docs: defer DWH client cutover before Project B

This commit is contained in:
User
2026-08-21 14:35:37 +02:00
parent 7118950416
commit 9974fb4bc0
12 changed files with 244 additions and 86 deletions
@@ -46,6 +46,21 @@ a credential must read a protected file or use an echo-free prompt.
The detailed evidence directory is a protected path on the server selected during the survey. The
repository receives only redacted reports after explicit owner review.
## Owner-approved sequencing amendment — 2026-08-21
The Mac `rest_api` acceptance and revocation of `legacy-shared` move to a mandatory gate immediately
before Project B. The survey therefore records two distinct decisions:
- `SURVEY_GO_PROJECT_A_PRIVATE`: technical prerequisite for requesting Project A private execution;
- `SURVEY_GO_PROJECT_B`: the complete shared-infrastructure decision, including Mac acceptance,
observation and legacy revocation.
The amendment authorizes the read-only survey and static preparation of non-secret Project A
candidate facts and artifacts. While the current decision is `SURVEY_NO_GO`, it does not authorize
creating installation roots, cloning/building the candidate, creating protected configuration or
backup state, stopping the legacy stack, starting the new stack, changing public ingress, or
starting Project B. Those remain separate explicit gates after the scoped survey passes.
### Task 1: Freeze the planning source
**Files:**
@@ -100,10 +115,13 @@ load balancer, Aritmolab, Authentik, Supabase, the DWH, and protected credential
If an Authentik credential cannot be located, stop and ask the owner. If a configuration owner or
rollback boundary is unclear, stop; do not infer authority from file readability.
**Step 3: Review the survey GO/NO-GO**
**Step 3: Review the scoped survey GO/NO-GO**
Expected: GO requires a verified old-stack recovery path, a new-installation root, enough resources,
a read-only DWH path, and no unresolved shared-infrastructure mutation.
Expected: `SURVEY_GO_PROJECT_A_PRIVATE` requires a verified old-stack recovery path, an approved
new-installation root, enough resources, a direct read-only DWH path, workspace/model inputs, and
no unresolved mutation in the private Project A scope. Public-origin, load-balancer and Authentik
unknowns may remain explicitly deferred only while Project A is loopback-only and Task 10 is
omitted. `SURVEY_GO_PROJECT_B` retains the complete survey requirements.
**Step 4: Checkpoint the survey**
@@ -115,9 +133,10 @@ Hash the protected report and record only its path, SHA-256, timestamp, and GO r
- Execute: `docs/plans/2026-08-20-psd-server-project-a-standalone.md`
- Complete: `docs/testing/evidence/psd-server-project-a-report-template.md`
**Step 1: Confirm the survey is GO**
**Step 1: Confirm the survey is GO for Project A private scope**
Expected: the survey report hash matches the journal and no unresolved blocker remains.
Expected: the survey report hash matches the journal and no unresolved blocker remains inside the
Project A private scope. Before any stop/start, obtain a separate explicit owner authorization.
**Step 2: Execute Project A task-by-task**
@@ -126,12 +145,14 @@ Do not configure Authentik, change the production Aritmolab sidebar, or open the
**Step 3: Run the Project A human guide**
Follow `docs/testing/psd-server-project-a-manual.md`. Record PASS/FAIL for every case; do not infer
manual PASS from automated output.
manual PASS from automated output. The Mac REST row may be
`DEFERRED_PRE_PROJECT_B` only under the dated owner amendment.
**Step 4: Close the Project A report**
Expected: automated gates and the human guide are PASS; one harmless PSD session reached F8 and
produced validated read-only SQL; rollback remains available.
produced validated read-only SQL; rollback remains available. The accepted report must list the
Mac REST item as an explicit deferred prerequisite rather than silently treating it as PASS.
**Step 5: Obtain explicit owner approval**
@@ -145,6 +166,10 @@ Record the approval and report digest. Project B remains forbidden without it.
**Step 1: Recheck source and running images**
Before freezing the candidate, close the pre-Project-B gate: validate the Mac installation with its
per-installation key, finish the 48-hour observation window including two 03:00 ETL cycles, revoke
`legacy-shared`, prove legacy `401` and v1 success, and obtain `SURVEY_GO_PROJECT_B`.
Run the Project A plan's identity commands again. Record application SHA, workspace SHA, core image
ID, frontend image ID, Qdrant image digest, Ollama image digest, and local-auth configuration revision.