4.9 KiB
Fleet Ops release acceptance
This file is release-scoped evidence, not a timeless claim. Older evidence under
artifacts/evidence/ is historical. Exact commands and production revisions are recorded
in PROJECT_STATE.md.
2026-08-21 release candidate
- Backend: 271/271 tests passed against an isolated clean PostgreSQL database.
- Browser acceptance: 155/155 Chromium tests passed in 6.0 minutes.
- Live-safe browser canary: 4/4 passed across Chromium and Firefox against the local deployed stack; unlike the acceptance suite, it never resets or mutates demo records.
- Accessibility: the principal login, dashboard, data-quality, knowledge, automation and audit routes have no automated critical/serious WCAG 2 A/AA/2.1 AA violations.
- Frontend: TypeScript, ESLint, production build, dependency audit and per-asset JS/CSS budgets passed; committed visual baselines cover the public entry and engineering story.
- Contracts: committed OpenAPI, event schema, MCP tools and all five n8n definitions match their code/manifest sources.
- Recovery: a custom-format PostgreSQL dump was restored into a disposable database; the Alembic revision and non-zero canonical table counts matched the source database.
- Operations: Prometheus/Alertmanager configuration validation passed, including the watchdog and authenticated n8n receiver route.
2026-08-21 production verification
- Immutable application revision
95c91797fa2c599443d69d9c96d83a85ee0711f7was promoted from a checksum-verified source archive after a fresh production backup. - Source revision and both OCI revision labels matched. Public readiness was green, Alembic was at head, all health-gated services were healthy and persisted demo data was retained without a deployment reset.
- Trivy found zero fixed HIGH/CRITICAL vulnerabilities in each exact production image.
- Prometheus successfully scraped the bearer-protected API target, Alertmanager carried the active delivery watchdog, and the authenticated n8n alert receiver remained active.
- The final non-destructive HTTPS canary passed 4/4 across Chromium and Firefox, including the core operator routes and a grounded answer from the real knowledge stack.
2026-08-21 resilience upgrade verification
- Immutable revision
00191e9b54ee6b961648a6e02abbb3a57957dba0was promoted from a checksum-verified archive after a verified production dump. A stable gateway now routes to two revision-specific API and two web replicas; stateful services are no longer restarted by routine application releases. - Moving host port 1236 from the legacy web container to the gateway was a one-time migration hand-off and produced 14 failures across 1,200 rapid probes. Future releases do not move that port; their acceptance gate is the zero-error versioned gateway reload.
- The subsequent M50 release exercised that steady-state path: the gateway remained online, atomically switched revision-specific API/web aliases and sustained 700/700 external readiness probes without interruption. Post-promotion Chromium/Firefox acceptance passed 4/4 and 360 concurrent authenticated reads had zero errors at p95 116.4 ms.
- The versioned gateway switch sustained 300/300 local rollout probes without an error. Production's non-destructive Chromium/Firefox canary passed 4/4, and 360 authenticated concurrent reads returned zero errors at p95 137.2 ms.
- PostgreSQL, backup, Prometheus, Alertmanager, Grafana and the gateway all reported healthy; Alembic was at head, the protected Prometheus target was present, and backup plus real restore-drill evidence remained current.
- Trivy 0.74 found zero fixed HIGH/CRITICAL vulnerabilities in the exact production API, web and gateway images. The separately built rclone/PostgreSQL backup-tools image is also clean after rebuilding rclone 1.75.0 with Go 1.26.6.
- The OneDrive worker is deployed as an opt-in profile but is not represented as active: it requires the owner's one-time interactive Microsoft OAuth authorization. Until that happens, verified local backups remain the active recovery source.
Evidence boundary
The complete local suite uses the deterministic provider and an isolated database so it is repeatable and safely destructive. Production verification is deliberately smaller and non-destructive; it verifies the real RAGcore/MCP/n8n health surfaces without resetting the shared demo. A successful local result is never presented as proof that an external service was live. The production subsection is added only after the exact committed release is deployed and observed.
Remaining product boundary
Fleet Ops remains a synthetic single-tenant PoC. It is not a production identity provider, payment system, accounting package or public reservation platform. External RAGcore, MCP Hub and n8n services remain independently operated dependencies and are accessed only through their documented adapters.