docs: add capability and infrastructure fit assessment
This commit is contained in:
968
docs/capability-fit-current.json
Normal file
968
docs/capability-fit-current.json
Normal file
@@ -0,0 +1,968 @@
|
||||
{
|
||||
"$schema": "./capability-fit.schema.json",
|
||||
"schema_version": "0.1.0",
|
||||
"assessment_id": "campaign-reference-2026-07-20",
|
||||
"assessed_at": "2026-07-20",
|
||||
"scope": {
|
||||
"title": "Campaign-centric internal pilot and small-production candidate",
|
||||
"reference_journeys": [
|
||||
"Internal operator authors, validates, builds, queues, sends and reconciles an email Campaign with managed attachments",
|
||||
"Operator inspects delivery and audit evidence"
|
||||
],
|
||||
"postponed": [
|
||||
"Workflow and workflow-driven user stories"
|
||||
]
|
||||
},
|
||||
"release": {
|
||||
"kind": "workspace_snapshot",
|
||||
"ref": "workspace-2026-07-20",
|
||||
"meta_commit": "05ae81d64195",
|
||||
"reproducible": false,
|
||||
"configuration_packages": [],
|
||||
"notes": [
|
||||
"The snapshot is untagged.",
|
||||
"Dirty repositories are recorded and local-only work is not treated as release-integrated."
|
||||
]
|
||||
},
|
||||
"composition": [
|
||||
{
|
||||
"module_id": "core",
|
||||
"repository": "govoplan-core",
|
||||
"commit": "e6f7c45f0a95",
|
||||
"manifest_version": "server-0.3.0",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "API, registry, migrations, sessions, kernel contracts and shared WebUI"
|
||||
},
|
||||
{
|
||||
"module_id": "tenancy",
|
||||
"repository": "govoplan-tenancy",
|
||||
"commit": "1dde03854733",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Tenant context and lifecycle"
|
||||
},
|
||||
{
|
||||
"module_id": "organizations",
|
||||
"repository": "govoplan-organizations",
|
||||
"commit": "45cda1a33f18",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Organization model"
|
||||
},
|
||||
{
|
||||
"module_id": "identity",
|
||||
"repository": "govoplan-identity",
|
||||
"commit": "7a1710af896f",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Normalized internal identity directory"
|
||||
},
|
||||
{
|
||||
"module_id": "access",
|
||||
"repository": "govoplan-access",
|
||||
"commit": "ab07075a679b",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Local authentication, sessions, API keys and RBAC"
|
||||
},
|
||||
{
|
||||
"module_id": "admin",
|
||||
"repository": "govoplan-admin",
|
||||
"commit": "c9e1fb287f50",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Administration surfaces"
|
||||
},
|
||||
{
|
||||
"module_id": "dashboard",
|
||||
"repository": "govoplan-dashboard",
|
||||
"commit": "a315a7c62b1d",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Module-aware home surface"
|
||||
},
|
||||
{
|
||||
"module_id": "policy",
|
||||
"repository": "govoplan-policy",
|
||||
"commit": "2511fbb5a864",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Policy explanation and configuration boundary"
|
||||
},
|
||||
{
|
||||
"module_id": "audit",
|
||||
"repository": "govoplan-audit",
|
||||
"commit": "5e4f84a789ea",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Database audit records and retrying audit outbox"
|
||||
},
|
||||
{
|
||||
"module_id": "campaigns",
|
||||
"repository": "govoplan-campaign",
|
||||
"commit": "2e593b7fa412",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Campaign authoring, build, delivery control and reporting"
|
||||
},
|
||||
{
|
||||
"module_id": "files",
|
||||
"repository": "govoplan-files",
|
||||
"commit": "f3210234d35a",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Managed files and Campaign attachments"
|
||||
},
|
||||
{
|
||||
"module_id": "mail",
|
||||
"repository": "govoplan-mail",
|
||||
"commit": "b0337b2d261a",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "SMTP and IMAP profiles and transports"
|
||||
},
|
||||
{
|
||||
"module_id": "calendar",
|
||||
"repository": "govoplan-calendar",
|
||||
"commit": "371a00aff51c",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Optional calendar outside the Campaign pilot minimum"
|
||||
},
|
||||
{
|
||||
"module_id": "docs",
|
||||
"repository": "govoplan-docs",
|
||||
"commit": "f2ade1d62475",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": true,
|
||||
