Readiness, evidence, and gate tables for Rackspace schema snapshots
This document is the safe evidence index for Rackspace schema operations. It records facts that can change between implementations or deployments. Follow the evidence rules before adding a value here. Raw evidence stays outside the repository.
Status: BLOCKED
Step 1 cannot start. The MySQL evidence, Rackspace firewall evidence, private Blob store, Connect installation, and GitHub ruleset are incomplete.
The following repository facts were verified on 2026-08-24:
| Fact | Safe value | Evidence source | Evidence ID | Owner | Review date |
|---|---|---|---|---|---|
| Vercel project | concourse | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Project root | apps/concourse | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Function region | iad1 | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Fluid Compute | Enabled | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Static IP feature | Enabled for iad1 | Vercel project inspection | Required | Conveyal operator | Before Step 1 |
| Connect installation | Not found | Vercel Connect inspection | Required | Conveyal operator | Before Step 1 |
main ruleset | Not configured | GitHub repository inspection | Not required | Repository admin | Before Step 1 |
| Ruleset ID | Not assigned | GitHub repository inspection | Not required | Repository admin | Before Step 1 |
| Required CI check | CI / verify | .github/workflows/ci.yml | Not required | Repository admin | Before Step 1 |
| Drizzle Kit | 1.0.0-rc.4 | Workspace dependency catalog | Not required | Implementer | During Step 0 |
| Application database | Turso through Vercel | Deployment bootstrap | Not required | Conveyal operator | Before Step 1 |
The Static IP row records only the feature state. Put both addresses and Rackspace allowlist proof in a protected local evidence report.
Complete this table with the local probe. Use the operator account only for inspection. Run QA before production, and put raw output in the protected local reports.
| Fact | QA value | Production value | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Server distribution | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Exact server version | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| TLS hostname validation | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Certificate issuer | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Certificate expiry | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Default character set | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Default collation | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
sql_mode | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
lower_case_table_names | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Server time zone | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Connection limit | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Visible non-system databases | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Largest database size | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Largest expected output | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Representative database | Pending | Pending | Pending | Pending | TBD | Before Step 1 |
Record the presence and count of each supported object type:
| Object type | QA count | Production count | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Base table | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| View | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Trigger | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Procedure | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Function | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Event | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
The snapshot and runtime accounts must be separate. Both accounts must use TLS and the Rackspace firewall path. The security document defines the account boundaries.
| Gate | QA status | Production status | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Operator can inspect inventory and grants | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Probe made no account or grant changes | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Separate accounts | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot metadata access | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
Snapshot SHOW CREATE access | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot base-table row reads denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot data changes denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot table DDL denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime data reads allowed | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
Runtime INSERT, UPDATE, DELETE grants | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime DDL denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime grant changes denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Inventory matches administrator view | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
An administrator must compare the account inventory with an authoritative inventory. MySQL hides objects that the account cannot access. A successful query does not prove complete visibility.
The production probe proves runtime DML privileges from inspected grants. It does not write application data. The version-matched fixture proves effective DML behavior in a rolled-back transaction.
| Gate | Required value | Status | Evidence ID | Owner |
|---|---|---|---|---|
| Rackspace firewall | Both iad1 Static IPs allowed | Not recorded | Pending | Conveyal operator |
| Workflow | Production use enabled | Not recorded | Pending | Conveyal operator |
| Private Blob | Private store connected to Production | Not configured | Pending | Conveyal operator |
| Private Blob automatic deletion | No lifecycle or scheduled cleanup | Not recorded | Pending | Conveyal operator |
| Vercel Connect | Installed for conveyal/concourse only | Not configured | Pending | Conveyal operator |
| Connect tracer permission | contents:write | Not recorded | Pending | Conveyal operator |
| Connect publication permissions | contents:write, pull_requests:write | Not recorded | Pending | Conveyal operator |
GitHub main ruleset | Active and includes administrators | Not configured | Not required | Repository admin |
| GitHub ruleset ID | Recorded safe numeric ID | Not configured | Not required | Repository admin |
| Required review | One approval | Not configured | Not required | Repository admin |
| Required check | CI / verify | Not configured | Not required | Repository admin |
main force pushes and deletion | Blocked | Not configured | Not required | Repository admin |
| Automatic head-branch deletion | Disabled | Not recorded | Pending | Repository admin |
| Local Git cleanup authentication | Credential helper with repository write | Not recorded | Pending | Repository admin |
Record the current platform limits before Step 8:
| Limit | Current value | Projected use | Ratio | Evidence source | Review date |
|---|---|---|---|---|---|
| Workflow events | Pending | Pending | — | Pending | Before Step 8 |
| Workflow steps | Pending | Pending | — | Pending | Before Step 8 |
| Workflow payload | Pending | Pending | — | Pending | Before Step 8 |
| Function duration | Pending | Pending | — | Pending | Before Step 8 |
| Function memory | Pending | Pending | — | Pending | Before Step 8 |
Function /tmp | Pending | Pending | — | Pending | Before Step 8 |
| Private Blob object size | Pending | Pending | — | Pending | Before Step 8 |
Each projected value must use no more than 70% of its current limit.
