129 lines
7.3 KiB
Markdown
129 lines
7.3 KiB
Markdown
# Custodian intake records
|
|
|
|
## CUST-IN-0011 — Provision a monitored external security-report Contact URI
|
|
|
|
```yaml
|
|
id: CUST-IN-0011
|
|
kind: intake
|
|
title: "Provision a monitored external security-report Contact URI"
|
|
status: routed
|
|
lane: red
|
|
priority: high
|
|
owner: policy-nexus
|
|
tags: [compliance-relevant]
|
|
origin: residual
|
|
origin_ref: CUST-WP-0063
|
|
selected_contact_uri: "https://security.coulomb.social/"
|
|
updated: "2026-08-23"
|
|
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Acceptance check 2026-08-23: security.coulomb.social resolves to 217.160.0.212 and aborts TLS with alert internal_error, while the governed Policy Nexus ingress at policy.coulomb.social resolves to 92.205.62.239 and its current package grants only that hostname. The private receipt mechanism is also not yet defined. Initial blocker message: a111b97c. Exact DNS/admission/package handoffs: railiance-apps fb32adf5 and rapp-policy-nexus 93acef37. Do not move DNS or publish security.txt until the production host grant, certificate/ingress, monitored receipt path, and private report-to-Risk-Nexus proof are complete."
|
|
state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
|
|
```
|
|
|
|
## CUST-IN-0012 — Repair the malformed legacy inbox message identity
|
|
|
|
```yaml
|
|
id: CUST-IN-0012
|
|
kind: intake
|
|
title: "Repair the malformed legacy inbox message identity"
|
|
status: closed
|
|
lane: green
|
|
priority: low
|
|
owner: hub-core
|
|
origin: residual
|
|
origin_ref: CUST-WP-0063
|
|
updated: "2026-08-23"
|
|
notes: "Closed 2026-08-23. State Hub now exposes the preserved risk-nexus message with valid stable id 0b8dd0bf-41d1-47da-96ac-40e443c32e47. PATCH /messages/{id}/read succeeded through the supported API, preserving its body and original 2026-08-20 chronology; the Custodian unread inbox is empty. No direct database mutation was used."
|
|
state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a"
|
|
```
|
|
|
|
## CUST-IN-0013 — Enforce durable SBOM catch-up operation idempotency
|
|
|
|
```yaml
|
|
id: CUST-IN-0013
|
|
kind: intake
|
|
title: "Enforce durable SBOM catch-up operation idempotency"
|
|
status: closed
|
|
outcome: absorbed
|
|
lane: blue
|
|
priority: high
|
|
owner: sbom-nexus
|
|
origin: residual
|
|
origin_ref: CUST-WP-0062
|
|
notes: "Activity Core completed ACTIVITY-WP-0033 and now sends a stable Idempotency-Key plus X-Activity-Core-Operation-ID for each workflow-run/repository pair. SBOM Nexus durably enforces that identity on both POST /sbom/{slug}/ingest and POST /sbom/{slug}/skip and replays the original terminal response. Live attended evidence on 2026-08-23 returned the same snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be for two requests with the same operation key and exact source reference. Scheduled Activity Core proof remains under CUST-WP-0064. Source handoff: State Hub message bc5caa49-25eb-4942-9deb-411b6080d0bb."
|
|
state_hub_intake_id: "01a02b44-89a9-7e94-820b-3d86340117ff"
|
|
```
|
|
|
|
## CUST-IN-0014 — Stop SBOM Nexus restarts on database lease rotation
|
|
|
|
```yaml
|
|
id: CUST-IN-0014
|
|
kind: intake
|
|
title: "Stop SBOM Nexus restarts on database lease rotation"
|
|
status: closed
|
|
outcome: absorbed
|
|
lane: blue
|
|
priority: high
|
|
owner: sbom-nexus
|
|
origin: residual
|
|
origin_ref: CUST-WP-0062
|
|
notes: "Live review after cutover found the Ready SBOM Nexus pod at restartCount 9 in under five hours. The last container ran exactly 30 minutes, then readiness/liveness returned HTTP 500 because PostgreSQL rejected the expired v-token-sbom-nex-* credential; Kubernetes restarted the process and it recovered. The corrected runtime deployed on 2026-08-23 rereads the mounted URL for every new connection, recycles the pool every five minutes, keeps credentials out of the engine URL, and separates process liveness from database readiness. Completion evidence at 2026-08-22T23:06:19Z exceeded the old failure point with 30m51s on one pod UID across repeated mounted Secret refreshes: Ready, restart count zero, process/database/repository checks passing, zero health 500s, and zero credential-pattern log matches. Absorbed by finished SBOM-WP-0004 and RAPP-SBOM-NEXUS-WP-0003."