"role": "Configured-system documentation"
|
||||
},
|
||||
{
|
||||
"module_id": "ops",
|
||||
"repository": "govoplan-ops",
|
||||
"commit": "341773a4ff8a",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": true,
|
||||
"dirty": false,
|
||||
"role": "Readiness and deployment-profile visibility"
|
||||
},
|
||||
{
|
||||
"module_id": "addresses",
|
||||
"repository": "govoplan-addresses",
|
||||
"commit": "f19350e65d76",
|
||||
"manifest_version": "0.1.8",
|
||||
"enabled": false,
|
||||
"dirty": true,
|
||||
"role": "Optional reusable recipient sources and CardDAV"
|
||||
}
|
||||
],
|
||||
"deployment_profile": {
|
||||
"id": "production-like-dev",
|
||||
"status": "partial",
|
||||
"description": "PostgreSQL and Redis run in containers while API, WebUI, worker and scheduler run from editable source trees.",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "configuration",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan/dev/production-like/docker-compose.yml"
|
||||
},
|
||||
{
|
||||
"kind": "documentation",
|
||||
"scope": "documented_model",
|
||||
"locator": "govoplan/dev/production-like/README.md"
|
||||
}
|
||||
]
|
||||
},
|
||||
"questionnaire": {
|
||||
"scope_outcomes": [
|
||||
{
|
||||
"id": "outcome.reference_journey",
|
||||
"question": "Which journey is assessed?",
|
||||
"state": "answered",
|
||||
"answer": "An internal operator authors, validates, builds, queues, sends and reconciles a Campaign with managed attachments.",
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "outcome.workflow",
|
||||
"question": "Is Workflow in scope?",
|
||||
"state": "answered",
|
||||
"answer": "No; Workflow is planned and explicitly postponed.",
|
||||
"evidence": []
|
||||
}
|
||||
],
|
||||
"data_policy": [
|
||||
{
|
||||
"id": "data.classification",
|
||||
"question": "Which data classes and legal bases apply?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "data.retention",
|
||||
"question": "What retention, deletion, archive and legal-hold rules apply?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
}
|
||||
],
|
||||
"identity_integrations": [
|
||||
{
|
||||
"id": "identity.pilot",
|
||||
"question": "May the pilot use local GovOPlaN accounts?",
|
||||
"state": "assumed",
|
||||
"answer": "Yes; federation is outside the verified composition.",
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "integration.mail",
|
||||
"question": "Which target SMTP/IMAP service and policy apply?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
}
|
||||
],
|
||||
"workload_growth": [
|
||||
{
|
||||
"id": "workload.campaign",
|
||||
"question": "What are Campaign frequency, recipients per Campaign, send window, import size and attachment volume?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "workload.platform",
|
||||
"question": "What are tenant, user, concurrency, file, database, queue and audit growth assumptions?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
}
|
||||
],
|
||||
"availability_operations": [
|
||||
{
|
||||
"id": "availability.rto_rpo",
|
||||
"question": "What availability, RPO and RTO are required?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "operations.ownership",
|
||||
"question": "Who operates database, queue, storage, TLS, secrets, monitoring, backup and incident response?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
}
|
||||
],
|
||||
"procurement_decisions": [
|
||||
{
|
||||
"id": "procurement.constraints",
|
||||
"question": "Which licensing, accessibility, security, certification, support and procurement conditions are mandatory?",
|
||||
"state": "not_assessed",
|
||||
"answer": null,
|
||||
"evidence": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"capabilities": [
|
||||
{
|
||||
"id": "platform.composition",
|
||||
"requirement": "Compose enabled backend and WebUI modules without hard optional-module dependencies.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/tests/test_module_system.py"
|
||||
},
|
||||
{
|
||||
"kind": "contract",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan/tools/checks/check-contracts.py",
|
||||
"note": "43 contracts, 29 providers, no issues"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Repeat checks on a clean pinned release candidate."
