Platform Module Task Board

This board mirrors the active platform sprint(s). Update alongside the sprint tracker.

Active sprint tasks

Source of truth: docs/implplan/SPRINT_20251229_043_PLATFORM_platform_service_foundation.md.

Task IDStatusNotes
OPR-4BDONE2026-07-13: Revalidated authenticated empty and populated GET /api/v2/topology/layout reads. The July 3 empty-graph guard remains the bounded product fix; focused HTTP proof passed 2/2, policy metadata includes platform.topology.read, and no new runtime defect was found. Live gateway acceptance remains OPR-6.
PLAT-COMPAT-001DONESprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: synthetic Platform compatibility endpoints are gated out of production.
PLAT-COMPAT-002DONESprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: registry search fails truthfully when no real registry backend is configured.
PLAT-COMPAT-003DONESprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: production no longer binds the no-op remote command executor.
PLAT-SVC-001DONEPlatform Service project scaffold.
PLAT-SVC-002DONEHealth aggregation endpoints.
PLAT-SVC-003DONEQuota aggregation endpoints.
PLAT-SVC-004DONEOnboarding state storage + APIs.
PLAT-SVC-005DONEPreferences storage + APIs.
QA-FIXTURE-READBACK-001DONESprint docs/implplan/SPRINT_20260517_002_Platform_advanced_assurance_fixture_readback.md: added config-gated GET /api/qa/fixtures/advanced-assurance-golden readback over local seed artifacts with digest validation.
QA-ASSURANCE-CASE-001DONESprint docs/implplan/SPRINT_20260517_003_Platform_advanced_assurance_case_summary.md: added fixture-backed GET /api/assurance/cases/{caseId} summary over validated local seed artifacts while reporting live import as incomplete.
QA-ASSURANCE-SCENARIO-001DONESprint docs/implplan/SPRINT_20260517_016_Platform_assurance_scenario_transactions.md: added operator-readable scenario transaction readbacks for ASSURE-001 through ASSURE-022 with fail-closed negative checks.
PLATFORM-20260605-008-003BLOCKEDSprint docs/implplan/SPRINT_20260605_008_Platform_regional_crypto_plugin_boundary.md: Platform-scoped signed runtime admission is implemented and tested; full closure waits on DevOps compose/read-only mount and image-payload proof.
TASK-051-05ADONESprint docs/implplan/SPRINT_20260518_051_No_PII_in_capsules_refactor.md: Platform owns shared.tenants.default_region with bootstrap/forward migrations for EvidenceLocker residency fallback.
PLAT-SVC-006DONEGlobal search aggregation.
PLAT-SVC-007DONEGateway route registration + scopes.
PLAT-SVC-008DONEObservability metrics/logging.
PLAT-SVC-009DONEDeterminism/offline tests.
PLAT-SVC-010DONEDocs/runbooks update.
B22-01DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/context/* contracts, policy/scope wiring, migration 047_GlobalContextAndFilters.sql, and endpoint/migration tests for deterministic ordering and preference round-trip behavior.
B22-02DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped v2 releases read-model endpoints (/api/v2/releases{,/activity,/approvals,/{releaseId}}) backed by deterministic projections and migration 048_ReleaseReadModels.sql.
B22-03DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/topology/* inventory endpoints (regions/environments/targets/hosts/agents/promotion paths/workflows/gate profiles) and migration 049_TopologyInventory.sql.
B22-04DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/security/{findings,disposition/{findingId},sbom-explorer} contracts and migration 050_SecurityDispositionProjection.sql while preserving separate VEX/exception write authority boundaries.
B22-05DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/integrations/{feeds,vex-sources} contracts and migration 051_IntegrationSourceHealth.sql with deterministic source health/freshness metadata.
B22-06DONESprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped legacy alias compatibility and deterministic deprecation telemetry for critical Pack 22 API surfaces.
POLICY-ARM64-003DONESprint docs-archive/implplan/SPRINT_20260507_002_Policy_arm64_dependency_readiness.md: documented PKCS#11/GOST ARM64 provider readiness and optional-route fail-closed evidence rules.