Record the Step 0 generation-proof results here:
| Fact | Recorded value | Evidence source | Evidence ID | Owner | Review date |
|---|---|---|---|---|---|
Exact pull() call | Pending | Step 0 branch | Not required | TBD | During Step 0 |
| Fixture output manifest | Pending | Local fixture | Pending | TBD | During Step 0 |
| QA output manifest | Pending | Local probe | Pending | TBD | During Step 0 |
| Production output manifest | Pending | Local probe | Pending | TBD | During Step 0 |
| Unstable output fields | Pending | All two-pull diffs | Pending | TBD | During Step 0 |
| Generated TypeScript result | Pending | Type check | Pending | TBD | During Step 0 |
| Migration ledger check | Pending | Fixture and live probes | Pending | TBD | During Step 0 |
| Temporary cleanup result | Pending | Local probe | Pending | TBD | During Step 0 |
| Human approval | Pending | Step 0 review | Not required | TBD | During Step 0 |
Do not put a hostname, database name, account name, report path, or credential in this table.
| Environment | Evidence ID | Report SHA-256 | Run date | Owner | Temporary output removed | Review date |
|---|---|---|---|---|---|---|
| QA | Pending | Pending | Pending | TBD | Pending | Pending |
| Production | Pending | Pending | Pending | TBD | Pending | Pending |
Persistent reports have no automatic retention limit. The owner removes a report only through the probe cleanup mode with its exact path and recorded hash.
Record credential custody without secret values:
| Credential | Owner | Created | Rotate by | Retired | Custody reference |
|---|---|---|---|---|---|
| Snapshot account | TBD | Pending | Pending | — | Pending |
| Runtime account | TBD | Pending | Pending | — | Pending |
| Artifact key version | TBD | Pending | Pending | — | Pending |
| Private Blob token | TBD | Pending | Pending | — | Pending |
| Connect configuration custody | TBD | Pending | Pending | — | Pending |
Record completed manual cleanup here:
| Operation ID | Resource | Terminal state | Eligible date | Target date | Removed date | Audit event |
|---|---|---|---|---|---|---|
| Pending | Pending | Pending | Pending | Pending | Pending | Pending |
Step 0 is complete when each required value in this document has a reviewed replacement. This rule
applies to Unknown, Pending, Not recorded, and Not configured values.
The Step 0 pull request must record:
Readiness, evidence, and gate tables for Rackspace schema snapshots
This document is the safe evidence index for Rackspace schema operations. It records facts that can change between implementations or deployments. Follow the evidence rules before adding a value here. Raw evidence stays outside the repository.
Status: BLOCKED
Step 1 cannot start. The MySQL evidence, Rackspace firewall evidence, private Blob store, Connect installation, and GitHub ruleset are incomplete.
The following repository facts were verified on 2026-08-24:
| Fact | Safe value | Evidence source | Evidence ID | Owner | Review date |
|---|---|---|---|---|---|
| Vercel project | concourse | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Project root | apps/concourse | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Function region | iad1 | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Fluid Compute | Enabled | Vercel project inspection | Not required | Conveyal operator | Before Step 1 |
| Static IP feature | Enabled for iad1 | Vercel project inspection | Required | Conveyal operator | Before Step 1 |
| Connect installation | Not found | Vercel Connect inspection | Required | Conveyal operator | Before Step 1 |
main ruleset | Not configured | GitHub repository inspection | Not required | Repository admin | Before Step 1 |
| Ruleset ID | Not assigned | GitHub repository inspection | Not required | Repository admin | Before Step 1 |
| Required CI check | CI / verify | .github/workflows/ci.yml | Not required | Repository admin | Before Step 1 |
| Drizzle Kit | 1.0.0-rc.4 | Workspace dependency catalog | Not required | Implementer | During Step 0 |
| Application database | Turso through Vercel | Deployment bootstrap | Not required | Conveyal operator | Before Step 1 |
The Static IP row records only the feature state. Put both addresses and Rackspace allowlist proof in a protected local evidence report.
Complete this table with the local probe. Use the operator account only for inspection. Run QA before production, and put raw output in the protected local reports.
| Fact | QA value | Production value | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Server distribution | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Exact server version | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| TLS hostname validation | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Certificate issuer | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Certificate expiry | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Default character set | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Default collation | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
sql_mode | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
lower_case_table_names | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Server time zone | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Connection limit | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Visible non-system databases | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Largest database size | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Largest expected output | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Representative database | Pending | Pending | Pending | Pending | TBD | Before Step 1 |
Record the presence and count of each supported object type:
| Object type | QA count | Production count | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Base table | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| View | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Trigger | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Procedure | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Function | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Event | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
The snapshot and runtime accounts must be separate. Both accounts must use TLS and the Rackspace firewall path. The security document defines the account boundaries.
| Gate | QA status | Production status | QA evidence ID | Production evidence ID | Owner | Review date |
|---|---|---|---|---|---|---|
| Operator can inspect inventory and grants | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Probe made no account or grant changes | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Separate accounts | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot metadata access | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
Snapshot SHOW CREATE access | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot base-table row reads denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot data changes denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Snapshot table DDL denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime data reads allowed | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
Runtime INSERT, UPDATE, DELETE grants | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime DDL denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Runtime grant changes denied | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
| Inventory matches administrator view | Unknown | Unknown | Pending | Pending | TBD | Before Step 1 |
An administrator must compare the account inventory with an authoritative inventory. MySQL hides objects that the account cannot access. A successful query does not prove complete visibility.