|
||||
],
|
||||
"gaps": [
|
||||
"The current snapshot is dirty and untagged."
|
||||
],
|
||||
"risks": [
|
||||
"A working module graph can still be unreproducible."
|
||||
],
|
||||
"recommendation": "Use the minimal Campaign composition and pin all artifacts before promotion.",
|
||||
"proof_check": "Run contract, migration, API and WebUI module-permutation gates on the release candidate."
|
||||
},
|
||||
{
|
||||
"id": "access.local",
|
||||
"requirement": "Provide tenant-scoped local accounts, sessions, API keys and RBAC.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-access/tests/test_auth_dependencies.py"
|
||||
},
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/tests/test_api_smoke.py#cookie-session-csrf"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Pilot accepts local accounts."
|
||||
],
|
||||
"gaps": [
|
||||
"MFA and federated lifecycle are not part of this conclusion."
|
||||
],
|
||||
"risks": [
|
||||
"Manual account lifecycle may not satisfy production identity policy."
|
||||
],
|
||||
"recommendation": "Use controlled local pilot accounts and define break-glass/bootstrap rules.",
|
||||
"proof_check": "Exercise joiner, role change, suspension and protected-owner recovery."
|
||||
},
|
||||
{
|
||||
"id": "campaign.journey",
|
||||
"requirement": "Author, validate, build, queue, send, reconcile and report a Campaign with frozen execution evidence.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/tests/test_api_smoke.py#campaign-create-validate-build-mock-send"
|
||||
},
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-campaign/tests",
|
||||
"note": "14 tests passed"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"This verifies implementation paths, not target-provider delivery."
|
||||
],
|
||||
"gaps": [
|
||||
"Substantial Campaign UI/code WIP is not release-integrated."
|
||||
],
|
||||
"risks": [
|
||||
"Local WIP can make the checkout look more complete than the release baseline."
|
||||
],
|
||||
"recommendation": "Integrate and retest Campaign work before usability or production acceptance.",
|
||||
"proof_check": "Run the complete journey with safe data and the target-like mail service."
|
||||
},
|
||||
{
|
||||
"id": "files.managed_attachments",
|
||||
"requirement": "Store and resolve managed Campaign attachments on durable storage.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-files/tests",
|
||||
"note": "14 tests passed"
|
||||
},
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-campaign/tests/test_attachment_building.py"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Deployment provides a durable storage root."
|
||||
],
|
||||
"gaps": [
|
||||
"Target backup and restore are not verified."
|
||||
],
|
||||
"risks": [
|
||||
"Node-local storage prevents safe independent API scaling."
|
||||
],
|
||||
"recommendation": "Use durable local storage for the pilot and assess object/shared storage before scaling.",
|
||||
"proof_check": "Back up and restore files together with database references."
|
||||
},
|
||||
{
|
||||
"id": "mail.smtp_imap",
|
||||
"requirement": "Send Campaign mail through SMTP and optionally append sent messages through IMAP.",
|
||||
"status": "available_unconfigured",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-mail/tests",
|
||||
"note": "22 tests passed"
|
||||
},
|
||||
{
|
||||
"kind": "documentation",
|
||||
"scope": "documented_model",
|
||||
"locator": "govoplan-campaign/docs/CAMPAIGN_DELIVERY_RUNBOOK.md"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Use a dedicated non-production service account and safe recipients."
