Pre-launch: no consolidated go/no-go section or formal signoff gate in launch runbook [SEC-A06] #391
Labels
No labels
agent:fix_bugfix
agent:fix_conflicts
agent:fix_security
agent:gap_analysis
agent:implement
agent:implement
agent:implement
agent:open_issues
agent:ready
agent:research
agent:security_audit
agent:verify
architecture
backend
blocker:hybrid
blocker:launch
blocker:limit-orders
blocker:v2
block:log_only
block:security
bug
ci
contracts
correctness
deploy
dev
devops
docs
documentation
duplicate
e2e
enhancement
epic
feature
frontend
functional-completion
gas
good first issue
governance
help wanted
high-risk
hooks
hybrid
indexer
infra
infrastructure
integrators
invalid
launch-blocker
limit-orders
localnet
localterra
low priority
missing-implementation
needs-design
ops
performance
priority
high
priority
medium
product
qa
QA
question
ready
ready
research
scripts
security
security-hardening
smartcontracts
tech-debt
testing
ux
UX
v2
verification
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
code/cl8y-dex-terraclassic#391
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Checklist Item
SEC-A06: Add launch decision language: when to pause launch, when to launch with accepted risk, and when to block launch. Verify: checklist includes explicit go/no-go section signed off before production deploy.
Summary
Launch decision criteria and blocker definitions exist but are spread across at least four separate documents with no single go/no-go section consolidating the three decisions (block / pause / go with accepted risk). The deploy runbook has no mandatory signoff gate that must be completed before going live.
What Was Checked
docs/runbooks/launch-checklist.md-- phased deploy checklist, no go/no-go sectiondocs/reviews/20260409T030009Z/RELEASE_READINESS_MATRIX.md-- blocker matrix exists but is a review artifact, not a required gate in the runbookdocs/reviews/20260409T030009Z/REVIEW.md-- top 10 blockers and launch criteria documentedhelp/checklist.mdSEC-J01/J02/J05 -- P0 blocker definitions and developer signoff requirement existQA_TEMPLATE.mdlines 1032-1050 -- three-role signoff table exists but is not referenced or required by the launch runbookExpected (per checklist)
The launch checklist or deploy runbook must contain an explicit go/no-go section with three defined decisions: when to block launch entirely, when to pause/delay launch, and when to go with documented accepted risk. A named signoff step must be a required gate before production deploy, not an optional template.
Actual
Launch criteria are defined across REVIEW.md, RELEASE_READINESS_MATRIX.md, and help/checklist.md (SEC-J01/J02) but none of these are embedded as a required step inside
docs/runbooks/launch-checklist.md. The deploy runbook can be followed to completion without ever reaching a go/no-go decision point. The signoff table in QA_TEMPLATE.md is not linked or required by any runbook step.Evidence
docs/runbooks/launch-checklist.md: four phases (Preconditions, Deploy, Governance-sensitive, Post-deploy) -- no go/no-go section, no signoff stepdocs/reviews/20260409T030009Z/RELEASE_READINESS_MATRIX.md: blocker matrix exists as a dated review artifact (2026-04-09), not a live runbook gatehelp/checklist.mdSEC-J05: "Require prelaunch signoff from developer" -- requirement stated but no runbook step enforces itQA_TEMPLATE.mdlines 1032-1050: signoff table with QA Tester, Dev Lead, Product Owner roles -- not referenced in launch runbookSuggested Fix
Add a Phase 0.5 (or final phase) to
docs/runbooks/launch-checklist.mdcontaining an explicit go/no-go section with:Add a mandatory signoff step at the end of the runbook requiring the developer (or named role) to post a comment on the launch issue with: decision (GO/PAUSE/BLOCK), date, open residual risks, and risk acceptance statement. Reference the QA_TEMPLATE.md signoff table as the format.
Verification Checklist
Steps to confirm the fix is complete and the checklist item can be marked done.
docs/runbooks/launch-checklist.mdcontains an explicit go/no-go section with BLOCK, PAUSE, and GO criteria definedLabels
pre-launchCc: @PlasticDigits
mentioned in issue #381
mentioned in commit
5b1ef3a074mentioned in merge request !916
mentioned in commit
9c9b10e87fVerification — SEC-A06 / GitLab #391
Result: All acceptance criteria PASS. No repo changes required; closing issue.
