Skip to content

EPIC: Release 1 operational closeout #44

Description

@krishagel

Summary

Track only the remaining work required to call Release 1 operationally ready. The original implementation checklist is historical: issues #1–30, #32, #34–36, #38–39, and #41 are closed, and the repository-wide product consolidation epic #346 is complete. This epic now follows current readiness evidence instead of the archived 2026 build plan.

The application, database, DNS/TLS, and staff-group synchronization are deployed. Known release blockers are live channel delivery, exact private mobile build evidence, one retained human sign-in verification, release-critical monitoring evidence, and an explicit live-or-disabled decision for media/export/malware-scanning capabilities. SMS can remain visibly blocked for Release 1 if email and push are live and no SMS work is routed.

Canonical workstreams

Release blockers

Non-blocking follow-up

Duplicate consolidation

Recommended order

  1. Finish P1: Finish exact-build private mobile distribution and durable Play testing #33 so exact private mobile builds are known.
  2. Finish P1: Activate Expo push and prove physical-device delivery #278 and P1: Light up the email channel — SES worker, sending enabled, delivery ledger #277 so push and email have honest end-to-end evidence.
  3. Record OIDC, monitoring, media/export, and malware-scanning truth; then run the existing monthly delivery-test capability once for the launch channels and complete the Release 1 go-live procedure.
  4. Continue P2: SMS carrier registration and worker — start now, it is the long pole #279, P2: Map emergency-operation records to current Washington retention schedules #42, and P2: Migrate push delivery from Expo relay to direct APNs/FCM #43 without making their incomplete state look live.

Definition of Done

  • Every Release blocker above is closed with its own Definition of Done satisfied
  • One complete staff-context Google OIDC sign-in/session is retained as aggregate evidence without storing credentials or staff identity (manual)
  • One successful append-only monthly delivery-test report covers every launch notification channel and reuses P1: Light up the email channel — SES worker, sending enabled, delivery ledger #277/P1: Activate Expo push and prove physical-device delivery #278 evidence where it represents the same provider actions; no duplicate notification is sent solely for this epic (manual)
  • The exact approved iOS and Android builds are installed through their intended private channels and match the retained version/build evidence (manual)
  • SMS is either live-verified or remains fail-closed, visibly unavailable, and receives no routable work
  • Release-critical CloudWatch alarms and actions are read back active for the exact release; publisher-dependent alarms are exercised by retained synthetic evidence (manual)
  • Event media/exports and malware scanning are either live-verified end to end or disabled server-side and absent from Release 1 operator paths
  • docs/INTEGRATIONS.md is current and contains no contradictory status for deployment, OIDC, monitoring, providers, EAS submission, or mobile installation
  • The four human-only actions, staff-only scope, server-side authorization, real/drill separation, append-only history, idempotency, and fail-closed provider behavior remain enforced
  • No student data, secret, real contact fixture, or new tenant-specific source literal is introduced
  • Production web and mobile builds succeed
  • Full test suite green
  • Zero lint warnings; typecheck clean
  • The product owner's direct instruction for the exact production release is recorded through the current go-live procedure (manual)
  • E2E flow(s) pass — N/A — the epic reuses the executable child-issue E2E evidence plus the manual operational/provider flows below

Acceptance tests / E2E flows

  • release-integrated-delivery-test (manual): an authenticated human runs the existing monthly delivery-test capability once for the launch channels and retains its append-only report; automation may prepare evidence but may not send the notifications.
  • mobile-private-build-smoke (manual): on the exact privately distributed iOS and Android builds, verify sign-in, secure unlock, authorized facilities, real/drill presentation, event navigation, and notification settings without starting a real incident.

Verification

Affected areas

  • Implementation primarily belongs to the canonical child issues above.
  • docs/INTEGRATIONS.md and docs/runbooks/go-live.md — OIDC, monitoring, media/export/malware, monthly-test, and exact-release truth owned directly by this epic where no child owns it.
  • Current media/export capability paths and infra/src/stack/** only if the release decision is to enable or disable those unowned boundaries.

Out of scope

Risk & rollback

  • Risk: high — the remaining work crosses live provider delivery and operational readiness.
  • Rollback: follow each child issue's rollback and the current deployment/mobile runbooks. Keep unverified channels dark, revert the affected immutable release, and preserve append-only event, delivery, audit, migration, and provider evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicTracking epic

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions