Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 20 additions & 8 deletions system/decisions.md
Original file line number Diff line number Diff line change
Expand Up @@ -372,8 +372,8 @@ part of the process, not excluded from it. (Ben, 2026-10-06)
no cooldown on security content. (Ben, 2026-10-06)

(decision-maintenance-window)=
**One window for every host**: one fixed weekly window, on Thursday
morning Pacific time and reserved for four hours, covers every host, so
**One window for every host**: one fixed-UTC weekly window, falling on
Thursday morning Pacific time and reserved for four hours, covers every host, so
the team keeps one simple model. (Ben, 2026-10-06)

(decision-ami-bake)=
Expand Down Expand Up @@ -497,8 +497,11 @@ database image) and publishes them together under the served index hash.
The bump pull request writes the database unit file's digest from the
attested build it dispatched, so the post-publish repin commit and the
second promotion go. The attestation verifier accepts the attestation of
the exact commit that became main by fast-forward. This reverses the
earlier ruling that kept the two-hop chain. (Ben, 2026-10-06)
the exact commit that became main by fast-forward (this clause is
superseded below by the two-commit database image sequence in
{ref}`the Wednesday transaction <decision-maintenance-redesign>`). This
reverses the earlier ruling that kept the two-hop chain. (Ben,
2026-10-06)

(decision-no-weekly-application-image)=
**No weekly application image**: a weekly promoter rebuild and window
Expand All @@ -511,7 +514,12 @@ report. (Ben, 2026-10-06)
previews and deploys every stack whose template or data changed in the
published commit, under the maintenance role, with a drift check as
proof. Host-replacing changes are refused and left to the window. The
maintenance stack deploys last and never mid-run. (Ben, 2026-10-06)
maintenance stack deploys last and never mid-run. (Ben, 2026-10-06; the
clauses on which stacks deploy and on host replacement are superseded
below by {ref}`the Wednesday transaction <decision-maintenance-redesign>`,
which prepares production stack changes on Wednesday and applies them
inside Thursday's lock, deploys build-substrate stacks at once, and
refuses host-replacing, removing and durable-replacing changes)

(decision-health-signal)=
**One health signal**: every pin-table row carries three ages (newest
Expand All @@ -520,7 +528,8 @@ is current, cooling or stalled. A row is stalled when the published
version lags upstream by the cooldown plus a week, or the deployed
version lags the published one by a week, and a stalled row is an
escalation with an owner. Per-chain alarms stay as diagnostics. (Ben,
2026-10-06)
2026-10-06; the owner clause is superseded below by
{ref}`team-owned escalation <decision-team-owned-escalation>`)

(decision-release-cut)=
**Release cut**: the release cut runs unattended in CodeBuild on a tag
Expand All @@ -546,8 +555,11 @@ rulings, I want to do this right"), and the design was adopted on merit
after an independent review. One Wednesday transaction replaces the
Sunday bump, the five-day promoter and the promoter pause: the bump runs
early Wednesday, the promoter builds from the merged state, and
preparation follows later that day. A human merge waits for Wednesday,
and a release cut builds from the last publication. Production stack
preparation follows later that day. A human merge waits for Wednesday
(superseded below by
{ref}`flexibility for team development <decision-extensibility>`, which
runs the transaction on every merge and keeps Wednesday as the scheduled
discovery), and a release cut builds from the last publication. Production stack
changes are prepared on Wednesday and applied inside Thursday's lock,
build-substrate stacks deploy at once, and host-replacing, removing and
durable-replacing changes are refused. Vendor and community packages
Expand Down
2 changes: 1 addition & 1 deletion system/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ repository's history. The rebuild starts from this page.
| Document | Status | Scope |
|---|---|---|
| [`specification.md`](specification) | DRAFT | Purpose and outcome; the pipelines and their stages; the stage contract; runs, the three output states, promotion, attempts and deletion; tools; the three repositories and their boundary; releases; the manifest edges; constraints; sequencing; what is not yet decided |
| [`decisions.md`](decisions) | DRAFT | The team's rulings, one dated line each with its author: Ben's rulings of 2026-09-27, earlier rulings, and the rulings carried from the build pending team review |
| [`decisions.md`](decisions) | DRAFT | The team's rulings, one dated line each with its author: Ben's rulings of 2026-09-27, his rulings of 2026-10-06 on weekly maintenance on SMDC, earlier rulings, and the rulings carried from the build pending team review |
| [`products.md`](products) | DRAFT | Product kinds and result-set kinds, logical key versus instance id, bundles, reading across runs, registration metadata with one source per field, one complete worked manifest |
| [`runs.md`](runs) | DRAFT | The run-model tables beside the kept `dev` schema; unit and attempt state machines; instances and the three custody states; promotion under one lock with before and after per key; guarded deletion as the only deleter; storage layout; identifiers |
| [`stage-contract.md`](stage-contract) | DRAFT | The `rapidpipe` package and its dependency direction; the stage declaration, one invocation form, attempts, the manifest, six exit codes, settings; local fixtures; what it replaces |
Expand Down