Skip to content

[P0 Observability] Establish canonical CWL telemetry SDK, Collector, and SIEM contract #1565

Description

@seonghobae

Defect

CWL currently has no verified canonical runtime owner for the organization-wide OpenTelemetry producer/exporter boundary, while multiple product repositories implement exporter/provider bootstrapping independently. That contradicts the required architecture product producer -> shared Telemetry SDK/Port -> OpenTelemetry Collector/gateway -> telemetry backend / normalized SIEM consumer and will make redaction, degraded delivery, receiver validation, event naming, data classification, and security-event projection drift independently by product.

This is an organization ownership defect. Product repositories must not solve it by copying another product's telemetry module or by making contextual-orchestrator a generic observability owner merely because it already has model-specific tracing.

Fresh evidence — 2026-09-01

Default-branch organization code search for OTLPSpanExporter returns direct exporter construction in at least three separate product implementations:

  • ContextualWisdomLab/naruon@042b0c70531b229af3acbd0421a2f23098d848b3 — backend/core/telemetry.py, direct gRPC OTLPSpanExporter construction;
  • ContextualWisdomLab/LineageWeave@cb187cadee5fb6c46d8a944815ccc154a1e028d1 — lineageweave/observability.py, direct HTTP OTLPSpanExporter construction;
  • ContextualWisdomLab/contextual-orchestrator@c6c3a0c9d6c2ec8f3509ccdc6db24b1562a32e7b — contextual_orchestrator/telemetry.py, direct HTTP exporter/provider construction.

A fourth implementation is proposed in governance-risk-compliance#51@1a8f90dd15f37ffc86b8a0efd217a8b2812e5f99: cwl_grc/telemetry.py constructs TracerProvider, MeterProvider, BatchSpanProcessor, PeriodicExportingMetricReader, OTLPSpanExporter, and OTLPMetricExporter inside the product. Its ADR explicitly makes the application own isolated SDK/provider construction. That PR is currently non-mergeable against the moved GRC develop base and should not be used to establish a fourth exporter contract.

Organization code search for TelemetryPort and cwl_telemetry returned zero results. No existing .github issue matching a reusable product runtime telemetry SDK/OTLP Collector/SIEM boundary was found before opening this issue.

Required ownership decision

Select and publish one canonical CWL runtime telemetry dependency/Port owner. The owner may be a dedicated reusable package or an explicitly designated existing generic runtime library, but it must not be a product-specific bounded context by accident. .github owns the engineering-governance contract and compatibility gate; the selected runtime package owns implementation/versioning.

Product repositories remain LOG/TRACE/METRIC PRODUCERS. The shared dependency owns validated logger/tracer/meter/exporter bootstrap and provider-neutral OTLP delivery policy. OpenTelemetry Collector/gateway is the TELEMETRY RECEIVER/ROUTER. SIEM is a normalized SECURITY EVENT CONSUMER, not a sink for every debug log. Authoritative audit ledger, domain events, security events, and operational telemetry remain distinct truth classes.

Version-one contract

The shared bootstrap must be explicit: importing the dependency cannot create hidden network traffic or ambient authority. A product passes service/version/environment and bounded product metadata, receives logger/tracer/meter/exporter Ports, and opts into configured receiver/export delivery.

Structured records need stable fields where applicable: event name, timestamp, severity, service/version, environment, opaque tenant/workspace reference, permitted principal reference, correlation/trace/span/request IDs, operation code, bounded context, resource reference, action/result/status, error type/code, retry count, duration, dependency/provider, source location, exact build/source revision, data classification, purpose code, and provenance reference. Secrets, tokens, passwords, raw Authorization/cookies/keys/DSNs, unnecessary raw PII, full prompt/response, and document bodies are forbidden.

Ordinary telemetry export failure must not arbitrarily fail a product transaction. Authoritative audit events require a durable audit/outbox path. Collector/SIEM degradation requires bounded queue/retry/backoff plus explicit drop/dead-letter/local-durable-buffer policy. Receivers must validate schema/version/content type/size/tenant/replay/idempotency/timestamp/auth/TLS. External telemetry must never become an implicit domain command or authorization update.

Only normalized security events such as authentication denial, privilege change, secret access, policy decision, malware/sandbox result, suspicious egress, integrity violation, audit-log failure, high-risk administration, tenant-boundary violation, data export, key rotation, and security-control-test result are projected to SIEM.

RED -> GREEN acceptance

  1. RED repository/organization fitness proves product-local construction of vendor-specific OTLP exporter/provider/collector/SIEM clients is rejected unless an ADR proves that repository is the canonical owner.
  2. A versioned shared API/contract exists with explicit bootstrap and no import-time network authority.
  3. Contract tests cover schema fields, bounded cardinality, secret/PII rejection, trace propagation, source/build identity, data classification and purpose codes.
  4. Failure-injection tests cover receiver timeout, retry/backoff, queue saturation, exporter shutdown, Collector outage, SIEM outage, and recovery without corrupting product transactions; audit/outbox durability is tested separately.
  5. Receiver/decoder tests cover hostile size/content type/schema/version/timestamp/replay/idempotency/auth/TLS cases.
  6. One producer -> shared SDK/exporter -> Collector/receiver -> backend/SIEM -> owner/retention/purpose matrix and degraded-mode sequence is canonical and executable.
  7. Migrate at least one current direct-exporter product without source-copying another product's telemetry implementation, then establish parity tests before further migrations.
  8. Add central compatibility/architecture checks so later products cannot reintroduce duplicated exporter/collector/SIEM plumbing.

