[User Story] One-command Core bootstrap, module lifecycle, scale-out, and environment promotion #13
Open
opened 2026-07-21 11:07:16 +02:00 by zemion
·
13 comments
No Branch/Tag Specified
Labels
Clear labels
area/api
area/auth
area/db
area/devex
area/docs
area/governance
area/marketing
area/migrations
area/module-system
area/rbac
area/release
area/security
area/tenancy
area/webui
audit/complexity
audit/duplication
audit/false-positive
audit/needs-design
audit/quick-fix
audit/structural
codex/needs-human
codex/ready
module/access
module/addresses
module/admin
module/appointments
module/approvals
module/audit
module/calendar
module/campaign
module/cases
module/committee
module/connectors
module/core
module/dashboard
module/dataflow
module/datasources
module/decisions
module/dist-lists
module/dms
module/docs
module/encryption
module/erp
module/evaluation
module/files
module/fit-connect
module/forms
module/forms-runtime
module/helpdesk
module/identity
module/identity-trust
module/idm
module/ledger
module/mail
module/mandates
module/notifications
module/ops
module/organizations
module/parties
module/payments
module/permits
module/policy
module/poll
module/portal
module/postbox
module/projects
module/quick-access
module/records
module/reporting
module/risk-compliance
module/scheduling
module/search
module/services
module/tasks
module/templates
module/tenancy
module/tickets
module/views
module/voting
module/wiki
module/workflow
module/workflow-engine
module/xoev
module/xrechnung
module/xta-osci
source/backlog-import
source/security-audit
source/todo-scan
HTTP API contracts, routers, schemas, or API smoke behavior.
Authentication, sessions, access bootstrap, or login behavior.
Database sessions, models, transactions, or persistence primitives.
Local developer workflow, scripts, tests, tooling, or release helpers.
Durable documentation and project guidance.
Governance policy, audit, privacy, retention, or compliance behavior.
Public website, product messaging, publication copy, or legal page content.
Alembic migrations, schema bootstrap, or persistence evolution.
Module discovery, manifests, capabilities, routing, or optional integrations.
Permissions, roles, delegation, or authorization policy.
Versioning, release locks, tags, packaging, or dependency pins.
Security posture, static analysis, supply-chain hardening, or vulnerability remediation.
Tenant boundaries, provisioning, or tenant-scoped data behavior.
Shared WebUI shell, frontend components, routing, or frontend tests.
Complexity finding from Radon, Xenon, or equivalent maintainability scans.
Duplicated-code finding from jscpd or equivalent similarity scans.
Audit finding reviewed as a narrow false positive or acceptable risk.
Audit finding that needs an architectural or product decision before implementation.
Audit finding that appears narrow and directly fixable.
Audit finding that needs design, refactoring, or behavior review.
Needs an explicit human decision before Codex should implement.
Suitable for Codex to pick up with the existing issue context.
GovOPlaN access, identity, authentication, RBAC, and administration behavior.
GovOPlaN Addresses module behavior or integration.
GovOPlaN Admin module behavior or integration.
GovOPlaN Appointments module behavior or integration.
GovOPlaN Approvals module behavior or integration.
GovOPlaN Audit module behavior or integration.
GovOPlaN Calendar module behavior or integration.
GovOPlaN campaign module behavior or integration.
GovOPlaN Cases module behavior or integration.
GovOPlaN Committee module behavior or integration.
GovOPlaN Connectors module behavior or integration.
GovOPlaN core runner, shared primitives, shell, or extension points.
GovOPlaN Dashboard module behavior or integration.
GovOPlaN Dataflow module behavior or integration.
GovOPlaN governed datasource contracts, catalogs, and integrations.
GovOPlaN formal Decisions module behavior or integration.
GovOPlaN Distribution Lists module behavior or integration.
GovOPlaN Dms module behavior or integration.
GovOPlaN Docs module behavior or integration.
GovOPlaN Encryption key custody, cryptographic policy, and E2EE integration.
GovOPlaN Erp module behavior or integration.
GovOPlaN Evaluation module behavior or integration.
GovOPlaN files module behavior or integration.
GovOPlaN Fit Connect module behavior or integration.
GovOPlaN Forms module behavior or integration.
GovOPlaN Forms Runtime module behavior or integration.
GovOPlaN Helpdesk module behavior or integration.
GovOPlaN Identity module behavior or integration.
GovOPlaN Identity Trust module behavior or integration.
GovOPlaN Idm module behavior or integration.
GovOPlaN Ledger module behavior or integration.
GovOPlaN mail module behavior or integration.
GovOPlaN Mandates, jurisdiction, responsibility, and authority behavior or integration.
GovOPlaN Notifications module behavior or integration.
GovOPlaN Ops module behavior or integration.
GovOPlaN Organizations module behavior or integration.
GovOPlaN procedure Parties, representation, and delivery-authority behavior or integration.
GovOPlaN Payments module behavior or integration.
GovOPlaN Permits module behavior or integration.
GovOPlaN Policy module behavior or integration.
GovOPlaN Poll module behavior or integration.
GovOPlaN Portal module behavior or integration.
