Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
9.6 KiB
State Hub retirement — cutover slice plan
Execution owner: STATE-WP-0079-T04/T05
Re-baselined: 2026-09-05
Inventory: SHR-INV-0001, original 425-item inventory in
prj-state-hub-retirement/inventory/. Counts below identify historical slices;
current owner contracts take precedence over the original owner assignments.
This checklist replaces the obsolete August 19–20 readiness snapshot. That
snapshot and the original off/dual/owner proposal remain in Git history.
RM_SLICE_* names were proposed controls, not proof of deployed flags. Do not
execute the old workstation dual-run instructions against the cluster service:
ADR-002 forbids central services from mutating workstation checkouts.
Evidence required to switch a slice
For each route family, identify the current caller and destination endpoint, compare representative identities/content/counts in a read-only parity run, record the exact deployment/source revisions, exercise rollback, and retain the switch receipt. An owner workplan marked finished or an imported Python router proves neither deployed endpoint availability nor data migration. Production writer changes require a concrete recoverable cutover, within user authorization. No new permanent receiving authority belongs in State Hub during retirement.
Current route-family checklist
| Slice / historical items | Receiver and contract evidence | Caller / route-switch evidence | Remaining gate and rollback |
|---|---|---|---|
| A1 registry / 27 | Repo Manager observation/scaffolding; STATE-WP-0081 and 0086 establish forge-derived projection | rmgr sync verified pushed commit 74a3b22 on primary/railiance01 in the preceding session |
Inventory remaining registry callers per endpoint. Keep current projection while proving the owner read; do not restore checkout mutation in central |
| A2 work records / 59 | RMGR-WP-0008 implements file-backed workplan, intake, decision, dependency and task mutations; RMGR-WP-0005 identifiers finished | Repository files + rmgr sync are the current write convention. Two ad-hoc task-filter callers identified and guidance corrected in this review |
Work-record caller inventory and per-kind writer receipts still required. Revert source commit and reconcile for a reviewed rollback; no second file authority |
| A3 registers / 49 | RMGR-WP-0008 register spine; SBOM Nexus is the current SBOM product owner | Live State Hub config uses Nexus for both SBOM reads/writes. Direct Nexus licence and snapshot reads return 200. Two more compatibility interfaces retired in the meter September 5 | Other registers need individual caller/parity receipts. Preserve SBOM history; remaining /sbom/ traffic and retained compatibility handlers prevent deleting the whole router |
| A4 work/repo UI / 22 | hub-core projection + UI clients; RMGR-ADR-003 excludes a Repo Manager dashboard | No complete State Hub UI redirect receipt established | First prove backing reads; rollback redirects to the retained UI |
| A5 topic spine / 8 | Published Repo Manager classification contract, accepted by HUB-WP-0004 | No complete State Hub caller-switch receipt established | Prove deployed consumer contract and parity; retain source-backed classification projection |
| B1 catalogs / 34 | HUB-WP-0004/0005 receiving architecture and /api/v2 absorption |
Completion covers the Core Hub route groups, not every State Hub capability/registry route | Map each State Hub catalog to a deployed endpoint and migration receipt |
| B2 messaging/interface log / 22 | Native /ports/messaging/messages uses a distinct envelope; new authenticated /ports/projections/statehub-inbox preserves bounded State Hub history |
T08 complete: 20-row import, six parity cases, private transport and disable/re-enable proof; no production reader switched | T09 / HUB-WP-0011: freshness, caller credentials and aliases before one reader switch. Interface log and writer cutover remain separate |
| B3 telemetry / 32 | Native /ports/events/progress exists; token/software catalogs need separate mappings |
Literal /progress and /token-events absence does not imply no native receiving contract |
Map native semantics and historical identity/count parity; writer exclusivity and rollback receipts remain necessary |
| B4 projection/policy / 20 | HUB-WP-0004/0005; policy publication belongs to policy-nexus | State Hub still serves its projection routes; no full family receipt established | Map individual projections and policy publication; retain source/runtime boundaries and current reads |
| B5 hub UI / 17 | Hub Core runtime/console exists | Core Hub absorption does not establish replacement of State Hub dashboard pages | Prove A4/B1–B4 data contracts before redirect; retain UI rollback |
