Browse Docs
Catalog
Config
Stacks
Operate
Docs

Backend seven-day execution plan (historical)

A repository document, rendered for the site. View source markdown.

Generated at: 2026-09-04T11:23:58.207Z UTC · source: committed helm-expt evidence for this rendered repository document.

Superseded for execution on 2026-09-10 by the unified Catalog and Workshop plan. The checkboxes and dated entries below preserve the historical checkpoint; they are not current completion counts. All B01–B42 tasks remain tracked in the unified plan.

Started 2026-09-06. This is an ordered, 42-task execution checklist, grouped into seven workdays of six substantial tasks. A day is a work block, not a promise that missing access or review will arrive on that date. Check off tasks only when their deliverable exists; an open PR is implemented, not landed.

The outcome is a reproducible backend with accurate source availability, useful successor configurations, reliable receipt bindings and understandable verification failures. The operating rules remain in AGENTS.md. Each implementation block gets a small independently reviewable PR from main. Do independent work when a task is blocked; do not stack unmerged branches.

Day 1: verification baseline and review backlog

  • [x] B01. Land the AICR legacy provenance repair #1770, preserving upstream bytes and checksum pins.
  • [x] B02. Land the Redis CI evidence refresh #1771, then record the first remaining full-chain failure.
  • [x] B03. Fix #1783: bind lifecycle identity and selection-dependent target facts; preserve Redis materialization bytes and add rejection tests.
  • [x] B04. Fix #1785: validate deployed baseline policy before recording its digest and make catalog consumers select the same receipt.
  • [x] B05. Review and land the independent ready PRs, especially variant generators #1765 and #1775; resolve findings before merge.
  • [x] B06. Run the complete verification baseline after merges; classify failures against the existing known-red register, without adding new regressions to it.

Day 2: precise source availability

  • [x] B07. Land #1786, retaining anonymous direct-URL and OCI observations for the four pins in #1381.
  • [x] B08. Inspect the seven-row refresh queue and check the actual source addresses used for each candidate; record version-specific results.
  • [ ] B09. Distinguish fetch failure, authentication requirement, digest mismatch and successful pinned-byte retrieval in source evidence; never infer one from another.
  • [ ] B10. Audit refresh and live scheduling consumers against those observations; fix demonstrated incorrect scheduling, preserving historical evidence.
  • [x] B11. Test that offline receipt verification requires no network and rejects source identity or digest substitution.
  • [ ] B12. Reconcile #1381 with current evidence and successor readiness; record the retirement decision or its precise remaining prerequisites.

Day 3: usable successor configurations

  • [ ] B13. Turn the Redis credential map #1772 into a reviewed useful base once its generator dependencies land.
  • [ ] B14. Do the same for the RabbitMQ consolidation proof #1773, preserving the required external credential contract.
  • [ ] B15. Complete available PostgreSQL successor static lanes and document the boundary between operator installation and database provisioning (#1376).
  • [ ] B16. Complete available MongoDB successor static lanes and artifact-specific licensing evidence (#1378).
  • [ ] B17. Complete MySQL operator publication and derived evidence after registry reauthentication; keep #1779 draft until its required gates pass.
  • [ ] B18. Verify render, scan, install prerequisites, installer package and Helm equivalence for each selected successor scope; list missing receipts explicitly.

Day 4: runtime and stack evidence

  • [ ] B19. Obtain Kubara contexts and target clusters, confirm one serial live runner, and validate prerequisites before mutation (#1759).
  • [ ] B20. Run the three registered red Kubara lanes serially; repair actual failures and preserve receipts.
  • [ ] B21. Complete each stack's missing receipts while preserving the platform matrix and certified-bundle reader contracts.
  • [ ] B22. Run successor installation and readiness checks where target prerequisites are available; distinguish controller health from database health.
  • [ ] B23. Run bounded successor upgrade and rollback checks where supported, retaining exact before/after identities.
  • [ ] B24. Regenerate dependent surfaces and remove known-red entries only for lanes whose receipts and verifiers now pass. If access is absent, finish offline preflight validation and proceed to Day 5.

Day 5: receipt integrity

  • [ ] B25. Audit producers for claims based on local intent rather than observed deployed state; prioritize policy and release receipts.
  • [ ] B26. Audit consumers for hardcoded historical receipt paths and inconsistent selection of newer evidence.
  • [ ] B27. Audit source, selection, namespace, configuration and target identity bindings across reusable proof helpers.
  • [ ] B28. Add focused negative tests for demonstrated evidence-substitution gaps; avoid tests that merely reproduce implementation.
  • [ ] B29. Verify historical receipts remain immutable and distinguish historical success from current-policy or current-source coverage.
  • [ ] B30. Re-run affected gates and reconcile any changed catalog claims with the exact supporting receipts.

Day 6: AICR, NIM, Timoni and delivery patterns

  • [x] B31. Land the source-backed AICR trust/mirror/skill comparison #1781, resolving review findings for #1450.
  • [ ] B32. Complete remaining NIM artifact-specific terms research for #1387, without downloading gated models or images.
  • [ ] B33. Admit a meaningfully different Timoni module after the adapter repair lands; prove its own materialization and lifecycle facts (#1588).
  • [ ] B34. Prove a multi-environment Timoni selection and identify remaining delivery evidence (#1587).
  • [x] B35. Reconcile remaining AICR configuration-plane work against existing receipts; do not redo completed work or claim H100 execution (#1608).
  • [ ] B36. Land the Flux/Argo survey #1778; map d2 layouts only after the maintainer supplies their list (#1758).

Day 7: maintainability and final proof

  • [x] B37. Measure verification costs and identify demonstrated redundant work before changing the chain.
  • [ ] B38. Improve failure messages for the highest-cost ambiguous failures, naming the source, receipt and recovery command.
  • [ ] B39. Verify deterministic regeneration and dependency coverage for the changed evidence surfaces.
  • [ ] B40. Run the full chain and relevant narrow gates on the integrated main baseline.
  • [ ] B41. Reconcile issue and PR status with actual landed changes, receipts, runtime limits and unresolved findings.
  • [ ] B42. Publish a concise completion record: completed task IDs, evidence links, gate results and the remaining human dependencies.

Human dependencies and fallback work

The maintainer has authorized autonomous integration of ready work. The backend stream continues to work on branches and does not push main.

DependencyAffected workIndependent work while waiting
Kubara contexts and clustersB19-B24Offline preflight and static proof validation
Registry credentials for #1699 and #1639Associated registry lanesDo not work around; continue public-source/static tasks
Registry reauthenticationB17 / #1779Other successor static lanes
d2 layout listB36Non-d2 delivery patterns
Human reading of nine bot-protected NGC terms pages (#1387)B32Keep terms unreviewed; audit structural reference and credential guards
H100 for #1581GPU executionKeep blocked; configuration-plane work only

Execution record

  • 2026-09-06: B07 implemented in #1786. Four OCI downloads match retained archive digests; the four historical direct URLs still return 403. Offline successor verification passes; claim integrity reports zero hard findings and 17 warnings. Full verification stops at the separate AICR README-origin failure fixed by #1770.
  • 2026-09-06: Review and merge request posted on #1757. #1783 and #1785 explicitly held for evidence-binding repairs; #1779 remains draft.
  • 2026-09-06: B32 has an existing human dependency recorded on #1387: nine artifact-specific NGC terms pages require a person to read them. The existing reference and credential guards are already implemented; do not bypass access controls or substitute general terms for an artifact-specific review.
  • 2026-09-07: B01, B03, B04 and B07 landed in #1770, #1783, #1785 and #1786. #1771 also landed; the integrated full-chain run is in progress, so B02 and B06 remain open until its outcome is classified.
  • 2026-09-07: B08 and B11 implemented in #1793. All seven retained refresh-candidate source archives downloaded anonymously and matched their existing SHA-256 pins. The offline action-queue gate checks the receipt; eleven negative cases reject identity changes, missing candidates, failed downloads and digest substitution. Replacement deferrals remain unchanged.
  • 2026-09-07: #1787 rebased onto the website's new docs-area index. Generated conflicts are resolved by regeneration; contributor grouping is preserved.
  • 2026-09-07: Progress checkpoint at main 404df15fc: 8/42 tasks were complete. B05 is complete after #1765 and #1775 merged with passing gates; B31 is complete after #1781 merged with passing gates and its #1450 comparison delivered. B37 remains open: the measured credential-boundary comparison in #1797/#1794 records 2,991 parsed documents, 3,282 skipped documents and 22 matching findings, with the retained CI timing comparison at 335.724 seconds versus 36.010 seconds. The optimization preserves traversal and does not demonstrate redundant work, so it did not satisfy the full B37 wording at that checkpoint.
  • 2026-09-07: #1772 merged at the same main checkpoint, but it delivers the Redis credential mapping only; B13 remains open until the reviewed useful base scope is complete. #1800 has all nine checks green but remains unmerged; #1773 is rebased and awaiting merge. #1779 and #1799 remain draft/authentication blocked. B36's d2 mapping remains blocked on the maintainer-supplied layout list.
  • 2026-09-07: Baseline main commit 2dde898e484ccb3e9eac881f8ac3efe7b0fc0c56 has tree a0893221d61210b65e08883380d6feabf48d62f2, exactly matching the reviewed #1803 commit 2c9ff3763d2e95471e7c9e49796af0d9c26f082f. Its nine CI checks passed in the full run, with separate site and installer-signature checks in the site run and the signature run. This completes B02 and B06 through exact-tree CI evidence. The local baseline at 994ec8c1a was stopped after roughly 86 of 436 steps and is not a local pass. The three registered Kubara failures in #1759 remain the only declared exceptions.
  • 2026-09-07: B35 is complete from the authoritative AICR v0.20.0 chain summary and ConfigHub release OCI receipt, which prove the configuration-plane work for #1622. Issue #1608 remains open for runtime/H100 delivery and controller follow-up; #1581 remains open for the H100 runtime promotion response and rollback. The signing story in #1402 is closed, so it is not a remaining dependency.
  • 2026-09-07: B37 is complete from a fresh pre-cache profile on the baseline main commit 2dde898e484ccb3e9eac881f8ac3efe7b0fc0c56. The reproducible observer is scripts/profile-proof-python.mjs. Site verification metrics recorded 2,111 Python calls, 586 unique script/input pairs, 1,525 repeated calls, 154,572 ms of Python time, and exit code 0; its verifier log records 942 generated files, 537 pages, and a passing result. The focused Redis chart catalog profile recorded 18 calls, 18 unique pairs, 0 repeats, 1,141 ms, and exit code 0 in its metrics. The repeated site pairs are demonstrated redundant work; the separate cache optimization in #1812 is merged; its later CI evidence does not change this pre-cache measurement. These are single-run observations for evidence, not stable performance benchmarks.
  • 2026-09-07: The checkpoint reaches 12/42 tasks. #1800, #1804, #1806, #1803, #1808, #1810, #1811 and #1812 are merged. Drafts #1807, #1809 and the static portion of #1799 and #1813 remain open. Registry credentials, the three Kubara lanes, the d2 layout list, and H100 runtime evidence remain dependencies.

Generated from the committed markdown file docs/planning/backend-seven-day-plan.md. The source file is the authoritative version.