Platform Module Task Board
This board mirrors the active platform sprint(s). Update alongside the sprint tracker.
Active sprint tasks
Source of truth: docs/implplan/SPRINT_20251229_043_PLATFORM_platform_service_foundation.md.
| Task ID | Status | Notes |
|---|---|---|
| OPR-4B | DONE | 2026-07-13: Revalidated authenticated empty and populated GET /api/v2/topology/layout reads. The July 3 empty-graph guard remains the bounded product fix; focused HTTP proof passed 2/2, policy metadata includes platform.topology.read, and no new runtime defect was found. Live gateway acceptance remains OPR-6. |
| PLAT-COMPAT-001 | DONE | Sprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: synthetic Platform compatibility endpoints are gated out of production. |
| PLAT-COMPAT-002 | DONE | Sprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: registry search fails truthfully when no real registry backend is configured. |
| PLAT-COMPAT-003 | DONE | Sprint docs/implplan/SPRINT_20260424_009_Platform_compatibility_stub_cleanup.md: production no longer binds the no-op remote command executor. |
| PLAT-SVC-001 | DONE | Platform Service project scaffold. |
| PLAT-SVC-002 | DONE | Health aggregation endpoints. |
| PLAT-SVC-003 | DONE | Quota aggregation endpoints. |
| PLAT-SVC-004 | DONE | Onboarding state storage + APIs. |
| PLAT-SVC-005 | DONE | Preferences storage + APIs. |
| QA-FIXTURE-READBACK-001 | DONE | Sprint docs/implplan/SPRINT_20260517_002_Platform_advanced_assurance_fixture_readback.md: added config-gated GET /api/qa/fixtures/advanced-assurance-golden readback over local seed artifacts with digest validation. |
| QA-ASSURANCE-CASE-001 | DONE | Sprint docs/implplan/SPRINT_20260517_003_Platform_advanced_assurance_case_summary.md: added fixture-backed GET /api/assurance/cases/{caseId} summary over validated local seed artifacts while reporting live import as incomplete. |
| QA-ASSURANCE-SCENARIO-001 | DONE | Sprint docs/implplan/SPRINT_20260517_016_Platform_assurance_scenario_transactions.md: added operator-readable scenario transaction readbacks for ASSURE-001 through ASSURE-022 with fail-closed negative checks. |
| PLATFORM-20260605-008-003 | BLOCKED | Sprint docs/implplan/SPRINT_20260605_008_Platform_regional_crypto_plugin_boundary.md: Platform-scoped signed runtime admission is implemented and tested; full closure waits on DevOps compose/read-only mount and image-payload proof. |
| TASK-051-05A | DONE | Sprint docs/implplan/SPRINT_20260518_051_No_PII_in_capsules_refactor.md: Platform owns shared.tenants.default_region with bootstrap/forward migrations for EvidenceLocker residency fallback. |
| PLAT-SVC-006 | DONE | Global search aggregation. |
| PLAT-SVC-007 | DONE | Gateway route registration + scopes. |
| PLAT-SVC-008 | DONE | Observability metrics/logging. |
| PLAT-SVC-009 | DONE | Determinism/offline tests. |
| PLAT-SVC-010 | DONE | Docs/runbooks update. |
| B22-01 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/context/* contracts, policy/scope wiring, migration 047_GlobalContextAndFilters.sql, and endpoint/migration tests for deterministic ordering and preference round-trip behavior. |
| B22-02 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped v2 releases read-model endpoints (/api/v2/releases{,/activity,/approvals,/{releaseId}}) backed by deterministic projections and migration 048_ReleaseReadModels.sql. |
| B22-03 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/topology/* inventory endpoints (regions/environments/targets/hosts/agents/promotion paths/workflows/gate profiles) and migration 049_TopologyInventory.sql. |
| B22-04 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/security/{findings,disposition/{findingId},sbom-explorer} contracts and migration 050_SecurityDispositionProjection.sql while preserving separate VEX/exception write authority boundaries. |
| B22-05 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped /api/v2/integrations/{feeds,vex-sources} contracts and migration 051_IntegrationSourceHealth.sql with deterministic source health/freshness metadata. |
| B22-06 | DONE | Sprint docs/implplan/SPRINT_20260220_018_Platform_pack22_backend_contracts_and_migrations.md: shipped legacy alias compatibility and deterministic deprecation telemetry for critical Pack 22 API surfaces. |
| POLICY-ARM64-003 | DONE | Sprint docs-archive/implplan/SPRINT_20260507_002_Policy_arm64_dependency_readiness.md: documented PKCS#11/GOST ARM64 provider readiness and optional-route fail-closed evidence rules. |
