Skip to content

Latest commit

 

History

History
74 lines (61 loc) · 6.83 KB

File metadata and controls

74 lines (61 loc) · 6.83 KB

Operations index

This page routes operators to the maintained procedure or reference that owns a task. It does not replace the engineering status or turn a recorded result into current readiness.

Start with the documentation hub for the full corpus. For routine local operation use the operational runbook; for a production-shaped incident use the on-call runbooks. The tables below cover the more specialized material in this directory.

Current procedures and controlled gates

These documents own commands, preconditions, or acceptance boundaries that an operator may need now. A document that requires separate authorization remains a procedure, not an authorization to run it.

Need Owning document Boundary
Rotate the shared admin credential Admin key rotation Requires write access to the externally managed Secret; admin calls fail while the rollout runs
Prepare a fresh non-target DuckDB capability rehearsal Current non-target scratch rehearsal READY_NOT_AUTHORIZED; identity preparation is local, while execution needs separate exact authorization
Configure Terraform's AWS identity AWS OIDC setup Repository and AWS owner inputs must already exist
Attach a production CDC source Production CDC source onboarding Complete the decision record and no-go checks before rollout
Run or triage controlled fault injection Chaos runbook Preserve the severity and exit criteria
Resume CI-soak work CI-soak next-session runbook Live repository facts override copied handoff text; external actions still need authority
Decide on external coverage reporting Codecov setup No workflow uploads coverage; the tracked config is policy the claims validator pins
Limit delegated agent retries after a failed atomic item Cycle guard Two attempts per named atomic item; one read-only diagnostic after FAIL; no raw retry of the same workload; preflight is mandatory before delegating
Back up, restore, or rehearse host loss Disaster recovery runbook Follow the data-preservation and drill boundaries
Recover dependencies after the recorded Colima lifecycle gap External dependency recovery gate The recorded pass does not establish workload or production readiness
Operate Flink jobs Flink operator reference Detailed job and checkpoint guidance; general service triage stays in the operational runbook
Install or upgrade through Helm Helm deployment reference Production values remain fail-closed until their owner inputs are supplied
Prepare a GitHub or registry release Publication checklist A checklist does not authorize push, publish, or release actions
Exercise PostgreSQL control-plane guarantees Control-plane testing Requires the live database path described by the guide
Receive independent security-test evidence Third-party pen-test intake Intake criteria do not claim that an engagement or test exists

Active designs and reference material

These files explain a live design boundary or implementation topology. They are inputs to later work, not general-purpose procedures.

Material Role Operator boundary
API DuckDB persistence and recovery design Current preservation/recovery authorization-boundary owner Status is CAPABILITY_REHEARSAL_REQUIRED; it is not an approved operator runbook
CI-soak Compose foundation Topology and historical implementation reference Its runtime-status sequence is superseded; resume from the current CI-soak runbook above
OpenSSF security posture Scope and interpretation of free supply-chain posture signals Neither Scorecard nor self-certification is a penetration test or attestation
Windows verification memory What the sharded Windows suite's per-process budget is spent on, measured Describes the test host; pinning the same variables in the API image is an owner decision that page does not take

Consumed and dated records

The following files preserve point-in-time outcomes and are not current instructions. Do not execute consumed identities or infer present readiness from an old PASS or blocker.

Record Preserved result Current use
E22 non-target scratch rehearsal CONSUMED_TRANSPORT_BLOCKED Archived evidence only; do not execute or reuse
E24 non-target scratch rehearsal CONSUMED_SCRATCH_REHEARSAL_BLOCKED Archived evidence only; do not execute or reuse
E26 non-target scratch rehearsal Executed once; SCRATCH_REHEARSAL_BLOCKED Archived pre-execution contract; do not execute or reuse
API DuckDB recovery chronology, 2026-08-10 to 2026-08-23 Interleaved design-and-execution snapshot through 2026-08-23 historical only; not executable. Current preservation and authorization boundaries belong to the recovery design above
External pentest evidence blocker, 2026-08-01 BLOCKED_NO_ENGAGEMENT_OR_EVIDENCE at the recorded audit Use the current intake guide and engineering status for present truth
npm environment approval verification, 2026-08-03 Read-only PASS at the recorded identity Evidence of that check only
npm environment approval blocker, 2026-08-01 BLOCKED_ENVIRONMENT_ABSENT before the later verification Superseded point-in-time evidence

Maintenance contract

  • List every other tracked Markdown file directly under docs/operations/ exactly once in one of the three sections above.
  • Classify by the document's declared status and authority boundary, not by a filename containing runbook or gate.
  • Keep immutable results intact. When a procedure is superseded, add the replacement relationship before moving the old narrative to the archive.
  • Run tests/unit/test_docs_operations_index.py and the documentation link gate after changing this directory.