vergabe-teilnahme/workplans/VERGABE-WP-0018-customer-factory-delivery.md
tegwick b7d7828f30 Require invited login and private downloads for the company pilot
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-11 16:35:13 +02:00

119 lines
5.4 KiB
Markdown

---
id: VERGABE-WP-0018
type: workplan
title: "Establish verified delivery for the primary customer tender product"
domain: communication
repo: vergabe-teilnahme
status: blocked
owner: the-custodian
topic_slug: vergabe-teilnahme
created: "2026-09-08"
updated: "2026-09-11"
related: [HFACT-WP-0001, REUSE-WP-0022]
state_hub_workstream_id: "27a95f7b-cec4-50ca-8383-c1c95d996217"
---
# Customer product delivery
## Core Idea
Make the existing tender-participation UI a repeatably tested customer product.
Use hosted capability discovery for planning, exercise the existing useful
tender/lot/approval workflow, and prevent image publication when application
acceptance fails. Preserve single-company scope until a separate tenancy design.
## Establish product authority and reuse discovery
```task
id: VERGABE-WP-0018-T01
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "ec53efce-ba3c-5965-9c64-ea0480bfae68"
```
Update product entry points and classification to reflect the user's explicit
customer-product selection. Add a reproducible `make plan-check WORKPLAN=...`
consumer of REUSE-WP-0022, with no model call or mutation credential. Pin and
record the tested provider revision and hosted snapshot receipt. A low lexical
score requires owner review; it does not authorize a duplicate capability.
## Gate releases with useful application acceptance
```task
id: VERGABE-WP-0018-T02
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "dc889dba-3e10-5017-af9f-4843119a103a"
```
Run existing application tests against disposable data, including tender create,
lot create, approval and submission. Add a reproducible container acceptance
target with locked dependencies, built assets and migration drift checks. Run it
on proposed changes and before the existing image publication step. Record
immutable reviewed source, CI outcome and resulting artifact separately.
## Accept the first Railiance customer pilot release
```task
id: VERGABE-WP-0018-T03
status: wait
priority: high
assignee: the-custodian
depends_on: [VERGABE-WP-0018-T02, HFACT-WP-0001-T05]
blocking_reason: "Image main-fa9f082 is tested and published. Await HFACT-WP-0001-T05 governed worker evidence plus exact Railiance tenant, deployment, database, storage, access and recovery acceptance."
state_hub_task_id: "6e428152-aad6-5184-8b1d-8860ec0b9ae6"
```
Coordinator: the-custodian; product acceptance: Bernd Worsch; deployment owner:
railiance-apps and admitted Railiance placement owner. Prepare exact chart/image,
host, tenant, credential binding, existing-data disposition, backup/restore,
rollback and UI acceptance evidence before release. Use the invited single-company pilot in VERGABE-WP-0019; existing `vergabe_db` is not test data and must not be relocated or
overwritten implicitly. No customer-ready claim until admitted release passes.
Return the release and consumer evidence to HFACT-WP-0001-T06/T07.
## Source acceptance — 2026-09-08
- Full application suite: 82 passed locally with SQLite and again with a
disposable PostgreSQL 16 container; no production data used.
- Clean container application target: 82 passed, Vite/Tailwind built, 139 static
files collected, no migration drift. One pre-existing naive-datetime warning.
- Runtime image built successfully; loopback health HTTP 200 as UID 999;
pytest absent from runtime. See `docs/evidence/2026-09-08-runtime-smoke.json`.
- Clean-build defect fixed: root `templates/` does not exist in published source;
application templates already reside under `vergabe_teilnahme/templates/`.
- Hosted discovery consumed from reuse-surface implementation `2621cf2`;
65-capability provenance and review disposition are in
`docs/evidence/2026-09-08-hosted-plan-check.json`.
T02 is complete with the live CI and immutable image receipts below.
T03 retains the concrete deployment/data/access/recovery gates. Attended Codex
source work is not a natural governed worker claim/heartbeat/close trace.
Live CI runs 15/16 exposed the runner's missing Buildx/BuildKit support, despite
local acceptance. Added pinned temporary CLI setup shared by application and
image workflows, and removed duplicate feature-push test scheduling. The next
exact PR revision must pass on the actual runner before T02 closes.
## Published return
PR 1 source at `fa9f08268a5669d3832753929bb5a2ad267bfa72` passed live
application CI 17 and was integrated on main. Main application CI 18 and image
publication 20 passed. Published image `main-fa9f082` has digest
`sha256:cb48658f5bfeeef91b8e16de94e8833be01a68bf72619567665c9f7fe927d062`.
T01/T02 are done; the workplan is blocked on T03's admitted customer release.
HFACT-WP-0001 consumes the source and artifact receipts without claiming a
current governed worker run. Forgejo PR 1 metadata needs its authenticated
`manually-merged` receipt; source integration itself is verified on main.
## Invited-pilot sequencing decision — 2026-09-11
The user selected an invited pilot with manual onboarding and deferred pricing.
VERGABE-WP-0019 owns concrete product readiness; RAPPS-WP-0014 owns deployment
and recovery. Their preparation can advance independently of T03's governed
worker dependency. This record continues to own factory-produced delivery
acceptance, so a manually prepared customer pilot cannot falsely close HFACT
worker proof. The old main-fa9f082 image predates the required login gate and
must not be used as the invited-pilot release merely because its CI passed.