docs: defer DWH client cutover before Project B

This commit is contained in:
User
2026-08-21 14:35:37 +02:00
parent 7118950416
commit 9974fb4bc0
12 changed files with 244 additions and 86 deletions
@@ -4,6 +4,11 @@
**Status:** Approved by the owner
**Owner sequencing amendment (2026-08-21):** the Mac `rest_api` acceptance and revocation of
`legacy-shared` are deferred to one mandatory pre-Project-B gate. This permits the bounded survey
and static, non-mutating Project A private preparation to proceed without changing the Mac. It does not
authorize stopping the legacy stack, starting the new stack, opening ingress, or beginning Project B.
**Design-time application baseline:** `main` at `5c0dc8c` (execution must freeze and record the
then-current `origin/main` SHA)
@@ -70,10 +75,14 @@ The program consists of one non-mutating common survey followed by two independe
projects:
```text
Common Survey PASS
Common Survey PASS for Project A private scope
-> Project A automated PASS
-> Project A human PASS
-> explicit authorization
-> Mac REST acceptance
-> 48-hour dual-key observation covering two 03:00 ETL cycles
-> legacy-shared revocation and negative proof
-> full pre-Project-B survey PASS
-> explicit Project B authorization
-> Project B automated PASS
-> Project B human PASS
-> final cutover acceptance
@@ -136,7 +145,8 @@ proved safe.
1. Freeze exact application and workspace SHAs and require clean source trees.
2. Publish and validate the multi-transport `psd-clinical` descriptor through the curator workflow.
3. Prove the Mac installation still selects REST and remains valid.
3. Preserve the Mac REST binding unchanged; its live acceptance is deferred to the mandatory
pre-Project-B gate.
4. Prepare the new source clone and protected operator/runtime directories beside the old source.
5. Extract only approved configuration facts from the legacy installation.
6. Create and verify backups and a restart recipe for the legacy stack.
@@ -182,12 +192,17 @@ Project A requires:
- optional private-route positive and negative isolation evidence when that route is used;
- completed human manual-test report with an explicit PASS.
The Mac row may be recorded only as `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. It is
not part of the private server acceptance, but it must become PASS before Project B starts.
Project A does not modify the production Aritmolab sidebar, production public route, or Authentik.
## Project B — Authentik and Aritmolab Integration
Project B begins only from the frozen, accepted Project A source, images, workspace revision, and
PASS report.
PASS report. It also requires the deferred Mac REST acceptance, the full 48-hour observation
window (including two scheduled 03:00 ETL cycles), revocation of `legacy-shared`, proof that the
legacy credential receives `401`, and the full pre-Project-B survey gate.
### Final request and data flow
@@ -46,6 +46,21 @@ a credential must read a protected file or use an echo-free prompt.
The detailed evidence directory is a protected path on the server selected during the survey. The
repository receives only redacted reports after explicit owner review.
## Owner-approved sequencing amendment — 2026-08-21
The Mac `rest_api` acceptance and revocation of `legacy-shared` move to a mandatory gate immediately
before Project B. The survey therefore records two distinct decisions:
- `SURVEY_GO_PROJECT_A_PRIVATE`: technical prerequisite for requesting Project A private execution;
- `SURVEY_GO_PROJECT_B`: the complete shared-infrastructure decision, including Mac acceptance,
observation and legacy revocation.
The amendment authorizes the read-only survey and static preparation of non-secret Project A
candidate facts and artifacts. While the current decision is `SURVEY_NO_GO`, it does not authorize
creating installation roots, cloning/building the candidate, creating protected configuration or
backup state, stopping the legacy stack, starting the new stack, changing public ingress, or
starting Project B. Those remain separate explicit gates after the scoped survey passes.
### Task 1: Freeze the planning source
**Files:**
@@ -100,10 +115,13 @@ load balancer, Aritmolab, Authentik, Supabase, the DWH, and protected credential
If an Authentik credential cannot be located, stop and ask the owner. If a configuration owner or
rollback boundary is unclear, stop; do not infer authority from file readability.
**Step 3: Review the survey GO/NO-GO**
**Step 3: Review the scoped survey GO/NO-GO**
Expected: GO requires a verified old-stack recovery path, a new-installation root, enough resources,
a read-only DWH path, and no unresolved shared-infrastructure mutation.
Expected: `SURVEY_GO_PROJECT_A_PRIVATE` requires a verified old-stack recovery path, an approved
new-installation root, enough resources, a direct read-only DWH path, workspace/model inputs, and
no unresolved mutation in the private Project A scope. Public-origin, load-balancer and Authentik
unknowns may remain explicitly deferred only while Project A is loopback-only and Task 10 is
omitted. `SURVEY_GO_PROJECT_B` retains the complete survey requirements.
**Step 4: Checkpoint the survey**
@@ -115,9 +133,10 @@ Hash the protected report and record only its path, SHA-256, timestamp, and GO r
- Execute: `docs/plans/2026-08-20-psd-server-project-a-standalone.md`
- Complete: `docs/testing/evidence/psd-server-project-a-report-template.md`
**Step 1: Confirm the survey is GO**
**Step 1: Confirm the survey is GO for Project A private scope**
Expected: the survey report hash matches the journal and no unresolved blocker remains.
Expected: the survey report hash matches the journal and no unresolved blocker remains inside the
Project A private scope. Before any stop/start, obtain a separate explicit owner authorization.
**Step 2: Execute Project A task-by-task**
@@ -126,12 +145,14 @@ Do not configure Authentik, change the production Aritmolab sidebar, or open the
**Step 3: Run the Project A human guide**
Follow `docs/testing/psd-server-project-a-manual.md`. Record PASS/FAIL for every case; do not infer
manual PASS from automated output.
manual PASS from automated output. The Mac REST row may be
`DEFERRED_PRE_PROJECT_B` only under the dated owner amendment.
