the-custodian/intakes.md

130 lines
7.3 KiB
Markdown
Raw Permalink Normal View History

# Custodian intake records
## CUST-IN-0011 — Provision a monitored external security-report Contact URI
```yaml
id: CUST-IN-0011
kind: intake
title: "Provision a monitored external security-report Contact URI"
status: routed
lane: red
priority: high
owner: policy-nexus
tags: [compliance-relevant]
origin: residual
origin_ref: CUST-WP-0063
selected_contact_uri: "https://security.coulomb.social/"
updated: "2026-08-23"
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Acceptance check 2026-08-23: security.coulomb.social resolves to 217.160.0.212 and aborts TLS with alert internal_error, while the governed Policy Nexus ingress at policy.coulomb.social resolves to 92.205.62.239 and its current package grants only that hostname. The private receipt mechanism is also not yet defined. Initial blocker message: a111b97c. Exact DNS/admission/package handoffs: railiance-apps fb32adf5 and rapp-policy-nexus 93acef37. Do not move DNS or publish security.txt until the production host grant, certificate/ingress, monitored receipt path, and private report-to-Risk-Nexus proof are complete."
state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
```
## CUST-IN-0012 — Repair the malformed legacy inbox message identity
```yaml
id: CUST-IN-0012
kind: intake
title: "Repair the malformed legacy inbox message identity"
status: closed
lane: green
priority: low
owner: hub-core
origin: residual
origin_ref: CUST-WP-0063
updated: "2026-08-23"
notes: "Closed 2026-08-23. State Hub now exposes the preserved risk-nexus message with valid stable id 0b8dd0bf-41d1-47da-96ac-40e443c32e47. PATCH /messages/{id}/read succeeded through the supported API, preserving its body and original 2026-08-20 chronology; the Custodian unread inbox is empty. No direct database mutation was used."
state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a"
```
## CUST-IN-0013 — Enforce durable SBOM catch-up operation idempotency
```yaml
id: CUST-IN-0013
kind: intake
title: "Enforce durable SBOM catch-up operation idempotency"
status: closed
outcome: absorbed
lane: blue
priority: high
owner: sbom-nexus
origin: residual
origin_ref: CUST-WP-0062
notes: "Activity Core completed ACTIVITY-WP-0033 and now sends a stable Idempotency-Key plus X-Activity-Core-Operation-ID for each workflow-run/repository pair. SBOM Nexus durably enforces that identity on both POST /sbom/{slug}/ingest and POST /sbom/{slug}/skip and replays the original terminal response. Live attended evidence on 2026-08-23 returned the same snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be for two requests with the same operation key and exact source reference. Scheduled Activity Core proof remains under CUST-WP-0064. Source handoff: State Hub message bc5caa49-25eb-4942-9deb-411b6080d0bb."
state_hub_intake_id: "01a02b44-89a9-7e94-820b-3d86340117ff"
```
## CUST-IN-0014 — Stop SBOM Nexus restarts on database lease rotation
```yaml
id: CUST-IN-0014
kind: intake
title: "Stop SBOM Nexus restarts on database lease rotation"
status: closed
outcome: absorbed
lane: blue
priority: high
owner: sbom-nexus
origin: residual
origin_ref: CUST-WP-0062
notes: "Live review after cutover found the Ready SBOM Nexus pod at restartCount 9 in under five hours. The last container ran exactly 30 minutes, then readiness/liveness returned HTTP 500 because PostgreSQL rejected the expired v-token-sbom-nex-* credential; Kubernetes restarted the process and it recovered. The corrected runtime deployed on 2026-08-23 rereads the mounted URL for every new connection, recycles the pool every five minutes, keeps credentials out of the engine URL, and separates process liveness from database readiness. Completion evidence at 2026-08-22T23:06:19Z exceeded the old failure point with 30m51s on one pod UID across repeated mounted Secret refreshes: Ready, restart count zero, process/database/repository checks passing, zero health 500s, and zero credential-pattern log matches. Absorbed by finished SBOM-WP-0004 and RAPP-SBOM-NEXUS-WP-0003."
state_hub_intake_id: "01a02e28-3beb-764a-b4fc-c34cdf59a01e"
```
## CUST-IN-0015 — Restore source-ref projection on later SBOM catch-up batches
```yaml
id: CUST-IN-0015
kind: intake
title: "Restore source-ref projection on later SBOM catch-up batches"
status: open
lane: blue
priority: high
owner: repo-manager
tags: [sbom, catch-up]
origin: residual
origin_ref: CUST-WP-0064
updated: "2026-08-28"
notes: "CUST-WP-0064-T04 is met: the 2026-08-24 07:15 UTC unassisted fire ingested clay-borg (snapshot 63abb22f, forgejo-archive-v1, revision 18c57f2e, 77 entries) and wrote truthful no-manifest terminals for citation-work and config-atlas at pinned SHAs. From 2026-08-25 through 2026-08-28 the same weekday schedule writes three no-checkout snapshots each day (feature-control / evidence-source / evidence-binder on 2026-08-28). never_count is 76. Diagnose why Repo Manager source-ref projection followed the 2026-08-24 batch and not later ones; do not widen catch_up_limit while diagnosing. SBOM Nexus and Activity Core are counterparties, not a second owner."
state_hub_intake_id: "01a049a5-4599-740c-a148-e40e5695c7b5"
```
2026-08-31 21:23:31 +02:00
## CUST-IN-0016 — Complete deferred ADR metadata and conflict rulings
```yaml
id: CUST-IN-0016
kind: intake
title: "Complete deferred ADR metadata and conflict rulings"
status: open
lane: green
priority: medium
owner: the-custodian
origin: residual
origin_ref: PNEX-WP-0003
updated: "2026-08-31"
notes: >-
PNEX-WP-0003 produced a reviewed 162-source ledger and a first release batch
of 60 explicit publications. Thirty-five additional publish rulings still
depended on publication metadata in their owning repositories; five conflict
rows still require owner rulings. On 2026-08-31 the Custodian reviewed the
first bounded owner slice: Autonomy Lanes, Contribution Convention, Project
Repository Flavor, Work Record Types, and Workplan Terminology are approved
for publication with accepted-1 metadata. The two constitution sources
remain out of the public batch because they declare sensitivity: internal;
Bootstrap Protocol also contains internal financial/legal formation detail.
Repo Classification remains deferred because its body says Draft v1.0 while
its front-matter says active. SBOM Convention remains deferred for a
freshness review against the newer SBOM Nexus authority model. Coordinate
the remaining owner responses from policy-nexus/docs/adr-review/ledger.json,
rulings.json, conflicts.md, and the per-repo cleanup packets. When a coherent
set becomes ready, hand it to Policy Nexus as a new bounded publication
batch. Do not reopen PNEX-WP-0003 for individual late returns, and do not let
Policy Nexus rewrite owner-controlled ADR bodies. Seven unpublished
superseded records remain excluded history unless a stable historical URL
is later required. PNEX-WP-0004 completed the first return on 2026-08-31:
the five approved fleet standards are live in the 65-document release at
current and immutable accepted-1 addresses. Twenty-eight publish rulings
remain (26 in other owner repos and two Custodian substantive reviews), plus
the five conflict rows. CCR-2026-0014 separately tracks a least-privilege
Forgejo source-read token for scheduled Policy Nexus builds.
2026-08-31 21:23:31 +02:00
```