Hand off credential-renewal scheduling demand to capacity review
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
codex 2026-09-14 03:46:30 +02:00
parent 8134847ef9
commit 8841395b2e

View file

@ -196,3 +196,16 @@ assessment has produced its retained report and owner receipt, missed-run
handling is demonstrated, and ownership for the ongoing weekly operation is handling is demonstrated, and ownership for the ongoing weekly operation is
registered before this workplan finishes. Hand off residual recommendations as registered before this workplan finishes. Hand off residual recommendations as
live records; the recurring assessment continues after this plan is finished. live records; the recurring assessment continues after this plan is finished.
### Scheduling evidence / live handoff for T01 — 2026-09-14
During SECRETS-WP-0010-T03, repeated `sso/keycape-factor-renewer` Jobs requesting
10m CPU failed scheduling at full requested CPU. The provider credential expired
and KeyCape lost readiness, blocking operator authentication. Informed Decision
used 1m CPU; reducing its request from 20m to 5m (limit remains 500m) freed 15m.
Scheduled Job keycape-factor-renewer-29822490 completed and self-revoked, ESO
updated the mounted credential, and KeyCape recovered. This is immediate recovery,
not a fleet sizing conclusion. T01 must include recurring maintenance-job demand
and reliable scheduling headroom, not only resident pod allocations. Evidence:
informed-decision/docs/evidence/2026-09-14-keycape-renewal-capacity-recovery.json.