Immediate consumer handling

governance-risk-compliance#51 should remain non-authoritative for shared exporter ownership. Its useful request correlation, route-template redaction, metric semantics, and tests may be preserved when the canonical dependency exists, but the product-local provider/exporter construction must be replaced by the released shared Port/adapter rather than copied forward.

Do not weaken product-local observability, security, coverage, or review gates while this owner path is unresolved.

Activity

  1. added
    enhancementNew feature or request
    priority: criticalImmediate blocker, P0, urgent deadlock, or critical incident
    on Sep 2, 2026
  2. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    사용자 지시에 따라 이 이슈도 연구 지원 시스템의 병목 후보로 조치합니다. .github lead는 중앙 소유권·호환성 계약을 맡고, runtime 구현 소유자는 현재 존재하는 범용 공유 패키지/API/PR을 조사해 명시적으로 지정합니다. contextual-orchestrator의 모델 tracing 존재만으로 범용 telemetry 소유권을 부여하지 않습니다.

    즉시 과업: 기존 구현·배포·소비자 상태를 현재 head에서 확인하고, 실제로 막힌 연구/CI 소비 경로를 제시하십시오. 본문의 과거 code-search 0건을 현재 부재의 증거로 재사용하지 않습니다. 재사용 가능한 소유자와 API가 있으면 승계하고, 없을 때만 최소 version-one explicit bootstrap/Port와 버전 경계를 설계합니다. secret/PII 차단, bounded delivery와 transaction 영향, 감사/outbox 분리, receiver 검증, 장애·복구, 최소 1개 소비자의 released adapter 이관/parity를 실제 테스트로 입증하십시오.

    이 작업은 Dependency Review 403 등 현재 확인된 직접 CI 차단 해소와 독립적으로 진행합니다. 검증되지 않은 신규 architecture gate를 연구 저장소에 일괄 적용해 병목을 늘리지 말고 canary 검증 후 전개합니다. 기존 보안·커버리지·리뷰 gate를 약화하지 않습니다. Claude 사용 제한 중에는 Codex 실행 경로를 사용합니다. 담당 runtime owner 후보·현재 head·첫 실제 명령·scoped PR·수용 증거를 이 이슈에 기록하십시오.

  3. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    #1565 기존 소유 후보 조사 — 2026-09-23

    담당: 중앙 governance/compatibility gate는 dot-github lead, 현재 기존 후보 조사·통합 전달은 임시 triage lead가 맡습니다. runtime 구현 owner는 아직 확정하지 않습니다. 현재 연구 Checks의 직접 차단 원인이라는 증거는 확보하지 못하므로 #810 직접 차단 수리와 분리합니다.

    첫 실제 조사: 인증된 GraphQL batch로 조직 저장소 목록 전체 페이지(hasNextPage=false)와 이 이슈 원문을 읽고 후보의 현재 default SHA, README, package manifest를 대조합니다.

    • context-graph-contracts develop@99cb5468ba3c15c5e79688f53dee74724fae2d13: README는 공통 버전 계약 저장소의 초기 protected baseline을 설명합니다. root pyproject.toml 조회는 null입니다. 이 근거만으로 실행 가능한 shared Telemetry SDK라고 채택할 수 없습니다.
    • EgressWeave main@bd0339bf43cf5041e861bac86a84cb6e7e32637e: pyproject는 egressweave0.3.0/Apache-2.0, 실제 공개 API는 EgressPolicy·TLSConfiguration·DNS-pinned sync/async HTTP client입니다. 안전한 전송 계층 재사용 후보지만 현재 logger/tracer/meter bootstrap runtime owner라는 근거는 아닙니다. manifest 버전만으로 PyPI 출판도 확정하지 않습니다.
    • CO의 모델 tracing이나 GRC#51 product-local exporter를 조직 runtime owner로 자동 승격하지 않습니다.

    다음 수용 단위: 기존 telemetry API/열린 PR와 실제 package release를 더 대조해 명시 runtime owner를 결정한 뒤, explicit bootstrap/no import-time network/secret·PII 차단/bounded failure·queue·trace identity/receiver auth·schema 및 audit-outbox 별도 계약을 갖춘 versioned adapter와 현재 direct-exporter 소비자 1곳의 parity·Collector 장애/복구 canary를 구현합니다. 중앙 fitness RED/GREEN은 canary 뒤 적용 범위를 늘립니다. 신규 저장소나 SDK boilerplate는 아직 만들지 않습니다. 이 조사는 구현/릴리스 완료 판정이 아닙니다.

