docs: defer DWH client cutover before Project B
This commit is contained in:
@@ -4,6 +4,11 @@
|
||||
|
||||
**Status:** Approved by the owner
|
||||
|
||||
**Owner sequencing amendment (2026-08-21):** the Mac `rest_api` acceptance and revocation of
|
||||
`legacy-shared` are deferred to one mandatory pre-Project-B gate. This permits the bounded survey
|
||||
and static, non-mutating Project A private preparation to proceed without changing the Mac. It does not
|
||||
authorize stopping the legacy stack, starting the new stack, opening ingress, or beginning Project B.
|
||||
|
||||
**Design-time application baseline:** `main` at `5c0dc8c` (execution must freeze and record the
|
||||
then-current `origin/main` SHA)
|
||||
|
||||
@@ -70,10 +75,14 @@ The program consists of one non-mutating common survey followed by two independe
|
||||
projects:
|
||||
|
||||
```text
|
||||
Common Survey PASS
|
||||
Common Survey PASS for Project A private scope
|
||||
-> Project A automated PASS
|
||||
-> Project A human PASS
|
||||
-> explicit authorization
|
||||
-> Mac REST acceptance
|
||||
-> 48-hour dual-key observation covering two 03:00 ETL cycles
|
||||
-> legacy-shared revocation and negative proof
|
||||
-> full pre-Project-B survey PASS
|
||||
-> explicit Project B authorization
|
||||
-> Project B automated PASS
|
||||
-> Project B human PASS
|
||||
-> final cutover acceptance
|
||||
@@ -136,7 +145,8 @@ proved safe.
|
||||
|
||||
1. Freeze exact application and workspace SHAs and require clean source trees.
|
||||
2. Publish and validate the multi-transport `psd-clinical` descriptor through the curator workflow.
|
||||
3. Prove the Mac installation still selects REST and remains valid.
|
||||
3. Preserve the Mac REST binding unchanged; its live acceptance is deferred to the mandatory
|
||||
pre-Project-B gate.
|
||||
4. Prepare the new source clone and protected operator/runtime directories beside the old source.
|
||||
5. Extract only approved configuration facts from the legacy installation.
|
||||
6. Create and verify backups and a restart recipe for the legacy stack.
|
||||
@@ -182,12 +192,17 @@ Project A requires:
|
||||
- optional private-route positive and negative isolation evidence when that route is used;
|
||||
- completed human manual-test report with an explicit PASS.
|
||||
|
||||
The Mac row may be recorded only as `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. It is
|
||||
not part of the private server acceptance, but it must become PASS before Project B starts.
|
||||
|
||||
Project A does not modify the production Aritmolab sidebar, production public route, or Authentik.
|
||||
|
||||
## Project B — Authentik and Aritmolab Integration
|
||||
|
||||
Project B begins only from the frozen, accepted Project A source, images, workspace revision, and
|
||||
PASS report.
|
||||
PASS report. It also requires the deferred Mac REST acceptance, the full 48-hour observation
|
||||
window (including two scheduled 03:00 ETL cycles), revocation of `legacy-shared`, proof that the
|
||||
legacy credential receives `401`, and the full pre-Project-B survey gate.
|
||||
|
||||
### Final request and data flow
|
||||
|
||||
|
||||
@@ -46,6 +46,21 @@ a credential must read a protected file or use an echo-free prompt.
|
||||
The detailed evidence directory is a protected path on the server selected during the survey. The
|
||||
repository receives only redacted reports after explicit owner review.
|
||||
|
||||
## Owner-approved sequencing amendment — 2026-08-21
|
||||
|
||||
The Mac `rest_api` acceptance and revocation of `legacy-shared` move to a mandatory gate immediately
|
||||
before Project B. The survey therefore records two distinct decisions:
|
||||
|
||||
- `SURVEY_GO_PROJECT_A_PRIVATE`: technical prerequisite for requesting Project A private execution;
|
||||
- `SURVEY_GO_PROJECT_B`: the complete shared-infrastructure decision, including Mac acceptance,
|
||||
observation and legacy revocation.
|
||||
|
||||
The amendment authorizes the read-only survey and static preparation of non-secret Project A
|
||||
candidate facts and artifacts. While the current decision is `SURVEY_NO_GO`, it does not authorize
|
||||
creating installation roots, cloning/building the candidate, creating protected configuration or
|
||||
backup state, stopping the legacy stack, starting the new stack, changing public ingress, or
|
||||
starting Project B. Those remain separate explicit gates after the scoped survey passes.
|
||||
|
||||
### Task 1: Freeze the planning source
|
||||
|
||||
**Files:**
|
||||
@@ -100,10 +115,13 @@ load balancer, Aritmolab, Authentik, Supabase, the DWH, and protected credential
|
||||
If an Authentik credential cannot be located, stop and ask the owner. If a configuration owner or
|
||||
rollback boundary is unclear, stop; do not infer authority from file readability.
