Commit Graph
3 Commits
Author SHA1 Message Date
curo1305 de2efd1664 test(12-05): add migration 0005→0006 integration regression and RUNBOOK migration ops
- test_migration_0006.py: proves display_name_override, cloud_items, cloud_item_topics,
  cloud_folder_states, unique constraints, indexes, and DDL privilege boundary
- Tests skip cleanly without INTEGRATION=1/INTEGRATION_DATABASE_URL (no dev DB mutation)
- RUNBOOK: add Database Migrations section with revision check, upgrade, recovery, and
  emergency schema-drift remediation commands
2026-06-20 10:47:11 +02:00
curo1305 fccb9c6394 security(12-04): add Phase 12 security gate evidence and cloud ops runbook
- SECURITY.md: Phase 12 threat register (T-12-01 through T-12-SC) with
  evidence for all 8 threat IDs; bandit/npm audit gate results;
  accepted risks for pip-audit tooling gap and DISABLED connection behavior
- RUNBOOK.md: Phase 12 cloud operations section covering connection
  management, browse refresh lifecycle, item metadata queries,
  stuck-refresh recovery, and security operation notes
2026-06-19 01:52:49 +02:00
curo1305andClaude Sonnet 4.6 670df192d6 docs(06-06): add RUNBOOK.md — env vars, startup, backup, health checks, escalation, failure modes
Covers D-14: all required env vars with examples, Docker Compose startup/shutdown
procedures, PostgreSQL + MinIO backup strategy with restore commands, health check
verification for all 7 services, on-call escalation for 6 alert classes, and
recovery steps for all 7 Phase 6 failure modes (Pitfalls 1, 5, 6, 7 + rate limit
edge cases + Grafana/Loki). docker scout CVE scan gate (D-10) documented in
Section 5 with prerequisites, pass/fail criteria, remediation, and Trivy fallback.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 19:05:05 +02:00