  4. seonghobae commented on Sep 26, 2026

    @seonghobae
    ContributorAuthor

    진행 기록 — 2026-09-26 UTC. ADR-0032가 범용 runtime 소유자를 전용 cwl-telemetry 패키지로 지정했습니다. SDK PR ContextualWisdomLab/cwl-telemetry#1 현재 head 6af2a93fd5069b91d5eddbc817c26a0c2d2fd560에서 로컬 전체 23개 테스트와 wheel/sdist 빌드가 통과했습니다. 고정 Collector의 인증·라우팅·장애 후 복구, 보안 수신기의 악성 입력·재전송, SIEM 전송의 정확한 확인 응답을 검사했습니다. Naruon 이관 PR ContextualWisdomLab/naruon#1772 head 79d6e89bc4c3e41085fcf07c98bb8c2706de9452는 직접 exporter 구성을 제거하고 SDK 개발용 SHA를 고정했습니다. 새 PostgreSQL에서 마이그레이션 후 실제 권한 변경 요청이 수신기 장애 중 성공했고, 새 DB 세션에서 감사 행이 남은 것을 확인했습니다. 중앙 소유권 gate PR #2357 head aa9e080b792a3f8b7275b44b9692df3a1e2c47f5는 생성 디렉터리 제외 스캐너를 immutable SHA로 호출하도록 고쳤고 미해결 리뷰 스레드는 0개입니다. 429 경로 수리 ContextualWisdomLab/contextual-orchestrator#1249는 Draft를 해제했으며 현재 head 3686c251b5eda8212fcb78965a8a22871987dc41에서 로컬 전체 5,050개 테스트와 벤치마크 100% 커버리지가 통과했습니다. 이 증거는 로컬 범위입니다. 관련 PR의 호스팅 Checks가 아직 대기 중이고 현재-head 독립 승인, SDK 보호 병합·공개 릴리스, 제품 이미지의 릴리스 휠 SHA-256 고정, 승인된 backend/SIEM 목적지·보존 기간·실제 전송, 중앙 gate 필수화는 남아 있습니다. 그러므로 #1565는 열린 상태로 유지합니다.

  5. seonghobae commented on Sep 26, 2026

    @seonghobae
    ContributorAuthor

    추가 진행 기록 — 2026-09-26 UTC. Naruon 이관 PR #1772 현재 head 666a913ab5be17310c2b765220b363a5d8c09f4f에서 중앙 소유권 검사 호출을 .github#2357의 검증된 immutable head aa9e080b792a3f8b7275b44b9692df3a1e2c47f5로 고정했습니다. actionlint와 실제 스캐너 호출이 통과했고, 직접 exporter bootstrap은 발견되지 않았습니다. 게이트웨이의 429 재라우팅 PR contextual-orchestrator#1249에서 현재 head 080677a3805ccc31c39ce687a73afb84acff0ef0의 새 종료 경로 리뷰 지적을 수정했습니다. 로컬 대기 작업은 취소·깨우고, 영속 작업은 복구 가능한 상태로 남깁니다. 네이티브 모듈을 CI 방식으로 빌드한 뒤 전체 5,052개 테스트 통과, 5개 건너뜀을 확인했으며 미해결 스레드는 0개입니다. Noema 429 후 재디스패치 권한 수리 .github#2373은 동일 저장소·HEAD·base와 재시도 상한을 검증했고 로컬 223개 테스트가 통과했지만, 다른 자동 세션이 오래된 CHANGES_REQUESTED를 이유로 Draft로 다시 전환했습니다. 이 Draft 상태는 새 Noema/OpenCode 리뷰 실행을 가로막아 승인 대기와 순환합니다. 모든 관련 PR의 호스팅 현재-head 필수 검사는 여전히 대기 중입니다. 승인된 backend/SIEM 목적지·보존 기간, SDK 보호 병합·릴리스, Naruon 제품 이미지의 릴리스 휠 SHA-256 고정, 중앙 gate 필수화가 남아 있으므로 #1565는 완료가 아닙니다.

  6. seonghobae commented on Sep 26, 2026

    @seonghobae
    ContributorAuthor

    2026-09-26 UTC 추가 증거. 중앙 소유권 PR .github#2357 현재 head 6482a3fe03c1efd49b87d4158cac45a6173a4aca에 ADR-0032가 지정한 ContextualWisdomLab/cwl-telemetry만을 위한 재사용 워크플로 예외를 추가했습니다. 기존 스캐너를 공유 SDK PR head 6af2a93…에 직접 실행하면 소유자가 구현해야 할 provider/exporter 구성 8건을 검출하므로, 이 예외가 없으면 조직 필수화 때 정당한 owner도 실패합니다. 다른 저장소에는 동일한 고정 스캐너가 계속 실행됩니다. 로컬 ownership 검사 26개(일반/GITHUB_ACTIONS=true)와 actionlint가 통과했습니다.

    실제 backend/SIEM 목적지는 아직 승인 근거가 없습니다. linux-cluster-ops 현재 기본 HEAD 7d6c0e6…의 APM ADR은 Status Proposed이고 Collector 도입과 로그 보존 기간 결정을 후속 단계로 둡니다. Naruon develop@042b0c7…의 docker-compose.observability.yml은 익명 Grafana Admin과 공개 포트를 가진 로컬 개발 스택이며, 현재 PR의 운영 문서도 이를 production-ready로 주장하지 않습니다. 이 두 자료를 실운영 목적지·보존 정책의 증거로 승격하지 않습니다. 관련 코드 PR은 열린 상태이고 현재 HEAD 필수 Checks 및 독립 승인이 남아 있습니다.

  7. seonghobae commented on Sep 26, 2026

    @seonghobae
    ContributorAuthor

    Progress at 2026-09-26 16:51 UTC: cwl-telemetry#1 head 9054639435cc4f2036dd3c83b7bf2fedcc450e2d now rejects duplicate SIEM acknowledgement Content-Type headers before marking the durable outbox delivered. The HTTPS regression failed before the fix and passed after it; full SDK suite: 23 passed; wheel and sdist built. naruon#1772 head 608f038b8431322f3ca892a1cf2aa3a2c63e0890 pins that exact SDK commit in the development telemetry extra and uv.lock; product tests: 29 passed, 2 skipped. The production image still needs a released SHA-256 pinned wheel. linux-cluster-ops develop@7d6c0e6f488dffb609eded3f8980ded570b54362 keeps its APM ADR-0001 at Proposed and describes Collector, retention, and AKS as future rollout; no approved live backend/SIEM destination or retention evidence was found there. Related protected PR checks remain queued without current-head independent approval, so no merge or production-complete claim is made.

