Skip to content

docs(OMN-15124): PARTIAL static evidence for candidate-isolation compatibility proof - #2637

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-15124-candidate-isolation-static-evidence
Aug 3, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-15124-candidate-isolation-static-evidence

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Aug 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

OMN-15124 (parent epic OMN-14724, live status In Progress, 0/5 ACs checked) asks for a candidate-in-isolation MSK/RDS compatibility proof. This PR does not close any AC. AWS SSO is dead on every host available to this session (human login pending), so every live isolation-lane / MSK / RDS / k8s step is BLOCKED. Of the candidate_isolation_compatibility packet's 12 manifest fields, exactly 2 are answerable with zero live AWS/network dependency; this PR records those 2 as labeled PARTIAL evidence plus a field-by-field gap statement for the remaining 10.

Seam declaration

Seam is omnibase_infra/docs/runbooks/managed-staging-proof-kit/fields.yaml (schema_version 1.0.0, packets.candidate_isolation_compatibility), landed by PR #2602 (merged) and matched field-by-field against tests/ci/test_managed_staging_proof_kit_seam.py::REQUIRED_FIELDS. This PR does not touch the manifest, the template, or the seam test — it adds a new, separate, dated evidence artifact under docs/evidence/OMN-15124/, which the seam test does not enforce (verified: tests/ci/test_managed_staging_proof_kit_seam.py still 13/13 passed after this change).

AC mapping (verbatim from the live ticket)

# AC Status
1 Isolation-environment run proving MSK IAM/TLS auth + ≥1 token-refresh cycle BLOCKED — no isolation lane, no AWS creds
2 Explicit topic bootstrap (auto-create OFF) + negative control (out-of-catalog denial) BLOCKED — needs live broker
3 RDS verify-full from typed config authority, no raw-endpoint fallback PARTIAL — static half only (see below); live half BLOCKED
4 Dashboard holds zero broker/RDS authority in candidate config BLOCKED — needs live k8s namespace read
5 Rolling plan §3 B5 tag bound to this ticket (plan diff cited) BLOCKED, non-AWS — the live plan (docs/plans/ROLLING_SEVEN_DAY_PLAN.md) has no §3 B5 row; its live section headings are 0-AIM/0-CHAIN/0/1/2/3. Decisions/4/5/6, and git log -p for the file shows no plan-diff citing OMN-15124 by row. Same class of gap as OMN-15123 AC #3 — this is a plan-authoring/reconciliation gap, not something a build session resolves unilaterally.

None of the 5 AC checkboxes are flipped by this PR.

What is actually in this PR

docs/evidence/OMN-15124/2026-08-03-candidate-isolation-static-evidence-partial.md — 2 filled fields, both re-run and pasted verbatim in this PR:

  • typed_config_authority: build_aiokafka_auth_kwargs_from_env.__module__ → omnibase_infra.event_bus.kafka_auth (pure module introspection, no live call, no network).
  • no_raw_endpoint_fallback (static half only): scripts/check_no_cloud_bus_wrapper.sh (exit 0, clean) + grep -rn PLAINTEXT src/omnibase_infra/event_bus/ (shows PLAINTEXT is a valid config-declared branch, not a silent fallback). The doc explicitly flags what this does not prove: that a live AWS_MSK_IAM-configured candidate actually fails closed rather than degrading to PLAINTEXT when IAM env is unset — that's the live half of the negative control, unexercised.

The remaining 10 fields are enumerated with their live-surface blocker in the doc's gap-statement table.

Adjacent context (not actioned)

Per the 2026-08-01 ticket comment: OMN-15639 tracks a separate MSK IAM group-authorization defect, explicitly out of this ticket's connection-level scope. Not touched here.

Pre-existing, unrelated CI note

node-migration-sync (local hook onex-check-node-migration-sync, CI job node-migration-sync.yml) fails on unmodified origin/dev HEAD itself — confirmed via git stash before this branch had any diff. Cause: merged PR #2632 deleted 9 vendored node-migration files that omnimarket dev still ships (my local omnimarket clone is at origin/dev tip, not stale). This is the documented recurring drift class (scripts/sync-node-migrations.sh header: "OMN-14975, 6th occurrence"). It is not a required status check on dev (confirmed via gh api .../branches/dev/protection/required_status_checks), so it will show red on this PR independently of anything done here — nothing is hidden. Re-vendoring would mean touching 9 SQL files inside the active tenant-RLS rekey stream (OMN-14894 et al.), which this docs-only ticket does not own. SKIP=onex-check-node-migration-sync was used for the local commit only (disclosed in the commit message); every other local hook (90+) ran and passed, including the skip-token/bypass-detection hooks themselves.

