docs: defer DWH client cutover before Project B
This commit is contained in:
@@ -4,6 +4,11 @@
|
||||
|
||||
**Status:** Approved by the owner
|
||||
|
||||
**Owner sequencing amendment (2026-08-21):** the Mac `rest_api` acceptance and revocation of
|
||||
`legacy-shared` are deferred to one mandatory pre-Project-B gate. This permits the bounded survey
|
||||
and static, non-mutating Project A private preparation to proceed without changing the Mac. It does not
|
||||
authorize stopping the legacy stack, starting the new stack, opening ingress, or beginning Project B.
|
||||
|
||||
**Design-time application baseline:** `main` at `5c0dc8c` (execution must freeze and record the
|
||||
then-current `origin/main` SHA)
|
||||
|
||||
@@ -70,10 +75,14 @@ The program consists of one non-mutating common survey followed by two independe
|
||||
projects:
|
||||
|
||||
```text
|
||||
Common Survey PASS
|
||||
Common Survey PASS for Project A private scope
|
||||
-> Project A automated PASS
|
||||
-> Project A human PASS
|
||||
-> explicit authorization
|
||||
-> Mac REST acceptance
|
||||
-> 48-hour dual-key observation covering two 03:00 ETL cycles
|
||||
-> legacy-shared revocation and negative proof
|
||||
-> full pre-Project-B survey PASS
|
||||
-> explicit Project B authorization
|
||||
-> Project B automated PASS
|
||||
-> Project B human PASS
|
||||
-> final cutover acceptance
|
||||
@@ -136,7 +145,8 @@ proved safe.
|
||||
|
||||
1. Freeze exact application and workspace SHAs and require clean source trees.
|
||||
2. Publish and validate the multi-transport `psd-clinical` descriptor through the curator workflow.
|
||||
3. Prove the Mac installation still selects REST and remains valid.
|
||||
3. Preserve the Mac REST binding unchanged; its live acceptance is deferred to the mandatory
|
||||
pre-Project-B gate.
|
||||
4. Prepare the new source clone and protected operator/runtime directories beside the old source.
|
||||
5. Extract only approved configuration facts from the legacy installation.
|
||||
6. Create and verify backups and a restart recipe for the legacy stack.
|
||||
@@ -182,12 +192,17 @@ Project A requires:
|
||||
- optional private-route positive and negative isolation evidence when that route is used;
|
||||
- completed human manual-test report with an explicit PASS.
|
||||
|
||||
The Mac row may be recorded only as `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. It is
|
||||
not part of the private server acceptance, but it must become PASS before Project B starts.
|
||||
|
||||
Project A does not modify the production Aritmolab sidebar, production public route, or Authentik.
|
||||
|
||||
## Project B — Authentik and Aritmolab Integration
|
||||
|
||||
Project B begins only from the frozen, accepted Project A source, images, workspace revision, and
|
||||
PASS report.
|
||||
PASS report. It also requires the deferred Mac REST acceptance, the full 48-hour observation
|
||||
window (including two scheduled 03:00 ETL cycles), revocation of `legacy-shared`, proof that the
|
||||
legacy credential receives `401`, and the full pre-Project-B survey gate.
|
||||
|
||||
### Final request and data flow
|
||||
|
||||
|
||||
Reference in New Issue
Block a user