add engineering/0023/SESSION-0023.0-TRANSCRIPT-2026-06-12T01-19--2026-06-12T02-00.md + replace placeholder/variant SESSION-0023.0-TRANSCRIPT-2026-06-12T01-19--INPROGRESS.md
This commit is contained in:
+60
-5
@@ -5,11 +5,28 @@
|
||||
> Type: planning-and-executing
|
||||
> Posture: yolo
|
||||
> Claude-Session: 41a32da1-5f00-4cb9-81a1-edd730cfd9e2
|
||||
> Status: **PLACEHOLDER — claimed at session start; finalized at session end.**
|
||||
>
|
||||
> This file reserves session ID 0023 for engineering. The driver replaces this
|
||||
> body with the full transcript and renames the file to its final
|
||||
> SESSION-0023.0-TRANSCRIPT-2026-06-12T01-19--<end>.md form at session end.
|
||||
> End: 2026-06-12T02-00 (PST)
|
||||
> Status: **FINALIZED.** gitea-forge-backups SLICE-5 + marker-refresh fix shipped
|
||||
> (PRs #59, #60, #61 merged); capability SLICE-1..5 complete.
|
||||
|
||||
## Next session
|
||||
|
||||
```
|
||||
/goal Brainstorm engineering#44 — Solution Design for the two-tier E2E gate machinery (hermetic local harness per merge + same suite on PPE per deploy), handbook §10.3 as primary input (feature P1 under epic #26)
|
||||
```
|
||||
|
||||
gitea-forge-backups is done. The next open work stream is engineering#44 (E2E gate
|
||||
machinery) — a **brainstorming** session to produce its Solution Design.
|
||||
|
||||
## Pipeline status (§9)
|
||||
|
||||
Gitea is **bootstrap infra outside flotilla** (no PPE/blue-green, spec D-6). The
|
||||
§9 pipeline's stand-in is the **scratch-environment gate** (§6.8/§7.3): T-1..T-4
|
||||
green on a scratch Gitea + scratch bucket before touching the live forge. This
|
||||
session satisfied it — **T-3 green against the scratch bucket** via the deployed
|
||||
off-VM checker before relying on the live alert. No UI surface → **E2E browser
|
||||
tests N/A**. The marker fix was verified directly on the live forge VM (additive,
|
||||
read-only). No flotilla deploy / release tag applies to this bootstrap-infra work.
|
||||
|
||||
## Launch prompt
|
||||
|
||||
@@ -67,6 +84,33 @@ per-run marker lands). PR #59 merged → main `36acc77`. Live VM script == repo.
|
||||
- Finalize RB-3/RB-4 in `infra/backup-restore-gitea.md`; DOC-2 update; spec SLICE-5
|
||||
done + changelog.
|
||||
|
||||
## Outcome — gitea-forge-backups SLICE-5 + marker fix COMPLETE
|
||||
|
||||
Both halves of the goal shipped; the gitea-forge-backups capability (SLICE-1..5) is
|
||||
now complete (recovery points exist off-host, retention proven, restore proven,
|
||||
lapses surfaced).
|
||||
|
||||
- **Marker-refresh fix (PR #59, merged):** root-caused to `objectCreator` being
|
||||
create-only (can't overwrite the fixed-name marker → HTTP 403, proven from the
|
||||
job journal). Fixed to unique per-run marker names; verified live (`systemctl
|
||||
start gitea-backup.service` exits 0, fresh marker lands). The backup job had been
|
||||
failing every 4 h for ~27 h — now green.
|
||||
- **SLICE-5 freshness checker (PR #60, merged):** off-VM Cloud Function gen2 +
|
||||
Cloud Scheduler (30 min) + log-based alert policy → email channel; ALR-1 (stale
|
||||
snapshot/marker > 6 h) + ALR-2 (on-VM `OnFailure=` failure-marker). Dedicated
|
||||
read-only runtime SA + dedicated build SA — VM's create-only SA untouched.
|
||||
**T-3 green** via the deployed off-VM path against the scratch bucket. RB-3/RB-4
|
||||
finalized; DOC-2 updated; spec v0.2.5.
|
||||
- **Alert scope fix (PR #61, merged):** scoped the alert policy to the live bucket
|
||||
so T-3 scratch runs don't page the operator.
|
||||
- **Plan archived:** `plans/2026-06-12-gitea-backups-slice-5.md` (on main, 617789b).
|
||||
|
||||
**Live GCP state (project wiggleverse, config gitea):** function
|
||||
`gitea-backup-freshness-checker` ACTIVE; scheduler `gitea-backup-freshness-30m`
|
||||
ENABLED; alert policy `11761102391334510705` (scoped to live bucket) → email
|
||||
channel `8452564362810973845` (ben@wiggleverse.org). Steady-state scheduled run
|
||||
logs `GITEA_BACKUP_OK`. Checker SA has read on the scratch bucket (for T-3 reruns).
|
||||
|
||||
## Deferred decisions
|
||||
|
||||
_Autonomous-mode low-confidence calls the driver made and would have
|
||||
@@ -87,3 +131,14 @@ finalize. Empty if none._
|
||||
- **ALR-2 via on-VM OnFailure failure-marker:** adds a small systemd drop-in on the
|
||||
forge VM. Reversible/additive. Flag if the operator prefers ALR-2 left as
|
||||
covered-by-staleness only (no VM-side change).
|
||||
- **One-time T-3 test alert email (FYI):** before the alert policy was scoped to the
|
||||
live bucket (PR #61), T-3 emitted `GITEA_BACKUP_ALERT` logs against the scratch
|
||||
bucket that matched the policy — so a single test alert email may have reached
|
||||
ben@wiggleverse.org around 08:48–08:51 UTC. It auto-resolves (steady state is OK)
|
||||
and future T-3 runs no longer page (scoped to the live bucket).
|
||||
- **Project IAM grants during provisioning (FYI):** granted `artifactregistry.admin`
|
||||
to the `gcf-admin-robot` + `gcp-sa-cloudbuild` service agents (standard first-deploy
|
||||
fix) and `cloudbuild.builds.builder` to the dedicated `gitea-checker-build` SA.
|
||||
Briefly granted then **reverted** four roles on the compute/VM SA (it doubles as
|
||||
the backup uploader and must stay create-only) — confirmed back to zero project
|
||||
roles.
|
||||
Reference in New Issue
Block a user