DataTalksClub / DataTalksClub/website

Epic: Rehearse migration, cut over safely, and retire legacy hosts

Open
#10 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

content courses data-migration decision email epic events human infra integration operations P0 security seo testing
Dominant language
Python
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Normative authority: 09 — Migration, rollout, and roadmap, _docs/PROCESS.md, and the ten numbered specifications.

PM disposition — 2026-08-31

OPEN / P0 / EPIC / HUMAN / DECISION / DEPENDENCY-BLOCKED / PRODUCTION NO-GO.

This is the coordination epic and last rollout gate. It coordinates accepted domain,
compatibility, infrastructure, email, verification, migration, and operational inputs; it is
not a broad implementation lane. No completion criterion is currently checked, and no issue
comment, local candidate, green narrow test, or scheduled regression authorizes production,
provider, protected-data, AWS, DNS/edge, sender, indexing, or legacy-retirement work.

The current audit baseline is origin/main face8e4808d65afbf0374d1ced7a88079950d663. Its push CI run 33295699282 is not a green release/deployment record: the required gate failed and the remaining jobs were cancelled. The legacy production host and existing writes therefore remain the safe state.

Outcome and boundaries

Deliver vertical slices on web.dtcdev.click, rehearse content/course migrations and rollback,
and execute production cutover only when the exact quantitative compatibility, security, data,
email, infrastructure, and operational gates pass. Legacy systems remain deployable and
recoverable until their replacement and observation gates pass. Do not combine cutover with an
unclassified URL redesign, broad SEO experiment, speculative redirect, or sender change.

The content-sync decision is now explicit and must be read consistently throughout this epic:

  • Closed #12 accepts GitHub as the sole
    editorial source and keeps the website read-only with no commit, branch, or pull-request
    creation.
  • Closed #226, recorded in
    open decision 1, selects source lock → immutable checkout → parse/dispatch → source-owned direct upsert → source-scoped draft/soft-delete transition → SyncLog and source status. Ordinary sync has no site-wide ContentRelease candidate, active pointer, activation step, rollback graph, or arbitrary older-SHA sync.
  • Historical ContentRelease rows remain read-only migration/provenance evidence until the
    accepted direct-sync readers and successor archive are complete. #38
    and #278 own that direct-sync/cutover/
    contract-removal chain.
  • Application-image rollback, database expand/reconcile/contract safety, DNS/edge rollback,
    redirect-artifact rollback, and Relay/outbox reconciliation remain required rollout controls.
    They are not content-release activation or rollback and must not be removed by textual cleanup.

Epic completion gate

  • Milestone-0 inventories, source/target ownership, decisions, ADRs, verification producer
    contracts, deterministic report contracts, migration commands, reconciliation reports, and
    runbooks are accepted at exact identities through #72,
    #76, #77,
    and #29's still-unresolved threshold packet.
  • Direct-sync source, public-reader, management, receipt, historical-provenance, and staged
    contract-removal lanes are accepted/deployed through #38,
    #219, #253,
    #272, and #273
    #278, with no unresolved consumer,
    source/family authority, rollback-window, or migration-provenance gate.
  • Course/Cohort compatibility and migration, Relay/Datamailer history and outbox
    reconciliation, and the inactive legacy-host redirect rehearsal pass through #50,
    #60, and #71
    with all outbound effects disabled during rehearsal.
  • The complete development rehearsal and redacted release report pass through #73
    on one exact green release candidate; this is not production evidence and cannot authorize
    a live canary or cutover.
  • Only after explicit owner authorization does #74
    execute production smoke, DNS/edge and eligible redirect activation, approved Relay purpose
    activation, quantitative observation/rollback, and read-only legacy retention. Legacy
    course writes/serving/sender runtime retirement follows that window; destructive legacy
    schema contraction remains separately owned by #287.

Accepted decisions and unresolved owner gates

The closed decisions #13#20,
#22, #23,
and #24#28
are policy inputs, not implementation or production evidence. #16
also records the owner override that removes the authenticated production-probe and per-route
owner/volume requirements for the course-host redirect; it does not waive #60's exact map or
authorize AWS/DNS/production activity.

#29 is only partially resolved: its
article/non-article product boundary is accepted, while the versioned platform-wide monitoring
and rollback-threshold matrix remains an explicit owner decision. #21,
#49, and #50
remain open email/delivery inputs. Closed historical #70
is superseded and is not rollout evidence.

Current gate inventory

“Accepted” means independently tested, PM-accepted, committed, merged, pushed, terminal green,
and bound to immutable source/artifact evidence where applicable. Open issue prose, a local
candidate, synthetic evidence, a development result, or a prior audit is not an accepted gate.

Gate Current disposition
#72 classification Open; source-only candidate is on lifecycle hold and not accepted/frozen.
#76 / #77 reporting Open and dependency-blocked; no accepted producer graph/report instance.
#219 historical migration Open/reopened; authorized applied-state/runtime classification is still required.
#253 projection baseline Open and needs grooming; no source-first repair handoff is accepted.
#38 and #272#278 direct-sync chain Open; needs grooming/dependency gates remain, with no accepted predecessor tip, public-authority manifest, receipt, or retirement contract.
#60 course rehearsal Open, groomed, rehearsal-only, dependency-blocked; no accepted production-like rehearsal.
#71 redirect Open, groomed, HUMAN, dependency-blocked; no accepted inactive workload or non-production rehearsal.
#73 development aggregate Open, groomed, HUMAN, dependency-blocked; no accepted report or go/no-go.
#74 production cutover Open, HUMAN, production NO-GO; no owner authorization, production smoke, observation, rollback, or retention evidence.
#287 legacy schema contraction Open and needs grooming; always downstream of accepted #74 observation and its own owner decision.

