{ "schema_version": "awoooi_priority_work_order_readback_v1", "generated_at": "2026-06-29T15:55:00+08:00", "status": "p0_ordered_readback_p0_006_timer_live_p0_005_refs_waiting_p0_003_payload_validator_ready", "source_refs": { "global_scorecard": "~/.codex/product-runtime-governance-completion-scorecard.snapshot.json", "workstation_dashboard": "~/.codex/codex-workstation-sync-dashboard.snapshot.json", "post_reboot_summary": "/home/wooo/reboot-recovery/reboot-auto-recovery-slo-20260629-153112/summary.txt", "full_stack_cold_start_check": "scripts/reboot-recovery/full-stack-cold-start-check.sh --monitor-read-only --no-color", "delivery_closure_workbench": "https://awoooi.wooo.work/api/v1/agents/delivery-closure-workbench", "public_gitea_queue_readback": "ops/runner/read-public-gitea-actions-queue.py --json", "credential_escrow_scorecard": "/tmp/awoooi-credential-escrow-intake-scorecard-20260629-1200-priority.json", "dr_escrow_evidence_checklist_generator": "scripts/reboot-recovery/dr-escrow-evidence-checklist.py", "gitea_private_inventory_p0_scorecard": "docs/operations/awoooi-gitea-private-inventory-p0-scorecard.snapshot.json", "reboot_auto_recovery_slo_scorecard": "docs/operations/awoooi-reboot-auto-recovery-slo-scorecard.snapshot.json", "reboot_auto_recovery_slo_metric": "/home/wooo/node_exporter_textfiles/reboot_auto_recovery_slo.prom", "credential_escrow_live_status": "/tmp/awoooi-p0-005-escrow-status-live.txt", "dr_escrow_evidence_checklist_latest": "/tmp/awoooi-dr-escrow-evidence-checklist-current.json", "gitea_repo_inventory_snapshot": "docs/security/gitea-repo-inventory.snapshot.json", "credential_escrow_intake_readiness_api": "/api/v1/agents/credential-escrow-evidence-intake-readiness", "credential_escrow_intake_readiness_service": "apps/api/src/services/credential_escrow_evidence_intake_readiness.py", "credential_escrow_intake_readiness_tests": "apps/api/tests/test_credential_escrow_evidence_intake_readiness_api.py", "gitea_authenticated_inventory_payload_validator": "scripts/security/gitea-authenticated-inventory-payload-validator.py", "gitea_authenticated_inventory_payload_validation_snapshot": "docs/operations/awoooi-gitea-authenticated-inventory-payload-validation.snapshot.json" }, "current_head": { "gitea_main_sha": "e8228fd2c4ef2a026eebc483f6b58fc0850aba6d", "latest_successful_deploy_marker": "15824e9ec chore(cd): deploy 57c1df1 [skip ci]", "latest_successful_deployed_source_sha": "57c1df19fca580dafa5980d82d164819de0dbcd5", "latest_source_readiness_commit_sha": "0c8d4e88c39157b92322fa41a92e6b15c317ac49", "latest_source_readiness_cd_run_id": "3882", "latest_source_readiness_cd_run_status": "Success", "source_readiness_ci_fix_required": false, "no_matching_runner_visible": false, "latest_verified_worktree_base_sha": "8f0c6d300", "latest_fetched_gitea_main_subject": "feat(awooop): expose ai automation work items" }, "completed_in_priority_order": [ { "workplan_id": "P0-001", "title": "建立主機 runtime inventory 權威資料", "status": "core_green_with_warnings", "evidence": { "hosts_checked": [ "192.168.0.110", "192.168.0.120", "192.168.0.121", "192.168.0.188" ], "full_stack_pass": 91, "full_stack_warn": 2, "full_stack_blocked": 0, "post_start_pass": 43, "post_start_warn": 5, "post_start_blocked": 0, "service_green": true, "host_188_hygiene_blocked": false, "wazuh_manager_registry_accepted": 6, "runtime_action_authorized": false }, "warnings_kept_visible": [ "110 systemd failed units remain", "188 momo daily sales stale but source preflight has no hard blocker" ] }, { "workplan_id": "P0-004", "title": "補 dev / prod CI/CD baseline", "status": "production_deploy_closure_verified", "evidence": { "non110_runner_ready": true, "latest_cd_run_id": "3868", "latest_cd_run_status": "Success", "production_deploy_status": "closure_verified", "production_image_tag_matches_main": true, "production_governance_fields_present": true, "runner_pressure_guard_ok": true } }, { "workplan_id": "P0-004-source-readiness", "title": "P0-004 CI/CD baseline source readiness", "status": "ready_for_template_copy_apply_gate", "evidence": { "required_source_count": 11, "present_required_source_count": 11, "missing_required_source_count": 0, "source_readiness_percent": 100, "blocked_source_ids": [] }, "safe_next_step": "open_template_copy_apply_gate_after_source_readiness_green" }, { "workplan_id": "P0-002", "title": "建立 product.awoooi.yaml 產品 manifest 