From 693f7f1962d3d1b3ee2f563cd0cb6d8e3f85a979 Mon Sep 17 00:00:00 2001 From: codex Date: Mon, 28 Sep 2026 20:25:41 +0200 Subject: [PATCH] Block CUST-WP-0071 and CUST-WP-0073 pending cross-repo requirements Remaining tasks wait on GLAS-WP-0012, RAPPS-WP-0014-T03 and platform/infra/warden owners; requirement tables added to both workplans. Co-Authored-By: Claude Sonnet 5.5 --- WORK-RECORDS.md | 12 ++++----- ...sured-workload-sizing-and-weekly-review.md | 23 +++++++++++++--- ...UST-WP-0073-agent-credential-separation.md | 26 ++++++++++++++++--- 3 files changed, 49 insertions(+), 12 deletions(-) diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 2be68ab..00ebbdd 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -71,9 +71,9 @@ | workplan | CUST-WP-0067 | finished | — | workplans/CUST-WP-0067-hub-authority-target-resolution.md | | workplan | CUST-WP-0068 | finished | — | workplans/CUST-WP-0068-cache-only-work-record-recovery.md | | workplan | CUST-WP-0070 | finished | — | workplans/CUST-WP-0070-publication-repo-category.md | -| workplan | CUST-WP-0071 | active | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | +| workplan | CUST-WP-0071 | blocked | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | | workplan | CUST-WP-0072 | finished | — | workplans/CUST-WP-0072-fleet-flavor-and-depends-on-backfill.md | -| workplan | CUST-WP-0073 | active | — | workplans/CUST-WP-0073-agent-credential-separation.md | +| workplan | CUST-WP-0073 | blocked | — | workplans/CUST-WP-0073-agent-credential-separation.md | | workplan | THE-WP-0001 | finished | — | workplans/THE-WP-0001-federation-interface.md | | task | CUST-WP-ADHOC-2026-05-02-T01 | done | — | workplans/ADHOC-2026-05-02.md | | task | CUST-WP-ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md | @@ -455,8 +455,8 @@ | task | CUST-WP-0070-T02 | done | — | workplans/CUST-WP-0070-publication-repo-category.md | | task | CUST-WP-0070-T03 | done | — | workplans/CUST-WP-0070-publication-repo-category.md | | task | CUST-WP-0071-T01 | done | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | -| task | CUST-WP-0071-T02 | progress | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | -| task | CUST-WP-0071-T03 | progress | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | +| task | CUST-WP-0071-T02 | wait | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | +| task | CUST-WP-0071-T03 | wait | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | | task | CUST-WP-0071-T04 | wait | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | | task | CUST-WP-0071-T05 | wait | — | workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md | | task | CUST-WP-0072-T01 | done | — | workplans/CUST-WP-0072-fleet-flavor-and-depends-on-backfill.md | @@ -464,9 +464,9 @@ | task | CUST-WP-0072-T03 | done | — | workplans/CUST-WP-0072-fleet-flavor-and-depends-on-backfill.md | | task | CUST-WP-0072-T04 | done | — | workplans/CUST-WP-0072-fleet-flavor-and-depends-on-backfill.md | | task | CUST-WP-0073-T01 | done | — | workplans/CUST-WP-0073-agent-credential-separation.md | -| task | CUST-WP-0073-T02 | progress | — | workplans/CUST-WP-0073-agent-credential-separation.md | +| task | CUST-WP-0073-T02 | wait | — | workplans/CUST-WP-0073-agent-credential-separation.md | | task | CUST-WP-0073-T03 | done | — | workplans/CUST-WP-0073-agent-credential-separation.md | -| task | CUST-WP-0073-T04 | progress | — | workplans/CUST-WP-0073-agent-credential-separation.md | +| task | CUST-WP-0073-T04 | wait | — | workplans/CUST-WP-0073-agent-credential-separation.md | | task | CUST-WP-0073-T05 | wait | — | workplans/CUST-WP-0073-agent-credential-separation.md | | task | THE-WP-0001-T01 | done | — | workplans/THE-WP-0001-federation-interface.md | | task | THE-WP-0001-T02 | done | — | workplans/THE-WP-0001-federation-interface.md | diff --git a/workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md b/workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md index 397ca71..0851a06 100644 --- a/workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md +++ b/workplans/CUST-WP-0071-measured-workload-sizing-and-weekly-review.md @@ -4,7 +4,7 @@ type: workplan title: "Size Railiance workloads from actual demand and establish a weekly allocation review" domain: infotech repo: the-custodian -status: active +status: blocked flavor: planning owner: the-custodian topic_slug: custodian @@ -94,10 +94,11 @@ updated reef-railiance-k3s owner evidence. ```task id: CUST-WP-0071-T02 -status: progress +status: wait priority: high assignee: the-custodian depends_on: [CUST-WP-0071-T01] +blocking_reason: "Await RAPPS-WP-0014-T03 (blocked, needs_human): populated two-user/document workflow run by Bernd and the company contact, giving representative load for p95 <= 2s / zero