a reviewed rollback; no second file authority
A3 registers / 49 RMGR-WP-0008 register spine; SBOM Nexus is the current SBOM product owner Live State Hub config uses Nexus for both SBOM reads/writes. Direct Nexus licence and snapshot reads return 200. Two more compatibility interfaces retired in the meter September 5 Other registers need individual caller/parity receipts. Preserve SBOM history; remaining /sbom/ traffic and retained compatibility handlers prevent deleting the whole router
A4 work/repo UI / 22 hub-core projection + UI clients; RMGR-ADR-003 excludes a Repo Manager dashboard No complete State Hub UI redirect receipt established First prove backing reads; rollback redirects to the retained UI
A5 topic spine / 8 Published Repo Manager classification contract, accepted by HUB-WP-0004 No complete State Hub caller-switch receipt established Prove deployed consumer contract and parity; retain source-backed classification projection
B1 catalogs / 34 HUB-WP-0004/0005 receiving architecture and /api/v2 absorption Completion covers the Core Hub route groups, not every State Hub capability/registry route Map each State Hub catalog to a deployed endpoint and migration receipt
B2 messaging/interface log / 22 Native /ports/messaging/messages uses a distinct envelope; new authenticated /ports/projections/statehub-inbox preserves bounded State Hub history T08 complete: 20-row import, six parity cases, private transport and disable/re-enable proof; no production reader switched T09 / HUB-WP-0011: freshness, caller credentials and aliases before one reader switch. Interface log and writer cutover remain separate
B3 telemetry / 32 Native /ports/events/progress exists; token/software catalogs need separate mappings Literal /progress and /token-events absence does not imply no native receiving contract Map native semantics and historical identity/count parity; writer exclusivity and rollback receipts remain necessary
B4 projection/policy / 20 HUB-WP-0004/0005; policy publication belongs to policy-nexus State Hub still serves its projection routes; no full family receipt established Map individual projections and policy publication; retain source/runtime boundaries and current reads
B5 hub UI / 17 Hub Core runtime/console exists Core Hub absorption does not establish replacement of State Hub dashboard pages Prove A4/B1B4 data contracts before redirect; retain UI rollback
C1 execution / 13 ACTIVITY-WP-0029 finished; Activity Core owns scheduling/ops_run STATE-WP-0079 records launch-request rejection (410), replacement semantics, and corrected unconsumed requests Verify every remaining execution caller uses the owner contract. Do not revive the obsolete launch queue for rollback
C2 jobs / 5 ACTIVITY-WP-0029 finished; scheduler is Activity Core, reconciliation engine is Repo Manager Receiving/sweep handoffs recorded in owner workplan Attach remaining per-job deployment and caller receipts; keep scheduler ownership distinct from work-record authority
D1 service catalog / 11 OPS-WP-0003 finished; reviewed packages and /api/v2 conformance gate Owner contract completion established; State Hub family-switch receipt still missing Compare catalog identities and UI bindings; preserve current reads until switched
D2 Fabric / 10 railiance-fabric authority, FIN-WP-0003 consumer gate August 31 dual-read import: 131 nodes/117 edges; green hash/count/provenance checks, rollback and roll-forward exercised Hosted runtime/persistence/auth/freshness remains RAIL-FAB-WP-0028 (proposed). Keep retained import rollback; do not claim the local authority is a hosted production receiver
D3 kaizen / 2 the-custodian, original two-tool disposition No fresh removal/delegation receipt collected in this review Locate current tools/consumers and owner contract before removal
E1 suggestions / 17 Archived history in the-custodian STATE-WP-0079 records eight read routes at 410, six MCP tools removed, dashboard removed Completed surface removal; tables retained for final dump
E2 legacy workplans / 13 Preferred /workplans routes and workplan_id parameters Workstream REST handlers return 410 and meter rejected calls. Task query alias still accepted Seven legacy meter records remain after today's two SBOM retirements; observe volume-scaled quiet periods and complete T07 attribution
E3 UI feedback / 1 State Hub until cutover Feedback still needed during transition T06 zero-normal-traffic gate; do not confuse it with retired suggestions
E4 meter / 9 State Hub until all other retirement evidence complete Eight retired / seven legacy interfaces, zero current candidates after September 5 action Retire last, after the remaining interfaces and final evidence are closed

What today's probes establish

  • Central health identifies primary/railiance01.
  • The live State Hub configuration has SBOM_NEXUS_READ_MODE=nexus and SBOM_NEXUS_WRITE_MODE=nexus, using the cluster SBOM Nexus service.
  • Direct Nexus /sbom/report/licences/ and /sbom/snapshots/ returned 200 from the State Hub pod. Their State Hub meter entries are now retired. This does not delete the compatibility handlers or historical data.
  • The earlier literal-prefix probe missed existing native messaging, event and projection ports. The bounded inbox projection now has live parity evidence. Scoped NetworkPolicy admission resolved State Hub-to-candidate transport; unauthenticated requests from the source pod now reach the 401 boundary.
  • Session trace identifies ad-hoc legacy task reads in fluid-telegram and ops-warden. Their corrected canonical queries return 200 with 8 and 5 tasks. No evidence identifies the other historical callers yet.

Evidence: docs/evidence/STATE-WP-0079-sbom-retirement-20260905.json and docs/evidence/STATE-WP-0079-caller-and-receiver-review-20260905.md.

Next executable work

  1. T07: observe the remaining legacy readers with component attribution. The known caller repositories and bundled State Hub skill now prescribe canonical reads. Preserve the quiet clocks; do not exercise legacy URLs to test them.
  2. T09 / HUB-WP-0011: establish monotonic freshness and stale-source behavior, caller-specific credentials and canonical/alias scope before one production inbox reader switch. T08's frozen snapshot parity and rollback are complete; see docs/evidence/statehub-inbox-pilot-20260905.md and JSON receipt.
  3. RAIL-FAB-WP-0028-T01 remains the owner decision for runtime, persistent store, auth, backup/restore and deployment repository. Its T02T04 deliver deployment, freshness and final direct-consumer receipts; no new Fabric authority here.
  4. Re-evaluate eligible interfaces from a fresh seven-day meter capture. The quiet ladder is 7 days for 199 historical calls, 30 for 1009,999, and 60 for 10,000+. A new call restarts the relevant clock, including rejected requests.

Freeze and infrastructure boundary

T06 remains blocked until move/replace families and legacy retirement complete, followed by a fresh zero-normal-read/write window. Final dump, restore proof, service stop and repository archive then form one separately reviewable operation. The original schema-history/keep items and nine infrastructure couplings (database, scheduler, connectivity) remain explicit final-window checks; they are not route flags. Ops Bridge connectivity survives retirement.