標準", "status": "ready_for_product_manifest_adoption", "evidence": { "manifest_present": true, "manifest_schema_present": true, "manifest_schema_version": "product_awoooi_manifest_v1", "product_id": "awoooi", "source_control_authority": "gitea", "github_status": "stopped_retired_do_not_use", "required_section_count": 5, "present_required_section_count": 5, "missing_required_section_count": 0, "required_contract_ref_count": 3, "present_contract_ref_count": 3, "missing_contract_ref_count": 0, "source_readiness_percent": 100 }, "safe_next_step": "adopt_product_manifest_schema_for_remaining_products_without_repo_creation_or_secret_read" } ], "in_progress_or_blocked_in_priority_order": [ { "workplan_id": "P0-005", "title": "產品資料與備份 contract", "status": "waiting_non_secret_credential_escrow_evidence_refs", "reason": "Production credential escrow readiness now exposes top-level safe_next_step, so the API no longer returns null. The remaining blocker is the real five non-secret DR credential escrow evidence refs; no secret values, marker writes, or runtime gates were opened.", "evidence": { "product_data_green": true, "stock_freshness_status": "ok", "stock_latest_trading_date": "2026-06-26", "backup_core_green": true, "dr_escrow_blocked": true, "summary_escrow_missing_count": 5, "offsite_configured": true, "rclone_configured": true, "script_missing_count": 0, "credential_marker_write_authorized_count": 0, "secret_value_collection_allowed": false, "checklist_generator_present": true, "checklist_schema_version": "awoooi_dr_escrow_evidence_checklist_v1", "placeholder_preflight_guard_present": true, "offsite_fresh": true, "rclone_gdrive_configured": true, "rclone_gdrive_fresh": true, "escrow_status_live_checked": true, "live_no_secret_status_path": "/tmp/awoooi-p0-005-escrow-status-live.txt", "checklist_latest_path": "/tmp/awoooi-dr-escrow-evidence-checklist-current.json", "credential_escrow_intake_api_route_live_checked": true, "production_missing_item_count": 5, "production_owner_response_accepted_count": 0, "production_runtime_gate_count": 0, "production_secret_value_collection_allowed": false, "production_top_level_safe_next_step_was_null_before_source_fix": true, "source_top_level_safe_next_step_present": true, "source_safe_next_step": "collect_redacted_non_secret_evidence_refs_then_rerun_preflight", "focused_p0_005_tests_passed": 16, "production_top_level_safe_next_step_readback": true, "production_safe_next_step": "collect_redacted_non_secret_evidence_refs_then_rerun_preflight", "production_readback_safe_next_step": "collect_redacted_non_secret_evidence_refs_then_rerun_preflight" }, "missing_items": [ "restic_repository_password", "offsite_provider_credentials", "break_glass_admin_credentials", "dns_registrar_recovery", "oauth_ai_provider_recovery" ], "professional_fix": { "owner": "DR evidence lane", "action": "Use the single DR escrow checklist packet with the five required item ids, accept only redacted evidence refs, then run the existing preflight once.", "exit_criteria": [ "effective_escrow_missing_count=0", "owner_response_accepted_count=1", "forbidden_true_field_count=0", "secret_value_collection_allowed=false", "post_reboot_readiness OVERALL_DECLARATION no longer includes DR_ESCROW_BLOCKED" ], "do_not_repeat": [ "Do not reopen cold-start or CI/CD work because escrow refs are missing.", "Do not create additional owner-package variants for the same five refs." ] }, "safe_next_step": "collect_five_non_secret_credential_escrow_evidence_refs_then_rerun_single_preflight" }, { "workplan_id": "P0-003", "title": "取得 Gitea private inventory 權限", "status": "payload_validator_ready_waiting_authenticated_or_admin_export_inventory", "reason": "P0-003 now has a Gitea-only scorecard, read-only API, Delivery Workbench active lane, live 110 public inventory refreshed to four repos, and a no-secret machine validator for redacted authenticated/admin export inventory payloads. GitHub is excluded from active P0 blocker math; current public-only inventory should validate as needs_supplement with accepted_payload_count=0, and private/internal coverage still requires an authenticated/admin redacted payload or owner attestation.", "evidence": { "private_inventory_source": "gitea", "github_lane_excluded_from_p0_blocker_count": true, "api_readback_schema_version": "gitea_private_inventory_p0_scorecard_readback_v1", "delivery_workbench_active_lane": "gitea_private_inventory", "delivery_workbench_github_blocked_preflight_target_count": 