Canonical dependency DAG

The following is a coordination map, not acceptance. Every arrow still requires the normal
engineer → independent tester → PM → focused commit → local no-FF merge/push → on-call process
for its owning issue.

accepted #219 classification
+ owner-approved source rollout/ownership/historical-selection manifest
  → #273 direct-sync schema + historical reconciliation

accepted #253 source-first projection baseline + #273
  → #274 deterministic direct-upsert runner + partial recovery

#273 + #274 + approved source/credential/ref and operations policy
  → #275 ingress + immutable checkout + jobs/locks/reconciliation

#253 + #273 + #274 + #275 + #272
+ owner-approved public-authority/cutover manifest
+ #44 for any search/graph unit; #109 only for any positive-cache unit
  → #276 source/family public-reader cutover

#32/#33 + #273 + #274 + #275
  → #277 Studio/admin parity (without candidate actions)

accepted #219/#253/#272/#273–#277
+ every #276 observation and rollback window explicitly closed
  → #278 staged-path/spec/runbook contract removal
  → #38 closes only after accepted sources and consumers are complete

accepted #60 map
  → #71 inactive redirect source and authorized non-production rehearsal
  → #73 development aggregate (after all other entry gates)

accepted #48/#49 + #50 source/runtime and one-sender evidence
+ accepted #60 + #66 + #71 + #72/#76/#77 + #78/#94 + #29 thresholds
  → #73 outbound-disabled rehearsal
  → #74 separately authorized production cutover/observation/retirement
  → #287 only for a later, separately resolved destructive schema contract

Redirect Lambda boundary

#71 consumes only the accepted, digest-bound
legacy-host map from #60 and owns an inactive DataTalksClub/aws-infra Lambda/API Gateway (or
equivalent) workload plus explicitly authorized non-production rehearsal. It must preserve the
accepted query/suffix/case/Unicode/method contract, issue one-hop mapped redirects, return true
404 for unknown paths, avoid PII telemetry, use exact existing DNS/ACM references, and never
delete or mutate the legacy ECS/database stack. #78/#94 gate development delivery/control
identity; they do not grant production authority.

Only #74, after #29's threshold matrix,
#60/#50/#71/#73 evidence, a terminal-green immutable release, and an explicit named owner/window/
DNS/edge authorization, may smoke destinations and activate the production redirect configuration.
No #71 source acceptance or #73 development rehearsal activates it. Redirect activation, app
rollback, and DNS/config rollback must remain distinct from rejected ContentRelease actions.

Stale vocabulary correction

The closed #12 and #226 issue histories contain earlier preview candidate, activate, and
rollback wording. The accepted direct-sync decision in #226 and open-decisions.md#1 is the
current authority: do not interpret that historical wording as a site-wide candidate/ready/
activate/rollback product graph. Likewise, any downstream rehearsal text that still says “fresh
four-repository content sync”, “atomic content activation”, “invalid-release rollback”, or
“active content release” is stale for direct-sync behavior and must be reconciled by its owning
issue before acceptance. In particular, #73's current body still contains those stale content
phrases despite its latest status comment; it is not a valid direct-sync contract until its PM
owner corrects them. Generic application-image, migration, DNS/edge, redirect-artifact, and
outbox/Relay rollback controls remain required.

Explicit non-goals

  • No production/protected-data/provider/credential/AWS/Terraform/DNS/edge/Search Console/sender
    access or mutation under this coordination record.
  • No content source repair, direct-sync implementation, public-reader cutover, Studio/admin
    implementation, course migration, redirect workload, rehearsal, report generation, or child
    acceptance is performed by #10's documentation update.
  • No restoration, emulation, or renaming of the rejected ContentRelease candidate/ready/
    activate/rollback graph; no arbitrary older-SHA sync, direct-row rewind, dual writer, or
    request-time fallback.
  • No legacy write/host/sender retirement or destructive schema contraction before the exact #74
    observation/retention gate and separately groomed #287 contract.
  • No completion checkbox is checked from labels, elapsed time, synthetic/local evidence, stale
    scheduled regression, or verbal/implicit owner approval.

Next actions

  1. Keep #10, #29, #38, #60, #71, #72, #73, #74, #219, #253, #272–#278, and #287 open at their
    current lifecycle states; obtain the missing owner/HUMAN manifests, threshold packet, source
    classification, and production authority without inferring any of them.
  2. Have the owning PM lanes reconcile #73's stale staged-content vocabulary and re-freeze its
    entry gates against the accepted direct-sync contract.
  3. Complete the direct-sync and course/email/redirect lanes in the DAG above, then require one
    exact green development release and independent #73 rehearsal before considering #74.
  4. Revisit #10 only after #74's explicit production cutover, observation, rollback, and retained
    legacy evidence pass; #287 remains a separate later contract.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with _docs/specs/09-migration-rollout-roadmap.md and _docs/PROCESS.md, then trace the linked gate issues from #72, #76, #77, #60, #71, #73, and #74 using the dependency DAG. Done means the specified migration, rehearsal, verification, rollback, observation, and owner-authorization gates are accepted; this epic does not authorize production work by itself.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, devops, infrastructure
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.