|
||||
],
|
||||
"gaps": [
|
||||
"No target provider, TLS chain, throttling or bounce/reply process was exercised."
|
||||
],
|
||||
"risks": [
|
||||
"Ambiguous provider outcomes can cause duplicate-send risk if reconciled incorrectly."
|
||||
],
|
||||
"recommendation": "Run target-like interoperability and failure drills before production use.",
|
||||
"proof_check": "Prove SMTP acceptance, IMAP append, throttling and outcome reconciliation."
|
||||
},
|
||||
{
|
||||
"id": "addresses.recipient_sources",
|
||||
"requirement": "Select reusable address lists as Campaign recipient sources.",
|
||||
"status": "available_unconfigured",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-addresses/tests",
|
||||
"note": "14 tests passed"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Enable the Addresses module explicitly."
|
||||
],
|
||||
"gaps": [
|
||||
"Addresses is disabled in the pinned root profile."
|
||||
],
|
||||
"risks": [
|
||||
"Recipient governance may differ between source data and frozen Campaign evidence."
|
||||
],
|
||||
"recommendation": "Enable only when reusable lists are a pilot requirement.",
|
||||
"proof_check": "Build a Campaign from a source list and verify immutable recipient provenance."
|
||||
},
|
||||
{
|
||||
"id": "audit.local",
|
||||
"requirement": "Retain tenant/system audit evidence and retry governed audit events.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-audit/tests",
|
||||
"note": "5 tests passed"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Conclusion covers local database evidence only."
|
||||
],
|
||||
"gaps": [
|
||||
"No central sink, retention enforcement or tamper-evident archive is verified."
|
||||
],
|
||||
"risks": [
|
||||
"Local audit evidence may not satisfy organizational records or SIEM requirements."
|
||||
],
|
||||
"recommendation": "Define retention and export requirements before production approval.",
|
||||
"proof_check": "Exercise privileged-event review, retention and any required external export."
|
||||
},
|
||||
{
|
||||
"id": "identity.federation",
|
||||
"requirement": "Integrate external LDAP/AD, OIDC/SAML or SCIM identity infrastructure.",
|
||||
"status": "scaffold",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "documentation",
|
||||
"scope": "documented_model",
|
||||
"locator": "govoplan-idm/README.md"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No end-to-end provider connector or federated login is verified."
|
||||
],
|
||||
"risks": [
|
||||
"Federation-dependent organizations cannot use the current pilot composition without extra implementation."
|
||||
],
|
||||
"recommendation": "Use local pilot accounts or assess and implement the selected provider path.",
|
||||
"proof_check": "Run provider metadata, login/provisioning, deprovisioning and failure tests."
|
||||
},
|
||||
{
|
||||
"id": "compliance.export_control",
|
||||
"requirement": "Screen persons and organizations against embargo/sanctions lists with review evidence.",
|
||||
"status": "planned",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "issue",
|
||||
"scope": "documented_model",
|
||||
"locator": "https://git.add-ideas.de/add-ideas/govoplan/issues/12"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No provider, list provenance, match policy, review flow or legal evidence exists."
|
||||
],
|
||||
"risks": [
|
||||
"The current composition must not be represented as performing export-control screening."
|
||||
],
|
||||
"recommendation": "Keep outside pilot claims until the user story is implemented and legally validated.",
|
||||
"proof_check": "Validate list ingestion, versioning, matching, false-positive review and audit evidence."
|
||||
},
|
||||
{
|
||||
"id": "workflow",
|
||||
"requirement": "Orchestrate the journey through Workflow.",
|
||||
"status": "planned",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "observation",
|
||||
"scope": "documented_model",
|
||||
"locator": "Assessment scope",
|
||||
"note": "Explicitly postponed"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"Workflow is outside this assessment."
|
||||
],
|
||||
"risks": [
|
||||
"Including it would overstate the assessed composition."
|
||||
],
|
||||
"recommendation": "Do not enable or claim Workflow for this reference pilot.",
|
||||
"proof_check": "Reassess in a later Workflow-focused composition."
