Document current production cleanup proof

This commit is contained in:
SimpleTest 2026-08-09 08:00:05 +03:00
parent 3c731b5aaf
commit 5990a1935e
2 changed files with 70 additions and 10 deletions

View File

@ -7,12 +7,14 @@ Do not replace unknown values with estimates.
## 1. Freeze the candidate ## 1. Freeze the candidate
- [ ] Record the candidate Git revision and immutable application, PostGIS, - [x] Record the candidate Git revision and immutable image references for the
socket-proxy, and edge image references. services that actually exist in the target topology, plus the externally
- [ ] Confirm that the target is the independent production checkout, Compose hosted database version. Production has no project-local PostGIS or
socket-proxy container.
- [x] Confirm that the target is the independent production checkout, Compose
project, database, volumes, secrets, Google/Firebase project, SMTP project, database, volumes, secrets, Google/Firebase project, SMTP
credentials, and Android identity. credentials, and Android identity.
- [ ] Keep development, hackathon test, and production credentials separate. - [x] Keep development, hackathon test, and production credentials separate.
- [x] Run the repository quality suite and retain its non-secret evidence. - [x] Run the repository quality suite and retain its non-secret evidence.
```bash ```bash
@ -20,12 +22,14 @@ git rev-parse HEAD
./scripts/quality.sh ./scripts/quality.sh
``` ```
The 2026-08-09 isolated run at local revision `e779188` exited successfully: The 2026-08-09 isolated run covering the E2E-cleanup implementation now
451 ExUnit tests passed, all configured compiler/format/xref/Credo/Sobelow/ committed as `3c731b5` exited successfully: 451 ExUnit tests passed, all
Dialyzer/dependency/container/Compose/Helm/migration/rollback/observability configured compiler/format/xref/Credo/Sobelow/Dialyzer/dependency/container/
gates passed, and the final runtime image scan reported zero detected Compose/Helm/migration/rollback/observability gates passed, and the final
vulnerabilities. The exact systemd unit result and resource observation are runtime image scan reported zero detected vulnerabilities. The final
recorded in `docs/verification.md`. manifest-transport-only shell adjustment then passed `bash -n`, ShellCheck,
and the complete production browser E2E replay. Exact identities and evidence
paths are recorded in `docs/verification.md`.
## 2. Verify production configuration without exposing secrets ## 2. Verify production configuration without exposing secrets

View File

@ -2266,3 +2266,59 @@ promoted.
- This is local verification only. The new aggregate delivery counters and - This is local verification only. The new aggregate delivery counters and
authenticated metrics scrape have not yet been deployed to production, and authenticated metrics scrape have not yet been deployed to production, and
the frozen hackathon test deployment and public Git remote were not changed. the frozen hackathon test deployment and public Git remote were not changed.
# 2026-08-09 current production identity and exact E2E cleanup proof
- The observed production checkout was
`8ab30ce7f5bd0a28e1423b8da2846fe0e224f50c`. Its application container used
immutable image ID
`sha256:5df2246085afca1599ed1ea40c3f1bbcf8687dcbc73f9ec8728a9135d4ceb8a0`;
the shared edge used
`sha256:e450c305cc0a729406392dad5064f835a6f05ef45b787519023e12c8d65cadd2`.
The topology used external PostgreSQL 18.4 and had no production
project-local PostGIS or socket-proxy container. The application remained
healthy with zero restarts and no OOM kill after verification.
- Read-only hash comparisons, without printing credential values, confirmed
that production and hackathon test use different database URLs,
`SECRET_KEY_BASE` values, origins, Compose projects, SMTP passwords and
senders, and Google OAuth client IDs and secrets. Production and development
likewise use different database URLs, application secrets, hosts, Compose
projects, SMTP credentials and senders, OAuth clients, Firebase/FCM
identities, VAPID private keys, and Android Firebase values. The common
production/test operator support inbox is an intentional routing destination,
not a shared application credential.
- The isolated quality unit
`codex-heavy-wnh-quality-e2e-proof-run-20260809-20260809-073901-3859326.service`
exited successfully after 4 minutes 3 seconds with a 323.2 MiB memory peak.
All 451 ExUnit tests and every configured quality/security gate passed; the
Debian 13.6 runtime-image scan reported zero detected vulnerabilities.
- Production E2E run `production-e2e-20260809-cleanup-proof-2` passed both the
activity approval/privacy/reporting scenario and the two-person medicine
help scenario in Chromium. The isolated unit
`codex-heavy-wnh-prod-e2e-cleanup-proof2-20260809-20260809-074956-10667.service`
exited successfully after 2 minutes 17 seconds with a 53.1 MiB memory peak.
Evidence is retained at
`output/production-full-e2e/production-e2e-20260809-cleanup-proof-2/`.
- The run-scoped cleanup manifest recorded `cleanup_verified=true` and exact
target/deletion agreement for 26 record types. Non-zero totals were six
users, six user tokens, one staff role, two requests, three assignments, two
request messages, one tracking session, two reviews, one activity, two
activity participants, two activity messages, one report, one category
proposal, six audit events, two abuse signals, eleven notifications, and
fourteen push jobs. The task asserted every recorded ID absent, found no
late fixture job, and found zero remaining fixture-prefix records.
- Every tracked product-table total returned to its pre-run value. The global
Oban table contained one additional row after the run; the cause of that
concurrent global change is unknown. All fourteen run-scoped Oban job IDs
were nevertheless recorded, deleted, and individually verified absent.
- Cleanup evidence SHA-256 values were
`f2ad4be23b35401404d3435a8278d7e4050846894178b77c802a6d01222ea51a`
for `browser-console.log`,
`aa4addd980e8fdd58a22acf834397fb0c2bdff6651c7025ad1d3e4af7014115d`
for `fixture.json`, and
`b6513900d7b44aae5b1b79444df6a9de88fa0f78724f46fc81e2cbf47bf743f7`
for `fixture-cleanup.log`.
- The frozen hackathon test checkout stayed at
`cf7bacdf61ffb171ebac85e32dfcf12bc6972d59`; its application, database, and
Mailpit remained healthy, and public readiness remained `ready`. The remote
repository and hackathon-test deployment were not mutated.