|
||||
|
||||
**Step 3: Review the survey GO/NO-GO**
|
||||
**Step 3: Review the scoped survey GO/NO-GO**
|
||||
|
||||
Expected: GO requires a verified old-stack recovery path, a new-installation root, enough resources,
|
||||
a read-only DWH path, and no unresolved shared-infrastructure mutation.
|
||||
Expected: `SURVEY_GO_PROJECT_A_PRIVATE` requires a verified old-stack recovery path, an approved
|
||||
new-installation root, enough resources, a direct read-only DWH path, workspace/model inputs, and
|
||||
no unresolved mutation in the private Project A scope. Public-origin, load-balancer and Authentik
|
||||
unknowns may remain explicitly deferred only while Project A is loopback-only and Task 10 is
|
||||
omitted. `SURVEY_GO_PROJECT_B` retains the complete survey requirements.
|
||||
|
||||
**Step 4: Checkpoint the survey**
|
||||
|
||||
@@ -115,9 +133,10 @@ Hash the protected report and record only its path, SHA-256, timestamp, and GO r
|
||||
- Execute: `docs/plans/2026-08-20-psd-server-project-a-standalone.md`
|
||||
- Complete: `docs/testing/evidence/psd-server-project-a-report-template.md`
|
||||
|
||||
**Step 1: Confirm the survey is GO**
|
||||
**Step 1: Confirm the survey is GO for Project A private scope**
|
||||
|
||||
Expected: the survey report hash matches the journal and no unresolved blocker remains.
|
||||
Expected: the survey report hash matches the journal and no unresolved blocker remains inside the
|
||||
Project A private scope. Before any stop/start, obtain a separate explicit owner authorization.
|
||||
|
||||
**Step 2: Execute Project A task-by-task**
|
||||
|
||||
@@ -126,12 +145,14 @@ Do not configure Authentik, change the production Aritmolab sidebar, or open the
|
||||
**Step 3: Run the Project A human guide**
|
||||
|
||||
Follow `docs/testing/psd-server-project-a-manual.md`. Record PASS/FAIL for every case; do not infer
|
||||
manual PASS from automated output.
|
||||
manual PASS from automated output. The Mac REST row may be
|
||||
`DEFERRED_PRE_PROJECT_B` only under the dated owner amendment.
|
||||
|
||||
**Step 4: Close the Project A report**
|
||||
|
||||
Expected: automated gates and the human guide are PASS; one harmless PSD session reached F8 and
|
||||
produced validated read-only SQL; rollback remains available.
|
||||
produced validated read-only SQL; rollback remains available. The accepted report must list the
|
||||
Mac REST item as an explicit deferred prerequisite rather than silently treating it as PASS.
|
||||
|
||||
**Step 5: Obtain explicit owner approval**
|
||||
|
||||
@@ -145,6 +166,10 @@ Record the approval and report digest. Project B remains forbidden without it.
|
||||
|
||||
**Step 1: Recheck source and running images**
|
||||
|
||||
Before freezing the candidate, close the pre-Project-B gate: validate the Mac installation with its
|
||||
per-installation key, finish the 48-hour observation window including two 03:00 ETL cycles, revoke
|
||||
`legacy-shared`, prove legacy `401` and v1 success, and obtain `SURVEY_GO_PROJECT_B`.
|
||||
|
||||
Run the Project A plan's identity commands again. Record application SHA, workspace SHA, core image
|
||||
ID, frontend image ID, Qdrant image digest, Ollama image digest, and local-auth configuration revision.
|
||||
|
||||
|
||||
@@ -12,13 +12,16 @@
|
||||
|
||||
## Preconditions
|
||||
|
||||
- Common survey result is GO and its digest is recorded.
|
||||
- Common survey result is `SURVEY_GO_PROJECT_A_PRIVATE` and its digest is recorded.
|
||||
- Every path below is replaced by the exact survey result before execution.
|
||||
- No production Nginx/load-balancer/sidebar/Authentik change is in scope.
|
||||
- The old stack remains running only until backup verification finishes; old and new stacks never
|
||||
run together.
|
||||
- The server's workspace deploy credential remains read-only. A curator with write access publishes
|
||||
the workspace change.
|
||||
- Owner amendment 2026-08-21 defers live Mac `rest_api` acceptance and `legacy-shared` revocation to
|
||||
the mandatory pre-Project-B gate. It does not authorize stop/start; those require a later explicit
|
||||
owner gate even after private preparation is complete.
