# Phase 1 Entry-Gate Audit — 2026-08-06

## Outcome

Phase 1 tasks 9.5-9.7 **cannot truthfully be completed**. The Timetabler change remains
55/87 checked, with 32 tasks open. Local tests pass for the paths they cover, but the
live Resource Booking staging catalogues are empty. The Resource Booking v2 receiver is
now deployed default-off, but the required fixed-watermark snapshot reconciliation has
not run. This remains an explicit acceptance NO-GO.

Exact candidate evidence:

- Timetabler: `b29ee4c21a04f7f4cb7cc7b36faa2484cf294007`, deployment run
  [31023018291](https://github.com/Mayvins/timetabler-be/actions/runs/31023018291) passed.
- Resource Booking: `fc9ecf670d8a1a542cba8b3efe7d1b057779285d`, deployment run
  [31078563334](https://github.com/Mayvins/resource-booking-be/actions/runs/31078563334) passed.
- Resource Booking Phase 2 planning input only:
  `88c3cd5eaff085c70ab84f4e446b68268c87008b`.
- Resource Booking v2 receiver: `a3dcecd0c50daff88bcd030dd5dc039b09d98feb`,
  staging run [31099640196](https://github.com/Mayvins/resource-booking-be/actions/runs/31099640196) passed default-off.

## Refreshed local evidence

| Check | Result |
| --- | --- |
| Python/source compile | PASS on Python 3.12.13 |
| Django checks | PASS, zero issues |
| Migration drift | PASS, no changes detected |
| Focused Ruff on changed Phase 1 modules | PASS; repository baseline has 2,252 existing violations and candidate has 2,251 |
| Bare repository test discovery | PASS — 48 PostgreSQL tests, no skips; legacy module/package collision repaired |
| PostgreSQL 16 clean migration through `api.0102` | PASS |
| PostgreSQL `0101 -> 0100 -> 0101`, cursor repair, then `0102` | PASS |
| 500-activity local atomic apply | PASS — 11.475 s, 1 receipt, 500 finalized members, 1 source sequence |
| Matching 500-activity duplicate | PASS — 1.912 s, no duplicate receipt/transaction |
| Deployment gate control flow | PASS with fake supervisor/probe — default-off, enabled singleton/liveness, missing-config rollback; final state disabled |
| 10,500-row eligible outbox claim explain | PASS locally — 0.113 ms execution for 100 rows after `ANALYZE` |
| Historical RB parser against baseline TT envelope | EXPECTED baseline rejection recorded; replacement receiver `a3dcecd` is deployed default-off against exact fixture hash |
| Live RB Staff/Location catalogues | FAIL/NO-GO — both empty after reset |

These results do not claim production-like performance or cross-service acceptance.