| C1 execution / 13 | ACTIVITY-WP-0029 finished; Activity Core owns scheduling/ops_run | STATE-WP-0079 records launch-request rejection (410), replacement semantics, and corrected unconsumed requests | Verify every remaining execution caller uses the owner contract. Do not revive the obsolete launch queue for rollback |
| C2 jobs / 5 | ACTIVITY-WP-0029 finished; scheduler is Activity Core, reconciliation engine is Repo Manager | Receiving/sweep handoffs recorded in owner workplan | Attach remaining per-job deployment and caller receipts; keep scheduler ownership distinct from work-record authority |
| D1 service catalog / 11 | OPS-WP-0003 finished; reviewed packages and /api/v2 conformance gate |
Owner contract completion established; State Hub family-switch receipt still missing | Compare catalog identities and UI bindings; preserve current reads until switched |
| D2 Fabric / 10 | railiance-fabric authority, FIN-WP-0003 consumer gate | August 31 dual-read import: 131 nodes/117 edges; green hash/count/provenance checks, rollback and roll-forward exercised | Hosted runtime/persistence/auth/freshness remains RAIL-FAB-WP-0028 (proposed). Keep retained import rollback; do not claim the local authority is a hosted production receiver |
| D3 kaizen / 2 | the-custodian, original two-tool disposition | No fresh removal/delegation receipt collected in this review | Locate current tools/consumers and owner contract before removal |
| E1 suggestions / 17 | Archived history in the-custodian | STATE-WP-0079 records eight read routes at 410, six MCP tools removed, dashboard removed | Completed surface removal; tables retained for final dump |
| E2 legacy workplans / 13 | Preferred /workplans routes and workplan_id parameters |
Workstream REST handlers return 410 and meter rejected calls. Task query alias still accepted | Seven legacy meter records remain after today's two SBOM retirements; observe volume-scaled quiet periods and complete T07 attribution |
| E3 UI feedback / 1 | State Hub until cutover | Feedback still needed during transition | T06 zero-normal-traffic gate; do not confuse it with retired suggestions |
| E4 meter / 9 | State Hub until all other retirement evidence complete | Eight retired / seven legacy interfaces, zero current candidates after September 5 action | Retire last, after the remaining interfaces and final evidence are closed |
What today's probes establish
- Central health identifies
primary/railiance01. - The live State Hub configuration has
SBOM_NEXUS_READ_MODE=nexusandSBOM_NEXUS_WRITE_MODE=nexus, using the cluster SBOM Nexus service. - Direct Nexus
/sbom/report/licences/and/sbom/snapshots/returned 200 from the State Hub pod. Their State Hub meter entries are now retired. This does not delete the compatibility handlers or historical data. - The earlier literal-prefix probe missed existing native messaging, event and projection ports. The bounded inbox projection now has live parity evidence. Scoped NetworkPolicy admission resolved State Hub-to-candidate transport; unauthenticated requests from the source pod now reach the 401 boundary.
- Session trace identifies ad-hoc legacy task reads in fluid-telegram and ops-warden. Their corrected canonical queries return 200 with 8 and 5 tasks. No evidence identifies the other historical callers yet.
Evidence: docs/evidence/STATE-WP-0079-sbom-retirement-20260905.json and
docs/evidence/STATE-WP-0079-caller-and-receiver-review-20260905.md.
Next executable work
- T07: observe the remaining legacy readers with component attribution. The known caller repositories and bundled State Hub skill now prescribe canonical reads. Preserve the quiet clocks; do not exercise legacy URLs to test them.
- T09 / HUB-WP-0011: establish monotonic freshness and stale-source behavior,
caller-specific credentials and canonical/alias scope before one production
inbox reader switch. T08's frozen snapshot parity and rollback are complete;
see
docs/evidence/statehub-inbox-pilot-20260905.mdand JSON receipt. - RAIL-FAB-WP-0028-T01 remains the owner decision for runtime, persistent store, auth, backup/restore and deployment repository. Its T02–T04 deliver deployment, freshness and final direct-consumer receipts; no new Fabric authority here.
- Re-evaluate eligible interfaces from a fresh seven-day meter capture. The quiet ladder is 7 days for 1–99 historical calls, 30 for 100–9,999, and 60 for 10,000+. A new call restarts the relevant clock, including rejected requests.
Freeze and infrastructure boundary
T06 remains blocked until move/replace families and legacy retirement complete, followed by a fresh zero-normal-read/write window. Final dump, restore proof, service stop and repository archive then form one separately reviewable operation. The original schema-history/keep items and nine infrastructure couplings (database, scheduler, connectivity) remain explicit final-window checks; they are not route flags. Ops Bridge connectivity survives retirement.