|
||||
|
||||
### Task 1: Freeze exact inputs
|
||||
|
||||
@@ -121,11 +124,11 @@ git push --set-upstream origin codex/psd-direct-transport
|
||||
|
||||
Merge through the repository's normal review path. Record the resulting `main` SHA.
|
||||
|
||||
**Step 6: Prove the Mac REST installation is unchanged**
|
||||
**Step 6: Record the deferred Mac REST proof**
|
||||
|
||||
The owner pulls/activates the new workspace commit on the Mac, confirms selected transport
|
||||
`rest_api`, runs workspace inspection/connection diagnostics, and records PASS. Project A server
|
||||
deployment stops if this cross-installation proof is not available.
|
||||
Do not change the Mac during Project A. Record `DEFERRED_PRE_PROJECT_B`, the unchanged expected
|
||||
transport `rest_api`, and the exact future diagnostics. The proof must become PASS before Project B,
|
||||
after protected delivery/configuration of the per-installation key.
|
||||
|
||||
### Task 3: Back up and stop the legacy installation
|
||||
|
||||
@@ -416,6 +419,11 @@ remembered-session survival after core restart. Do not retain cookie jars after
|
||||
|
||||
### Task 10: Optionally add the private network-path test
|
||||
|
||||
**Current scope boundary (owner, 2026-08-21):** omit this entire task and keep Project A
|
||||
loopback-only. Any future use requires a separate shared-infrastructure authorization after the
|
||||
public-origin and load-balancer activities pass; the Project A private survey decision alone is
|
||||
insufficient.
|
||||
|
||||
**Files:**
|
||||
- Modify only surveyed test-specific load-balancer/Nginx files
|
||||
- Create: test certificate through the existing managed mechanism
|
||||
@@ -487,12 +495,14 @@ secrets in the ordinary evidence archive.
|
||||
|
||||
**Step 3: Complete human acceptance**
|
||||
|
||||
Every row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly blocking.
|
||||
Every private-server row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly
|
||||
blocking. Only the Mac REST row may be `DEFERRED_PRE_PROJECT_B` under the dated owner amendment.
|
||||
|
||||
**Step 4: Record the gate**
|
||||
|
||||
Record exact SHAs/images, workspace revision, preprocessing identity/counts, session ID, report
|
||||
digest, rollback status, and explicit `PROJECT_A_PASS` or `PROJECT_A_FAIL`.
|
||||
digest, rollback status, and explicit `PROJECT_A_PRIVATE_PASS` or `PROJECT_A_FAIL`. A private PASS
|
||||
does not authorize Project B while the deferred gate remains open.
|
||||
|
||||
**Step 5: Stop on FAIL**
|
||||
|
||||
|
||||
@@ -13,6 +13,11 @@
|
||||
## Preconditions
|
||||
|
||||
- Project A automated and human reports are PASS and explicitly owner-approved.
|
||||
- The Mac `rest_api` installation passes source validation and connection diagnostics with its
|
||||
per-installation key.
|
||||
- The dual-key observation has lasted at least 48 hours and includes two scheduled 03:00 ETL cycles.
|
||||
- `legacy-shared` is revoked; v1 remains successful and the legacy credential is proven `401`.
|
||||
- The current survey decision is `SURVEY_GO_PROJECT_B`, not only the private Project A decision.
|
||||
- Application SHA, workspace SHA, images, Project A report digest, and rollback configuration match
|
||||
the accepted evidence.
|
||||
- The production route is closed before authentication/session-storage changes.
|
||||
|
||||
@@ -290,10 +290,14 @@ ThothII, and core → Supabase DWH/auth session schema/Qdrant/Ollama/LLM/Authent
|
||||
Separate files owned by the new ThothII installation, workspace curator, Nginx, load balancer,
|
||||
Aritmolab, Authentik, and Supabase. Mark shared files as owner-gated.
|
||||
|
||||
**Step 3: State GO or NO-GO**
|
||||
**Step 3: State the scoped GO or NO-GO decisions**
|
||||
|
||||
GO requires all mandatory paths, permissions, backup owners, and rollback boundaries. NO-GO must
|
||||
name concrete missing facts and the person/system needed to resolve them.
|
||||
State both `SURVEY_GO_PROJECT_A_PRIVATE` and `SURVEY_GO_PROJECT_B`. The private decision requires
|
||||
all paths, permissions, backup owners and rollback boundaries used by Project A; it may defer
|
||||
public-origin, load-balancer, Authentik and Mac REST closeout facts that Project A does not mutate.
|
||||
The Project B decision requires every shared/public fact plus the Mac acceptance, completed
|
||||
observation window and revoked legacy credential. Each NO-GO must name concrete missing facts and
|
||||
the person/system needed to resolve them.
|
||||
|
||||
**Step 4: Hash and retain the report**
|
||||
|
||||
|
||||
Reference in New Issue
Block a user