docs: refresh capability release baseline

This commit is contained in:
2026-07-22 15:21:27 +02:00
parent 5447299289
commit c29f1e9977
2 changed files with 152 additions and 116 deletions

View File

@@ -1,8 +1,8 @@
{
"$schema": "./capability-fit.schema.json",
"schema_version": "0.1.0",
"assessment_id": "campaign-reference-2026-07-20",
"assessed_at": "2026-07-20",
"assessment_id": "campaign-reference-2026-07-22",
"assessed_at": "2026-07-22",
"scope": {
"title": "Campaign-centric internal pilot and small-production candidate",
"reference_journeys": [
@@ -14,30 +14,31 @@
]
},
"release": {
"kind": "workspace_snapshot",
"ref": "workspace-2026-07-20",
"meta_commit": "05ae81d64195",
"reproducible": false,
"kind": "tagged_release",
"ref": "stable-catalog-202607220843",
"meta_commit": "5447299289a1",
"reproducible": true,
"configuration_packages": [],
"notes": [
"The snapshot is untagged.",
"Dirty repositories are recorded and local-only work is not treated as release-integrated."
"The live stable catalog has a valid Ed25519 signature trusted through release-key-1.",
"Core v0.1.13 and Campaign v0.1.10 are tagged and package-integrated; this is not target-environment or production approval.",
"No configuration revision or configuration package is pinned yet."
]
},
"composition": [
{
"module_id": "core",
"repository": "govoplan-core",
"commit": "e6f7c45f0a95",
"manifest_version": "server-0.3.0",
"commit": "d487726f4d2c",
"manifest_version": "0.1.13",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "API, registry, migrations, sessions, kernel contracts and shared WebUI"
},
{
"module_id": "tenancy",
"repository": "govoplan-tenancy",
"commit": "1dde03854733",
"commit": "efbec827616b",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": false,
@@ -46,7 +47,7 @@
{
"module_id": "organizations",
"repository": "govoplan-organizations",
"commit": "45cda1a33f18",
"commit": "39c081c4fb8f",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": false,
@@ -58,22 +59,22 @@
"commit": "7a1710af896f",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Normalized internal identity directory"
},
{
"module_id": "access",
"repository": "govoplan-access",
"commit": "ab07075a679b",
"manifest_version": "0.1.8",
"commit": "f1d64d247e12",
"manifest_version": "0.1.11",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Local authentication, sessions, API keys and RBAC"
},
{
"module_id": "admin",
"repository": "govoplan-admin",
"commit": "c9e1fb287f50",
"commit": "11ecf362a36d",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": false,
@@ -82,7 +83,7 @@
{
"module_id": "dashboard",
"repository": "govoplan-dashboard",
"commit": "a315a7c62b1d",
"commit": "4b960ad37f0d",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": false,
@@ -91,8 +92,8 @@
{
"module_id": "policy",
"repository": "govoplan-policy",
"commit": "2511fbb5a864",
"manifest_version": "0.1.8",
"commit": "1063622d311a",
"manifest_version": "0.1.9",
"enabled": true,
"dirty": false,
"role": "Policy explanation and configuration boundary"
@@ -100,7 +101,7 @@
{
"module_id": "audit",
"repository": "govoplan-audit",
"commit": "5e4f84a789ea",
"commit": "d3d2c60d7dc1",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": false,
@@ -109,46 +110,46 @@
{
"module_id": "campaigns",
"repository": "govoplan-campaign",
"commit": "2e593b7fa412",
"manifest_version": "0.1.8",
"commit": "735e874bd03c",
"manifest_version": "0.1.10",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Campaign authoring, build, delivery control and reporting"
},
{
"module_id": "files",
"repository": "govoplan-files",
"commit": "f3210234d35a",
"manifest_version": "0.1.8",
"commit": "2b34f6e30578",
"manifest_version": "0.1.9",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Managed files and Campaign attachments"
},
{
"module_id": "mail",
"repository": "govoplan-mail",
"commit": "b0337b2d261a",
"manifest_version": "0.1.8",
"commit": "3e2302909022",
"manifest_version": "0.1.10",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "SMTP and IMAP profiles and transports"
},
{
"module_id": "calendar",
"repository": "govoplan-calendar",
"commit": "371a00aff51c",
"commit": "9bcf41bb1fbb",
"manifest_version": "0.1.8",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Optional calendar outside the Campaign pilot minimum"
},
{
"module_id": "docs",
"repository": "govoplan-docs",
"commit": "f2ade1d62475",
"manifest_version": "0.1.8",
"commit": "be52b716caed",
"manifest_version": "0.1.10",
"enabled": true,
"dirty": true,
"dirty": false,
"role": "Configured-system documentation"
},
{
@@ -163,10 +164,10 @@
{
"module_id": "addresses",
"repository": "govoplan-addresses",
"commit": "f19350e65d76",
"manifest_version": "0.1.8",
"commit": "93dddbb8c52a",
"manifest_version": "0.1.9",
"enabled": false,
"dirty": true,
"dirty": false,
"role": "Optional reusable recipient sources and CardDAV"
}
],
@@ -293,20 +294,20 @@
"kind": "contract",
"scope": "current_workspace",
"locator": "govoplan/tools/checks/check-contracts.py",
"note": "43 contracts, 29 providers, no issues"
"note": "43 modules, 33 providers, 19 requirements, no issues"