## Every unchecked task and current disposition

| Task | Disposition | Evidence still required |
| --- | --- | --- |
| 0.1 | Cross-service contract blocker | Timetabler v2 provider fixtures now define envelope/order/completeness/hash/tombstone/size behavior; RB adapter acceptance and joint schema-evolution approval are still absent |
| 0.2 | Cross-service deployment blocker | Kafka is the intended Phase 1 transport, but exact topic/schema/ack/retention/replay and broker evidence are not approved or configured |
| 0.3 | Cross-service mapping blocker | Deployment/source scope, academic term/calendar/timezone/DST and occurrence-expansion fixtures remain unapproved |
| 0.4 | Decision approval blocker | Code no longer age-discards matching retries, but the shared first-arrival late/quarantine policy lacks cross-service approval/evidence |
| 2.6 | Timetabler implementation/evidence gap | Current engine path locks activities/families/Staff/Locations with timeouts; complete week/resource-map/receipt/version ordering plus lock-timeout/deadlock tests are absent |
| 6.4 | Cross-service acceptance pending | RB receiver `a3dcecd` is deployed against the matching fixture hash, but ingestion remains off and fixed-watermark snapshot/live replacement/tombstone evidence is not yet recorded |
| 6.5 | Staging acceptance failure | RB mirror-only schema exists, but no TT Staff/Locations are populated; a real conflicting RB write test cannot yet pass |
| 6.6 | Cross-service observability decision | Publication, broker receipt, RB inbox outcome, mirror apply and projection/reconciliation states need agreed typed outcomes and staging proof |
| 7.2 | Cross-service integration blocker | TT now exposes the fixed-watermark composite snapshot; RB compatibility, missing/stale/orphan repair, and a real zero-drift run remain absent |
| 7.3 | Timetabler implementation/evidence gap | Some structured logs exist; end-to-end tracing across request/receipt/change/outbox/publish/effect/reconciliation is incomplete |
| 7.4 | Timetabler implementation/evidence gap | Status commands exist; required exported metrics for lag/lock/deadlock/offset/rebalance/reconciliation are incomplete |
| 7.5 | External operations gap | No attested shared dashboards/alerts, thresholds, owners or escalation exercise |
| 7.6 | External operations gap | Repository runbooks exist, but coordinated broker/adapter/offset/rollback procedures are not approved/exercised by named owners |
| 8.1 | Timetabler test gap | Current tests cover create/update version, delete/tombstone, rollback and bulk previous state; archive and real bulk-import/post-commit matrices remain incomplete |
| 8.2 | Timetabler test gap | Current tests cover single/partial/reschedule plus static writer guards; exhaustive bulk/week/duration/variant/swap/booking/import/JTA/cascade/command execution matrix is absent |
| 8.3 | Timetabler test gap | Static pre-schedule no-outbox guard exists; full pre-schedule through accepted drag/drop exactly-once flow has not run |
| 8.4 | Timetabler test gap | Manual constraint-break has writer tracking, but parity/variant/resource-map/post-commit execution test is absent |
| 8.5 | Timetabler test gap | One mutation and one engine failure rollback are tested; injection after every database stage is absent |
| 8.6 | Timetabler test gap | Duplicate and conflicting hash are tested; live late first-arrival/redelivery consumer matrix is incomplete |
| 8.7 | Timetabler/broker test gap | No real worker crash matrix before commit, after commit/before offset and after offset |
| 8.8 | Timetabler test gap | Durable post-commit row timing is tested; Redis/WebSocket/confirmed/downstream Kafka failure/retry matrix is incomplete |
| 8.9 | Timetabler PostgreSQL test gap | Concurrent aggregate versions pass; overlapping/non-overlapping changes, lock timeout, deadlock behavior and publisher concurrency remain untested |
| 8.10 | Cross-service acceptance failure | Ordering/replay/restart/reconciliation/mirror-only E2E has not run and cannot run with current contract/catalogue state |
| 8.11 | External performance gap | Local 500-activity timing passes the nominal 30-second value, but production-like broker/adapter/Redis/lock/max-poll/load/soak measurement is absent |
| 8.12 | Conditional blocker | Cannot decide or waive engine TTL extension/renewal until task 8.11 produces an approved percentile result |
| 9.1 | Staging attestation failure | Timetabler now has a checked-in default-off PM2 gate, but its exact release run and runtime capture/outbox/migration/config/process attestation are not yet acceptance evidence |
| 9.2 | Staging bootstrap failure | Adapter code deployed disabled; no compatible bootstrap, seed, fixed watermark or zero-drift reconciliation occurred |
| 9.3 | Staging acceptance failure | RB database enforces mirror-only mode structurally, but catalogues contain no TT resources and publisher/consumer are off |
| 9.4 | External operations gap | Coordinated publisher/consumer pause, in-flight position capture, replay/reconcile and safe resume exercise not run |
| 9.5 | Hard acceptance blocker | Depends on every acceptance/test item above; current staging and contract checks fail |
| 9.6 | Hard approval blocker | No complete immutable cross-service report or named RB, TT, QA, product and operations GO; rollback/DR evidence absent |
| 9.7 | Hard Phase 2 blocker | Cannot record an approved Phase 1 prerequisite while 9.5 and 9.6 are incomplete |

## Genuinely external evidence still unavailable here

- secret-safe server `.env` and service-manager attestation for both exact deployments;
- actual Kafka cluster/topic/partition/ACL/TLS/SASL/retention/message-size/DLQ/group
  configuration and broker canary;
- fixed-watermark bootstrap, replay-after-mark, consumer offsets and unfiltered
  reconciliation against the reset staging database;
- live mirror-only conflict rejection with populated Staff and Location mirrors;
- coordinated real Scheduling Engine/drag-drop/manual/import/cascade end-to-end paths;
- production-like concurrency/message-size/load/soak/restart/max-poll/30-second-window
  and disaster-recovery/rollback exercises;
- immutable QA evidence plus named Resource Booking, Timetabler, QA, product and
  operations approvals.

## Gate decision

Do not check tasks 9.5, 9.6 or 9.7. Keep Timetabler publication and Resource Booking
ingestion/reverse delivery disabled. Execute the coordinated fixed-watermark snapshot
reconciliation against the matching deployed receiver, then continue the procedure in
`phase1-staging-bootstrap-no-go.md`.
