diff --git a/docs/design-decisions.md b/docs/design-decisions.md index e3f559d..52821c5 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -1610,10 +1610,16 @@ ## D-071: Routine update cadence and Juju controller patch policy -**Status:** PROPOSED 2026-07-04 (filed by the jumphost controller-update workstream; -number relinquished by the main stream per the 2026-07-03 addendum-10 contention note). -Mechanism: `runbooks/ops-update-procedure.md` (DOCFIX-086). Operator to rule on the -policy points below; the runbook is usable per-window under individual gating meanwhile. +**Status:** PARTIALLY RULED (point 1 of 4 RULED 2026-07-21; points 2-4 open). Filed +PROPOSED 2026-07-04 (by the jumphost controller-update workstream; number relinquished by +the main stream per the 2026-07-03 addendum-10 contention note). Mechanism: +`runbooks/ops-update-procedure.md` (DOCFIX-086); usable per-window under individual gating +meanwhile. Point 1 RULED 2026-07-21 (GA-R5): question as presented = "adopt the proposed +cadence trigger (monthly review window; security pulls forward)?"; operator selection, exact +utterance: "Adopt as proposed (Recommended)". Cadence = monthly review of `can-upgrade-to` + +controller patch delta; non-empty review opens a maintenance window run via +ops-update-procedure; security-driven charm revisions may pull a window forward; no +on-discovery updates. **Problem:** the cloud accumulates available updates on two layers with no standing policy for either: (a) the Juju controller/agents (patch releases on the 3.6 track;