the-custodian/docs/recovery/fleet-projection-reset-2026-08-28.md
codex 5c6d8df755
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs: record central fleet projection reset (CUST-WP-0068-T09)
Image main-54b09ee. the-custodian reset-ack then fleet refuse-mode:
52 applied, 69 noop, 2 identifier-collision refusals, 0 retirements.
Fleet-ack not run — nothing was refused for retirement.
2026-08-28 21:42:05 +02:00

3.8 KiB

Fleet projection reset — 2026-08-28

Coordination: CUST-WP-0068-T09 / STATE-WP-0083. Central State Hub image forgejo.coulomb.social/coulomb/state-hub:main-54b09ee (Helm revision 48, schema e2b3c4d5f6a7). Reset ran in-cluster from pod state-hub-5bd5ffd656-plx7z via /tmp/sh-projection-reset.py. The HTTP tunnel does not reach central Postgres; this is the only sanctioned write path (ADR-012 decision 7).

Refuse-mode applies creates and updates when nothing would be retired. It refuses only when a record would be tombstoned, or when an identifier is already held by another repository. Acknowledgement cannot authorise the second class.

the-custodian (ack)

Status applied at commit 989806a. Retired interactive-the-custodian (archived ADHOC-2026-03-29 already live as cust-wp-adhoc-2026-03-29). Created 13 identified tasks (CUST-WP-0010-T1/T2/T3, CUST-WP-0054-T01..T10). Updated 125 tasks. Cancelled none. 74 workplans updated (mostly derived_from_commit / backing path).

A subsequent refuse-mode pass on the same repository was noop.

Fleet refuse-mode

125 repositories. No errors. Zero workplans retired. Zero tasks cancelled.

Status Count
applied 52
noop 69
refused 2
unreadable 2

Totals: 122 workplans updated, 149 tasks created, 745 tasks updated, 0 retired, 0 released.

Fleet-ack was not run. Nothing was refused for retirement, so there was no stale set to acknowledge. Re-running with acknowledgement would not create the colliding records below.

Refused — identifier collisions (ack does not authorise)

railiance-bootstrap currently holds no hub workplans. The forge still derives four identifiers already live on railiance-cluster:

Record Held by Holder status Holder path
RAIL-BS-WP-0003 railiance-cluster 7ee9ee22-… finished workplans/archived/260622-RAIL-BS-WP-0003-pgpool-ha-failover-fix.md
RAIL-BS-WP-0005 railiance-cluster b236de41-… finished workplans/archived/260622-RAIL-BS-WP-0005-kubeconfig-delivery.md
RAIL-BS-WP-0008 railiance-cluster 5032c55c-… finished workplans/RAIL-BS-WP-0008-activity-core-wp0016-triage-output-deploy.md
RAIL-BS-WP-0009 railiance-cluster 2c9e8e96-… finished workplans/RAIL-BS-WP-0009-activity-core-admin-sync-smoke.md

railiance-hosts likewise holds no hub workplans. The forge derives RAIL-HO-WP-0004, already live on railiance-infra (cee078e9-…, finished, workplans/archived/260702-RAIL-HO-WP-0004-production-readiness.md).

These are extraction leftovers: the files still exist in the older repositories, and the identifiers belong to the successor. Disposition is a source-file decision in those repos, not a projection acknowledgement.

Unreadable (STATE-WP-0084)

Forge 404, classified as unreadable rather than empty — nothing retired:

  • vergabe_teilnahme (underscore slug). The hyphenated vergabe-teilnahme applied.
  • markitect-project

Private repositories remain unread without a forge token. Absence here is not evidence of absence in the files.

Left on purpose

  • adhoc-2026-08-25@retired-20260827 still has hub status: active. The live file is already cust-wp-adhoc-2026-08-25 (finished). Reset correctly skips a tombstoned slug; C-07 still flags the leftover status. That is a status-finish, not another reset.
  • 557 task rows with null record_id (34 open) are out of scope: the reset must not guess identity.
  • Three railiance-wp-0001/0002/0004 rows remain live because archived files still back them. The unbacked four from T09 (0017/0018/0022/0023) are already tombstoned.

Full refuse-mode JSON: /tmp/custodian-reset/fleet-refuse-2026-08-28.json (pod copy /tmp/fleet-refuse.json).