docs: plan complete ase housekeeping cutover

This commit is contained in:
Simo committed 2026-08-26 20:26:19 +02:00
1 parent d42cd2af53
commit 74756dfed2
2 files changed
+1225 -23

No files matched your search

File diff suppressed because it is too large. Load diff
@@ -18,6 +18,10 @@ delivery details differ, this document is authoritative for phases 02 onward.
The master architecture remains authoritative for domain ownership and product
behavior.
This completion specification supersedes the earlier documents only for the
route namespace: the new surface uses `/ase`, never `/admin`, as its canonical
production root.
## Approved decisions
- Build complete verticals behind the existing non-production gate.
@@ -26,8 +30,9 @@ behavior.
- Implement in vertical slices rather than UI-first placeholders.
- Keep current `/admin` and `/mod` behavior unchanged until the final cutover
commit.
- At cutover, make the new Command Deck the real `/admin`, remove `/mod`, and
remove obsolete legacy routes without redirects.
- At cutover, make the new Command Deck live at `/ase`, remove the legacy
`/admin`, `/admin-next`, and `/mod` trees, and remove obsolete legacy routes
without redirects.
- Use hybrid personalization: mandatory content is capability-derived; operators
may pin and reorder allowed shortcuts and optional widgets.
- Add only backward-compatible database migrations before cutover.
@@ -55,10 +60,12 @@ All work is committed to `codex/housekeeping-complete`, based on the latest
`origin/main`. No pull request is opened until every vertical and the cutover are
implemented, reviewed, and verified.
The existing `/admin-next` entry remains unavailable when
`NODE_ENV=production`. Development and test environments use it to exercise the
new shell before cutover. The final cutover changes the canonical `/admin` route;
it does not weaken the production preview gate.
The foundation currently exposes `/admin-next`. The first completion change
renames that preview tree and its links to `/ase-next`; the preview remains
unavailable when `NODE_ENV=production`. Development and test environments use
`/ase-next` to exercise the new shell before cutover. The final cutover publishes
the canonical `/ase` tree and removes the preview entry; it does not weaken the
production preview gate before that point.
The branch is built in this order:
@@ -75,17 +82,18 @@ The branch is built in this order:
After cutover the public administration route tree is:
```text
/admin Operations workspace
/admin/people/* users, tickets, CFH, bans, moderation, teams
/admin/content/* articles, events, polls, media, engagement
/admin/economy/* catalog, shop, transactions, vouchers, values
/admin/hotel/* rooms, furni, badges, radio, emulator, Studio
/admin/system/* settings, ACL, logs, DevOps, maintenance
/ase Operations workspace
/ase/people/* users, tickets, CFH, bans, moderation, teams
/ase/content/* articles, events, polls, media, engagement
/ase/economy/* catalog, shop, transactions, vouchers, values
/ase/hotel/* rooms, furni, badges, radio, emulator, Studio
/ase/system/* settings, ACL, logs, DevOps, maintenance
```
`/admin` is the operational home, not a duplicate menu page. `/mod` has no route
after cutover. A workflow has one canonical owner and one canonical destination;
the new tree must not retain duplicate hubs or aliases.
`/ase` is the operational home, not a duplicate menu page. `/admin`,
`/admin-next`, and `/mod` have no route after cutover. A workflow has one
canonical owner and one canonical destination; the new tree must not retain
duplicate hubs or aliases.
## Module ownership
@@ -331,11 +339,13 @@ legacy UI routes is an application cutover, not a destructive data migration.
The final cutover commit is created only after all vertical gates pass. It:
1. moves the completed shell and Operations workspace to `/admin`;
2. changes domain preview hrefs to canonical `/admin/<domain>` hrefs;
1. moves the completed shell and Operations workspace from `/ase-next` to
`/ase`;
2. changes domain preview hrefs to canonical `/ase/<domain>` hrefs;
3. updates internal links, navigation configuration, and authorization fallback
destinations;
4. removes `/mod` and every legacy route marked `REMOVE`;
4. removes the legacy `/admin`, `/admin-next`, and `/mod` route trees plus every
legacy route marked `REMOVE`;
5. removes legacy pages whose behavior moved or merged into canonical routes;
6. removes the temporary preview entry and flag if no longer used by tests;
7. adds no compatibility redirects.
@@ -363,8 +373,8 @@ The final branch requires:
- production build with temporary environment restoration;
- visual verification at desktop and mobile widths for every domain and shared
state;
- route-level smoke checks for canonical pages, denied access, and removal of
`/mod`/obsolete routes;
- route-level smoke checks for canonical `/ase` pages, denied access, and
removal of `/admin`, `/admin-next`, `/mod`, and obsolete routes;
- a broad whole-branch code review followed by one reviewed fix wave if needed.
Repository-wide pre-existing formatter debt is reported separately and must not
@@ -389,7 +399,8 @@ before serving the cutover release.
- A new task-assignment system for inbox items.
- A replacement authentication or ACL model.
- Rank-based authorization thresholds.
- Compatibility redirects for removed admin/mod routes.
- Compatibility redirects for removed `/admin`, `/admin-next`, or `/mod`
routes.
- Destructive cleanup of legacy database data.
- Rewriting specialized domain engines that already work; they are integrated
behind consistent domain contracts instead.
@@ -406,6 +417,6 @@ The program is complete only when:
operate against real domain services;
- capability enforcement and audit evidence cover every exposed read and
mutation path;
- `/admin` serves the new HK, `/mod` and removed legacy routes are unreachable,
and no compatibility redirects exist;
- `/ase` serves the new HK; `/admin`, `/admin-next`, `/mod`, and removed legacy
routes are unreachable; and no compatibility redirects exist;
- final local, CI, deployment, health, and visual evidence are all recorded.