Gates run

  • uv run pytest tests/ci/test_managed_staging_proof_kit_seam.py -q → 13 passed
  • pre-commit (full suite except the one pre-existing hook above) → all passed
  • prepush-smart-tests (governed selector) → no impacted tests, allowed
  • prepush-deploy-scope-dod → passed

What remains blocked (unblock steps)

  1. AC1/AC2/AC4 and the live half of AC3: needs a live isolation lane (host/k8s context) with AWS creds — AWS SSO human login first.
  2. AC5: needs an operator/plan-governance decision on how (or whether) to bind a §3 B5-equivalent row to OMN-15124 in the live rolling plan.

OMN-15124

Evidence-Ticket: OMN-15124
Evidence-Source: OCC#6027
promotion-receipt: OCC-6027

Merge-sweep update: after omnibase_infra#2639 merged, this branch was updated onto current dev; the earlier node-migration-sync disclosure is historical commit-time context, not a current claim that dev remains out of sync. OCC#6027 binds this updated head for the receipt gate.

@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 51 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: d51bb86f-9fb2-4694-a08a-24c08c8223da

📥 Commits

Reviewing files that changed from the base of the PR and between ab75503 and 8222eb6.

📒 Files selected for processing (1)
  • docs/evidence/OMN-15124/2026-08-03-candidate-isolation-static-evidence-partial.md

Comment @coderabbitai help to get the list of available commands.

jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 3, 2026
#6017)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2637

* evidence: OCC companion self-bind for #6017

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
jonahgabriel added a commit that referenced this pull request Aug 3, 2026
…cit AWS-blocked fields

Fills the managed-staging-proof-kit template
(docs/runbooks/managed-staging-proof-kit/fields.yaml ->
one_tenant_contract_freeze) with only the subset of the 19 required fields
answerable from committed, offline repo state:

- topic_catalog + zero_collision_readback (offline, real
  build_canary_catalog_from_candidate()/verify_zero_collision() output, 164
  topics / 56 groups, captioned as NOT the live cluster readback)
- msk_epoch / group_start_reset_policy from the committed namespace yaml
- rollback_authority from the teardown-rollback runbook's §0 ownership table
- zero_prod_diff (self-referential grep against this file)

9 fields are marked BLOCKED — AWS SSO is dead on this host (human login
pending) and there is no DB/deploy access, so account/region/namespace,
MSK/RDS identifiers, gateway, synthetic tenant, digests-at-freeze-time, and
omnidash exclusion cannot be produced here. A stale 7-day-old digest is cited
for context only, explicitly not as a current value.

plan_row_binding is separately BLOCKED for a structural reason: the current
ROLLING_SEVEN_DAY_PLAN.md (rewritten 2026-08-01 under §0-AIM) no longer
contains a "§3" heading or the "unverifiable by construction" string the
ticket's AC #3 cites -- flagged as a plan-governor reconciliation gap, not
fixed here.

freeze_signature is deliberately left unfilled: this commit is not the
OMN-15123 freeze event because the artifact is incomplete (11/19 rows
blocked or partial). The packet says so explicitly so it cannot be
mistaken for a completed freeze.

SKIP=onex-check-node-migration-sync: this docs-only change trips the
always_run onex-check-node-migration-sync local hook, which fails
identically on a stock unmodified origin/dev checkout (verified before
touching anything) because omnimarket dev still carries 9 per-node RLS
migration files that omnibase_infra's same-day OMN-15423/OMN-15655 landing
(commits 35fb883/3860bec7, merged 2026-08-03) already removed from the
vendored tree + manifest as part of the house-tenant migration
consolidation. The standard remediation (scripts/sync-node-migrations.sh)
was attempted and reverted: it re-vendors those 9 files verbatim from
omnimarket's stale copies, which reintroduces content the consolidation
deliberately removed and fails
tests/unit/scripts/validation/test_application_migration_manifest.py (2
tests) on push. Confirmed non-required in CI per
scripts/enforcement_parity_manifest.yaml (OMN-14556 entry). Same disclosed
pattern used minutes earlier in this session by the sibling OMN-15124 lane
(PR #2637) for the identical pre-existing drift. Not fixed here — fixing it
requires either updating sync-node-migrations.sh's selection logic to
respect the house-tenant consolidation, or omnimarket removing its stale
per-node files; both are real cross-repo engineering work outside this
docs-evidence ticket's scope.

No AWS/DB/deploy mutation performed. No ticket status flipped.

OMN-15123
…atibility proof

0/5 ACs are satisfiable this session: AC1-AC4 require a live isolation-lane run
against real MSK/RDS (AWS SSO dead, human login pending -- BLOCKED); AC5 cites
a rolling-plan §3 B5 row that does not exist in the live plan document (same
class of gap as OMN-15123 AC #3).

Adds docs/evidence/OMN-15124/2026-08-03-candidate-isolation-static-evidence-partial.md
recording the only 2 of 12 manifest fields answerable with zero live AWS/network
dependency (typed_config_authority module introspection; no_raw_endpoint_fallback's
static half via check_no_cloud_bus_wrapper.sh + PLAINTEXT grep), plus a
field-by-field gap statement for the remaining 10. No AC checkbox is flipped;
this is explicitly labeled PARTIAL, not a completed packet.

