Operationalize RC10 data retention
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 06:58:10 +02:00
parent bf867f8f4f
commit 7b96037853
22 changed files with 1306 additions and 2 deletions
+15
View File
@@ -321,6 +321,21 @@ The smoke never passes `--apply`. It fails if the cleanup summary is not a
dry-run, if any export/file deletion is reported, or if the dry-run candidate
fields are missing.
## RC-10 data operations
`docs/DATA_OPERATIONS_RUNBOOK.md` is the executable retention source of truth.
`scripts/audit_data_operations.py` reports storage growth, disk pressure,
persisted path integrity, old failed work and national/regional/maritime
source families without mutation. `scripts/cleanup_storage_artifacts.py` can
only remove old unreferenced artifacts from the explicit derived/cache/export
allowlist.
Every unknown category, upload, original, model, operator evidence and release
evidence path is protected by default. Apply mode requires an exact
confirmation token and a recent checksum-verified release backup containing a
SHA-256 storage inventory. The backup root is mounted read-only at
`/app/backups`; no cleanup is scheduled implicitly.
## Governed cross-domain raster and soil evidence
MercatorNet thematic products use the ordinary raster Dataset and immutable