Runbook Coverage Tracking

Audience: operations leads and on-call engineers tracking which Stella Ops modules have operational runbooks for their critical failure modes.

This document tracks operational runbook coverage across Stella Ops modules. It is an inventory and gap tracker — the authoritative entry point for responding to an incident is the Incident Response Runbook (see also the Incident Mode pointer).

Target: runbooks for the critical failure modes of every operationally significant module.

Maintenance note: keep the Coverage Summary and Available Runbooks sections in sync with the files in this directory. When you add a runbook, add it to both, and update the module’s status. New runbooks should follow the structure of an existing, well-formed runbook such as attestor-hsm-connection.md.


Coverage Summary

Status reflects whether a module has dedicated runbooks for its primary failure modes. “Runbooks” counts the files currently in this directory for that module.

ModuleRunbooksStatus
Scanner5✅ Covered
Policy Engine6✅ Covered
Release Orchestrator5✅ Covered
Attestor5✅ Covered
Feed Connectors4✅ Covered
Database (Postgres)1✅ Covered
Crypto Subsystem1✅ Covered
Evidence Locker1✅ Covered
Backup/Restore1✅ Covered
Vulnerability / VEX2✅ Covered
Reachability1✅ Covered
Air-Gap / HLC Sync2✅ Covered
Replay1✅ Covered
Assistant1✅ Covered
Authority (OAuth/OIDC)0🔴 Gap

Available Runbooks

Scanner

Policy Engine

Release Orchestrator

Attestor

Feed Connectors

Database Operations

Crypto Subsystem

Evidence Locker

Backup / Restore

Vulnerability & VEX Operations

Reachability

Air-Gap / HLC Sync

Replay

Assistant

Incident Index


Gap Analysis

Remaining gaps


Doctor Check Integration

Runbooks should be linked from Doctor check remediation output so an operator who hits a failing check is routed straight to the fix. Tracking integration status:

ModuleDoctor ChecksLinked to Runbook
Postgres40
Crypto80
Storage30
Evidence40

Next step: update Doctor check implementations to include runbook links in their remediation output.


Last updated: 2026-05-31 (UTC). Inventory reconciled against the runbook files in this directory; per-check counts in the Doctor table are carried over from the prior revision and were not re-verified — see flagged follow-up.