docs: defer DWH client cutover before Project B
This commit is contained in:
@@ -12,13 +12,16 @@
|
||||
|
||||
## Preconditions
|
||||
|
||||
- Common survey result is GO and its digest is recorded.
|
||||
- Common survey result is `SURVEY_GO_PROJECT_A_PRIVATE` and its digest is recorded.
|
||||
- Every path below is replaced by the exact survey result before execution.
|
||||
- No production Nginx/load-balancer/sidebar/Authentik change is in scope.
|
||||
- The old stack remains running only until backup verification finishes; old and new stacks never
|
||||
run together.
|
||||
- The server's workspace deploy credential remains read-only. A curator with write access publishes
|
||||
the workspace change.
|
||||
- Owner amendment 2026-08-21 defers live Mac `rest_api` acceptance and `legacy-shared` revocation to
|
||||
the mandatory pre-Project-B gate. It does not authorize stop/start; those require a later explicit
|
||||
owner gate even after private preparation is complete.
|
||||
|
||||
### Task 1: Freeze exact inputs
|
||||
|
||||
@@ -121,11 +124,11 @@ git push --set-upstream origin codex/psd-direct-transport
|
||||
|
||||
Merge through the repository's normal review path. Record the resulting `main` SHA.
|
||||
|
||||
**Step 6: Prove the Mac REST installation is unchanged**
|
||||
**Step 6: Record the deferred Mac REST proof**
|
||||
|
||||
The owner pulls/activates the new workspace commit on the Mac, confirms selected transport
|
||||
`rest_api`, runs workspace inspection/connection diagnostics, and records PASS. Project A server
|
||||
deployment stops if this cross-installation proof is not available.
|
||||
Do not change the Mac during Project A. Record `DEFERRED_PRE_PROJECT_B`, the unchanged expected
|
||||
transport `rest_api`, and the exact future diagnostics. The proof must become PASS before Project B,
|
||||
after protected delivery/configuration of the per-installation key.
|
||||
|
||||
### Task 3: Back up and stop the legacy installation
|
||||
|
||||
@@ -416,6 +419,11 @@ remembered-session survival after core restart. Do not retain cookie jars after
|
||||
|
||||
### Task 10: Optionally add the private network-path test
|
||||
|
||||
**Current scope boundary (owner, 2026-08-21):** omit this entire task and keep Project A
|
||||
loopback-only. Any future use requires a separate shared-infrastructure authorization after the
|
||||
public-origin and load-balancer activities pass; the Project A private survey decision alone is
|
||||
insufficient.
|
||||
|
||||
**Files:**
|
||||
- Modify only surveyed test-specific load-balancer/Nginx files
|
||||
- Create: test certificate through the existing managed mechanism
|
||||
@@ -487,12 +495,14 @@ secrets in the ordinary evidence archive.
|
||||
|
||||
**Step 3: Complete human acceptance**
|
||||
|
||||
Every row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly blocking.
|
||||
Every private-server row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly
|
||||
blocking. Only the Mac REST row may be `DEFERRED_PRE_PROJECT_B` under the dated owner amendment.
|
||||
|
||||
**Step 4: Record the gate**
|
||||
|
||||
Record exact SHAs/images, workspace revision, preprocessing identity/counts, session ID, report
|
||||
digest, rollback status, and explicit `PROJECT_A_PASS` or `PROJECT_A_FAIL`.
|
||||
digest, rollback status, and explicit `PROJECT_A_PRIVATE_PASS` or `PROJECT_A_FAIL`. A private PASS
|
||||
does not authorize Project B while the deferred gate remains open.
|
||||
|
||||
**Step 5: Stop on FAIL**
|
||||
|
||||
|
||||
Reference in New Issue
Block a user