  8. seonghobae commented on Sep 26, 2026

    @seonghobae
    ContributorAuthor

    Central gate rollout evidence at 2026-09-26 17:02 UTC: the active inherited organization ruleset on cwl-telemetry default branch is CWL Central required workflows (ruleset 18156473). Its workflow list is OpenCode, PR scheduler, Security Scan, Strix, Semgrep, Noema, and CodeQL; it does not include the proposed telemetry-ownership reusable workflow from .github#2357. The naruon#1772 caller pilots the gate, but this is not yet organization-wide enforcement of acceptance #8. Default-branch organization code search currently finds OTLPSpanExporter construction on naruon, LineageWeave, and contextual-orchestrator; no OTLPTraceExporter or otlptracehttp matches were returned. This search is a lead, not proof that non-Python clients do not exist. No ruleset was altered and no merge gate was bypassed.

  9. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 01:26 UTC 진행 기록. 중앙 소유권 PR .github#2357은 6735225553b7a5324aee7a505214658db82f4e79로 최신 기본 브랜치를 합쳤고 관련 검사 391개가 GITHUB_ACTIONS=true에서 통과했습니다. 429 복구 PR contextual-orchestrator#1249도 675ce18973249436b813be0ff28ec0941b77552b로 기본 브랜치를 합쳤고 관련 검사 209개가 로컬·CI 환경에서 각각 통과했습니다. 두 PR의 새 HEAD에 대한 호스팅 검사와 독립 리뷰는 아직 끝나지 않았습니다.

    SDK cwl-telemetry#1@d0acfd06fc3a7a08a57aca245812b6dec221094d의 Noema 작업은 중앙 실행 36358414117에서 self-hosted cwlab-s1-02를 배정받아 모델 판정 단계에 들어갔습니다. OpenCode 재실행 36321038864와 CodeQL 생산자 36340807558의 핵심 작업은 여전히 대기 중입니다. CodeQL 그룹에는 두 러너가 배정돼 실제 스캔을 수행하고 있으나, SDK의 완료 증거는 아직 없습니다.

    운영 SIEM 목적지·담당자·정책 버전·만료 검증은 확인되지 않았습니다. Wardnet#90은 오프라인 변환 초안이고 운영 전달은 Wardnet#81의 미완료 범위라서 운영 SIEM 승인 근거로 쓰지 않습니다. SDK 출시, Naruon의 출시 wheel 고정, 조직 필수 gate, 이슈의 전체 수용 조건은 아직 완료되지 않았습니다.

  10. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 03:28 UTC 재확인. cwl-telemetry#1의 현재 HEAD는 d0acfd06fc3a7a08a57aca245812b6dec221094d이며 로컬 uv run --frozen pytest -q는 25 passed (53.13s)였습니다. 이 결과는 출시·운영 배포 증거가 아닙니다.

    현재 HEAD의 OpenCode 필수 검사 작업은 opencode-agent의 유효한 APPROVED/CHANGES_REQUESTED 리뷰가 없어 실패했습니다. CodeQL 호환성 검사 작업의 실패 로그는 중앙 스캔 dispatch 이후 종결 판정을 기다리는 상태를 가리키며, 코드 취약점 판정으로 해석할 근거는 아직 없습니다. Noema의 continue-noema-transport 작업은 03:28 UTC에도 queued, runner 미배정이었습니다. 조직 self-hosted 러너 6개는 같은 조회에서 모두 online/busy였으나, 각 작업의 우선순위나 안전한 재배치 가능성은 확인되지 않았습니다.

    .github#2357, contextual-orchestrator#1249, naruon#1772는 계속 열려 있고 현재 HEAD 승인·필수 검사·병합 및 운영 SIEM 전달/보존 증거가 부족합니다. #1565의 수용 조건은 아직 완료되지 않았습니다.

  11. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 03:52 UTC: 중앙 소유권 PR .github#2357을 최신 기본 브랜치 480c19604e4805839bef9541a0e965d5bd9e22b0에 병합하고 HEAD 6a9b7783507c17efa515ad9148e362ca1a351590를 푸시했습니다. 충돌은 없었고 GITHUB_ACTIONS=true python3 -m pytest tests/test_telemetry_ownership.py -q에서 28개가 통과했습니다. 새 HEAD의 호스팅 필수 검사와 독립 승인은 아직 대기 중입니다. Strix 통합 셸 검사는 이 시각 계속 실행 중이므로 통과로 기록하지 않습니다.

    429 복구 PR contextual-orchestrator#1249@675ce18973249436b813be0ff28ec0941b77552b의 Strix 재실행은 실패했습니다. 실행 36365087140의 산출물은 SARIF 결과 0건이지만 보고서가 변경 파일을 하나도 식별하지 않고 일반 문구만 담아, 현재 fail-closed 검사에서 거절됐습니다. 이를 취약점 0건 승인으로 해석하지 않습니다.

    조직 PR 최신 검색에서 Wardnet의 SIEM exporter 작업은 wardnet#90의 Draft/충돌 상태이며 wardnet#81의 외부 효과 내구성 작업은 열려 있습니다. 따라서 승인된 운영 SIEM 목적지·담당자·배포/만료 증거는 계속 미확인입니다. cwl-telemetry 출시도 확인되지 않았습니다.

