the-custodian/history/20260928-blocked-workplan-graph.md
codex 49f505615a
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Draft CUST-WP-0074: qualify task wait states (external vs human gate)
Derived-state shape chosen over new stored statuses; reuses task-block
depends_on, needs_human and blocking_reason. Blocked-workplan graph
snapshot recorded under history/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-28 20:52:02 +02:00

93 lines
4.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Blocked workplan graph — 2026-09-28
Snapshot taken from the State Hub primary on 2026-09-28 for `CUST-WP-0074`.
Edges were extracted from the text of `wait` tasks (workplan-id references
by regex; repo-only references read by hand), because only 7 formal
dependency edges existed among open workplans. Treat the fan-out counts as
prioritisation evidence, not verified edges.
## Numbers
- 1465 workplans in the hub: 1297 finished, 53 archived, 108 blocked
(105 after excluding `@retired` slugs), 3 proposed, 2 backlog, 2 active.
- 220 `wait` tasks in the blocked set; 29 set `blocking_reason`, 5 set
`needs_human`.
- 48 blocked workplans have exactly one wait task (single gate).
- 6 blocked workplans have no wait task at all.
- Only 2 blocked workplans untouched since 2026-09-01 — this is not rot,
it is stranded waits.
## Existing modelling found
| Layer | What exists |
|---|---|
| State Hub | `workplan_dependencies` table, `/workplans/{id}/dependencies/`, C-20 indexes frontmatter `depends_on`; task columns `needs_human`, `intervention_note`, `blocking_reason`; workplan frontmatter `blocked_on:` watched by C-25 |
| railiance-fabric | `coordination_graph.py`, `export --format coordination`, `/ui/graph-explorer?mode=coordination` (`RAIL-FAB-WP-0029`, blocked on hosting under `RAIL-FAB-WP-0028`) |
| coordination-engine | `spec/coordination-model-v0.2.md` (`depends_on` as commitment), `spec/cross-owner-wait-mode-v0.1.md` (specified, not live) |
Decision: improve these; do not create a `helix-fabric` sibling.
## Gate roots (fan-out on the right)
```
R1 FLEX-WP-0020 (rename → access-engine)
├─ NK-WP-0039 ├─ RAIL-FAB-WP-0031 ├─ REUSE-WP-0023 ├─ USER-WP-0034
└─ RCLK-WP-0002 (needs an access-engine contract)
R2 Operator credential provisioning (OpenBao; CCR-2026-0004; scoped attended applies)
├─ RPF-WP-0035 → SECRETS-WP-0008
├─ SECRETS-WP-0006 / 0007 / 0009 ; MASON-WP-0004 / 0005
├─ SAND-WP-0015 → SAND-WP-0014 → GLAS-WP-0012 → GLAS-WP-0015
├─ IR-WP-0005 + IR-WP-0006 → IR-WP-0007
├─ RPF-WP-0015 / 0027 / 0038 ; RAIL-HO-WP-0012
└─ WARDEN-WP-0027 / 0034 / 0039 / 0040
R3 audit-core owner returns (intake replies)
├─ FLEX-WP-0031 ├─ NK-WP-0031 ├─ NK-WP-0040 ├─ APPROVAL-WP-0002
└─ INFO-WP-0029 ; TEN-WP-0012 ; NK-WP-0035 (needs info-tech-canon)
R4 Two real users on Vergabe (VERGABE-WP-0019, human acceptance)
├─ RAPPS-WP-0014 ├─ VERGABE-WP-0018 (also HFACT-WP-0001-T05, active)
└─ CUST-WP-0071 ← measurements ← RAPP-QONTO-WP-0002, FIN-WP-0004
R5 ArgoCD lane (sequential)
RPF-WP-0044 → RPF-WP-0043 → RAPP-POLICY-NEXUS-WP-0002 → MASON-WP-0006 (dated 2026-12-21)
RPF-WP-0048 (+24h soak) → ACTIVITY-WP-0041 → ACTIVITY-WP-0040 ; ACTIVITY-WP-0032
R6 State Hub retirement / Fabric authority
RAIL-FAB-WP-0028 → RAIL-FAB-WP-0029 ; STATE-WP-0079 → HUB-WP-0006 / 0011 / 0012
RAPPCOREHUB-WP-0003 → RAPPCOREHUB-WP-0002 → CORE-WP-0010 ; ORGREF-WP-0001
R7 Clock: RCLK-WP-0002 (four engines' contracts) + RCLK-WP-0005 → RCLK-WP-0004 ; RAIL-HO-WP-0013
R8 Identity: KEY-WP-0035, NK-WP-0033 custody, privacyidea token non-resolvable
→ USER-WP-0026 / 0027 / 0028 / 0037, HUB-WP-0012, NK-WP-0042, KEY-WP-0013
```
Most-referenced targets by extracted in-degree: SECRETS-WP-0007 (6),
HFACT-WP-0001 (6, active), SECRETS-WP-0010 (5, finished — a stale wait
signal), SECRETS-WP-0006 (4), STATE-WP-0079 (4), SAND-WP-0015 (4),
VERGABE-WP-0019 (4).
## Unblock order (fan-out per unit of effort)
1. Execute `FLEX-WP-0020` — one owner, scripted preflight, 5 dependents.
2. One attended OpenBao provisioning session — clears R2 and the HIGH
open item on CNPG backups (`RAILIANCE-WP-0015`).
3. Ask audit-core for its intake replies (R3) via the cross-owner-wait
pattern; do not reassign their tasks.
4. Get two real users into Vergabe (R4); `CUST-WP-0071` waits on it too.
5. Run the ArgoCD lane in order (R5); the soak is time-gated.
6. Finish `RAIL-FAB-WP-0028` — unblocks the graph view and the retirement
chain.
7. Park the time-gated ones: `MASON-WP-0006` (2026-12-21), the
`NK-WP-0022` / `RMASTER-WP-0020` retention windows,
`WHITEHAT-WP-0006` / `0008` (need a named target owner).
## Hygiene (not really blocked)
No wait task: `fluid-wp-0008`, `fluid-wp-0009`, `ft-wp-0001`,
`glas-wp-0015`, `key-wp-0013`, `three-phoenix-ha-cluster`. Self-ordering
chain: `FEP-WP-0002 → 0003 → 0004`, plus `0006`, `0008`. Trivial gate:
`testdrive-jsui-publication`. Roughly 15 workplans; the real blocked set
is 85–90.