Historical audit-record custody (#180, #184)
The deployed old pool is now a read-only receipt archive. Active DRQ item creation, checks, allocation and destruction use the numbered system of record; no old receipt is imported into its genesis.
Keep AU_POOL_URL on the old authority with its original POOL_TOKEN. It is separate from the new residency-pool job entry and credential. Only these authenticated reads remain:
GET /audit/current?resource=…: latest completed record, with admission, authority, digest, destination and readback validation.GET /audit/status?resource=…: latest record, including an unfinished start or failure; never permission to promote.GET /audit/receipt?id=…: an immutable historical record, including admission and parent links.
The entry checks Australian ingress, authentication and execution. The actual archive object authenticates again and checks its own Australian activation before SELECT-only storage access. Missing/foreign observation refuses without opening storage. Reads create no table, observation, receipt or replacement identity. Old jobs, registry operations, schedules and audit writes refuse, including native RPC; old alarms do not dispatch or rearm.
S5 must export the old receipts and their admission/parent records outside Git, read the files back and verify content identities before proposing the exact deletion list. Deletion still needs the owner's approval. Original schema-v2 au-pool and owner-machine fields, names, times and hashes remain unchanged; historical evidence is not a current location check.
PLAN 2 cancelled the daily recheck schedule. The old location and drift runners now refuse before credential, network or filesystem access; the GitHub workflow has no schedule and the launchd example is disabled. Inventory no longer expects a daily activation or treats an old daily receipt as fresh. Dataset receipt coverage, pending-adoption expiry and quarantine admission checks remain enforced.
The producer library and its tests remain for separately reviewed producer adoption. Its start-before-fetch, completion-before-promotion and owner-machine rules are not a writable endpoint on this archive. No ABN, Address, ORIC or other production service is rebuilt by this cutover.
A completion proves the recorded admitted run and matching readback, not every current byte or hidden copy. Public datasets mixed with personal information still need Australian build provenance and use-time content verification. Trace and sampled analytics are observations, not provider attestation. See ADR-0033 for active admission and the package contract for limits.
Active address producer
ADR-0040 separately adopts the producer library for Address. The active authority runs inside the exact assigned object, reusing its activation and local assignment. Its /address-audit control route uses the active pool credential. It never sends a mutation to AU_POOL_URL.
Records remain outside Git. Every immutable release has its own current completion, so a retained fallback keeps valid lineage. Owner-machine evidence records the host, clean build commit, machine timezone and AU start/end network traces; it does not attest the physical machine city. The operator acquires source bytes only after admission, and publication completes only after full readback. New deployment checks read the active authority; runtime dataset reads verify content inside the assigned object.