|
||||
}
|
||||
],
|
||||
"infrastructure": [
|
||||
{
|
||||
"id": "runtime.web_api",
|
||||
"requirement": "Serve matching WebUI and API artifacts with health endpoints.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/tests/test_module_system.py"
|
||||
},
|
||||
{
|
||||
"kind": "route",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/src/govoplan_core/server/fastapi.py#/health"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Build immutable matching artifacts for promotion."
|
||||
],
|
||||
"gaps": [
|
||||
"No production image or service bundle is supplied by the profile."
|
||||
],
|
||||
"risks": [
|
||||
"Editable source processes are unsuitable as a production artifact."
|
||||
],
|
||||
"recommendation": "Package and supervise WebUI/API from one release candidate.",
|
||||
"proof_check": "Deploy the built artifacts and run health/module-route checks."
|
||||
},
|
||||
{
|
||||
"id": "runtime.worker",
|
||||
"requirement": "Run durable asynchronous Campaign jobs.",
|
||||
"status": "available_unconfigured",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "configuration",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan/tools/launch/launch-production-like-dev.sh"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Redis and a supervised worker are required when Celery is enabled."
|
||||
],
|
||||
"gaps": [
|
||||
"Target heartbeat, restart and queue-age alerting are not proved."
|
||||
],
|
||||
"risks": [
|
||||
"Queued work can stall silently without monitoring."
|
||||
],
|
||||
"recommendation": "Start one worker for the pilot and split queues only after measurement.",
|
||||
"proof_check": "Interrupt and restart a worker while preserving job/reconciliation safety."
|
||||
},
|
||||
{
|
||||
"id": "runtime.scheduler",
|
||||
"requirement": "Run periodic recovery and cleanup safely.",
|
||||
"status": "partial",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-core/tests/test_calendar_outbox_worker.py"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Relevant Calendar work is local WIP."
|
||||
],
|
||||
"gaps": [
|
||||
"No distributed leader election or target supervision is established."
|
||||
],
|
||||
"risks": [
|
||||
"Multiple schedulers can duplicate periodic dispatch without locking."
|
||||
],
|
||||
"recommendation": "Omit from the Campaign-only pilot or run one supervised instance.",
|
||||
"proof_check": "Prove missed-schedule recovery and single-leader behavior."
|
||||
},
|
||||
{
|
||||
"id": "data.postgresql",
|
||||
"requirement": "Persist application state in PostgreSQL with explicit migrations.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "configuration",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan/dev/postgres"
|
||||
},
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan/tools/checks/postgres-integration-check.py"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Target database remains deployment-owned."
|
||||
],
|
||||
"gaps": [
|
||||
"HA, patching, WAL policy and capacity are not assessed."
|
||||
],
|
||||
"risks": [
|
||||
"A single unprotected database is a system-wide failure point."
|
||||
],
|
||||
"recommendation": "Use managed or dedicated PostgreSQL with explicit migration and backup controls.",
|
||||
"proof_check": "Run migrations and restore a target-like database."
|
||||
},
|
||||
{
|
||||
"id": "queue.redis",
|
||||
"requirement": "Provide the Celery broker and queue persistence.",
|
||||
"status": "available_unconfigured",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "configuration",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan/dev/production-like/docker-compose.yml#redis"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"Authentication, TLS, eviction, HA and queue-loss policy are not assessed."
|
||||
],
|
||||
"risks": [
|
||||
"Broker loss or eviction can delay work even when database business state survives."
|
||||
],
|
||||
"recommendation": "Configure private persistent Redis and monitor queue age/depth.",
|
||||
"proof_check": "Exercise broker interruption and worker recovery."
|
||||
},
|
||||
{
|
||||
"id": "storage.local",
|
||||
"requirement": "Persist managed files on a durable single-node/shared path.",
|
||||
"status": "verified",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "contract",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-files/src/govoplan_files/backend/storage/backends.py"
|
||||
}
|
||||
],
|
||||
"conditions": [
|
||||
"Path is durable, private, writable and backed up."