Seam kit (fields.yaml, templates, seam test) from PR #2602 is unmodified --
seam test still 13/13 green.

SKIP=onex-check-node-migration-sync used for this local commit only: that
pre-commit hook (always_run:true, unconditional) fails on unmodified origin/dev
HEAD itself -- verified via git stash before touching this branch -- because
merged infra PR #2632 deleted 9 vendored node-migration files that omnimarket
dev still ships. This is the documented recurring OMN-14975 drift class (see
scripts/sync-node-migrations.sh header, "6th occurrence"); the corresponding
CI job (node-migration-sync.yml) is NOT a required status check on infra dev
and will independently show the same pre-existing red on this PR, so nothing
is hidden. Re-vendoring here would mean touching 9 SQL files in the active
tenant-RLS rekey stream (OMN-14894 et al.) that this ticket does not own --
out of scope for a docs-only candidate-isolation-proof ticket.

OMN-15124
@jonahgabriel
jonahgabriel force-pushed the jonah/omn-15124-candidate-isolation-static-evidence branch from 4b9b86e to 8222eb6 Compare August 3, 2026 20:06
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Blocking findings (critical): 0
Total findings: 0
Models succeeded: none

Note: All reviewer models failed or were unavailable. Degraded results are informational during the pilot phase (OMN-8468/OMN-8524) and do not block merge. Error: all review endpoints [192.168.86.201:8000 192.168.86.201:8001 ] unreachable — preflight short-circuit (no models available)


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

@jonahgabriel
jonahgabriel merged commit 0e92540 into dev Aug 3, 2026
201 of 213 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15124-candidate-isolation-static-evidence branch August 3, 2026 20:33
jonahgabriel added a commit that referenced this pull request Aug 3, 2026
…cit AWS-blocked fields (#2638)

Fills the managed-staging-proof-kit template
(docs/runbooks/managed-staging-proof-kit/fields.yaml ->
one_tenant_contract_freeze) with only the subset of the 19 required fields
answerable from committed, offline repo state:

- topic_catalog + zero_collision_readback (offline, real
  build_canary_catalog_from_candidate()/verify_zero_collision() output, 164
  topics / 56 groups, captioned as NOT the live cluster readback)
- msk_epoch / group_start_reset_policy from the committed namespace yaml
- rollback_authority from the teardown-rollback runbook's §0 ownership table
- zero_prod_diff (self-referential grep against this file)

9 fields are marked BLOCKED — AWS SSO is dead on this host (human login
pending) and there is no DB/deploy access, so account/region/namespace,
MSK/RDS identifiers, gateway, synthetic tenant, digests-at-freeze-time, and
omnidash exclusion cannot be produced here. A stale 7-day-old digest is cited
for context only, explicitly not as a current value.

plan_row_binding is separately BLOCKED for a structural reason: the current
ROLLING_SEVEN_DAY_PLAN.md (rewritten 2026-08-01 under §0-AIM) no longer
contains a "§3" heading or the "unverifiable by construction" string the
ticket's AC #3 cites -- flagged as a plan-governor reconciliation gap, not
fixed here.

freeze_signature is deliberately left unfilled: this commit is not the
OMN-15123 freeze event because the artifact is incomplete (11/19 rows
blocked or partial). The packet says so explicitly so it cannot be
mistaken for a completed freeze.

SKIP=onex-check-node-migration-sync: this docs-only change trips the
always_run onex-check-node-migration-sync local hook, which fails
identically on a stock unmodified origin/dev checkout (verified before
touching anything) because omnimarket dev still carries 9 per-node RLS
migration files that omnibase_infra's same-day OMN-15423/OMN-15655 landing
(commits 35fb883/3860bec7, merged 2026-08-03) already removed from the
vendored tree + manifest as part of the house-tenant migration
consolidation. The standard remediation (scripts/sync-node-migrations.sh)
was attempted and reverted: it re-vendors those 9 files verbatim from
omnimarket's stale copies, which reintroduces content the consolidation
deliberately removed and fails
tests/unit/scripts/validation/test_application_migration_manifest.py (2
tests) on push. Confirmed non-required in CI per
scripts/enforcement_parity_manifest.yaml (OMN-14556 entry). Same disclosed
pattern used minutes earlier in this session by the sibling OMN-15124 lane
(PR #2637) for the identical pre-existing drift. Not fixed here — fixing it
requires either updating sync-node-migrations.sh's selection logic to
respect the house-tenant consolidation, or omnimarket removing its stale
per-node files; both are real cross-repo engineering work outside this
docs-evidence ticket's scope.

No AWS/DB/deploy mutation performed. No ticket status flipped.

OMN-15123
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant