diff --git a/docs/operations/sre-k3s-controlled-automation-work-items.snapshot.json b/docs/operations/sre-k3s-controlled-automation-work-items.snapshot.json index bb08a961d..d8e6303b5 100644 --- a/docs/operations/sre-k3s-controlled-automation-work-items.snapshot.json +++ b/docs/operations/sre-k3s-controlled-automation-work-items.snapshot.json @@ -313,7 +313,13 @@ "verifier": "ledger schema and API readback verifier", "rollback": "revert source commit", "exit_condition": "production API returns the exact committed ledger and rollups", - "next_action": "complete loader/API tests then deploy" + "confirmed_truth": [ + "the local machine-readable ledger records all 18 ordered work items and keeps source, CD, runtime and recipient-visible evidence separate" + ], + "runtime_gaps": [ + "bounded production readback at 2026-07-19T06:27:25+08:00 still returned the 2026-07-17T02:00:46+08:00 ledger: AIA-SRE-007/012/016/018 remained planned and AIA-SRE-015/017 remained in_progress, so production does not expose this committed source truth" + ], + "next_action": "after the separately owned CI/CD blocker is repaired, integrate once and require the production API generated_at, all 18 item statuses and rollups to match the exact committed ledger" }, { "id": "AIA-SRE-002", @@ -836,7 +842,8 @@ ], "runtime_gaps": [ "production exposed six fallback context receipts but the deployed verifier rejected all six under the alert-card-only contract, while the deployed coverage could still treat unverified fallback metadata as ready; this source revision fixes both false-negative and false-green paths but still has no production same-run receipt", - "release c0afb10861cbb76bc232fad3bbeea0d675cd9b80 reached Gitea CD 5384 terminal failure without a deploy marker, so production remained on e614f061f781c6e20a3964875d7ab3c28cf91190" + "release c0afb10861cbb76bc232fad3bbeea0d675cd9b80 reached Gitea CD 5384 terminal failure without a deploy marker, so production remained on e614f061f781c6e20a3964875d7ab3c28cf91190", + "bounded production readback at 2026-07-19T06:27:25+08:00 received zero bytes from /api/v1/agents/telegram-alert-monitoring-coverage-readback before the 12-second client deadline, so no Telegram/KM/RAG/MCP/PlayBook runtime closure can be claimed" ], "next_action": "after the separately owned CI/CD blocker is repaired, integrate this exact tested receipt-contract revision once and read back one same-run Telegram/KM/RAG/MCP/PlayBook/DR closure receipt; source evidence must not be counted as runtime closure" }, @@ -920,7 +927,8 @@ "the host99 Agent99 independent pull/reduced relay has no production deployment, freshness, dedupe or controlled-repair receipt", "production Alertmanager exposes integration-only notification counters; the bounded check now passes after adding a scrape-time receiver_contract label, but apply and alert resolution remain pending", "the recipient-visible Agent99 recovered-card closure contract is source-tested only; no production Telegram provider acknowledgement or same-run runtime closure receipt exists yet", - "production runtime e614f061f7 still reports both alert-operation-log and AI-card-delivery DB readbacks unavailable with zero 7-day automation lifecycle receipts; the bounded serial readback fix is source-only until a successful deploy marker" + "production runtime e614f061f7 still reports both alert-operation-log and AI-card-delivery DB readbacks unavailable with zero 7-day automation lifecycle receipts; the bounded serial readback fix is source-only until a successful deploy marker", + "bounded /api/v1/telegram/health readback at 2026-07-19T06:27:25+08:00 was configured but degraded_callback_ingress_unverified: interactive_buttons_ready=false, no durable/fresh ingress receipt and no controlled-action receipt, so all registered callback actions correctly remain fail-closed rather than being counted as working buttons" ], "next_action": "deploy one exact source revision through the authorized release lane, then verify receiver-contract freshness, host99 Agent99 exact-host polling, dedupe, callback execution, current firing alert resolution and recipient-visible same-run delivery receipts; source tests must not be counted as runtime closure" },