GovOPlaN Postbox module behavior or integration.
GovOPlaN Projects module behavior or integration.
GovOPlaN configurable task-local Quick Access behavior and integrations.
GovOPlaN Records and eAkte lifecycle behavior or integration.
GovOPlaN Reporting module behavior or integration.
GovOPlaN Risk Compliance module behavior or integration.
GovOPlaN Scheduling module behavior or integration.
GovOPlaN Search module behavior or integration.
GovOPlaN versioned institutional Services behavior or integration.
GovOPlaN Tasks module behavior or integration.
GovOPlaN Templates module behavior or integration.
GovOPlaN Tenancy module behavior or integration.
GovOPlaN Tickets module behavior or integration.
GovOPlaN governed task views, interface projections, and workflow view integration.
GovOPlaN Voting module behavior or integration.
GovOPlaN Wiki module behavior or integration.
GovOPlaN Workflow module behavior or integration.
GovOPlaN Workflow Engine runtime, persistence, or integration.
GovOPlaN Xoev module behavior or integration.
GovOPlaN Xrechnung module behavior or integration.
GovOPlaN Xta Osci module behavior or integration.
priority
p0
Immediate stop-the-line priority.
priority
p1
High priority for the next focused work window.
priority
p2
Normal planned priority.
priority
p3
Low priority or opportunistic cleanup.
Imported from markdown backlog, roadmap, plan, or TODO files.
Created from a structured security or code-quality audit report.
Imported from inline TODO/FIXME/HACK markers by the Gitea TODO importer.
status
blocked
Cannot progress without a decision, dependency, credential, or external change.
status
in-progress
Currently being worked.
status
needs-info
Needs clarifying input before implementation can proceed safely.
status
ready
Ready for implementation.
status
triage
Needs review, ownership, priority, or acceptance criteria.
type
bug
A reproducible defect, regression, or incorrect behavior.
type
debt
Cleanup, refactoring, risk reduction, or deferred engineering work.
type
docs
Documentation, process, or developer workflow work.
type
feature
New user-visible behavior or platform capability.
type
task
Implementation, maintenance, migration, or operational work.
type
user-story
End-to-end user journey or real-world process story used to steer product slices.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: GovOPlaN/govoplan#13
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
System Administrator Lifecycle User Story
Story
This is a product-level story owned by the GovOPlaN platform rather than by an
individual domain module. It joins installation, module lifecycle, operations,
configuration packages, and release provenance into one administrator journey.
Terms
WebUI, PostgreSQL, Redis, installer worker, migration runner, and durable
storage configuration. No optional GovOPlaN module package is installed.
that may access only first-run and module-lifecycle functions. It is retired
when the selected identity/access configuration becomes healthy.
contract, migrations, WebUI contribution, checksums, and SBOM references.
non-secret system/module settings, policies, compositions, and secret
references. Secret values are never exported.
versions, configuration revision, migration order, preflight results,
maintenance/drain requirements, health checks, and permitted rollback or
forward-recovery actions.
Acceptance journeys
One-command first installation
starting downloaded artifacts.
and connectivity requirements; generates deployment-local secrets with
restrictive permissions; and never prints them.
migration runner. Readiness does not pass until migrations and durable
dependencies are healthy.
command is idempotent and shows or repairs the existing installation rather
than creating another identity or database.
Module selection, installation, and update
outbound-network policy.
update-available releases with their channel, provenance, contracts,
migrations, permissions, configuration requirements, and release notes.
mutation. The administrator can amend the selection or confirm the plan.
state and can reconnect without losing progress.
graph, configuration schema, and health checks are mandatory gates.
rollback, or manual-intervention state. It never reports success merely
because the initiating request returned.
repeated requests are idempotent.
Horizontal scaling
with respect to local container disks. Durable state uses PostgreSQL, Redis,
and configured shared file/object storage.
default Compose profile supports local scale-out; an orchestrator profile
supplies equivalent health/readiness probes and rolling replacement.
while any healthy replica can serve read and normal domain traffic.
drain state. Operators can see skew and safely retire a replica.
work remain correct when requests move between replicas.
Development, test, and production promotion
the WebUI. The package is versioned, checksummed, attributable, and contains
secret references or required-secret declarations, never secret values.
values, missing capabilities/secrets, compatibility changes, and the exact
apply plan.
addressable. Undo is a new audited revision that restores the earlier
configuration where contracts permit it.
immutable release and configuration identifiers.
confirmation, and executes the same ordered plan. Environment-specific
secret bindings and endpoints remain local.
anonymized fixtures, and backup/restore are separate explicit operations.
Safety and governance requirements
checksums, provenance, expiry/revocation semantics, and audit evidence.
not imply host/package-management access.
package migrations that require forward recovery.
commit a stale result.
prerequisites, database compatibility windows, and post-change probes.
outbound-network policy, storage, TLS/cookie posture, and observability.
machine-readable dependency/SBOM provenance.
Implementation slices
images, signed distribution manifest, Core-only Compose profile, bootstrap
preflight, generated secrets, readiness, and idempotent rerun/repair.
one-time enrollment, initial catalog/keyring configuration, and retirement
after durable administrator access is established.
directory contracts into the installed Core WebUI with compatibility,
provenance, release-note, and update-state presentation.
locks, signed-package validator, rollback drill, and run evidence behind a
plan/confirm/progress UI. Add initial catalog-entry synthesis and artifact
acquisition where the current release console still assumes local sources.
migration compatibility window, reconnectable progress, health verification,
retry/recovery, and update notification.
expose role-specific commands/images, implement worker registration/drain,
and prove multiple API and worker replicas against shared dependencies.
canonical serialization, secret references, validation/diff, immutable
revision storage, audit, apply, and undo-as-new-revision.
preview, environment bindings, acceptance evidence, exact recipe generation,
signed transfer, and independently confirmed application.
catalogs, revoked keys, failed migrations, replica loss, configuration undo,
and development-to-test-to-production promotion in release CI and target
drills.
Explicit non-goals for the first distribution slice
standard cluster scheduler through the same role/readiness contracts.
Codex State: note
Summary
Changed Files
docs/SYSTEM_ADMINISTRATOR_LIFECYCLE_USER_STORY.mddocs/REFERENCE_JOURNEY_PROGRAM.mdVerification
PYTHONPATH=. .venv/bin/python -m pytest -q -> 57 passedNext / Blocked
Executable deployment-compiler slice
Implemented and pushed in
GovOPlaN/govoplan@82e836b:Production remains deliberately blocked until image/signature/enrollment/ingress gates are complete.
Child work
Local implementation progress (pending push):
Verification: 25 installer tests, 15 Core configuration/policy tests, 6 Files storage tests, Ruff, git diff --check, a live Garage 2.3 bootstrap, and real Files S3 put/get/stat/delete all pass. The consolidated focused suite also passes, including 31 WebUI module permutations and the full-product build.
This completes a useful portion of the horizontal-scaling and managed-storage journey, but not multi-host HA. Remaining cluster work is now tracked explicitly in #27.
Codex State: progress
Summary
Changed Files
docs/INSTALLATION_AND_DEPLOYMENT_ARCHITECTURE.mddocs/RECOVERY_AND_ROLLBACK_GUARANTEES.mddocs/SYSTEM_ADMINISTRATOR_LIFECYCLE_USER_STORY.mdVerification
30 deployment-installer tests and the full workspace focused gate passedNext / Blocked
Suggested status label:
status/in-progressCodex State: note
Summary
Package distribution slice completed in
f7590a7: protected per-module wheel/npm workflows, exact registry artifact locking, signed runtime package-lock binding, and the optionalgovoplandeveloper meta-package are implemented and pushed across all packageable repositories. Initial registry population is tracked separately in #38 because it requires a dedicated least-privilege package token.Codex State: Kubernetes rehearsal completed
The scale-out slice now has a clean immutable subject and passing live rehearsal:
v0.1.18runtime, including the tracked WebUI entrypoint;389df7c).Receipt SHA-256:
259f8e33b7b7a7161e1278f3ae94d52d99d88fcc2659fd1f1f8a2808cfb08abc.This completes the source-controlled and same-host rehearsal work for the Kubernetes part of this story. GovOPlaN #27 remains open for repetition on independent physical failure domains; #37 remains the wider controlled production maturity/recovery evidence gate. The other module-lifecycle and environment-promotion acceptance journeys remain independently tracked.
Codex State: progress
Summary
Changed Files
docs/DEPLOYMENT_PROFILES.mddocs/INSTALLATION_AND_DEPLOYMENT_ARCHITECTURE.mddev/production-like/README.mdVerification
tools/checks/check-focused.sh (passed)Next / Blocked
7b0ab31on main.Suggested status label:
status/in-progressThe normalized source ideas and user-story orientation are now preserved in
govoplan/docs/PRODUCT_INPUT_REGISTER.md. This issue remains the canonical live work item for the corresponding outcome.Codex State: progress
Summary
Verification
Core module-system suite: 125 tests passedFocused cross-repository suite: 56 WebUI permutations and module checks passedManifest registry: 67/67 modules passedNext / Blocked
Suggested status label:
status/in-progressCodex State: progress
Summary
Verification
Local catalog validation: signed=true, trusted=true, sequence=202608061915, warnings=[]Website production build passedNext / Blocked
Suggested status label:
status/in-progressCodex State: progress
Summary
Changed Files
govoplan@78811f7govoplan-core@44196f5govoplan-admin@9d522efaddideas-govoplan-website@dc9c48fVerification
39 targeted release/publication tests passedCore module-system regression suite passedAdmin test suite and Core TypeScript build passed67/67 manifest shape gate and consolidated focused check passedWebsite catalog validator (including Core signature validation) and production build passedNext / Blocked
Suggested status label:
status/in-progressImplemented the next public-catalog governance slice.
Delivered:
Commits: GovOPlaN/govoplan@dce7256, GovOPlaN/govoplan-core@40cc012, GovOPlaN/govoplan-admin@bc589a3.
This closes the permission-disclosure slice, not the broader bootstrap/user-story issue.