|
|
state_hub_intake_id: "01a02e28-3beb-764a-b4fc-c34cdf59a01e"
|
|
```
|
|
|
|
## CUST-IN-0015 — Restore source-ref projection on later SBOM catch-up batches
|
|
|
|
```yaml
|
|
id: CUST-IN-0015
|
|
kind: intake
|
|
title: "Restore source-ref projection on later SBOM catch-up batches"
|
|
status: open
|
|
lane: blue
|
|
priority: high
|
|
owner: repo-manager
|
|
tags: [sbom, catch-up]
|
|
origin: residual
|
|
origin_ref: CUST-WP-0064
|
|
updated: "2026-08-28"
|
|
notes: "CUST-WP-0064-T04 is met: the 2026-08-24 07:15 UTC unassisted fire ingested clay-borg (snapshot 63abb22f, forgejo-archive-v1, revision 18c57f2e, 77 entries) and wrote truthful no-manifest terminals for citation-work and config-atlas at pinned SHAs. From 2026-08-25 through 2026-08-28 the same weekday schedule writes three no-checkout snapshots each day (feature-control / evidence-source / evidence-binder on 2026-08-28). never_count is 76. Diagnose why Repo Manager source-ref projection followed the 2026-08-24 batch and not later ones; do not widen catch_up_limit while diagnosing. SBOM Nexus and Activity Core are counterparties, not a second owner."
|
|
state_hub_intake_id: "01a049a5-4599-740c-a148-e40e5695c7b5"
|
|
```
|
|
|
|
## CUST-IN-0016 — Complete deferred ADR metadata and conflict rulings
|
|
|
|
```yaml
|
|
id: CUST-IN-0016
|
|
kind: intake
|
|
title: "Complete deferred ADR metadata and conflict rulings"
|
|
status: open
|
|
lane: green
|
|
priority: medium
|
|
owner: the-custodian
|
|
origin: residual
|
|
origin_ref: PNEX-WP-0003
|
|
updated: "2026-08-31"
|
|
notes: >-
|
|
PNEX-WP-0003 produced a reviewed 162-source ledger and a first release batch
|
|
of 60 explicit publications. Thirty-five additional publish rulings still
|
|
depended on publication metadata in their owning repositories; five conflict
|
|
rows still require owner rulings. On 2026-08-31 the Custodian reviewed the
|
|
first bounded owner slice: Autonomy Lanes, Contribution Convention, Project
|
|
Repository Flavor, Work Record Types, and Workplan Terminology are approved
|
|
for publication with accepted-1 metadata. The two constitution sources
|
|
remain out of the public batch because they declare sensitivity: internal;
|
|
Bootstrap Protocol also contains internal financial/legal formation detail.
|
|
Repo Classification remains deferred because its body says Draft v1.0 while
|
|
its front-matter says active. SBOM Convention remains deferred for a
|
|
freshness review against the newer SBOM Nexus authority model. Coordinate
|
|
the remaining owner responses from policy-nexus/docs/adr-review/ledger.json,
|
|
rulings.json, conflicts.md, and the per-repo cleanup packets. When a coherent
|
|
set becomes ready, hand it to Policy Nexus as a new bounded publication
|
|
batch. Do not reopen PNEX-WP-0003 for individual late returns, and do not let
|
|
Policy Nexus rewrite owner-controlled ADR bodies. Seven unpublished
|
|
superseded records remain excluded history unless a stable historical URL
|
|
is later required. PNEX-WP-0004 completed the first return on 2026-08-31:
|
|
the five approved fleet standards are live in the 65-document release at
|
|
current and immutable accepted-1 addresses. Twenty-eight publish rulings
|
|
remain (26 in other owner repos and two Custodian substantive reviews), plus
|
|
the five conflict rows. CCR-2026-0014 separately tracks a least-privilege
|
|
Forgejo source-read token for scheduled Policy Nexus builds.
|
|
```
|