# Custodian intake records ## CUST-IN-0011 — Provision a monitored external security-report Contact URI ```yaml id: CUST-IN-0011 kind: intake title: "Provision a monitored external security-report Contact URI" status: routed lane: red priority: high owner: policy-nexus tags: [compliance-relevant] origin: residual origin_ref: CUST-WP-0063 selected_contact_uri: "https://security.coulomb.social/" updated: "2026-08-23" notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Acceptance check 2026-08-23: security.coulomb.social resolves to 217.160.0.212 and aborts TLS with alert internal_error, while the governed Policy Nexus ingress at policy.coulomb.social resolves to 92.205.62.239 and its current package grants only that hostname. The private receipt mechanism is also not yet defined. Initial blocker message: a111b97c. Exact DNS/admission/package handoffs: railiance-apps fb32adf5 and rapp-policy-nexus 93acef37. Do not move DNS or publish security.txt until the production host grant, certificate/ingress, monitored receipt path, and private report-to-Risk-Nexus proof are complete." state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689" ``` ## CUST-IN-0012 — Repair the malformed legacy inbox message identity ```yaml id: CUST-IN-0012 kind: intake title: "Repair the malformed legacy inbox message identity" status: closed lane: green priority: low owner: hub-core origin: residual origin_ref: CUST-WP-0063 updated: "2026-08-23" notes: "Closed 2026-08-23. State Hub now exposes the preserved risk-nexus message with valid stable id 0b8dd0bf-41d1-47da-96ac-40e443c32e47. PATCH /messages/{id}/read succeeded through the supported API, preserving its body and original 2026-08-20 chronology; the Custodian unread inbox is empty. No direct database mutation was used." state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a" ``` ## CUST-IN-0013 — Enforce durable SBOM catch-up operation idempotency ```yaml id: CUST-IN-0013 kind: intake title: "Enforce durable SBOM catch-up operation idempotency" status: closed outcome: absorbed lane: blue priority: high owner: sbom-nexus origin: residual origin_ref: CUST-WP-0062 notes: "Activity Core completed ACTIVITY-WP-0033 and now sends a stable Idempotency-Key plus X-Activity-Core-Operation-ID for each workflow-run/repository pair. SBOM Nexus durably enforces that identity on both POST /sbom/{slug}/ingest and POST /sbom/{slug}/skip and replays the original terminal response. Live attended evidence on 2026-08-23 returned the same snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be for two requests with the same operation key and exact source reference. Scheduled Activity Core proof remains under CUST-WP-0064. Source handoff: State Hub message bc5caa49-25eb-4942-9deb-411b6080d0bb." state_hub_intake_id: "01a02b44-89a9-7e94-820b-3d86340117ff" ``` ## CUST-IN-0014 — Stop SBOM Nexus restarts on database lease rotation ```yaml id: CUST-IN-0014 kind: intake title: "Stop SBOM Nexus restarts on database lease rotation" status: closed outcome: absorbed lane: blue priority: high owner: sbom-nexus origin: residual origin_ref: CUST-WP-0062 notes: "Live review after cutover found the Ready SBOM Nexus pod at restartCount 9 in under five hours. The last container ran exactly 30 minutes, then readiness/liveness returned HTTP 500 because PostgreSQL rejected the expired v-token-sbom-nex-* credential; Kubernetes restarted the process and it recovered. The corrected runtime deployed on 2026-08-23 rereads the mounted URL for every new connection, recycles the pool every five minutes, keeps credentials out of the engine URL, and separates process liveness from database readiness. Completion evidence at 2026-08-22T23:06:19Z exceeded the old failure point with 30m51s on one pod UID across repeated mounted Secret refreshes: Ready, restart count zero, process/database/repository checks passing, zero health 500s, and zero credential-pattern log matches. Absorbed by finished SBOM-WP-0004 and RAPP-SBOM-NEXUS-WP-0003." state_hub_intake_id: "01a02e28-3beb-764a-b4fc-c34cdf59a01e" ``` ## CUST-IN-0015 — Restore source-ref projection on later SBOM catch-up batches ```yaml id: CUST-IN-0015 kind: intake title: "Restore source-ref projection on later SBOM catch-up batches" status: open lane: blue priority: high owner: repo-manager tags: [sbom, catch-up] origin: residual origin_ref: CUST-WP-0064 updated: "2026-08-28" notes: "CUST-WP-0064-T04 is met: the 2026-08-24 07:15 UTC unassisted fire ingested clay-borg (snapshot 63abb22f, forgejo-archive-v1, revision 18c57f2e, 77 entries) and wrote truthful no-manifest terminals for citation-work and config-atlas at pinned SHAs. From 2026-08-25 through 2026-08-28 the same weekday schedule writes three no-checkout snapshots each day (feature-control / evidence-source / evidence-binder on 2026-08-28). never_count is 76. Diagnose why Repo Manager source-ref projection followed the 2026-08-24 batch and not later ones; do not widen catch_up_limit while diagnosing. SBOM Nexus and Activity Core are counterparties, not a second owner." state_hub_intake_id: "01a049a5-4599-740c-a148-e40e5695c7b5" ``` ## CUST-IN-0016 — Complete deferred ADR metadata and conflict rulings ```yaml id: CUST-IN-0016 kind: intake title: "Complete deferred ADR metadata and conflict rulings" status: open lane: green priority: medium owner: the-custodian origin: residual origin_ref: PNEX-WP-0003 updated: "2026-08-31" notes: >- PNEX-WP-0003 produced a reviewed 162-source ledger and a first release batch of 60 explicit publications. Thirty-five additional publish rulings still depended on publication metadata in their owning repositories; five conflict rows still require owner rulings. On 2026-08-31 the Custodian reviewed the first bounded owner slice: Autonomy Lanes, Contribution Convention, Project Repository Flavor, Work Record Types, and Workplan Terminology are approved for publication with accepted-1 metadata. The two constitution sources remain out of the public batch because they declare sensitivity: internal; Bootstrap Protocol also contains internal financial/legal formation detail. Repo Classification remains deferred because its body says Draft v1.0 while its front-matter says active. SBOM Convention remains deferred for a freshness review against the newer SBOM Nexus authority model. Coordinate the remaining owner responses from policy-nexus/docs/adr-review/ledger.json, rulings.json, conflicts.md, and the per-repo cleanup packets. When a coherent set becomes ready, hand it to Policy Nexus as a new bounded publication batch. Do not reopen PNEX-WP-0003 for individual late returns, and do not let Policy Nexus rewrite owner-controlled ADR bodies. Seven unpublished superseded records remain excluded history unless a stable historical URL is later required. ```