0, "delivery_workbench_review_readiness_percent": 60, "delivery_workbench_active_blocker_count": 4, "gitea_inventory_status": "partial", "gitea_visibility_scope": "public_only", "gitea_public_repo_count": 4, "accepted_inventory_payload_count": 0, "owner_coverage_attestation_received_count": 0, "expected_product_count": 11, "present_product_row_count": 11, "missing_product_row_count": 0, "all_active_product_repos_have_gitea_owner_readiness_row": true, "gitea_public_repos": [ "wooo/awoooi", "wooo/ewoooc", "wooo/agent-bounty-protocol", "wooo/2026FIFAWorldCup" ], "gitea_readonly_token_present": false, "active_blockers": [ "gitea_repo_inventory_status_not_ok", "gitea_visibility_scope_public_only_or_unknown", "gitea_authenticated_inventory_payload_not_accepted", "gitea_owner_coverage_attestation_not_received" ], "authenticated_payload_validation_status": "needs_supplement", "authenticated_payload_validation_accepted_payload_count": 0, "authenticated_payload_validation_blocker_count": 4, "authenticated_payload_validator_present": true, "authenticated_payload_validator_source": "scripts/security/gitea-authenticated-inventory-payload-validator.py", "authenticated_payload_validation_snapshot": "docs/operations/awoooi-gitea-authenticated-inventory-payload-validation.snapshot.json", "token_value_collection_allowed": false, "repo_write_allowed": false, "refs_sync_allowed": false, "github_primary_switch_authorized": false, "runtime_gate_count": 0 }, "professional_fix": { "owner": "Gitea inventory lane", "action": "Use the Gitea-only P0 scorecard, accept only redacted authenticated/admin export inventory payloads, and keep GitHub as do_not_use historical context only.", "exit_criteria": [ "private_inventory_source=gitea", "github_lane_excluded_from_p0_blocker_count=true", "gitea_repo_inventory.status=ok", "gitea_repo_inventory.visibility_scope in authenticated/admin_export", "all_active_product_repos_have_gitea_owner_readiness_row=true" ] }, "safe_next_step": "supply_authenticated_or_admin_export_redacted_inventory_payload_then_run_gitea_authenticated_inventory_payload_validator" }, { "workplan_id": "P0-006", "title": "主機重啟自動偵測、自動觸發與 10 分鐘恢復 SLO", "status": "blocked_waiting_fresh_all_host_reboot_window", "reason": "Verify-only readback confirms the live SLO timer remains enabled and active on 110, observes all required hosts, and has only host_boot_observation_older_than_target_window as blocker. The 10-minute claim still requires a fresh all-host reboot event or separately approved reboot drill.", "evidence": { "target_minutes": 10, "can_claim_all_services_recovered_within_target": false, "source_controls_added": true, "host_boot_probe_source_present": true, "slo_systemd_timer_source_present": true, "slo_exporter_source_present": true, "post_start_blocked": 0, "service_green": true, "product_data_green": true, "backup_core_green": true, "wazuh_dashboard_degraded": false, "all_host_reboot_detection_missing": false, "host_boot_probe_missing_hosts": false, "local_disk_free_gib_after_cleanup": 145.514, "slo_installer_source_present": true, "live_slo_timer_enabled": true, "live_slo_timer_active": true, "live_slo_service_last_result": "success", "live_slo_metric_present": true, "observed_hosts": [ "110", "120", "121", "188" ], "missing_hosts": [], "unreachable_hosts": [], "stale_hosts": [ "110", "120", "121", "188" ], "max_observed_uptime_seconds": 519376, "active_blockers": [ "host_boot_observation_older_than_target_window" ], "host_188_service_green": true, "safe_next_step_from_scorecard": "timer_deployed_and_services_readback_green_wait_for_next_all_host_reboot_event_or_approved_reboot_drill_to_prove_10_minute_slo", "latest_live_slo_artifact": "/home/wooo/reboot-recovery/reboot-auto-recovery-slo-20260629-153112" }, "professional_fix": { "owner": "reboot auto-recovery lane", "action": "Keep the live boot-triggered SLO timer enabled. Do not reboot from this lane. Use the next actual all-host reboot event, or a separately approved reboot drill, to prove max_observed_uptime_seconds<=600 with service/data/backup readback still green.", "exit_criteria": [ "can_claim_all_services_recovered_within_target=true", "observed_hosts=110,120,121,188", "missing_hosts=[]", "unreachable_hosts=[]", "max_observed_uptime_seconds<=600 during a fresh all-host reboot