What was verified
launch-checklist.mdhas explicit go/no-go section (BLOCK / PAUSE / GO / GO with accepted risk)docs/runbooks/launch-checklist.mdPhase 5 (lines 69–138);make verify-issue-391### BLOCK — do not launchlists all four P0 categories### GO with accepted risksection requires closed P0s, risk-accepted gaps, and listed residual risks### Mandatory sign-off gate; intro Mandatory gate blocks mainnet Phase 1 until Phase 5 complete; Phase 5 is last phase before RollbackQA_TEMPLATE.mdrole tableQA_TEMPLATE.md#sign-off; embeds QA Tester / Dev Lead / Product Owner tableAutomated checks
make check-launch-go-no-go-docsis also wired intomake lint.Cross-links confirmed
docs/deployment-guide.md→ Phase 5 go/no-go anchordocs/security-model.md,docs/testing.md,docs/qa-onboarding.mdreference Phase 5 / #391skills/AGENTS_LAUNCH_GO_NO_GO.mdmentioned in merge request !927
mentioned in merge request !930
mentioned in issue #410
mentioned in issue #397
mentioned in issue #337
mentioned in issue #424
mentioned in issue #398
Deploy trace — columbus-5 — 2026-07-12 UTC
Filled from
docs/templates/deploy-trace.mdfor soft-launch (non-economic). Paste onto #391.cl8ydeploy)terra1zlmv2xydxcusurtr6rl78wsvytdc6mfex6hep7da811ea6763e94162d57294d34c6dc71d68c9338brouie-review-1238-gda811ea-dirty(working tree had soft-launch script/docs fixes after store; on-chain wasm hashes match local artifacts)3.5.0-rc.0; remotenode_info.version0.38.19; sample height ~29458706https://terra-classic-rpc.publicnode.com:443/https://terra-classic-lcd.publicnode.comterra1hu4zggf3f8yw6jw3rxrjxn2drwad675gq5k2lvdeployments/mainnet-soft-launch/addresses.envContract code IDs
terra1ejpgvv7g3hj0u6fpcnxhflqp84g0w3cnaskqkg5733ygwlmf963sfchseaE268F6B8661461386FEE00F8E886E094BD73D8561D1BCAAB12DDF50352A6626EDC60D2A137141689E8195272EA825C6A4079CF5A994E673B41CD4A476D937964terra1e7s0h9ftxakwca5gxspyt4haeuaqxds6swr08ul3tsepq7el924sprrsrwE56363CC04DD29FA52325F5035840A64065DFE1CEFCBE50F2FD20224A51C17FCterra1wcczsdk7jwj99n3my6wx8wr4ee0hn6yaapgd792lgx5elrdtrn2scfnecz8D11905C70E18ED2EBACFD08A5468DA4353DCB4FD33F587AF55C435382CE5998Canonical instantiate txs (bootstrap-governance run): factory
69B1BAEF747D61900A27ED7D1DB6B786A24681F9D1AA6B2E143A047D3DAFE135, routerF5EB88CDC31B78D1DAC77B3B2D838268DC86B7654BA4C15718FBCE735825C629, fee-discount9C7C2550B03596C598053C4A3C83E7E5B400610D60263642D4720A136F0FF543.Handoff: fee-discount
update_configC9F7D3751EA2190B26A14B4DA38645B2AC141D1612A084D44C9FA1A1BCFD1BC6; factoryupdate_configD7689FA31B479937D39A2468BFE6BB1522202E19FAD4BD4137894ECFE6513640.set_discount_registry_all1695ADE7D5E5B7496708737E940BC8DA9723908DEB48C80FC720B915F65D0C1C.Soft-launch tokens + pairs
terra1dmuruhht32x8f47nvm73pwp6q7uf2jtfhdt3nxcql4mmqkyfsraqn2dt94terra1k6cqupylk0wp4pj273pntwhv9py0q5guyqye8ssvukn9xq7mes7sdlmenaterra1ejq3mjjgnklpa3pg4jterlfwsny055gpmcjf3fz0ev3ueajnzeysz6xxgrterra178fgrfzv7njtmdp9vghyf2dx77sah8u8jluzs7ym562chaxnmj2s6mn6m9terra1fga508hzx8dd7x8q4uhm6mdhkqv6fxrtsea3r27smdqmv5k2jgxq5zk9fcterra12k67cvfs7y7g8lca3qr4g4py6s6j69fu24gze5pjfamfpckv8mps7cymmeterra17dpnjlpgsnm8muu4msfjra4f2hrptnjp2jdpkka4p0e3px42ayxq0pmc2zterra18fzufz8cs7ez49xjwgs248x85za5v50yug55fj7lyxp9hapxyr7qnh3czstotal_share(verified)terra1klwuxas6x7p6fjde60kq70t0hu86wvt3fvyr2vgs0nn32fnv0q4qwznwp4100000000000terra1y5xxv980jn0qu7n7y3slhtjehta6nlpqjkgcxl80uetdx84dxa4qegjhtx10000000000terra16827w2c7zcvetck9xz8d6ds3379v77gelwra6jdafqkx9q9u0r8qvkluu014142135623terra1ra7cugjhchr45kdupxe2al5fna0zxu6syl8xhpanfk8dsvkq9lksf6fm9l7071067811terra1nqjvd2xatac5ydcs6nstw7zp2yjc20p632ycxtevtf3rr2554fqswstx0n100000000000terra1havxdjfyphjazc342r3cj2n3kslsptac2eunvw8uzayusywg9t4shtuz7v70710678118terra1p0sd0t2ggm9ye43gp0ryadx3wwkz5hzn99hnz93ve99397xvuufsvsmw737071067811terra1mp72n97rzwmqwudzycjj0e4jveetjnp622gnprv6ugqt3hfxg60sr5gkjm50000000000terra16k6huf87gzvnlgpvf85f8xfgawl6y2l5d4d5qdpyhknqaran9s5qx63c3r70710678118terra1pc7dvcucrl9sr4r2nhr2rv3ywhthskqqtvtvaerx9cff7l8gesdskjgmn6100000000000Wasm artifact hashes (
smartcontracts/artifacts/— matches on-chaindata_hash)On-chain code
data_hash(LCD/cosmwasm/wasm/v1/code/{id}): MATCH for 11505–11508.Test results (pre-deploy evidence — SEC-H08)
make test-contractscargo-audit-smartcontracts/cargo-audit-indexer;test-contracts/test-frontend/test-indexer-integrationwere skipped. Risk acceptance: soft-launch proceeds on artifact↔chain hash match + post-deploy verify.make test-indexer-integrationmake test-frontendmake test-mainnet-soft-launch-defaultsmake check-fee-discount-tier-docsOK: 11 tiers aligned(verified 2026-07-12)../scripts/smoke-pool-swap.shPost-deploy verification
qa-verify-deploy-config(2026-07-12T03:42:43Z) — RESULT: PASS (12 checks, 0 failures):smoke-pool-swap(EMBER/CORAL): pooltotal_share=100000000000; hybrid sim offer1000000→return_amount=981991,commission_amount=17999. Full output:deployments/mainnet-soft-launch/smoke-pool-swap.txt.Env/address cross-check (
qa-verify-env-addresses): Coolify frontend/indexer not pinned yet — defer untilfrontend.env.example/indexer.env.exampleare applied ondex.cl8y.com/indexer.dex.cl8y.com.Additional on-chain checks (manual)
terra1zlmv2…config.governancepair_code_id/lp_token_code_idget_pair_countcl8y_tokenterra16wtml2q66g82fdkx66tap0qjkahqwp4lwq3ngtygacg5q0kzycgqvhpax3factory[6036, 10184](SL1)get_tierscount 11)set_discount_registry+set_discount_registry_allNotes
terra1weddl9adjexzz82v2cyyh9x9mleneear0aeu55eyj22287pzsyls3c4qjz, fee-discountterra15a5s3s9wexcy6dvlrjua4quq03mm6ve7rh93ttvf4pup8rvlqyfqsc2sf2(Unauthorized onadd_tier)../scripts/resume-mainnet-soft-launch-pairs.sh.make qa-verify-deploy-configdefaults to LocalTerra RPC; for mainnet setTERRA_RPC_URL/TERRA_LCD_URLand provide factory/router/fee addresses viaindexer/.env(script does not yet honor bareFACTORY_ADDRESS=env alone).mentioned in issue #514
Deploy trace — columbus-5 — 2026-08-15 UTC (#514 / MR !1058)
cl8ydeploystore; 2-of-3 migrate)terra1zlmv2xydxcusurtr6rl78wsvytdc6mfex6hep7pair_code_idpointer)2b9290f33a1a6cc7331827f442a0ac13fa45c5b5node_info.version0.38.19; app4.0.1https://terra-classic-rpc.publicnode.com:443/https://terra-classic-lcd.publicnode.comContract code IDs
terra1ejpgvv7g3hj0u6fpcnxhflqp84g0w3cnaskqkg5733ygwlmf963sfchseapair_code_idnow 11580terra1e7s0h9ftxakwca5gxspyt4haeuaqxds6swr08ul3tsepq7el924sprrsrwterra1wcczsdk7jwj99n3my6wx8wr4ee0hn6yaapgd792lgx5elrdtrn2scfneczWasm artifact hashes (on-chain
data_hash= local sha256)Store: pair 10F0E1C1… · fee-discount 6581E6AF…
Post-deploy verification
GetTierstier 9:discount_bps9500,limit_discount_bps10000.terra12z8vz3vgnalt8trykd6nntdyp54e95yqsdtjj3GetDiscount: same; unregistered both 0.contract_info.code_id= 11580; EMBER/CORALGetFeeConfigstill 180 bps / CMM treasury.make smoke-pool-swap(EMBER/CORAL, 1e6 EMBER pool-only): OK.Full tx table + I13 notes: #514
Frontend Coolify rebuild of
dex.cl8y.comin progress (not this trace).mentioned in issue #532
mentioned in issue #584
mentioned in merge request !1108
F6 / #584 columbus-5 migrate is partial (factory 1.9.0 / code 11602; 11/14 pairs on 11601 / 1.15.0). Three pairs still 11586 / 1.14.0 after publicnode RPC resets. Full tx table + remaining addrs are on #584. Launch BLOCK remains until 14/14 smoke.
F6 / #584 columbus-5 migrate complete. Factory 1.9.0 / code 11602; all 14 pairs 1.15.0 / 11601;
pair_code_id11601 (F8F97C11…1787). Smoke 14/14 on #584. #581 / 8266 still blocked on source review.