From 14d14bf4a084adb2759af254d39ee12b6cdc9e7c Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Tue, 25 Aug 2026 21:05:13 +0300 Subject: [PATCH] Document final local launch verification --- docs/verification.md | 37 ++++++++++++++++++++++++++++++++++ scripts/kind-rolling-verify.sh | 2 ++ 2 files changed, 39 insertions(+) diff --git a/docs/verification.md b/docs/verification.md index e6d7e72..4ed8ef3 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -3524,3 +3524,40 @@ promoted. `https://whoneedhelp.imalto.site/healthz/ready` returned the exact ready payload after verification. Production, the frozen hackathon test, shared Caddy, and the public Git remote were not changed or pushed. + +# 2026-08-25 staff-directory and final local quality recheck + +- Read-only inspection of the development database found the two deployed GIN + trigram indexes used by the staff user directory + (`users_email_trigram_index` and `users_display_name_trigram_index`) plus the + cursor-order index (`users_moderation_cursor_index`). With sequential scans + disabled only for an `EXPLAIN` proof, PostgreSQL selected both trigram indexes + through a `BitmapOr`. On the current 1,016-user development data set the + normal planner selected a sequential scan because its estimated cost was + lower; this observation is not a million-user performance claim. +- The authenticated staff workspace was exercised read-only at desktop + 1280x800 and mobile 390x844 viewports. Overview, cursor-paginated user search + and detail, support/legal, moderation, analytics, and audit-log screens + rendered without current browser-console errors. Searching for the existing + `SimpleTest` account returned exactly that account. No user status, role, + support case, moderation record, or audit record was changed. +- The first isolated quality attempt correctly failed ShellCheck `SC2016` on an + intentional container-side expansion in the rolling verifier. The command is + now locally documented with a scoped ShellCheck suppression matching the + existing container-side expansion pattern; no runtime behaviour changed. +- The complete replacement unit + `codex-heavy-wnh-quality-20260825-r2-20260825-205940-1130636.service` + completed successfully in 2 minutes 46.905 seconds with a 281 MiB memory + peak and zero swap use. ExUnit reported 487 passing tests. All configured + compiler, formatting, xref, Credo, Sobelow, Dialyzer, dependency, Compose, + Helm, migration, rollback, observability, infrastructure-image, and final + release-image gates passed. The final Debian 13.6 release image reported zero + detected vulnerabilities at the configured scan severity. +- Exact post-run inspection found no container, network, volume, or temporary + audit/security image with the run identifiers + `wnh_quality_202608251759401130640` or + `20260825175940-1130640`. Both development web replicas had no matched error, + exception, crash, failure, or timeout log entry during the inspected preceding + hour. This was local verification only: production, the frozen hackathon + deployment, shared Caddy, and the public Git remote were not changed or + pushed. diff --git a/scripts/kind-rolling-verify.sh b/scripts/kind-rolling-verify.sh index 1dc9f4f..b431e8f 100755 --- a/scripts/kind-rolling-verify.sh +++ b/scripts/kind-rolling-verify.sh @@ -161,6 +161,8 @@ web_readiness_snapshot() { : >"$jsonl_file" for pod in "${web_pods[@]}"; do + # PORT is intentionally expanded inside each web container. + # shellcheck disable=SC2016 if ! body=$( "${kube[@]}" exec -c web "$pod" -- sh -c \ 'curl --silent --show-error --fail --max-time 2 \