Publication status
Operational documentation not yet public
Procedures that must not be published as usage guidance without evidence, real commands, and acceptance results.
Items requiring more evidence before publication
- A complete application environment-variable catalog outside the chart plus Tomcat and Docker runtime references
- Publish, resolve, and proxy commands for every format, including minimum client versions and acceptance output
- Backup and restore order plus consistency checks covering PostgreSQL, artifact storage, and raw SBOMs together
- An upgrade and rollback runbook covering application and Flyway compatibility plus the data layer
- Incident response and security-reporting flow
- Measured capacity, failover, RTO/RPO, and SLA
- Verified air-gapped operating profile
Completion standard
An item leaves this list only after publishing repeatable steps, required roles and secret sources, success and failure outcomes, rollback or recovery behavior, and dated acceptance evidence.
Priority and dependency
Prioritize evidence gaps by production impact; interdependent items must not be considered complete in isolation.
- P0: coordinated backup and restore, upgrade and rollback, secret boundaries, and incident response
- P0: commands, minimum versions, and acceptance results for every format and client used in production
- P1: capacity, failover, RTO or RPO, and operational runbooks for the target topology
- P1: dependency, intelligence, and image-supply flow for restricted-connectivity or air-gapped profiles
- P2: public SDK or endpoint matrix, troubleshooting examples, and support or SLA material
Evidence owner and publication gate
Assign a product owner, platform owner, security reviewer, and documentation approver to each open item. Do not move content to verified until a second person reruns the commands in a clean environment and the material passes secret scanning.
Safe interim use
An internal runbook can be used for items that remain on this list, but it must state release, topology, owner, and date; assumptions must not be presented as production guarantees, and results must not flow automatically into public documentation.