Replay the accepted local RAR runtime

This procedure covers only Scanner Web, Platform and Router Gateway selected by devops/compose/local-runtime-chains.json. It preserves the accepted images and existing runtime settings. It does not rebuild/publish images, deploy Console assets, change Scanner Worker/cohorts, repair Authority, recreate ExportCenter, or perform SCN live acceptance.

ReleaseOrchestrator has left the active RAR allowlist. Its sole current runtime registration is devops/compose/local-scn-runtime.json, alongside Policy Engine and Scanner Worker. The remaining RAR images, source and chains are unchanged. Historical four-service receipts are retained without rewriting them or treating their RO entry as current execution authority.

The replay helper is deliberately bound to the accepted binary source and image IDs in its source. Changing that accepted profile requires a new reviewed source change; this is not an arbitrary-image deployment command. Source definitions, not temporary override files, must describe the final runtime. The accepted source is per target: local-runtime-chains.json carries a manifest default and an optional per-service binarySourceSha; the Gateway was re-derived on 2026-09-02 to clean 409106c5d4 (image sha256:c89ce1eb030b..., the RAR-12 raw-request-target binary; buildinfo clean, 0 dirty) while platform and scanner-web stay at 4bcb645bd036.

Preconditions

  1. Confirm the approved target and a quiet runtime boundary with SCN. Canonical RAR replay and its fresh handoff precede SCN’s live Baseline/Consumer recapture. Never change the Gateway bind or recreate these services during SCN forcing, activation or soak.
  2. Use primary main with committed, unmodified canonical inputs and helper. Preserve unrelated work; do not reset, stash or sweep the primary checkout. All selected Compose inputs and includes must be committed under devops/compose, with existing networks last.
  3. Keep the accepted images and rollback configuration available locally. The helper reads image buildinfo through a networkless, read-only, non-root shell; no application starts in that probe.
  4. Keep the protected Compose .env, existing certificate/signing inputs and mounted payloads in place. Do not print credentials or save rendered Compose output. No new secret values are needed.
  5. Use Node with the repository’s existing yaml dependency installed. Create the ignored receipt directory tmp/qa/rar-20260830/canonical/ if absent. Each command below needs a new absolute JSON output path directly inside that directory; existing evidence is never overwritten.

Source checks and preflight

node tools/scripts/validate/check-local-runtime-sources.cjs --self-test
node tools/scripts/validate/check-local-runtime-sources.cjs --root <absolute-primary-repository>
node tools/scripts/deploy/replay-local-runtime.cjs --self-test
node tools/scripts/deploy/replay-local-runtime.cjs --target <service> --receipt <new-preflight.json>

Also run tools/scripts/validate/check-compose-healthchecks.sh --self-test and its normal check with the supported Bash environment (Git Bash on Windows). This gate recognizes a registered partial profile only after proving an earlier base and an effective enabled healthcheck. It reads three manifests — local-runtime-chains.json (rar), local-scn-runtime.json (scn, chain shape only; provenance is replay-local-scn.cjs’s) and local-overlay-chains.json (local overlays that carry overrides, owned by the healthcheck register) — and a service may be registered in exactly one of them; a digest-only pin overlay needs no registration because the gate counts by shape. Removing that required check or adding an unchecked standalone service must still fail; exemption pins are not increased. Its source inventory includes tracked and new nonignored files, not ignored generated installation output. This source census is distinct from live container health.

The gate reads the two explicitly named, disjoint RAR and SCN manifests. A duplicate service owner fails. SCN baseline/recovery health is checked while candidate image IDs remain null; candidate profiles receive no inheritance exemption until their image/repository-digest pair is complete.

Allowed RAR service keys are scanner-web, platform, and router-gateway. Inspect the receipt before execution. It binds the exact source/helper/dependency hashes, current container/image identity, full ordered chain, clean image provenance, environment equality, mounts, process/security settings, ports, network IDs/aliases and healthcheck configuration. It must be execution-ready. A changed HEAD/input/helper requires a fresh preflight and review.

The source checker independently checks the service-specific chains, preserved security fields, immutable images, secret-placeholder shape, and the exact registered Gateway route removal. It is not a substitute for the replay helper’s resolved-model and live-state comparison.

The sole missing-input allowance is the unrelated OFFLINEKIT_ACTIVATOR_AUTHORITY_CLIENT_SECRET. The helper may supply a process-local placeholder only after proving the resolved and uninterpolated target/resource models do not reference it. This is never a credential or authority for a whole-stack operation. Existing optional Authority env-file pointers remain protected inputs, not copied values.