failures." state_hub_task_id: "82192370-2fd7-5363-88d2-3c67889d3d68" ``` @@ -122,10 +123,11 @@ pilot sample provisional. A successful smoke test alone is not sizing proof. ```task id: CUST-WP-0071-T03 -status: progress +status: wait priority: high assignee: the-custodian depends_on: [CUST-WP-0071-T01, CUST-WP-0071-T02] +blocking_reason: "Await CUST-WP-0071-T02 representative sample; Forgejo/runner demand and zero-request workload review need owner input (railiance-cluster, railiance-forge, resource-control)." state_hub_task_id: "6dc67558-eb1e-5bb6-a667-986f884dd495" ``` @@ -258,3 +260,18 @@ zero-failed-operations target (document transfer excluded from that latency threshold). The current seven-day telemetry remains provisional until the representative workflow runs. This is an acceptance criterion, not a claim that it has passed. Keep the run and its evidence under existing T02. + +## Blocked — requirements on other repos (2026-09-28) + +The bounded review is complete: T01 done, seven-day telemetry recorded, and the +provisional keep decision (60m/256Mi) is evidenced. No further step is +implementable here; workplan set to `blocked`. Requirements: + +| Owner | Requirement | Gates | +|-------|-------------|-------| +| railiance-apps (RAPPS-WP-0014-T03, needs_human) | Two-user/document acceptance run on the deployed pilot with Bernd and the company contact | T02 | +| vergabe-teilnahme (VERGABE-WP-0019, blocked) | Release/tenant assumptions and fixture for the representative run | T02 | +| resource-control, railiance-cluster, railiance-forge | Owner review of Forgejo/runner demand (namespace CPU p95 1454m) and twelve zero-request workloads | T03 | +| activity-core | Durable weekly schedule (Mon 08:00 Europe/Berlin), retained report, owner receipt, missed-run handling | T05 (after T04) | + +Resume when RAPPS-WP-0014-T03 records the acceptance run; T03 → T04 → T05 follow. diff --git a/workplans/CUST-WP-0073-agent-credential-separation.md b/workplans/CUST-WP-0073-agent-credential-separation.md index 373f66a..b3c6269 100644 --- a/workplans/CUST-WP-0073-agent-credential-separation.md +++ b/workplans/CUST-WP-0073-agent-credential-separation.md @@ -4,7 +4,7 @@ type: workplan title: "Separate agent credentials and establish supervised privileged execution" domain: infotech repo: the-custodian -status: active +status: blocked owner: the-custodian topic_slug: custodian flavor: implementation @@ -84,8 +84,9 @@ limits or authorization of a live cutover. Existing human-only lanes still apply ```task id: CUST-WP-0073-T02 -status: progress +status: wait priority: high +blocking_reason: "Await GLAS-WP-0012 (glas-harness) production acceptance of the local supervised profile; then railiance-platform RBAC, railiance-enablement k3s config, railiance-infra principal mapping and ops-warden certificate issuance." state_hub_task_id: "4b88b0b7-dc7e-5612-aa5d-1a08f0530c35" ``` @@ -146,8 +147,9 @@ drill Secret was deleted with its UID precondition; absence verified and the ```task id: CUST-WP-0073-T04 -status: progress +status: wait priority: medium +blocking_reason: "Await CUST-WP-0073-T02: the verified agent identity and execution path must exist before it can be documented; Codex/Grok read-denial guard needs glas-harness or harness-owner delivery." state_hub_task_id: "90725511-4e31-549f-b567-47feff1a9ca4" ``` @@ -239,3 +241,21 @@ There is no eligible acceptance-rate sample or autopilot grant yet. T05 remains the founder's trigger-based rotation deferral, not cancelled or done. Neither workplan completion nor live credential separation is claimed. + +## Blocked — requirements on other repos (2026-09-28) + +Nothing further is implementable in this repository; T01 and T03 are done and +T04's local guidance is complete. Workplan set to `blocked`. Requirements: + +| Owner | Requirement | Gates | +|-------|-------------|-------| +| glas-harness (GLAS-WP-0012, blocked; T03 progress, T02/T04/T05 wait) | End-to-end production acceptance receipt for the local supervised profile, usable for an interactive agent | T02 | +| railiance-platform | ServiceAccount/cert, ClusterRole and binding in git; no `secrets`/`pods/exec` | T02 | +| railiance-enablement | k3s `write-kubeconfig-mode: 600` in install config | T02 | +| railiance-infra | Host principal mapping; remove unrestricted sudo/admin kubeconfig from the agent account | T02 | +| ops-warden | Certificate issuance for the agent identity | T02 | +| harness owners (Codex/Grok) | Read-denial guard equivalent to the Claude hook, or a recorded statement that none exists | T04 | + +Resume when GLAS-WP-0012 records production acceptance: then T02 proof +(`auth can-i`, whoami, approved/unapproved action, admin-path denial) and T04 +documentation of the verified path. T05 stays trigger-based.