Close CUST-WP-0064 after the 2026-08-24 unassisted fire ingested clay-borg, close CUST-WP-0065 now that all 120 active repos project a classification, and close ADHOC-2026-08-25. Mark CUST-WP-0067 T02/T10 done (reverse relays already gone; work-record recovery lives on 0068). Park the later no-checkout SBOM regression as CUST-IN-0015. Teach the classification gate to use this host's checkout path.
5.2 KiB
5.2 KiB
Custodian intake records
CUST-IN-0011 — Provision a monitored external security-report Contact URI
id: CUST-IN-0011
kind: intake
title: "Provision a monitored external security-report Contact URI"
status: routed
lane: red
priority: high
owner: policy-nexus
tags: [compliance-relevant]
origin: residual
origin_ref: CUST-WP-0063
selected_contact_uri: "https://security.coulomb.social/"
updated: "2026-08-23"
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Acceptance check 2026-08-23: security.coulomb.social resolves to 217.160.0.212 and aborts TLS with alert internal_error, while the governed Policy Nexus ingress at policy.coulomb.social resolves to 92.205.62.239 and its current package grants only that hostname. The private receipt mechanism is also not yet defined. Initial blocker message: a111b97c. Exact DNS/admission/package handoffs: railiance-apps fb32adf5 and rapp-policy-nexus 93acef37. Do not move DNS or publish security.txt until the production host grant, certificate/ingress, monitored receipt path, and private report-to-Risk-Nexus proof are complete."
state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
CUST-IN-0012 — Repair the malformed legacy inbox message identity
id: CUST-IN-0012
kind: intake
title: "Repair the malformed legacy inbox message identity"
status: closed
lane: green
priority: low
owner: hub-core
origin: residual
origin_ref: CUST-WP-0063
updated: "2026-08-23"
notes: "Closed 2026-08-23. State Hub now exposes the preserved risk-nexus message with valid stable id 0b8dd0bf-41d1-47da-96ac-40e443c32e47. PATCH /messages/{id}/read succeeded through the supported API, preserving its body and original 2026-08-20 chronology; the Custodian unread inbox is empty. No direct database mutation was used."
state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a"
CUST-IN-0013 — Enforce durable SBOM catch-up operation idempotency
id: CUST-IN-0013
kind: intake
title: "Enforce durable SBOM catch-up operation idempotency"
status: closed
outcome: absorbed
lane: blue
priority: high
owner: sbom-nexus
origin: residual
origin_ref: CUST-WP-0062
notes: "Activity Core completed ACTIVITY-WP-0033 and now sends a stable Idempotency-Key plus X-Activity-Core-Operation-ID for each workflow-run/repository pair. SBOM Nexus durably enforces that identity on both POST /sbom/{slug}/ingest and POST /sbom/{slug}/skip and replays the original terminal response. Live attended evidence on 2026-08-23 returned the same snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be for two requests with the same operation key and exact source reference. Scheduled Activity Core proof remains under CUST-WP-0064. Source handoff: State Hub message bc5caa49-25eb-4942-9deb-411b6080d0bb."
state_hub_intake_id: "01a02b44-89a9-7e94-820b-3d86340117ff"
CUST-IN-0014 — Stop SBOM Nexus restarts on database lease rotation
id: CUST-IN-0014
kind: intake
title: "Stop SBOM Nexus restarts on database lease rotation"
status: closed
outcome: absorbed
lane: blue
priority: high
owner: sbom-nexus
origin: residual
origin_ref: CUST-WP-0062
notes: "Live review after cutover found the Ready SBOM Nexus pod at restartCount 9 in under five hours. The last container ran exactly 30 minutes, then readiness/liveness returned HTTP 500 because PostgreSQL rejected the expired v-token-sbom-nex-* credential; Kubernetes restarted the process and it recovered. The corrected runtime deployed on 2026-08-23 rereads the mounted URL for every new connection, recycles the pool every five minutes, keeps credentials out of the engine URL, and separates process liveness from database readiness. Completion evidence at 2026-08-22T23:06:19Z exceeded the old failure point with 30m51s on one pod UID across repeated mounted Secret refreshes: Ready, restart count zero, process/database/repository checks passing, zero health 500s, and zero credential-pattern log matches. Absorbed by finished SBOM-WP-0004 and RAPP-SBOM-NEXUS-WP-0003."
state_hub_intake_id: "01a02e28-3beb-764a-b4fc-c34cdf59a01e"
CUST-IN-0015 — Restore source-ref projection on later SBOM catch-up batches
id: CUST-IN-0015
kind: intake
title: "Restore source-ref projection on later SBOM catch-up batches"
status: open
lane: blue
priority: high
owner: repo-manager
tags: [sbom, catch-up]
origin: residual
origin_ref: CUST-WP-0064
updated: "2026-08-28"
notes: "CUST-WP-0064-T04 is met: the 2026-08-24 07:15 UTC unassisted fire ingested clay-borg (snapshot 63abb22f, forgejo-archive-v1, revision 18c57f2e, 77 entries) and wrote truthful no-manifest terminals for citation-work and config-atlas at pinned SHAs. From 2026-08-25 through 2026-08-28 the same weekday schedule writes three no-checkout snapshots each day (feature-control / evidence-source / evidence-binder on 2026-08-28). never_count is 76. Diagnose why Repo Manager source-ref projection followed the 2026-08-24 batch and not later ones; do not widen catch_up_limit while diagnosing. SBOM Nexus and Activity Core are counterparties, not a second owner."