Execute one reviewed target

After the start notice and receipt review, run the following as one command:

node tools/scripts/deploy/replay-local-runtime.cjs --target <service> --execute --reviewed-receipt <preflight.json> --reviewed-sha256 <sha256> --receipt <new-execution.json>

The only live operation is up -d --no-deps --force-recreate --no-build --pull never <one-service>. The helper reserves and flushes an exclusive output file before the action, repeats the complete preflight, and requires a new container ID with the same image, unchanged runtime configuration and network IDs, and exact canonical Compose labels. It never uses stdin Compose inputs or removes orphans.

Then verify health, logs and live behavior. Check that every required service document is usable before interpreting publication absence. Registry search must retain its Platform owner; jobs must retain Scheduler; the retired quota shims must not reappear. API-prefixed retired paths must return JSON endpoint-not-found, not HTML or an unrelated owner. The current binary recognizes /api and /v1 as API-miss prefixes, but not the retired /scheduler host prefix: its old GET URLs may return the exact pinned SPA index as HTML200. Record that as no API route, never JSON/API success. Run tools/scripts/qa/verify-rar7-native-route-window.mjs --phase pre|post --workspace <primary> --output <new-json-under-tmp/qa> with protected process-only QA credentials; its20 checks cover five native reads, anonymous401, insufficient-scope403 and differentiated old-alias results. It also requires one published owner per native GET and no publisher for each alias. Re-run verify-rar6-console-reads.mjs for ordinary browser acceptance of the same served artifact. Do not substitute these checks for browser login, FND-17 recovery revocation, or SCN-ID forcing/rollback/soak acceptance.

Platform’s known analytics-maintenance 3F000 exception remains explicitly recorded in the RAR sprint; configuration parity does not repair it or establish globally zero-error acceptance.

Gateway recovery

The canonical rollback chain adds only docker-compose.local-router-gateway-rollback.yml; it selects the same image and the readonly archived42-route configuration. The normal chain selects37. The five removals (RAR-7 fourth sitting, 2026-09-02) are ^/api/v1/search(.*) and ^/api/v1/advisory-ai(.*) (the served Console now calls the native /v1/search and /v1/advisory-ai surfaces advisoryai publishes), ^/api/v1/advisories(.*) (dead rewrite to an unpublished path), ^/api/v1/federation/(.*) (Release Orchestrator maps the controller only behind STELLAOPS_FEATURE_FEDERATION and publishes it natively when on) and ^/api/offlinekit/v1(.*) (static Microservice entry for an auto-published surface, 2026-08-28 ruling). The earlier window, 43-to-42, removed the lineage C-collision row ^/api/v1/lineage(.*) after the live aggregate showed sbomservice as the only owner of /api/v1/lineage/* (exportcenter renamed its surface to /v1/lineage-evidence-packs/*; RAR-7, 2026-09-02). The earlier window, 47-to-43, removed the four ExportCenter rewrites ^/api/export-center/v1/exports(?=/|$)(.*), ^/api/export-center(?=/|$)(.*), ^/export-center/v1/exports(?=/|$)(.*) and ^/export-center(?=/|$)(.*), retired after the rebuilt Export host on its owner database returned a genuine signed download through the gateway and the served Console’s native /v1/exports reads passed in the browser (RAR-6, 2026-09-02). The windows 48-to-47 (broad Graph rewrite), 49-to-48 (Findings static hint) and 54-to-49 (three /api/v1/notifier aliases, the Pack Registry alias and /scheduler) are historical. Notify/JobEngine native owners are unchanged; the Export worker was not rebuilt in this window (generic export runs stay Running); this is not a consolidated-owner or data cutover. Retained route order/content and all non-route configuration must match (the 47-to-43 window additionally admitted the reviewed removal of the /export-center approved passthrough prefix; this window has no non-route delta). Both directions preserve the complete pinned native Console inventory (Console6087b20a86, rebuilt from clean 6087b20a86 on 2026-09-02 after the AdvisoryAI native repoint; Console675af87d84 and Console32907 are historical). Older60/57/54/49/48/47/43 configurations are historical evidence, not this window’s immediate recovery baseline.