  12. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 04:12 UTC 로컬 검증 추가: .github#2357@6a9b7783507c17efa515ad9148e362ca1a351590에서 GITHUB_ACTIONS=true python3 -m pytest tests/test_telemetry_ownership.py -q는 28 passed, 기본 브랜치의 새 Strix fixture까지 포함한 bash scripts/ci/test_strix_quick_gate.sh는 test_strix_quick_gate: PASS와 종료 코드 0을 반환했습니다. 이 셸 검사는 약 36분 실행됐으며 중단하거나 시간 제한을 줄이지 않았습니다. 이 결과는 로컬 검증이며 현재 HEAD의 호스팅 필수 검사·독립 리뷰·병합·운영 배포를 대신하지 않습니다.

  13. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 04:31 UTC 러너 할당 변경. 중앙 CodeQL 그룹(id 4)에 3대(cwlab-s1-01, cwlab-s1-03, cwlab-s1-05)가 있고 중앙 control 그룹(id 6)에 1대(cwlab-s2-01)만 있는 상태에서, SDK Noema 전송 재시도 작업 108754570058은 01:38 UTC부터 cwlab-control 배정을 기다렸습니다. cwlab-s1-01의 현재 HEAD CodeQL 작업 108765680780이 04:27:42 UTC 종료된 뒤 러너가 online/idle이고 기존 cwlab-control 라벨을 가진 것을 두 번 확인해, 러너 1061765를 control 그룹(id 6)으로 옮겼습니다. 변경 후 CodeQL 2대, control 2대가 online으로 조회됐고 종료된 CodeQL 작업은 completed/failure 상태 그대로였습니다. 활성 작업은 취소하지 않았습니다.

    이 변경은 짧은 재시도/접수 작업과 CodeQL 스캔의 러너 수를 2:2로 맞춘 가역적인 배치 조정입니다. 04:31 UTC에도 SDK Noema 재시도 작업은 queued이고, 현재 HEAD 승인이나 PR 검사 통과를 증명하지 않습니다. 이후 실제 배정·재발송·리뷰 판정을 별도로 확인해야 합니다.

  14. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 04:51 UTC queue audit (live GitHub API): the central Noema workflow's latest 100 runs included 23 queued runs. Their repository/PR/head identities in the immutable run names were compared with current PR heads in one GraphQL query. Twenty-two matched. The one superseded run, contextual-orchestrator#1282 at old head 962c414, was a queued repository_dispatch; its live PR head was 58dec5c. I cancelled only that old-head run and verified completed/cancelled. This did not cancel a current-head dispatch.

    The cwl-telemetry#1 Noema transport continuation remained queued (runner_id=0) at 04:51 UTC. In the latest 100 runs, 18 central CodeQL and 15 central OpenCode runs were also queued. Six organization self-hosted runners were online and rapidly changing busy/idle state; a momentary idle sample alone does not establish misrouting or available sustained capacity. No current-head approval or merge is claimed.

  15. 5 remaining items

  16. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 05:36 UTC local image verification for naruon PR #1772 at exact head a4660fc4d568fc103c4d8a65d63d893bf2d805a4: docker build --target backend-runtime --build-arg OCI_IMAGE_REVISION=<that SHA> succeeded; local image digest sha256:5fcc8411eb3fcd6b47d2784b4ef3e3b9479c21e2da439d064af8b3c33c072fb8. Inside that image as appuser, importlib.metadata reported the direct OTLP exporter umbrella, gRPC/HTTP/proto packages absent; opentelemetry-sdk==1.43.0 remained. python -m pip check passed. cwl-telemetry is also absent. This is direct local candidate-image evidence for dependency removal, not a published/deployed image or functional parity: SDK release and hash-pinned image adoption remain open.

  17. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 05:48 UTC local SDK/product compatibility probe. I layered cwl-telemetry#1@c22ca4ee0a0f3eefbe8a79038555e10aa410fa0d onto the previously built naruon#1772@a4660fc4d568fc103c4d8a65d63d893bf2d805a4 backend image. The SDK wheel passed its local SHA-256 check (37ff13c363305cf44eb5abb8416ce501003d0ef66a0652c64fa4fe46975b3314) before install; pip check passed. In the derived image as appuser, the real HTTPS OTLP export and unavailable-receiver product tests passed. The full observability test file passed 15/15 after repository-root Compose/observability fixtures were added to a separate temporary test layer. The bare runtime image intentionally omits those source-tree fixtures, so its initial five file-existence failures were not runtime regressions.

    This probe used an unpublished wheel and downloaded transitive dependencies without the required production hash lock. It proves local compatibility only. SDK release, exact release artifact hashes, installation in the actual product image, hosted current-head checks, independent review, deployment and SIEM ownership remain open.

  18. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 05:51 UTC exact-target queue cleanup:

    • SDK PR Add Palette journal for profile repo #1 live head c22ca4ee0a0f3eefbe8a79038555e10aa410fa0d was compared with queued central OpenCode repository_dispatch run 36372123065, whose immutable title targeted the old head d0acfd06fc3a7a08a57aca245812b6dec221094d. I cancelled that run and verified completed/cancelled.
    • Naruon PR docs(adr): design dispatch+poll architecture to restore central CodeQL #1772 live head a4660fc4d568fc103c4d8a65d63d893bf2d805a4 was compared with queued central CodeQL repository_dispatch run 36344401947, whose immutable title targeted the old head 83c7dcd562b491cbe99fb5965031926e1364dea7. Normal cancellation was accepted but repeated reads still showed queued; a run-ID-specific force-cancel was then accepted and the run reached completed/cancelled.