|
||||
],
|
||||
"gaps": [
|
||||
"Node-local storage cannot support independent API replicas."
|
||||
],
|
||||
"risks": [
|
||||
"Files can be lost or become inconsistent with database state."
|
||||
],
|
||||
"recommendation": "Use for a bounded pilot only with coordinated backup.",
|
||||
"proof_check": "Restore files and verify all database references."
|
||||
},
|
||||
{
|
||||
"id": "storage.object",
|
||||
"requirement": "Use S3-compatible storage for independently scalable file persistence.",
|
||||
"status": "partial",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "test",
|
||||
"scope": "current_workspace",
|
||||
"locator": "govoplan-files/tests/test_connector_providers.py"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No chosen target service or storage-backend interoperability drill."
|
||||
],
|
||||
"risks": [
|
||||
"Provider semantics, CA or lifecycle mismatch can break file access/retention."
|
||||
],
|
||||
"recommendation": "Select and exercise the target object store before horizontal scaling.",
|
||||
"proof_check": "Upload, retrieve, version, back up and restore representative objects."
|
||||
},
|
||||
{
|
||||
"id": "edge.proxy_tls",
|
||||
"requirement": "Terminate HTTPS and enforce proxy/security policy.",
|
||||
"status": "external_system",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "route",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-ops/src/govoplan_ops/backend/api/v1/routes.py#deployment-security"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No proxy, certificates, renewal, header or request-limit configuration is shipped here."
|
||||
],
|
||||
"risks": [
|
||||
"Incorrect proxy/cookie/CORS configuration can expose sessions or block legitimate use."
|
||||
],
|
||||
"recommendation": "Supply and monitor the edge through the target platform.",
|
||||
"proof_check": "Run external TLS/header/cookie/CORS and upload-limit tests."
|
||||
},
|
||||
{
|
||||
"id": "security.secret_store",
|
||||
"requirement": "Inject and rotate master, database, mail and connector secrets.",
|
||||
"status": "external_system",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "configuration",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan/.env.example"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No target secret manager or rotation drill is selected."
|
||||
],
|
||||
"risks": [
|
||||
"Loss of the master key makes encrypted credentials unavailable; leakage compromises connectors."
|
||||
],
|
||||
"recommendation": "Use target-native secret injection and document rotation/recovery.",
|
||||
"proof_check": "Rotate a non-production credential and recover from a protected backup."
|
||||
},
|
||||
{
|
||||
"id": "operations.monitoring",
|
||||
"requirement": "Detect API, database, worker, queue, storage and delivery degradation.",
|
||||
"status": "partial",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "route",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-ops/src/govoplan_ops/backend/api/v1/routes.py#/ops/readiness"
|
||||
},
|
||||
{
|
||||
"kind": "contract",
|
||||
"scope": "committed_source",
|
||||
"locator": "govoplan-core/src/govoplan_core/server/fastapi.py#slow-request-logging"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No metrics exporter, log collector, dashboards, alert routes or SLO is verified."
|
||||
],
|
||||
"risks": [
|
||||
"Failures and queue backlog can remain unnoticed."
|
||||
],
|
||||
"recommendation": "Integrate external monitoring before small production.",
|
||||
"proof_check": "Trigger each readiness/delivery failure and verify an actionable alert."
|
||||
},
|
||||
{
|
||||
"id": "operations.backup_restore",
|
||||
"requirement": "Back up and restore database, files, configuration and keys as a coherent service.",
|
||||
"status": "partial",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "documentation",
|
||||
"scope": "documented_model",
|
||||
"locator": "govoplan-core/docs/DEPLOYMENT_OPERATOR_GUIDE.md"
|
||||
},
|
||||
{
|
||||
"kind": "issue",
|
||||
"scope": "documented_model",
|
||||
"locator": "https://git.add-ideas.de/add-ideas/govoplan-core/issues/29"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"No target full-service restore drill or measured RPO/RTO exists."