Version2 binds both forward and recovery Compose inputs before the initial action, rehashes inputs and dependencies and checks HEAD after it, and compares preserved Gateway mounts/settings to the original forward cohort before recovery. Other services must be stable within each newly reviewed window; recovery never restores their old identities. The helper’s post-action phase proves identity/configuration parity, not healthy runtime or live behavior. Capture healthy/restarts0 and the forcing checks separately before handoff.

RO retirement does not permit ignoring the old manifest hash. Recovery reads historical and current whole manifests at their recorded ancestor/current commits and verifies both receipt hashes. It then permits only removal of the exact retired RO profile, requires every surviving RAR record to match, and compares the verified target projection. The proof remains part of the new review binding. Original helper bytes are verified against their recorded commit; the current helper needs a fresh reviewed preflight, and the YAML dependency must remain identical. Other source files, images, networks, mounted bytes and runtime settings retain their existing checks. Console and Platform recovery consumers use the same manifest proof; this does not relax the Console-only helper’s deliberately historical54-route boundary.

The Console-only helper (replay-local-console.cjs, manifest local-console-runtime.json) was re-derived on 2026-09-02 for its third window (candidate Console6087b20a86 after the AdvisoryAI native repoint, baseline Console675af87d84, on the committed 42-route table) and earlier that day for its second window: candidate Console675af87d84 (clean rebuild after P8-14 moved the frontend tree), baseline Console32907 (live-proven on the 49-route table), and the then-committed 48-route configuration pinned (that window is complete; the route table has since moved to 47 through the canonical Gateway replay). Its forward recreate therefore also loads the source-retired Findings static hint; its rollback restores Console32907 on that same 48-route table. The old int6 artifact is historical and must not be paired with any table that lacks the aliases it needed. Route recovery to the archived 49 bytes is the canonical Gateway rollback chain above, with the new Console retained, never an old Console mount paired with the new route table.

First prepare a rollback, without executing it:

node tools/scripts/deploy/replay-local-runtime.cjs --target router-gateway --rollback --forward-receipt <forward-execution.json> --forward-sha256 <sha256> --receipt <new-rollback-preflight.json>

After reviewing that receipt, use the same arguments plus --execute, --reviewed-receipt <rollback-preflight.json> --reviewed-sha256 <sha256>, and a different output path.

The exact forward replacement ID/image and verified helper history are mandatory, even when the candidate is stopped, unhealthy or restarting. A positively identified post-action verification failure may also qualify: Compose returned zero, replacement/image checks passed, and the retained failure snapshot identifies that same replacement. Unknown, pre-action, nonzero-Compose and identity-drifted failures do not qualify. They require explicit retained-state investigation, not a bypass flag. These identity controls have offline tests; they do not claim a live stopped-container rollback drill.

Separate SCN owner-read preparation

The SCN manifest records the retained RO source 4bcb645bd03643c7941de4c935873e061b103940 as a baseline. Policy/RO candidate pins record bf9deddee1eae37e8610882df0dda7653ef11543 as their candidate binary source, not as deployed state. No RAR replay command may select those candidates or recreate Policy/RO/Worker.

docker-compose.local-policy-engine.yml and docker-compose.local-release-orchestrator.yml preserve their baseline images and configuration. The image-only docker-compose.local-policy-engine-scn-candidate.yml and docker-compose.local-release-orchestrator-scn-candidate.yml layer after the corresponding baseline profile and before existing networks. Exact forward and recovery chains belong to the SCN manifest; never reconstruct them from the old SCN5 temporary label chain.

Before adoption, the canonical tools/scripts/deploy/preserve-policy-ro-runtime-secrets.cjs must preserve both DataProtection key rings and RO’s token cache through its reviewed, bounded capture path. It leaves the exact original stopped on success; restart invalidates that capture. The three new RW binds forbid implicit host-directory creation. Restricted Windows ACLs and matching bytes are not Linux uid10001 write/rotation proof, and preservation is not deployment acceptance. Existing agent-CA mounts, physical networks and compose_policy-messaging-plugin-scratch remain unchanged. Follow the SCN cutover procedure for preservation, baseline adoption, candidate forcing and explicit recovery. Worker execution remains separate and is refused by the Policy/RO controller.

Closeout

Require no temporary Compose inputs in the three active RAR labels, canonical replay parity and the required live checks. Preserve protected runtime inputs, mounted Console/plugin payloads and rollback images. Distill nonsecret evidence and hashes into the sprint; raw DLL/log/network/config evidence is never committed. Remove obsolete temporary files only after checking all live references, not merely these three targets. Deliver the new source/configuration/chain handoff before SCN recaptures its live baseline.