This page routes operators to the maintained procedure or reference that owns a task. It does not replace the engineering status or turn a recorded result into current readiness.
Start with the documentation hub for the full corpus. For routine local operation use the operational runbook; for a production-shaped incident use the on-call runbooks. The tables below cover the more specialized material in this directory.
These documents own commands, preconditions, or acceptance boundaries that an operator may need now. A document that requires separate authorization remains a procedure, not an authorization to run it.
| Need | Owning document | Boundary |
|---|---|---|
| Rotate the shared admin credential | Admin key rotation | Requires write access to the externally managed Secret; admin calls fail while the rollout runs |
| Prepare a fresh non-target DuckDB capability rehearsal | Current non-target scratch rehearsal | READY_NOT_AUTHORIZED; identity preparation is local, while execution needs separate exact authorization |
| Configure Terraform's AWS identity | AWS OIDC setup | Repository and AWS owner inputs must already exist |
| Attach a production CDC source | Production CDC source onboarding | Complete the decision record and no-go checks before rollout |
| Run or triage controlled fault injection | Chaos runbook | Preserve the severity and exit criteria |
| Resume CI-soak work | CI-soak next-session runbook | Live repository facts override copied handoff text; external actions still need authority |
| Decide on external coverage reporting | Codecov setup | No workflow uploads coverage; the tracked config is policy the claims validator pins |
| Limit delegated agent retries after a failed atomic item | Cycle guard | Two attempts per named atomic item; one read-only diagnostic after FAIL; no raw retry of the same workload; preflight is mandatory before delegating |
| Back up, restore, or rehearse host loss | Disaster recovery runbook | Follow the data-preservation and drill boundaries |
| Recover dependencies after the recorded Colima lifecycle gap | External dependency recovery gate | The recorded pass does not establish workload or production readiness |
| Operate Flink jobs | Flink operator reference | Detailed job and checkpoint guidance; general service triage stays in the operational runbook |
| Install or upgrade through Helm | Helm deployment reference | Production values remain fail-closed until their owner inputs are supplied |
| Prepare a GitHub or registry release | Publication checklist | A checklist does not authorize push, publish, or release actions |
| Exercise PostgreSQL control-plane guarantees | Control-plane testing | Requires the live database path described by the guide |
| Receive independent security-test evidence | Third-party pen-test intake | Intake criteria do not claim that an engagement or test exists |
These files explain a live design boundary or implementation topology. They are inputs to later work, not general-purpose procedures.
| Material | Role | Operator boundary |
|---|---|---|
| API DuckDB persistence and recovery design | Current preservation/recovery authorization-boundary owner | Status is CAPABILITY_REHEARSAL_REQUIRED; it is not an approved operator runbook |
| CI-soak Compose foundation | Topology and historical implementation reference | Its runtime-status sequence is superseded; resume from the current CI-soak runbook above |
| OpenSSF security posture | Scope and interpretation of free supply-chain posture signals | Neither Scorecard nor self-certification is a penetration test or attestation |
| Windows verification memory | What the sharded Windows suite's per-process budget is spent on, measured | Describes the test host; pinning the same variables in the API image is an owner decision that page does not take |
The following files preserve point-in-time outcomes and are not current instructions. Do not execute consumed identities or infer present readiness from an old PASS or blocker.
| Record | Preserved result | Current use |
|---|---|---|
| E22 non-target scratch rehearsal | CONSUMED_TRANSPORT_BLOCKED |
Archived evidence only; do not execute or reuse |
| E24 non-target scratch rehearsal | CONSUMED_SCRATCH_REHEARSAL_BLOCKED |
Archived evidence only; do not execute or reuse |
| E26 non-target scratch rehearsal | Executed once; SCRATCH_REHEARSAL_BLOCKED |
Archived pre-execution contract; do not execute or reuse |
| API DuckDB recovery chronology, 2026-08-10 to 2026-08-23 | Interleaved design-and-execution snapshot through 2026-08-23 | historical only; not executable. Current preservation and authorization boundaries belong to the recovery design above |
| External pentest evidence blocker, 2026-08-01 | BLOCKED_NO_ENGAGEMENT_OR_EVIDENCE at the recorded audit |
Use the current intake guide and engineering status for present truth |
| npm environment approval verification, 2026-08-03 | Read-only PASS at the recorded identity | Evidence of that check only |
| npm environment approval blocker, 2026-08-01 | BLOCKED_ENVIRONMENT_ABSENT before the later verification |
Superseded point-in-time evidence |
- List every other tracked Markdown file directly under
docs/operations/exactly once in one of the three sections above. - Classify by the document's declared status and authority boundary, not by a
filename containing
runbookorgate. - Keep immutable results intact. When a procedure is superseded, add the replacement relationship before moving the old narrative to the archive.
- Run
tests/unit/test_docs_operations_index.pyand the documentation link gate after changing this directory.