P3-WP14 enterprise pilot handover runbook
Boundary and ownership
This runbook is a handover procedure, not evidence that a pilot has been deployed. All enterprise identities, endpoints, credentials, change windows, recovery objectives, and external approvals are TBD_EXTERNAL. Do not insert secrets in this document or its related JSON artifacts.
Preflight
- Confirm the approved release manifest and its SHA-256 values; the current local engineering migration head is
20260818_559.
- Confirm source/deployment mirror parity, required configuration allowlist, backup manifest, rollback image/package, and the approved enterprise change record.
- Confirm product, business, technical, security, and operations owners are assigned; do not proceed if any five-party signoff prerequisite is BLOCKED_EXTERNAL.
- Confirm the target environment, network policy, IdP, data sources, monitoring, notification, ITSM, security/legal controls, and conditional capabilities that are in scope.
Install, 升级, and 回滚
- Install only the approved signed package in the approved target environment.
- Before upgrade, create and verify the approved backup manifest; run the reviewed migration path and health checks under the restricted migrator.
- If a stop condition occurs, halt new writes according to the approved change plan, restore the matching backup, return to the documented prior artifact, and record the evidence and decision.
- Do not use an empty local migration round trip as proof that a nonempty enterprise rollback succeeded.
恢复 and incident response
- Use the approved backup manifest, recovery objective, owner, and change window.
- Restore PostgreSQL, object storage, graph data, configuration, and approved artifacts according to their individual runbooks; validate authorization and audit behavior after restoration.
- Escalate P0 immediately to product, technical, security, and operations owners; log P1 with its formal decision requirement.
- Preserve hashes, timestamps, evidence references, and incident identifiers; do not preserve raw enterprise data or credentials in the acceptance package.
Daily and weekly operations
- 每日巡检: health, scheduled work, alert delivery, authorization denials, backup completion, incident queue, and capacity indicators.
- 每周巡检: restore readiness, release/rollback package integrity, access review, pending P1/P2/P3 decisions, SLO trend, evidence retention, and training remediation.
- Operations must distinguish a local test result from target-environment telemetry and must record unavailable integrations as TBD_EXTERNAL.
培训 and transfer
User and operations training must cover role boundaries, source and data responsibility, incident escalation, audit evidence, upgrade, rollback, and restore. Capture attendance, exercises, failed exercises, and 补训 in the enterprise record; material existence is not attendance evidence.
远端保存建议
After explicit enterprise authorization, save the approved signed manifest, non-secret test logs, migration/recovery reports, P0/P1 decisions, training records, and five-party evidence to the approved enterprise-controlled remote repository with retention controls. P3-WP14 does not push, deploy, or upload any artifact. Remote repository identity, authorization, retention policy, and completion record remain TBD_EXTERNAL.