**Step 4: Close the Project A report**
Expected: automated gates and the human guide are PASS; one harmless PSD session reached F8 and
produced validated read-only SQL; rollback remains available.
produced validated read-only SQL; rollback remains available. The accepted report must list the
Mac REST item as an explicit deferred prerequisite rather than silently treating it as PASS.
**Step 5: Obtain explicit owner approval**
@@ -145,6 +166,10 @@ Record the approval and report digest. Project B remains forbidden without it.
**Step 1: Recheck source and running images**
Before freezing the candidate, close the pre-Project-B gate: validate the Mac installation with its
per-installation key, finish the 48-hour observation window including two 03:00 ETL cycles, revoke
`legacy-shared`, prove legacy `401` and v1 success, and obtain `SURVEY_GO_PROJECT_B`.
Run the Project A plan's identity commands again. Record application SHA, workspace SHA, core image
ID, frontend image ID, Qdrant image digest, Ollama image digest, and local-auth configuration revision.
@@ -12,13 +12,16 @@
## Preconditions
- Common survey result is GO and its digest is recorded.
- Common survey result is `SURVEY_GO_PROJECT_A_PRIVATE` and its digest is recorded.
- Every path below is replaced by the exact survey result before execution.
- No production Nginx/load-balancer/sidebar/Authentik change is in scope.
- The old stack remains running only until backup verification finishes; old and new stacks never
run together.
- The server's workspace deploy credential remains read-only. A curator with write access publishes
the workspace change.
- Owner amendment 2026-08-21 defers live Mac `rest_api` acceptance and `legacy-shared` revocation to
the mandatory pre-Project-B gate. It does not authorize stop/start; those require a later explicit
owner gate even after private preparation is complete.
### Task 1: Freeze exact inputs
@@ -121,11 +124,11 @@ git push --set-upstream origin codex/psd-direct-transport
Merge through the repository's normal review path. Record the resulting `main` SHA.
**Step 6: Prove the Mac REST installation is unchanged**
**Step 6: Record the deferred Mac REST proof**
The owner pulls/activates the new workspace commit on the Mac, confirms selected transport
`rest_api`, runs workspace inspection/connection diagnostics, and records PASS. Project A server
deployment stops if this cross-installation proof is not available.
Do not change the Mac during Project A. Record `DEFERRED_PRE_PROJECT_B`, the unchanged expected
transport `rest_api`, and the exact future diagnostics. The proof must become PASS before Project B,
after protected delivery/configuration of the per-installation key.
### Task 3: Back up and stop the legacy installation
@@ -416,6 +419,11 @@ remembered-session survival after core restart. Do not retain cookie jars after
### Task 10: Optionally add the private network-path test
**Current scope boundary (owner, 2026-08-21):** omit this entire task and keep Project A
loopback-only. Any future use requires a separate shared-infrastructure authorization after the
public-origin and load-balancer activities pass; the Project A private survey decision alone is
insufficient.
**Files:**
- Modify only surveyed test-specific load-balancer/Nginx files
- Create: test certificate through the existing managed mechanism
@@ -487,12 +495,14 @@ secrets in the ordinary evidence archive.
**Step 3: Complete human acceptance**
Every row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly blocking.
Every private-server row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly
blocking. Only the Mac REST row may be `DEFERRED_PRE_PROJECT_B` under the dated owner amendment.
**Step 4: Record the gate**
Record exact SHAs/images, workspace revision, preprocessing identity/counts, session ID, report
digest, rollback status, and explicit `PROJECT_A_PASS` or `PROJECT_A_FAIL`.
digest, rollback status, and explicit `PROJECT_A_PRIVATE_PASS` or `PROJECT_A_FAIL`. A private PASS
does not authorize Project B while the deferred gate remains open.
**Step 5: Stop on FAIL**
@@ -13,6 +13,11 @@
## Preconditions
- Project A automated and human reports are PASS and explicitly owner-approved.
- The Mac `rest_api` installation passes source validation and connection diagnostics with its
per-installation key.
- The dual-key observation has lasted at least 48 hours and includes two scheduled 03:00 ETL cycles.
- `legacy-shared` is revoked; v1 remains successful and the legacy credential is proven `401`.
- The current survey decision is `SURVEY_GO_PROJECT_B`, not only the private Project A decision.
- Application SHA, workspace SHA, images, Project A report digest, and rollback configuration match
the accepted evidence.
- The production route is closed before authentication/session-storage changes.
+7 -3
View File
@@ -290,10 +290,14 @@ ThothII, and core → Supabase DWH/auth session schema/Qdrant/Ollama/LLM/Authent
Separate files owned by the new ThothII installation, workspace curator, Nginx, load balancer,
Aritmolab, Authentik, and Supabase. Mark shared files as owner-gated.
**Step 3: State GO or NO-GO**
**Step 3: State the scoped GO or NO-GO decisions**
GO requires all mandatory paths, permissions, backup owners, and rollback boundaries. NO-GO must
name concrete missing facts and the person/system needed to resolve them.
State both `SURVEY_GO_PROJECT_A_PRIVATE` and `SURVEY_GO_PROJECT_B`. The private decision requires
all paths, permissions, backup owners and rollback boundaries used by Project A; it may defer
public-origin, load-balancer, Authentik and Mac REST closeout facts that Project A does not mutate.
The Project B decision requires every shared/public fact plus the Mac acceptance, completed
observation window and revoked legacy credential. Each NO-GO must name concrete missing facts and
the person/system needed to resolve them.
**Step 4: Hash and retain the report**