ops(legacy): plan non-backup legacy env/data/state disposal after inventory #599

Open
opened 2026-05-29 08:19:26 +02:00 by codex · 4 comments
Collaborator

Context

M01 deleted only the approved legacy backup target. Remaining non-backup legacy material was explicitly out of scope.

This issue depends on the inventory follow-up and should not execute any destructive action by itself.

Scope

After inventory, propose a low-priority disposal plan for remaining non-backup legacy material:

  • keep;
  • cold archive;
  • tombstone/quarantine;
  • later delete with explicit operator approval.

Acceptance

  • Plan names exact path classes, not broad roots.
  • Separates secret-bearing/env material from ordinary state/data.
  • Includes rollback/restore consideration if any deletion is proposed.
  • No destructive command is run from this issue.
  • Any future deletion gets a separate issue with an exact approval phrase.

Priority

Low priority. Do after inventory and only when it reduces future confusion.

Refs: #557, #597.

## Context M01 deleted only the approved legacy backup target. Remaining non-backup legacy material was explicitly out of scope. This issue depends on the inventory follow-up and should not execute any destructive action by itself. ## Scope After inventory, propose a low-priority disposal plan for remaining non-backup legacy material: - keep; - cold archive; - tombstone/quarantine; - later delete with explicit operator approval. ## Acceptance - Plan names exact path classes, not broad roots. - Separates secret-bearing/env material from ordinary state/data. - Includes rollback/restore consideration if any deletion is proposed. - No destructive command is run from this issue. - Any future deletion gets a separate issue with an exact approval phrase. ## Priority Low priority. Do after inventory and only when it reduces future confusion. Refs: #557, #597.
Author
Collaborator

Read-only inventory completed in PR #611.

Sanitized result:

  • no live Docker mount refs;
  • no systemd/cron refs;
  • no open files under /opt/vps-home-platform-infra;
  • cleanpush symlink appears unused by live checks;
  • remaining env and state are secret-bearing/recovery-sensitive and should go through #599, not direct deletion.

No destructive action was performed.

Read-only inventory completed in PR #611. Sanitized result: - no live Docker mount refs; - no systemd/cron refs; - no open files under `/opt/vps-home-platform-infra`; - cleanpush symlink appears unused by live checks; - remaining `env` and `state` are secret-bearing/recovery-sensitive and should go through #599, not direct deletion. No destructive action was performed.
Collaborator

Architectural guidance (claude) — legacy disposal planning. Per STATUS_NOW "Legacy path semantics", classify /opt/vps-home-platform-infra path-by-path into 4 buckets BEFORE any deletion: (1) live bind-mounted data/config → move as-is, do NOT delete; (2) legacy backups + retired control-plane → delete only after accepted soak + log review + smokes + 48h green; (3) rollback-only material → keep until M01 live-dependency cutover is done; (4) tool cruft → delete if unused >7d. This issue is the PLAN (text). Destructive execution stays behind the legacy-boundary-approved operator gate — produce the classification + gated sequence, delete nothing here.

**Architectural guidance (claude) — legacy disposal planning.** Per STATUS_NOW "Legacy path semantics", classify `/opt/vps-home-platform-infra` path-by-path into 4 buckets BEFORE any deletion: (1) live bind-mounted data/config → move as-is, do NOT delete; (2) legacy backups + retired control-plane → delete only after accepted soak + log review + smokes + 48h green; (3) rollback-only material → keep until M01 live-dependency cutover is done; (4) tool cruft → delete if unused >7d. This issue is the PLAN (text). Destructive execution stays behind the `legacy-boundary-approved` operator gate — produce the classification + gated sequence, delete nothing here.
Author
Collaborator

M06 cleanup: moved to 10 - Improvements and marked status:parked. This issue is explicitly low-priority, non-destructive, and depends on inventory/future operator-approved disposal planning. No runtime or legacy path mutation was performed.

M06 cleanup: moved to `10 - Improvements` and marked `status:parked`. This issue is explicitly low-priority, non-destructive, and depends on inventory/future operator-approved disposal planning. No runtime or legacy path mutation was performed.
Collaborator

Iskra judgment

Field Value
Target pdurlej/platform#issue#599
Priority park
Action park
Scores reach 2 / impact 2 / confidence 5
Piotr fit medium
Effort small
Labels judge/park
Judge iskra via openclaw

Rationale: This should stay parked because it is useful hygiene only after inventory and must remain a non-destructive planning task with explicit future approvals.

Caveat: Do not execute deletion from this issue; any future destructive action needs a separate exact approval phrase.

Structured openclaw.judge.v0 payload
<!-- openclaw.judge.v0 -->
{
  "confidence": 5,
  "effort_hint": "small",
  "escalation": {
    "kind": "none",
    "reason": ""
  },
  "evidence_refs": [
    {
      "note": "Issue proposes a low-priority disposal plan for remaining non-backup legacy env, data, and state after inventory.",
      "type": "forgejo",
      "value": "issue-title-body-labels-and-target-snapshot"
    },
    {
      "note": "Body requires exact path classes, secret-bearing separation, rollback consideration, and no destructive command from this issue.",
      "type": "forgejo",
      "value": "issue-body-acceptance"
    },
    {
      "note": "Current labels mark the work as not-ready, parked, security-sensitive ops with runtime and process risk.",
      "type": "snapshot",
      "value": "target-snapshot-labels"
    }
  ],
  "impact": 2,
  "judge_actor": {
    "name": "iskra",
    "runtime": "openclaw"
  },
  "judged_at": "2026-06-11T01:02:00Z",
  "labels_to_apply": [
    "judge/park"
  ],
  "piotr_fit": "medium",
  "priority": "park",
  "rationale_summary": "This should stay parked because it is useful hygiene only after inventory and must remain a non-destructive planning task with explicit future approvals.",
  "reach": 2,
  "recommended_next_action": "park",
  "rerun_reason": "no_prior_judgment",
  "schema": "openclaw.judge.v0",
  "target": {
    "kind": "issue",
    "number": 599,
    "repo": "pdurlej/platform"
  },
  "target_snapshot": {
    "body_hash": "sha256:84059a541316de93ead4316ec040315a67febf5d2b1fca73b39dfb5caf1d72ce",
    "commit_count": null,
    "evidence_hash": "sha256:0ec3a605977c2c802e9b591e13c1efd605d3dca3c0f13f2cbea9527f6032562b",
    "head_sha": null,
    "labels": [
      "class/security-sensitive",
      "kind/ops",
      "not-ready",
      "risk/process",
      "risk/runtime",
      "size/small",
      "status:parked",
      "tier/full"
    ],
    "labels_hash": "sha256:29f76c139169ef382494fcaeac153793ac4aaec293595dcb1bdade7a5aba7632",
    "state": "open",
    "title_hash": "sha256:6c43d595ba26a85daa0c92a547b5432784fd49dda43a00f13c8a206aefd85528",
    "updated_at": "2026-06-02T23:47:18+02:00"
  },
  "top_caveat": "Do not execute deletion from this issue; any future destructive action needs a separate exact approval phrase."
}
<!-- /openclaw.judge.v0 -->
### Iskra judgment | Field | Value | | --- | --- | | Target | `pdurlej/platform#issue#599` | | Priority | park | | Action | park | | Scores | reach 2 / impact 2 / confidence 5 | | Piotr fit | medium | | Effort | small | | Labels | `judge/park` | | Judge | `iskra` via `openclaw` | **Rationale:** This should stay parked because it is useful hygiene only after inventory and must remain a non-destructive planning task with explicit future approvals. **Caveat:** Do not execute deletion from this issue; any future destructive action needs a separate exact approval phrase. <details> <summary>Structured openclaw.judge.v0 payload</summary> ```json <!-- openclaw.judge.v0 --> { "confidence": 5, "effort_hint": "small", "escalation": { "kind": "none", "reason": "" }, "evidence_refs": [ { "note": "Issue proposes a low-priority disposal plan for remaining non-backup legacy env, data, and state after inventory.", "type": "forgejo", "value": "issue-title-body-labels-and-target-snapshot" }, { "note": "Body requires exact path classes, secret-bearing separation, rollback consideration, and no destructive command from this issue.", "type": "forgejo", "value": "issue-body-acceptance" }, { "note": "Current labels mark the work as not-ready, parked, security-sensitive ops with runtime and process risk.", "type": "snapshot", "value": "target-snapshot-labels" } ], "impact": 2, "judge_actor": { "name": "iskra", "runtime": "openclaw" }, "judged_at": "2026-06-11T01:02:00Z", "labels_to_apply": [ "judge/park" ], "piotr_fit": "medium", "priority": "park", "rationale_summary": "This should stay parked because it is useful hygiene only after inventory and must remain a non-destructive planning task with explicit future approvals.", "reach": 2, "recommended_next_action": "park", "rerun_reason": "no_prior_judgment", "schema": "openclaw.judge.v0", "target": { "kind": "issue", "number": 599, "repo": "pdurlej/platform" }, "target_snapshot": { "body_hash": "sha256:84059a541316de93ead4316ec040315a67febf5d2b1fca73b39dfb5caf1d72ce", "commit_count": null, "evidence_hash": "sha256:0ec3a605977c2c802e9b591e13c1efd605d3dca3c0f13f2cbea9527f6032562b", "head_sha": null, "labels": [ "class/security-sensitive", "kind/ops", "not-ready", "risk/process", "risk/runtime", "size/small", "status:parked", "tier/full" ], "labels_hash": "sha256:29f76c139169ef382494fcaeac153793ac4aaec293595dcb1bdade7a5aba7632", "state": "open", "title_hash": "sha256:6c43d595ba26a85daa0c92a547b5432784fd49dda43a00f13c8a206aefd85528", "updated_at": "2026-06-02T23:47:18+02:00" }, "top_caveat": "Do not execute deletion from this issue; any future destructive action needs a separate exact approval phrase." } <!-- /openclaw.judge.v0 --> ``` </details>
Sign in to join this conversation.
No labels
W6d-automerge-calibration
agent/claude-code
agent/codex
agent/hermes
agent/iskra
agent/ollama
agent/patchwarden
automerge-candidate
class/security-sensitive
cutover-gate
dependency/blocked
dependency/blocks-others
dependency/cross-repo
dependency/needs-confirmation
domain:agents
domain:ci
domain:docs
domain:forgejo
domain:infra
domain:memory
domain:runtime
domain:signal
domain:ux
flow/architecture
flow/blocked
flow/deployed
flow/done
flow/implementation
flow/intake
flow/maintained
flow/observed
flow/ready
flow/refining
flow/retired
flow/review
iterating
judge/codex-candidate
judge/hermes-candidate
judge/low-confidence
judge/needs-refinement
judge/operator-needed
judge/p0
judge/p1
judge/p2
judge/p3
judge/park
judge/patchwarden-candidate
judge/stale-priority
kind/adr
kind/bug
kind/chore
kind/feature
kind/infra
kind/ops
kind/refactor
kind/research
large-impact
merge/auto
merge/manual
merge/manual-dependency-conflict
merge/manual-failing-tests
merge/manual-merge-conflict
merge/manual-missing-review
merge/manual-operator-preference
merge/manual-red-zone
merge/manual-security-sensitive
merge/manual-unclear-scope
merge/manual-unknown
meta
mode:operator-only
mode:patchwarden-iskra-approved
mode:safe-auto
needs-operator-decision
needs-triage
not-ready
observed/erroring
observed/needs-followup
observed/pending
observed/retire-candidate
observed/unused
observed/used
operator-emotional
owner-attention
phase/02
phase/03
priority:p0
priority:p1
priority:p2
priority:p3
proposed
ready-for-agent
ready-for-operator
recovery
review:claude-reviewed
review:codex-reviewed
review:dziadek-reviewed
review:needs-human
risk/exposure
risk/process
risk/product
risk/runtime
safety:external-write
safety:no-prod-mutation
safety:prod-impact
safety:secret-touch
size/large
size/medium
size/small
size/tiny
size/unknown
source/adr
source/agent-generated
source/manual
source/operator-chat
source/voice-note
status:blocked
status:codex-ready
status:merged:pending-evidence
status:needs-evidence
status:operator-needed
status:parked
tier/full
tier/lite
tier/stacked
tier:0-platform-substrate
tier:1-iskra-value-layer
tier:2-tools-products-modules
type:bug
type:chore
type:docs
type:feat
type:policy
type:research
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pdurlej/platform#599
No description provided.