    Neither cancellation is current-head scan/review evidence. The target PRs still need new current-head dispatches, terminal checks and independent approval. No current-head run was cancelled.

  19. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 05:57 UTC bounded central-queue audit and cleanup (latest 100 queued runs per workflow):

    • CodeQL: 82 queued; 77 repository_dispatch titles parsed into target repository/PR/head, 70 matched their live open PR heads and seven had superseded heads. Each of those seven was revalidated by run event/title/status and fresh PR head before cancellation; all seven reached completed/cancelled. Five unparseable runs were left untouched. Run IDs: 36383091141, 36382552041, 36382356038, 36382265952, 36381906033, 36381489395, 36342291787.
    • OpenCode: 68 queued; 67 parseable repository_dispatch titles, 16 superseded. Each was revalidated immediately before cancellation and all 16 reached completed/cancelled. The unparseable run was untouched. Run IDs: 36383176690, 36382617809, 36381304369, 36379879312, 36379625339, 36379143228, 36378263087, 36377786862, 36377585858, 36375932974, 36375122162, 36374550963, 36372835688, 36372249887, 36370497248, 36369645629.
    • Noema: 30 queued; only nine parseable repository_dispatch titles were eligible for this check, and none was superseded. The other 21 runs used pull_request_target or workflow_run or lacked a parseable title and were left untouched because their event-specific identity was not proven.

    The post-cleanup queued counts were CodeQL 76 and OpenCode 52; arrivals continued, so these are observations, not throughput proof. No current-head run was cancelled. Runner capacity and required current-head review/checks remain open; this cleanup does not authorize a merge.

  20. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 06:03 UTC 재확인: 중앙 검사 대기는 계속됩니다. cwl-telemetry PR #1의 현재 HEAD c22ca4ee0a0f3eefbe8a79038555e10aa410fa0d에서 필수 Noema admit-current-head와 OpenCode required-workflow-bootstrap가 queued이며, 해당 작업의 runner_id=0입니다. Naruon PR #1772의 HEAD a4660fc4d568fc103c4d8a65d63d893bf2d805a4도 두 진입 작업이 queued입니다. 조직 self-hosted runner 6대가 online이며 순간 유휴 상태는 변동합니다. 중앙 control 그룹은 workflow 참조를 허용하고 runner 두 대를 보유합니다. 따라서 일시적인 idle 관측만으로 runner 그룹 설정 결함이나 안전한 재배정안을 확정할 수 없습니다.

    429 복구 PR contextual-orchestrator#1249의 현재 HEAD 675ce18973249436b813be0ff28ec0941b77552b에서 Strix run 36365087140은 Run Strix (quick) 단계에서 실패했습니다. 업로드된 strix-reports artifact 10950196833의 SARIF 결과는 비었고, 최종 보고서는 섹션 제목만 담아 변경 소스 파일을 식별하지 못했습니다. 검증기는 scan report does not identify a changed source file로 fail-closed 했습니다. 이는 취약점 부재나 검사 통과의 증거가 아닙니다. 중앙 Strix 지시문 PR #2480이 변경 소스 경로를 보고하도록 요청하는 수정이며, 해당 PR의 병합과 새 hosted 검사 증거가 필요합니다.

    최근 중앙 OpenCode dispatch 실패 사례 run 36370302775는 대상 argos가 명시 허용 목록에 없어 차단됐고, CodeQL run 36373480215는 dispatch head가 live head와 달라 차단됐습니다. 둘 다 현재 #1565 관련 HEAD의 소스 실패로 분류하지 않았습니다. 우회 병합이나 보안 게이트 완화는 하지 않았습니다.

  21. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 06:09 UTC 진행 기록:

    • 중앙 Strix 보고서 근거 보강 PR .github#2480을 현재 main@3295c259bcb688673170a1902f46d1d6c775bad4에 병합해 HEAD 507170c757fd62bc678b74cd76d386fe903fe9e1로 갱신했습니다. 충돌은 없었고 bash -n, STRIX_TEST_CASE_FILTER=pr-changed-scope-bounded bash scripts/ci/test_strix_quick_gate.sh, GITHUB_ACTIONS=true uv run --no-project --with pytest --with pyyaml python -m pytest tests/test_strix_preflight_continuation.py -q(4 passed), three-dot diff check가 통과했습니다. 새 HEAD의 hosted 검사·독립 리뷰는 아직 필요합니다.
    • Grok·Antigravity CLI 검토를 반영한 장기 제품 목표 .github#2483도 같은 main에 병합해 HEAD d102c585a042348c9e7a8cdcfc74ce9f62f9a081로 갱신했습니다. 문서 diff 검사와 CodeGraph sync가 통과했습니다. 이 PR도 새 HEAD의 hosted 검사·리뷰가 필요합니다.
    • 후보 책임 저장소를 재확인했습니다. Wardnet 보존 PR #90의 실제 src/bin/wardnet-event-exporter.rs는 stdin NDJSON을 OCSF/OTLP JSON/RFC5424로 변환해 stdout에 쓰며 네트워크 전송이 없습니다. 해당 ADR도 재시도·승인 응답·보존 정책을 별도 책임으로 둡니다. 따라서 이 코드는 승인된 /v1/security-events 목적지나 배포 증거가 아닙니다. 확인한 조직/관련 저장소의 Actions 비밀·변수 이름에는 SIEM 목적지가 보이지 않았으며, 비밀 값은 조회하지 않았습니다. 다른 운영 설정의 존재 여부는 미확인입니다.
  22. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 06:15 UTC: 중앙 소유권/호환성 검사 PR #2357을 main@3295c259bcb688673170a1902f46d1d6c775bad4에 맞춰 충돌 없이 갱신했습니다. 현재 HEAD는 520748a22804eecf80d2f9e455e788487abe668c입니다. tests/test_telemetry_ownership.py 28개가 일반 환경과 GITHUB_ACTIONS=true 환경에서 각각 통과했고, actionlint .github/workflows/telemetry-ownership.yml 및 git diff --check도 통과했습니다. 원래 작업트리의 추적되지 않은 uv.lock은 변경하지 않았습니다. 새 HEAD의 필수 hosted 검사와 독립 리뷰는 아직 대기 중이므로 병합 증거가 아닙니다.

    2026-09-28 06:26 UTC 추가 검증: 변경 문자열을 참조하는 테스트를 전수 조회한 뒤 tests/test_hourly_review_repair_callers.py, tests/test_required_review_runner_image_contract.py, tests/test_telemetry_ownership.py를 GITHUB_ACTIONS=true로 함께 실행해 62 passed를 확인했습니다. PR 본문도 이 현재 HEAD 근거에 맞춰 갱신했습니다. Hosted 검사·리뷰 대기는 그대로입니다.

  23. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 06:38 UTC 현재 SDK 출시 경계 재확인:

    • cwl-telemetry#1 HEAD c22ca4ee0a0f3eefbe8a79038555e10aa410fa0d는 open이며 독립 승인과 필수 검사가 남아 있습니다. Strix job 108800688516은 진행 중입니다. 미해결 리뷰 스레드는 0개입니다.
    • 현재 소스의 collector/production.yaml은 보안 로그를 별도 HTTPS 수신자로 라우팅하고 영속 큐를 설정합니다. security_consumer.py는 인증·테넌트·스키마를 검증해 SQLite outbox에 보관하며, security_sender.py는 승인된 HTTPS /v1/security-events가 동일 event ID를 확인한 뒤에만 전달 완료로 표시합니다. 이는 소스 계약과 로컬 검증이며 운영 배포·SIEM 수신 증거가 아닙니다.
    • prepare-release.yml은 병합된 정확한 main에서 잠금 테스트와 빌드를 실행하고 SHA-256 목록을 포함한 초안 릴리스를 만듭니다. 현재 게시된 릴리스는 없습니다. SDK 저장소에 gh pr merge --auto --squash를 요청했으나 GitHub가 Auto merge is not allowed for this repository로 거절했습니다. 승인·검사 충족 뒤 현재 HEAD를 다시 확인하고 규칙에 맞춰 수동 병합해야 합니다.
    • 중앙 Noema run 36361513987의 noema-review는 cwlab-s1-02에서 실제 실행 중이며 06:35 UTC부터 모델 판정을 준비하고 있습니다. 대상 contextual-orchestrator#1273의 현재 HEAD와 일치하므로 취소하지 않았습니다. cwlab-s1-04는 같은 시각 GitHub API에서 offline이며, 이것만으로 다른 작업의 대기 원인을 확정하지 않았습니다.

    릴리스 자산의 게시·해시 검증, 제품 이미지의 고정 wheel 설치, 운영 Collector→SIEM 목적지·담당자·보존·재전송 증거는 여전히 미확인입니다. 이 상태에서 #1565를 닫거나 병합 완료로 기록하지 않습니다.

  24. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 06:45 UTC 정책·운영 소유권 근거 보정:

    • GRC의 OpenTelemetry 증거 ADR PR #42는 feat/internal-control-model 브랜치로 병합됐습니다. 현재 기본 브랜치 develop@529cf321f134e26c0cd379ee53c06ab5297363b6의 전체 tree에는 해당 ADR/runbook이나 SIEM 운영 설정이 없습니다. 기능 브랜치 문서는 GRC가 증거 요약의 소유자라고 기술하지만, 승인된 /v1/security-events 게이트웨이·운영 담당자·실제 배포를 입증하지 않습니다.
    • ADR-0032의 운영 90일/정규화 보안 이벤트 365일은 CWL의 초기 제안값입니다. ISO/IEC 27002:2022와 NIST SP 800-92는 로그 통제·조직별 보존 정책 수립을 안내하며 모든 조직에 적용할 고정 일수를 제공하지 않습니다. 따라서 법률·계약상 더 짧은 기간, 삭제·법적 보존 절차, 담당자 승인이 배포 전에 필요합니다.
    • Project Add Palette journal for profile repo #1 목록(최대 1,000개 항목)과 조직 Issue 제목/본문 검색에서 이 SIEM 목적지의 승인 기록을 확인하지 못했습니다. 검색 결과만으로 존재하지 않는다고 단정하지 않으며, 운영 설정의 위치는 미확인입니다.

    이 근거는 정책 초안과 기본 브랜치 채택, 운영 배포를 구분합니다. 승인 없는 목적지로 보안 이벤트를 보내지 않았습니다.