window", "POST_START_BLOCKED=0", "SERVICE_GREEN=1", "PRODUCT_DATA_GREEN=1", "BACKUP_CORE_GREEN=1", "HOST_188_SERVICE_GREEN=1", "live_slo_metric_present=true" ] }, "safe_next_step": "keep_timer_live_wait_for_next_all_host_reboot_event_or_separately_approved_reboot_drill_to_prove_10_minute_slo" } ], "noise_integrated_risk_register": [ { "signal": "canceled_or_superseded_cd_runs", "why_it_matters": "Canceled runs hide whether the latest main actually deployed and can make a completed source fix look failed.", "professional_handling": "Only the latest non-canceled run for the current main head is a deploy signal; older canceled runs become context, not blockers.", "exit_criteria": "latest_main_deploy_readback_success=true" }, { "signal": "ui_redaction_commits_during_p0_recovery", "why_it_matters": "Concurrent UI-only commits can cancel P0 CI runs and consume attention while not changing cold-start or DR truth.", "professional_handling": "Keep UI-only changes on controlled-runtime profile and verify production readback after the newest head; do not reopen host recovery.", "exit_criteria": "production_deploy_status=closure_verified and P0 endpoints unchanged" }, { "signal": "dirty_local_awooop_worktree", "why_it_matters": "Local uncommitted frontend copy can create false test failures and pollute P0 diagnosis.", "professional_handling": "Run P0 verification in clean Gitea main worktrees; never stage or revert user dirty files during P0 recovery.", "exit_criteria": "all P0 test receipts come from clean main worktree" }, { "signal": "legacy_github_lane", "why_it_matters": "Retired GitHub blockers inflate P0 blocker count and distract from active Gitea/runtime work.", "professional_handling": "Keep GitHub stopped/do_not_use; remove it from active P0 next actions and route inventory work to Gitea.", "exit_criteria": "active_p0_next_actions contain no GitHub recovery work" }, { "signal": "warning_only_cold_start_findings", "why_it_matters": "Warnings can reveal hygiene debt, but treating them as reboot blockers delays recovery closure.", "professional_handling": "Keep warnings visible with owner and due lane; close reboot recovery when BLOCKED=0 and service/data health are green.", "exit_criteria": "cold_start_blocked=0 and warning items assigned outside reboot recovery" }, { "signal": "stale_or_incomplete_priority_snapshots", "why_it_matters": "Old snapshots can contradict live production readback and send work back to already-fixed items.", "professional_handling": "Live production readback wins; snapshots must be refreshed only when they change the next executable P0 action.", "exit_criteria": "priority snapshot current_head matches latest successful deploy marker" } ], "professional_execution_rules": [ "Treat noise as a risk input when it masks, delays, or misroutes a P0; otherwise keep it as context.", "Do not split noise into a separate project; attach it to the P0 row it can affect.", "Every P0 row must have one owner lane, one action, and measurable exit criteria.", "Do not re-run cold-start, CD, or UI checks unless their result can change the next P0 action.", "One blocker gets one checklist and one preflight; do not produce duplicate owner packets for the same missing evidence." ], "stopped_or_do_not_use": [ { "workplan_id": "P0-003A", "title": "GitHub 全產品備援鏡像", "status": "removed_deleted_do_not_use", "allowed_actions": 0 } ], "operation_boundaries": { "github_api_used": false, "github_cli_used": false, "workflow_dispatch_performed": false, "runner_registration_performed": false, "secret_or_runner_token_read": false, "credential_secret_value_read": false, "credential_marker_written": false, "host_write_performed": false, "docker_restart_performed": false, "nginx_restart_performed": false, "firewall_change_performed": false, "k3s_restart_or_node_drain_performed": false, "database_write_or_restore_performed": false }, "next_execution_order": [ "P0-006: keep the live reboot SLO timer active; no reboot or service restart from this lane; next proof is the next fresh all-host reboot event or separately approved reboot drill.", "P0-005: collect five non-secret credential escrow evidence refs and rerun one preflight; production API safe_next_step reads back correctly and backup/offsite freshness is green.", "P0-003: supply authenticated/admin redacted inventory payload or owner coverage attestation, then run the new Gitea payload validator; public-only live inventory remains four repos and GitHub remains stopped/retired/do_not_use." ] }