Audited against origin/master — NOT DONE, none of the three fix options. And the audit turned up something sharper than "nobody got to it":
**This is the one backend workflow with no…
Audited against origin/master — NOT DONE, and the blast radius is fleet-wide. Staying open.
No convergence check exists. The shared deploy path is `spikersoft-backend/.gitea/workflows/_…
Audited against origin/master — the incident was remediated; none of the four prevention items landed. Staying open, and the prevention half is the part that matters.
The remediation is…
Audited against origin/master — NOT DONE, and fix 3 as written is currently impossible. That's the useful finding, so leading with it.
**Fix 3 — "alert on the notifications DLQ / failure…
Audited against origin/master — all the code and provisioning landed; only the one-time key rotation remains. Staying open on that single step.
Committed and complete:
- `spikersoft-fil…
Audited against origin/master — tier 2 is done and annotated; tier 1 (the headline fix) has no evidence of any kind. Staying open.
Tier 2 — Gitea→MinIO direct path: DONE, and…
Audited against origin/master — the blocking gate has cleared; only the live cutover verification remains. Staying open on that.
The tier-3 image now exists, which the 2026-07-22 board…
Audited against origin/master — NOT DONE. No implementing change of any kind.
git log origin/master --grep='#603'across all repos: zero commits.- No global-service coverage guard…
Audited — UNVERIFIABLE FROM GIT, with no positive evidence of a fix. Treat as still open.
Passwords live in OpenBao and Keycloak, neither of which is in git — correctly so, per the central…
Audited against origin/master — PARTIAL, exactly as the 2026-07-22 reconciliation comment says. The credential tooling shipped; the suite split has not started.
**Done — persona…
Audited against origin/master — NOT DONE. Neither the replay nor the systemic fix exists. Flagging the time-sensitive part first.
No replay tooling of any kind. `git grep -iE…
Audited against origin/master — the premise has gone stale; this ticket needs restating rather than simply closing or leaving.
**The pin was deliberately reverted, and that's now…
Audited against origin/master — NOT DONE. Zero implementing change; all four acceptance criteria unstarted. Recording the greps so this doesn't need re-deriving:
- **No KV path, policy or…
Audited against origin/master — the literal complaint was fixed; the impact persists. Staying open.
Fixed: every workflow carrying the pull now uses the sudo form. `git grep -l "sudo…
Audited against origin/master — the workflow shipped, but the mirror is empty and zero stacks were repointed. Staying open. Concrete numbers so the remaining work is measurable:
Built:…
Audited against origin/master — the seam itself is adopted fleet-wide, but 6 stacks were left behind and Stage 4 is unswept. Staying open.
**Adopted centrally rather than per-service,…
New finding — a sixth item, not in the original five. Turned up while auditing #610. Locations only below, no values.
spikersoft-infrastructure/mailserver/docker-stack.yml commits **five…
Audited against origin/master — NOT DONE, and this is the same live defect as #482, not a distinct one. Recommending a merge.
Same corruption, same object, same failing job. Both…
Noting for the record — this was closed today (2026-07-29 ~15:36Z) with no closing comment, and I'm leaving it closed on the assumption that was deliberate. But the **durable fix is definitively…