Change records
Production Change Record
1. Validate script syntax: `bash -n runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh`.
Change Metadata
- Change id: CR-2026-04-21-graph-v1-kong-route-rollout
- Date and time (UTC): 2026-04-21 00:54-00:57
- Requester: owner
- Approver (owner): owner
- Executor: GitHub Copilot agent (owner-approved execution)
- Environment: VPS production
- Related ticket or incident id: gateway-graph-v1-extension
Scope
- Services or stacks affected:
runtime/stacks/infrastructure/gateway(Kong bootstrap routes/plugins), gateway docs and validation artifacts - Expected impact: additive graph route coverage on Kong (
/graph/docs,/graph/v1/*) with no removal of existing graph compatibility routes - User-facing risk window: low after apply; fallback routes remain available
Risk Assessment
- Risk level: medium
- Main failure modes:
- route-priority conflict with
graph-protected - incorrect rewrite target for graph v1
- accidental JWT gate on docs route
- route-priority conflict with
- Data integrity impact if failed: none expected (routing/auth layer only)
Preconditions
- Owner approval captured.
- Backup or rollback checkpoint confirmed.
- Validation plan prepared.
- Communication plan prepared.
Execution Plan
- Validate script syntax:
bash -n runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh. - Load live gateway env and apply bootstrap script in approved window.
- Verify Kong route/plugin inventory for
graph-docs-publicandgraph-v1-protected. - Run route and CORS smoke checks from validation artifact.
- Record evidence and update completion status in state docs.
Rollback Plan
- Remove
graph-docs-publicandgraph-v1-protectedroutes from Kong Admin API if regression appears. - Remove associated per-route plugins (
request-transformer,rate-limiting,jwt) for those routes. - Re-run known-good bootstrap baseline from repository and re-validate prior graph route set.
Validation Results
- Route validation:
GET /graph/docs-> HTTP 500 (public route reached, not JWT-gated)GET /graph/v1/healthwithout JWT -> HTTP 401 (expected deny)GET /graph/v1/healthwith valid JWT -> HTTP 500 (JWT allow-path reached upstream)
- Health validation: Kong bootstrap apply completed successfully (
Kong Ocelot migration applied successfully.) - Auth and access validation:
graph-v1-protectedroute hasjwt,request-transformer, andrate-limitinggraph-docs-publicroute hasrequest-transformerandrate-limiting
- Log and alert review: no gateway apply errors observed during command execution
Evidence References
- Validation runbook:
docs/operations/validations/2026-04-21-graph-v1-kong-access-validation.mdx - Mapping update:
runtime/stacks/infrastructure/gateway/ocelot-to-kong-mapping.md - Bootstrap source:
runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh - Declarative state source:
runtime/stacks/infrastructure/gateway/kong.yml
Outcome
- Result: success
- Start time (UTC): 2026-04-21T00:54:00Z
- End time (UTC): 2026-04-21T00:57:00Z
- Follow-up actions: investigate upstream graph application responses returning HTTP 500 for
/docsand/api/v1/healthprobes (routing/auth path is functioning) - Owner sign-off: pending