  25. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 07:06 UTC, Noema 429 continuation follow-up:

    • The old draft .github#2371 still targets a product repository's repository_dispatch, while current main dispatches through the central .github handler and rechecks the live PR head/base. Its remaining valid guard was the exact retry transition.
    • Successor PR #2488 at 5ec9f39a5372d38e77ea7992bcf58a0a2789c8cc carries that guard on current main: attempts 0→1 and 1→2 are allowed; a repeated or malformed attempt fails before dispatch. The executable shell regression failed before the workflow change, then passed. 69 focused Noema tests, the Actions-environment test, actionlint, and diff check passed locally.
    • fix(ci): bind Noema continuation to the next retry attempt #2488 is open with auto-merge enabled. At 07:06 UTC it had no review and 14 queued checks; this is not merge or hosted recovery evidence. fix(noema): dispatch capacity continuation with scoped write token #2371 remains open until the successor's valid delta lands and is verified on main.
    • The central OpenCode bootstrap for fix(ci): bind Noema continuation to the next retry attempt #2488 requested the CWL central control runner group and self-hosted/linux/x64 labels. The group permits that workflow. Its job remained queued with runner_id=0; an online control runner changed from idle to busy during the check. This does not prove a runner configuration defect, so no unrelated run was cancelled or gate bypassed.

    SDK release, product image, approved SIEM destination/operator, deployed retention/replay, and exact-head reviews/terminal required checks remain outstanding.

  26. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 07:16 UTC, central ownership gate durability repair:

    The scanner checkout in .github#2357 pointed to commit d7d2d4de4225bdc1f1bce372c42c581428baff1f. That commit is not an ancestor of current main@3295c259bcb688673170a1902f46d1d6c775bad4; only the PR branch contains it, while this repository deletes branches on merge. A squash merge could therefore leave the reusable workflow depending on an unreferenced commit.

    PR #2357 now has HEAD b0aa70d1f06280101ea019c124a1417db8a3d0e8. The workflow reads the exact governance PR/merge-group head during its own review and main for product callers. The scanner's expected SHA-256 remains verified before execution. The new regression failed before the change; afterward 28 focused tests, 62 related tests under GITHUB_ACTIONS=true, actionlint, and diff check passed locally.

    At this HEAD, unresolved review threads are 0, 17 checks are queued, and there is no qualifying independent approval. Product adoption and merge remain unverified.

  27. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 07:32 UTC 러너 배치 확인: cwlab-s1-05(id 1063159)는 cwlab-control 라벨을 갖고도 CWL central CodeQL 그룹(4)에 있었습니다. GitHub Actions runner-group API로 CWL central control 그룹(6)에 이동했고 HTTP 204 및 그룹 멤버 조회로 반영을 확인했습니다. CodeQL 그룹에는 cwlab-s1-03이 남아 있습니다. 07:34 UTC 기준 Noema continuation job 108820584480은 여전히 queued/runner_id=0이며 SDK Strix job 108800688516은 진행 중입니다. 그룹 이동이 대기 시간 개선으로 이어졌는지는 미확인입니다. 관련 PR .github#2357 HEAD b0aa70d1f06280101ea019c124a1417db8a3d0e8과 cwl-telemetry#1 HEAD c22ca4ee0a0f3eefbe8a79038555e10aa410fa0d 모두 현재 필수 검사/독립 승인 전이라 병합하지 않았습니다.

  28. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 중앙 호환성 검사 보완: .github#2357의 새 HEAD 891ddf1aa764349d0056cd513b7dd919c01e20e8에서 조건식으로 OpenTelemetry provider 생성자를 선택한 뒤 호출하는 두 경로가 기존 검사에서 누락됨을 재현했습니다. RED: 추가 테스트에서 실제 결과 () 대 기대 결과 2건. 조건식 양쪽의 가능한 바인딩을 합쳐 별칭 호출 및 즉시 호출을 탐지하도록 수정했고, 검사 스크립트 SHA-256 워크플로 핀을 갱신했습니다. GREEN: tests/test_telemetry_ownership.py 29 passed, GITHUB_ACTIONS=true 29 passed, actionlint 통과, git diff --check 통과. 로컬 증거이며 현재 HEAD의 GitHub 필수 검사는 아직 queued, 독립 승인은 미확인이라 병합 증거로 쓰지 않습니다. PR: #2357

  29. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 추가 검사 보완: .github#2357 HEAD 4748a02. 조건식 외에 Python의 Provider or fallback, condition and Provider 형태도 생성자 선택 뒤 호출할 때 기존 AST 검사를 우회했습니다. RED 테스트로 2건 누락을 재현하고 같은 가능한 바인딩 결합 경로에서 수정했습니다. 워크플로 검사 파일 SHA-256 핀을 새 스크립트 바이트로 갱신했습니다. GREEN: 관련 테스트 29 passed, GITHUB_ACTIONS=true 29 passed, actionlint 및 git diff --check 통과. 새 HEAD의 GitHub 필수 검사는 아직 queued이며 독립 승인은 없습니다. 이전 HEAD의 검사·리뷰는 병합 증거로 사용하지 않습니다.

  30. seonghobae commented on Sep 28, 2026

    @seonghobae
    ContributorAuthor

    2026-09-28 07:55 UTC Noema continuation 배정 진단: 중앙 run 36361513987의 admit-current-head job 108739480960은 group id 6(CWL central control), runner cwlab-s1-01에서 01:43 UTC 성공했습니다. 같은 run의 continue-noema-transport job 108820584480은 06:57 UTC부터 queued, runner_id=0입니다. 07:55 UTC 그룹 6의 온라인 러너 3대는 모두 순간 조회상 idle이었습니다. 이 실행에서 그룹 접근 자체가 불가능하다는 가설은 앞선 성공 작업과 맞지 않습니다. 배정 지연의 서버 측 원인은 미확인이고, 대기 중인 후속 작업을 중복 발행하거나 취소하지 않았습니다. https://github.com/ContextualWisdomLab/.github/actions/runs/36361513987

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incident

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions