target-revenue/workplans/TREV-WP-0008-governance-and-pilot-rollout.md
custodian-sync f56d82f09a chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-05:
  - update .custodian-brief.md for target-revenue
2026-08-05 15:59:58 +02:00

263 lines
13 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: TREV-WP-0008
type: workplan
title: "Governance formalization and pilot rollout (coulomb / net-kingdom / helix-forge / railiance)"
domain: infotech
repo: target-revenue
status: finished
owner: claude
topic_slug: infotech
created: "2026-07-29"
updated: "2026-08-05"
state_hub_workstream_id: "b46a30e8-8ef6-44f7-96af-a098cb4084b4"
---
# Governance formalization and pilot rollout
The midterm goal: govern and monetize the evolution of repos across the
`coulomb` Forgejo org's product lines — `coulomb-loop`, `net-kingdom`,
`helix-forge`, and the `railiance-*` family (`railiance-apps`,
`railiance-bootstrap`, `railiance-cluster`, `railiance-enablement`,
`railiance-fabric`, `railiance-forge`, `railiance-hosts`, `railiance-infra`,
`railiance-master`, `railiance-platform`). This workplan formalizes the
governance the framework has been designed around but never actually
written down, and prepares (but does not itself execute) the first real
Phase declarations.
**Hard gate, stated up front:** `SCOPE.md` §3 lists "governing third-party
product Phases in production" as out of scope "after legal + Stage 0
package ready" — i.e., not yet. This workplan's rollout tasks (T03T04)
produce **draft, non-binding** Phase Manifests as worked examples, exactly
like `examples/phase-001/` already is. **No real Commercial Entitlement may
be sold, no real Development Credit tracked, and no repo's actual License
header changed to TRSL, until T05 (the go-live gate) is explicitly
accepted** — after TRSL/CUA specialist legal review (`workplans/TREV-WP-0004-global-jurisdiction-research.md` /
`workplans/TREV-WP-0005-enforcement-network-research.md` T10 syntheses
feed this) and T01 (Licensor governance) are both resolved. Moving fast on
T01T04 must not create pressure to skip T05.
## Governance document: TRSL-Governance.md
```task
id: TREV-WP-0008-T01
status: done
priority: high
state_hub_task_id: "bae630d7-907b-4eb4-bad4-d72803ccbd33"
```
Produce `specs/TRSL-Governance.md`, per `spec/TargetRevenueLicenseConcept.md`
§20 (complexity budget, versioning, extension governance, operator
governance). Must resolve one question this rollout makes concretely
unavoidable for the first time: **who is "the Licensor"** across four
different product lines under one Forgejo org — a single shared Licensor
entity for all four (simplest, but conflates genuinely different products'
commercial decisions), or a per-product-line Licensor (each of
`coulomb-loop`, `net-kingdom`, `helix-forge`, `railiance` declaring its own
Phases independently under a shared TRSL/CUA template)? This was never
forced while the framework was single-repo-hypothetical; it is now.
Also define: change process for the License/CUA templates themselves once
multiple product lines depend on them, extension canonicalization review
(coordinate with `workplans/TREV-WP-0007-degeneration-policy-and-canonical-profiles.md`
T04's narrower checklist), and dispute/conflict-of-interest handling per
concept §20.3§20.4.
**Result:** `specs/TRSL-Governance.md` produced. **Licensor identity
resolved (maintainer decision, 2026-07-29): a single shared Licensor,
Binky Hedgehog GmbH, operating as the `binky` tenant**, across all four
product lines — not per-product-line. This unblocks (but does not itself
resolve) the License §11.1/CUA §18 arbitral-institution/governing-law
template blank, now that the Licensor's own jurisdiction (Germany) is
known. Documents versioning (already implemented across every layer
§20.2 names — URN `@version` suffixes, document headers, ADRs) and
extension governance status (registration/conformance implemented;
canonicalization checklist implemented via WP-0007-T04; compatibility,
deprecation, and conflict-of-interest rules **not yet defined** — named as
open items, not silently assumed). Operator governance (§20.4) tabulated
against the actual hosted Trust Service instance: signing-key disclosure
and public verification already implemented (WP-0006); key-rotation
history publication, a Trust-Service-specific terms-of-service document,
and an extension-specific dispute procedure are flagged as open, not
blocking T02T04 but named so T05's go-live gate can weigh them
explicitly.
## Repo inventory and Phase-candidate survey
```task
id: TREV-WP-0008-T02
status: done
priority: high
state_hub_task_id: "4f4f4922-4bc6-4ff9-a408-b836287186db"
```
For each of `coulomb-loop`, `net-kingdom`, `helix-forge`, and the
`railiance-*` family: survey current repo goals and status (via the state
hub's `get_domain_summary`/`list_domain_repos`/repo-goal tools, or direct
repo inspection where hub data is thin) to identify one plausible first
Milestone Release candidate per product line — a bounded, recently- or
soon-to-be-completed piece of work with a defensible Target Multiple
classification (`specs/TargetRevenueFrameworkCore.md` §1.4), not an
arbitrary pick. Document why each candidate was chosen and what was
passed over.
**Result:** `specs/PilotPhaseCandidateSurvey.md` produced. State hub
`get_repo_goals` returned no data for `coulomb-loop`/`net-kingdom`/
`helix-forge`, so this used direct repo inspection instead (per the
task's own fallback), including an Explore-agent survey of all ten
`railiance-*` repos. Findings: **`coulomb-loop`** — no candidate;
SCOPE.md explicitly excludes product application code. **`net-kingdom`**
`NK-WP-0002` Local Identity (finished 2026-03-05), Incremental (10x);
passed over the deferred/superseded `NK-WP-0001` Keycloak plan and two
real-but-internal-ops-hardening finished workplans (`NET-WP-0020`,
`NK-WP-0021`). **`helix-forge`** — no candidate; its own SCOPE.md states
"it is not yet an application implementation." **`railiance-*`** —
`vergabe-teilnahme` (`RAILIANCE-WP-0002`/`-0014`, finished 2026-05-19 /
2026-07-11), a production Django app for German public-tender
participation, Product-defining (100x); the only genuinely product-shaped
deliverable across all ten repos, passing over nine repos' worth of
internal infrastructure (cluster substrate, CI/CD, secrets platform,
architecture taxonomy, etc.). Two of four product lines have a defensible
candidate; two do not, for stated principled reasons, feeding T03.
## Draft pilot Phase Manifests (non-binding worked examples)
```task
id: TREV-WP-0008-T03
status: done
priority: high
state_hub_task_id: "942943ae-14a2-4f23-888e-6084aa9c6024"
```
Using T02's candidates, draft one Phase Manifest per product line
following `specs/PhaseManifestSpecification.md` and
`schemas/phase_manifest.schema.json` exactly — structurally valid,
conformance-tested the same way `examples/phase-001/` is, but explicitly
marked **draft / not yet declared** (no real Commercial Use restriction
takes effect from these). Choose an applicable Monetization Extension per
Phase from `workplans/TREV-WP-0007-degeneration-policy-and-canonical-profiles.md`
T03's catalog.
**Result:** `examples/pilot-candidates/` produced, for T02's two real
candidates only (`coulomb-loop`/`helix-forge` had none). Each manifest
uses a `trsl:phase:draft-*` id specifically so it cannot be confused with
a declared Phase, an empty `ledger.json`, and validates cleanly against
`schemas/phase_manifest.schema.json`
(`tests/test_pilot_candidate_manifests.py`, 4 tests). **NetKingdom Local
Identity** (`NK-WP-0002`): 200,000 EUR Initial Target (Incremental 10x),
`development-license` extension, `future_license: MIT`. **Railiance
vergabe-teilnahme**: 3,500,000 EUR Initial Target (Product-defining
100x), `development-license` + `cost-plus-operations` extensions
(reflecting its actual hosted-application delivery model), `future_license:
Apache-2.0`. Both reference the real commit each Milestone Release
finished at (`3890dca`, `398b0fe`) for traceability. A top-level
`examples/pilot-candidates/README.md` states plainly that no Commercial
Entitlement is for sale, no Development Credit is tracked, and neither
repo's actual License header has changed — nothing here is authorized to
go live regardless of how complete it looks (T05 still gates that).
**Addendum, 2026-07-29:** the maintainer separately chose `info-tech-canon`
(outside the original four product lines) as the actual first repo to
build up the practical Phase-declaration routine on — **explicitly
confirmed as a dry run, not a T05 go-live decision.** A third draft
manifest, `examples/pilot-candidates/info-tech-canon-service-surface/`,
was added (candidate: the cumulative service surface across
`ITC-WP-0001``ITC-WP-0012`, all finished; Product-defining 100x;
`specs/PilotPhaseCandidateSurvey.md` §4a). Notable complication surfaced
and flagged rather than smoothed over: this repo's current `LICENSE` is
already MIT-0 — a real Phase here would mean *replacing* an already-open
license with restricted pre-conversion TRSL terms, a materially different
and more visible step than the other two candidates. The full onboarding
routine (`scripts/trf_onboard.py register-phase``append-entry`
`status`) was exercised end-to-end against a real, ephemeral local
instance of the hosted Trust Service (Docker Postgres, migrations
00010004 applied, `binky` Licensor token seeded, `uvicorn` running the
actual `service/app.py`) — register, a 10,000 EUR illustrative
development-credit entry, and a status check all worked exactly as
`specs/TrustServiceOnboarding.md` describes, with no code changes needed.
The dry-run Postgres container and service process were both torn down
afterward; nothing from this exercise persists beyond the draft manifest
files themselves.
## Contributor rights instrument (CLA)
```task
id: TREV-WP-0008-T04
status: done
priority: medium
state_hub_task_id: "666a800b-96a7-4664-9448-24af989b57c5"
```
`CONTRIBUTING.md` currently blocks external contributions into any
governed Milestone Release until a contributor-rights instrument exists
(per `history/260729-TRSL-ContributorRights-Research.md`). If any pilot
candidate from T02 has, or expects, external contributors before its
Conversion Event, this is now practically blocking, not theoretical.
Produce `specs/TRSL-ContributorLicenseAgreement-Draft.md`: a CLA scoped
narrowly to the current Phase's TRSL terms plus its already-declared
Future License, per the T04 research's recommendation. Same preliminary-
candidate treatment as the License/CUA V1C1 documents (status banner,
Appendix A-style candidate notes) — this is a new legal document, not
exempt from that pattern.
**Result:** `specs/TRSL-ContributorLicenseAgreement-Draft.md` produced,
implementing the research's CLA-not-assignment recommendation. §2 grants
rights under the current Phase's TRSL terms; §3 is the clause the
research flagged as the actual gap a plain DCO leaves open — an
irrevocable grant to relicense the Contribution under the Phase's
**already-declared** Future License at Conversion, deliberately narrow
(scoped to the one Future License fixed at the time of submission, not
"any future license"). §4 patent grant modeled on the Apache CLA pattern
with the litigation-termination clause deliberately omitted, flagged
Appendix A item 1 rather than guessed at. Same preliminary-candidate
status banner and Appendix A pattern as the License/CUA V1C1 documents;
governing law (§9) matches their alpha/beta arbitration default, now
citing the resolved Licensor jurisdiction from `specs/TRSL-Governance.md`
§1. `CONTRIBUTING.md` updated to point at this draft while keeping the
external-contribution block in effect until it is actually accepted, not
merely drafted.
## Go-live gate (human decision)
```task
id: TREV-WP-0008-T05
status: done
priority: high
human_accept_required: true
human_accepted_by: Bernd
human_accepted_at: "2026-08-05"
state_hub_task_id: "af688189-8151-4170-925f-b3c4806a68ed"
```
**Go-live gate — accepted 2026-08-05.** Full decision record:
`history/260805-T05-GoLive-info-tech-canon.md`.
**First real Phase (named by this acceptance):**
| | |
| --- | --- |
| Repo | `coulomb/info-tech-canon` (Forgejo id 47) |
| Phase id | `trsl:phase:info-tech-canon-service-surface` |
| Manifest (repo) | `info-tech-canon/trf/phase-service-surface.json` |
| Initial Target | 141,800 EUR |
| Future License | MIT |
| Longstop | 2029-01-01T00:00:00Z |
| Policy | `trsl:policy:linear-longstop-v0@1.0` |
**Pilot scope of the alpha/beta legal waiver (explicitly confirmed at
acceptance):** this Phase only under Binky Hedgehog GmbH / `binky`;
TRSL/CUA V1C1 as preliminary candidates under the 2026-07-29 jurisdiction
and Enforcement Network alpha/beta defaults; CLA still draft (external
contributions remain blocked); no other product line authorized by this
single acceptance.
**Trust Service at go-live:** registered on the local pilot instance
`http://127.0.0.1:8765` (Postgres `trf-pilot-pg` / volume
`trf-pilot-pgdata`) because WP-0011's public reef deployment was not yet
available. Git-committed Manifest is the durable declaration;
ledger/metrics are live on that pilot instance pending migration to a
public Trust Service when WP-0011 lands.
**Prior sub-decision (2026-07-30), superseded for Phase-declaration
status only:** org-wide TRSL LICENSE text adoption
(`history/260730-TRSL-OrgWideLicenseRollout.md`) remains a separate,
earlier act — it did not by itself declare any Phase. As of this T05
acceptance, one Phase is declared as above.