|
||||
],
|
||||
"risks": [
|
||||
"Partial restore can produce missing files, unusable secrets or inconsistent evidence."
|
||||
],
|
||||
"recommendation": "Treat Core #29 and a target restore drill as a production gate.",
|
||||
"proof_check": "Restore the whole service into an isolated environment and measure it."
|
||||
},
|
||||
{
|
||||
"id": "operations.disaster_recovery",
|
||||
"requirement": "Recover the service after site or dependency loss within agreed RPO/RTO.",
|
||||
"status": "not_assessed",
|
||||
"evidence": [
|
||||
{
|
||||
"kind": "absence",
|
||||
"scope": "current_workspace",
|
||||
"locator": "No target DR plan or exercise evidence supplied"
|
||||
}
|
||||
],
|
||||
"conditions": [],
|
||||
"gaps": [
|
||||
"RPO/RTO, off-site copies, recovery order, failover, communications and exercise schedule are unknown."
|
||||
],
|
||||
"risks": [
|
||||
"Service and evidence may be unrecoverable after a major incident."
|
||||
],
|
||||
"recommendation": "Define and exercise DR before any availability commitment.",
|
||||
"proof_check": "Run a documented end-to-end recovery exercise."
|
||||
}
|
||||
],
|
||||
"data_flows": [
|
||||
{
|
||||
"id": "browser.api",
|
||||
"from": "User browser",
|
||||
"to": "Reverse proxy and GovOPlaN WebUI/API",
|
||||
"data": [
|
||||
"Session and CSRF cookies",
|
||||
"Campaign content",
|
||||
"Recipient personal data",
|
||||
"Managed files"
|
||||
],
|
||||
"trust_boundary": "Client/public to application",
|
||||
"controls": [
|
||||
"HTTPS",
|
||||
"Exact CORS origins",
|
||||
"Secure cookies",
|
||||
"Tenant and RBAC enforcement",
|
||||
"Request limits"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "api.database",
|
||||
"from": "GovOPlaN API and workers",
|
||||
"to": "PostgreSQL",
|
||||
"data": [
|
||||
"Tenant and identity records",
|
||||
"Campaign drafts, snapshots and jobs",
|
||||
"Connector metadata",
|
||||
"Audit evidence"
|
||||
],
|
||||
"trust_boundary": "Application to primary state store",
|
||||
"controls": [
|
||||
"Dedicated database identity",
|
||||
"Private or encrypted transport",
|
||||
"Migrations",
|
||||
"Backup and retention"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "api.queue.worker",
|
||||
"from": "GovOPlaN API",
|
||||
"to": "Redis and Celery worker",
|
||||
"data": [
|
||||
"Job identifiers",
|
||||
"Queue routing and retry metadata"
|
||||
],
|
||||
"trust_boundary": "Request plane to asynchronous processing plane",
|
||||
"controls": [
|
||||
"Private authenticated broker",
|
||||
"Bounded payloads",
|
||||
"Idempotent claims",
|
||||
"Queue monitoring"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "worker.mail",
|
||||
"from": "GovOPlaN Campaign worker",
|
||||
"to": "External SMTP and IMAP services",
|
||||
"data": [
|
||||
"Recipient addresses",
|
||||
"Message bodies",
|
||||
"Attachments",
|
||||
"Sent-message copy"
|
||||
],
|
||||
"trust_boundary": "GovOPlaN to external communication provider",
|
||||
"controls": [
|
||||
"Scoped service account",
|
||||
"TLS and CA policy",
|
||||
"Sender and recipient policy",
|
||||
"Rate limits",
|
||||
"Outcome reconciliation"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "worker.connectors",
|
||||
"from": "GovOPlaN connector worker",
|
||||
"to": "External address, file, object or calendar service",
|
||||
"data": [
|
||||
"Addresses",
|
||||
"Files and provenance",
|
||||
"Calendar resources"
|
||||
],
|
||||
"trust_boundary": "GovOPlaN to organizational/external content systems",
|
||||
"controls": [
|
||||
"Explicit sync direction",
|
||||
"Scoped credentials",
|
||||
"Endpoint allow-list",
|
||||
"Provenance",
|
||||
"Conflict and reconciliation policy"
|
||||
]
|
||||
}
|
||||
],
|
||||
"assumptions": [
|
||||
"The pilot can use local accounts and one internal tenant or office.",
|
||||
"A dedicated non-production SMTP/IMAP account and safe recipients are available.",
|
||||
"Pilot load fits one API and one worker until measured otherwise.",
|
||||
"Durable local storage is acceptable for the pilot."