The production probe proves runtime DML privileges from inspected grants. It does not write application data. The version-matched fixture proves effective DML behavior in a rolled-back transaction.
| Gate | Required value | Status | Evidence ID | Owner |
|---|---|---|---|---|
| Rackspace firewall | Both iad1 Static IPs allowed | Not recorded | Pending | Conveyal operator |
| Workflow | Production use enabled | Not recorded | Pending | Conveyal operator |
| Private Blob | Private store connected to Production | Not configured | Pending | Conveyal operator |
| Private Blob automatic deletion | No lifecycle or scheduled cleanup | Not recorded | Pending | Conveyal operator |
| Vercel Connect | Installed for conveyal/concourse only | Not configured | Pending | Conveyal operator |
| Connect tracer permission | contents:write | Not recorded | Pending | Conveyal operator |
| Connect publication permissions | contents:write, pull_requests:write | Not recorded | Pending | Conveyal operator |
GitHub main ruleset | Active and includes administrators | Not configured | Not required | Repository admin |
| GitHub ruleset ID | Recorded safe numeric ID | Not configured | Not required | Repository admin |
| Required review | One approval | Not configured | Not required | Repository admin |
| Required check | CI / verify | Not configured | Not required | Repository admin |
main force pushes and deletion | Blocked | Not configured | Not required | Repository admin |
| Automatic head-branch deletion | Disabled | Not recorded | Pending | Repository admin |
| Local Git cleanup authentication | Credential helper with repository write | Not recorded | Pending | Repository admin |
Record the current platform limits before Step 8:
| Limit | Current value | Projected use | Ratio | Evidence source | Review date |
|---|---|---|---|---|---|
| Workflow events | Pending | Pending | — | Pending | Before Step 8 |
| Workflow steps | Pending | Pending | — | Pending | Before Step 8 |
| Workflow payload | Pending | Pending | — | Pending | Before Step 8 |
| Function duration | Pending | Pending | — | Pending | Before Step 8 |
| Function memory | Pending | Pending | — | Pending | Before Step 8 |
Function /tmp | Pending | Pending | — | Pending | Before Step 8 |
| Private Blob object size | Pending | Pending | — | Pending | Before Step 8 |
Each projected value must use no more than 70% of its current limit.
Record the Step 0 generation-proof results here:
| Fact | Recorded value | Evidence source | Evidence ID | Owner | Review date |
|---|---|---|---|---|---|
Exact pull() call | Pending | Step 0 branch | Not required | TBD | During Step 0 |
| Fixture output manifest | Pending | Local fixture | Pending | TBD | During Step 0 |
| QA output manifest | Pending | Local probe | Pending | TBD | During Step 0 |
| Production output manifest | Pending | Local probe | Pending | TBD | During Step 0 |
| Unstable output fields | Pending | All two-pull diffs | Pending | TBD | During Step 0 |
| Generated TypeScript result | Pending | Type check | Pending | TBD | During Step 0 |
| Migration ledger check | Pending | Fixture and live probes | Pending | TBD | During Step 0 |
| Temporary cleanup result | Pending | Local probe | Pending | TBD | During Step 0 |
| Human approval | Pending | Step 0 review | Not required | TBD | During Step 0 |
Do not put a hostname, database name, account name, report path, or credential in this table.
| Environment | Evidence ID | Report SHA-256 | Run date | Owner | Temporary output removed | Review date |
|---|---|---|---|---|---|---|
| QA | Pending | Pending | Pending | TBD | Pending | Pending |
| Production | Pending | Pending | Pending | TBD | Pending | Pending |
Persistent reports have no automatic retention limit. The owner removes a report only through the probe cleanup mode with its exact path and recorded hash.
Record credential custody without secret values:
| Credential | Owner | Created | Rotate by | Retired | Custody reference |
|---|---|---|---|---|---|
| Snapshot account | TBD | Pending | Pending | — | Pending |
| Runtime account | TBD | Pending | Pending | — | Pending |
| Artifact key version | TBD | Pending | Pending | — | Pending |
| Private Blob token | TBD | Pending | Pending | — | Pending |
| Connect configuration custody | TBD | Pending | Pending | — | Pending |
Record completed manual cleanup here:
| Operation ID | Resource | Terminal state | Eligible date | Target date | Removed date | Audit event |
|---|---|---|---|---|---|---|
| Pending | Pending | Pending | Pending | Pending | Pending | Pending |
Step 0 is complete when each required value in this document has a reviewed replacement. This rule
applies to Unknown, Pending, Not recorded, and Not configured values.
The Step 0 pull request must record: