Record final pilot readiness recheck

This commit is contained in:
SimpleTest 2026-08-13 01:37:08 +03:00
parent 0393cadcad
commit 9c482603af

View File

@ -1,8 +1,82 @@
# Who Need Help — implementation verification # Who Need Help — implementation verification
Observed through 2026-08-12 in the local workspace. This report separates observed Observed through 2026-08-13 in the local workspace. This report separates observed
results from product limits and unknown production properties. results from product limits and unknown production properties.
## Current local candidate and operations recheck on 2026-08-13
- Application source candidate `0393cadcadf001b50901af05cf5950139b6808f0` passed the
complete isolated `scripts/quality.sh` pipeline in user-systemd unit
`codex-heavy-wnh-quality-0393cad-20260813-012423-3600824.service`.
ExUnit reported 469 passing tests with seed `346927`; the fourteen browser
map tests passed; every configured quality and security gate passed; and the
final Debian 13.6 runtime-image scan reported zero detected
vulnerabilities. The unit exited successfully after 4 minutes 22.551
seconds with a measured 325.8 MiB systemd-unit memory peak. One Oban
notifier process logged an Ecto Sandbox owner-exit diagnostic while the test
owner was shutting down; the suite still completed with 469 passes and a
successful unit result.
- After this evidence was recorded, documentation-only updates became the local
release candidate. A fresh read-only production release plan compared the
then-current documentation revision with
production revision `dafcdb36cbe221af0c880fd05da3321e181ddd2c`. It observed
seventeen pending
commits, one reviewed `application_safe` migration
(`20260812120611_allow_inbox_only_nearby_subscriptions.exs`), external
PostgreSQL 18.4, unchanged shared-edge routing, and all twelve environment
capability groups `READY`. The plan completed without changing production.
- Production's configured rate-limit map contains all twelve required
authentication and anonymous-intake policies with positive limits and
windows. The implementation has a retained local one-CPU benchmark, but the
selected product thresholds have not yet been validated against real-user
behaviour or an approved abuse policy; they are not presented as measured
capacity limits.
- The scheduled off-site backup that began on 2026-08-13 at 00:00 EEST
completed successfully after 4 minutes 31.812 seconds. It created Restic
snapshot
`112640d797b843c6388a5d68a5348294483a7b8dc1f46951695cc0feeb152abd`,
verified the custom-format PostgreSQL backup and checksum, and passed the
isolated restore drill. The restore-verified heartbeat was written with mode
`0600` on the independent BuyVM monitor host at
`/home/simple/.local/state/who-need-help/production-backup.json`.
- The independent BuyVM monitor remained enabled and active on its minute
schedule. Its fresh check at `2026-08-12T22:48:15Z` reported production
readiness and the authenticated aggregate metrics scrape `up`. Its installed
configuration still has no backup-freshness section because no operator
maximum acceptable backup age has been selected. The heartbeat therefore
proves current backup/restore execution but does not yet produce a stale-
backup alert or establish an RPO.
- The connected physical phone again passed
`scripts/verify-play-installed-android.sh`: package
`org.whoneedhelp.mobile`, version `0.1.2 (3)`, installer Google Play, a
signing identity from the protected Play App Signing set, verified
`whoneedhelp.com` App Link resolving to `MainActivity`, and no Android claim
on the browser-only OAuth callback.
- The local candidate is deployed only to the development environment. This
recheck did not apply the production release, modify the frozen hackathon
test deployment or shared Caddy, save Google Play Console fields, or push the
public Git remote.
### Frozen-test memory observation on 2026-08-13
- A read-only server inspection found production healthy at about 197 MiB of
container memory, while the frozen `test.whoneedhelp.com` application used
about 2.47 GiB. BEAM attributed about 2.45 GiB of the frozen-test VM to ETS;
table `prometheus_metrics_dist` contained 10,748,076 pending raw histogram
samples and occupied 290,222,909 machine words at the first sample.
- The frozen test runs commit
`cf7bacdf61ffb171ebac85e32dfcf12bc6972d59`, which predates the supervised
ten-second Prometheus distribution drain added in commit `882df25`. A second
read-only sample 13.071 seconds later contained 144 more rows. This directly
establishes an unbounded-in-that-revision telemetry buffer as the dominant
memory consumer; it does not establish an application-data leak.
- The test remained externally ready and its container had not been OOM-killed.
No restart, table mutation, image replacement, Caddy change, or frozen-test
checkout change was made. The corrective telemetry code exists in the local
candidate and current production ancestry, but applying it to the frozen
hackathon deployment would change submitted project material and therefore
requires a separate decision after judging.
## Current launch-boundary and transactional-email proof on 2026-08-12 ## Current launch-boundary and transactional-email proof on 2026-08-12
- A follow-up SMTP-envelope regression run completed successfully in isolated - A follow-up SMTP-envelope regression run completed successfully in isolated