|
||||
],
|
||||
"open_questions": [
|
||||
"What are the target organization's data classes, legal bases, retention and external-disclosure rules?",
|
||||
"Which identity, mail, file, address and monitoring systems are mandatory?",
|
||||
"What are Campaign volume, concurrency, growth, availability, RPO and RTO?",
|
||||
"Who owns each external runtime component and operational control?",
|
||||
"Which accessibility, security, support and procurement constraints are mandatory?"
|
||||
],
|
||||
"risks": [
|
||||
{
|
||||
"id": "risk.reproducibility",
|
||||
"statement": "The dirty, untagged workspace cannot be reproduced as a release.",
|
||||
"impact": "Uncertain deployed behavior and unsafe promotion or rollback.",
|
||||
"treatment": "Integrate scoped work and create a clean pinned release candidate.",
|
||||
"owner": null,
|
||||
"residual_risk": "Module and environment differences still require release-environment verification."
|
||||
},
|
||||
{
|
||||
"id": "risk.delivery_provider",
|
||||
"statement": "Target SMTP/IMAP behavior and failure modes are unproved.",
|
||||
"impact": "Failed, delayed or duplicate communication and incomplete evidence.",
|
||||
"treatment": "Run target-like interoperability, throttling and uncertainty drills.",
|
||||
"owner": null,
|
||||
"residual_risk": "External provider outages and ambiguous outcomes remain operational risks."
|
||||
},
|
||||
{
|
||||
"id": "risk.recovery",
|
||||
"statement": "Backup/restore and disaster recovery are not demonstrated across all state and keys.",
|
||||
"impact": "Irrecoverable or inconsistent service after loss.",
|
||||
"treatment": "Complete Core #29 and an isolated full-service restore/DR exercise.",
|
||||
"owner": null,
|
||||
"residual_risk": "Recovery time and data loss remain bounded by the selected external infrastructure."
|
||||
}
|
||||
],
|
||||
"recommendations": [
|
||||
"Proceed only with a controlled internal Campaign pilot after the bounded proof checks pass.",
|
||||
"Use the minimal composition and enable Addresses only for an explicit reusable-recipient journey.",
|
||||
"Do not claim Workflow, export-control screening, identity federation or production DR as implemented.",
|
||||
"Treat a clean release candidate, target mail proof, monitoring and coherent restore drill as production gates."
|
||||
],
|
||||
"proof_checks": [
|
||||
"Pin and build a clean matching backend/WebUI release candidate and rerun cross-repository gates.",
|
||||
"Run a safe target-like Campaign through SMTP acceptance, IMAP append, reporting and audit.",
|
||||
"Drill worker, Redis and ambiguous-delivery failures without duplicate sends.",
|
||||
"Restore PostgreSQL, managed files, configuration and encrypted credentials and measure RPO/RTO.",
|
||||
"Validate proxy/TLS, cookies/CORS, account bootstrap, secret redaction, monitoring and alert delivery.",
|
||||
"Measure representative Campaign/file/queue/database load and external throttling."
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user