}
],
"conditions": [
"Repeat checks on a clean pinned release candidate."
"Package integration is verified; repeat checks on the installed target composition."
],
"gaps": [
"The current snapshot is dirty and untagged."
"No target deployment acceptance is recorded."
],
"risks": [
"A working module graph can still be unreproducible."
"A reproducible module graph can still be installed or configured incorrectly."
],
"recommendation": "Use the minimal Campaign composition and pin all artifacts before promotion.",
"proof_check": "Run contract, migration, API and WebUI module-permutation gates on the release candidate."
"recommendation": "Use the signed stable catalog and verify the minimal Campaign composition after installation.",
"proof_check": "Run contract, migration, API and WebUI module-permutation gates on the installed release."
},
{
"id": "access.local",
@@ -348,21 +349,27 @@
},
{
"kind": "test",
"scope": "current_workspace",
"scope": "committed_source",
"locator": "govoplan-campaign/tests",
"note": "14 tests passed"
"note": "Campaign v0.1.10 is exactly the catalog-selected tagged source"
},
{
"kind": "configuration",
"scope": "committed_source",
"locator": "https://govoplan.add-ideas.de/catalogs/v1/channels/stable.json#sequence-202607220843",
"note": "Core v0.1.13 and Campaign v0.1.10 have matching catalogued Python and WebUI refs"
}
],
"conditions": [
"This verifies implementation paths, not target-provider delivery."
],
"gaps": [
"Substantial Campaign UI/code WIP is not release-integrated."
"Usability and target-provider acceptance remain separate."
],
"risks": [
"Local WIP can make the checkout look more complete than the release baseline."
"Package integration does not prove provider behavior or production operations."
],
"recommendation": "Integrate and retest Campaign work before usability or production acceptance.",
"recommendation": "Use the catalogued Campaign release for usability and target-provider acceptance.",
"proof_check": "Run the complete journey with safe data and the target-like mail service."
},
{
@@ -554,7 +561,7 @@
}
],
"conditions": [
"Build immutable matching artifacts for promotion."
"Materialize the matching catalogued artifacts in the target."
],
"gaps": [
"No production image or service bundle is supplied by the profile."
@@ -562,7 +569,7 @@
"risks": [
"Editable source processes are unsuitable as a production artifact."
],
"recommendation": "Package and supervise WebUI/API from one release candidate.",
"recommendation": "Install matching catalogued WebUI/API refs and supervise them as immutable artifacts.",
"proof_check": "Deploy the built artifacts and run health/module-route checks."
},
{
@@ -595,12 +602,13 @@
"evidence": [
{
"kind": "test",
"scope": "current_workspace",
"locator": "govoplan-core/tests/test_calendar_outbox_worker.py"
"scope": "committed_source",
"locator": "govoplan-calendar/tests/test_outbox.py",
"note": "Committed and pushed after the catalogued Calendar v0.1.8 tag"
}
],
"conditions": [
"Relevant Calendar work is local WIP."
"Calendar outbox and recovery work is remote-integrated source but not stable-package-integrated."
],
"gaps": [
"No distributed leader election or target supervision is established."
@@ -928,9 +936,9 @@
"risks": [
{
"id": "risk.reproducibility",
"statement": "The dirty, untagged workspace cannot be reproduced as a release.",
"impact": "Uncertain deployed behavior and unsafe promotion or rollback.",
"treatment": "Integrate scoped work and create a clean pinned release candidate.",
"statement": "The signed package selection is reproducible but has not been accepted as an installed target composition.",
"impact": "Installation or configuration drift can still produce uncertain deployed behavior.",
"treatment": "Materialize the signed catalog in an isolated target and run installed-artifact acceptance gates.",
"owner": null,
"residual_risk": "Module and environment differences still require release-environment verification."
},
@@ -955,10 +963,10 @@
"Proceed only with a controlled internal Campaign pilot after the bounded proof checks pass.",
"Use the minimal composition and enable Addresses only for an explicit reusable-recipient journey.",
"Do not claim Workflow, export-control screening, identity federation or production DR as implemented.",
"Treat a clean release candidate, target mail proof, monitoring and coherent restore drill as production gates."
"Treat installed-release acceptance, target mail proof, monitoring and a coherent restore drill as production gates."
],
"proof_checks": [
"Pin and build a clean matching backend/WebUI release candidate and rerun cross-repository gates.",
"Materialize the signed catalog into an isolated installation and rerun contract, migration and module-permutation gates against the installed artifacts.",
"Run a safe target-like Campaign through SMTP acceptance, IMAP append, reporting and audit.",
"Drill worker, Redis and ambiguous-delivery failures without duplicate sends.",
"Restore PostgreSQL, managed files, configuration and encrypted credentials and measure RPO/RTO.",