# Legacy application retirement — completed execution record

Prepared 2026-09-09 from the live host. This is the next Phase 3 operational cleanup,
before resuming Stage 19 matching. It is independent of the FDR accounting-authority
cutover, sealed acceptance and the current native-persistence release-parity gates.

**Status: narrowed retirement completed on 2026-09-09; postchecks passed at 12:26 UTC.**
The owner explicitly authorized execution after the reuse-protection review. Three legacy IIS
sites and pools, three legacy-only renewals, the acceptance marker task and four application
directories were removed. `GottSibylaDocumental` was disabled; its SID/profile remain.
The four removed directories contained 389 files totaling 65,060,258 bytes (about 62 MiB).

The [reuse protection register](legacy-reuse-protection-260909.md) and
`local/legacy-retirement-protection.json` supersede the earlier removal scope.
The proposed legacy-database drop is withdrawn pending data-disposition reconciliation;
shared live dependencies are explicitly protected. All four protected databases and 17 protected
paths remain. Current Web, API readiness, Docs and IdentityServer discovery returned HTTP 200;
dashboard returned its baseline 302; the current worker remains Running. All three protected
Hermes jobs remain enabled with latest recorded status `ok`; they were not invoked as probes.
Installed certificates and the enabled shared win-acme renewal task were preserved.

Execution evidence: `D:\Backups\SibylaRetirement\20260909-120359\execution-20260909-122459`
contains the action journal, cancellation receipts, post-execution IIS inventory and `postchecks.json`.
The original recovery archive and its pinned artifact index remain intact.

## Pre-execution inventory and approved disposition (executed above)

**Subsequent checkout retirement, 2026-09-09 12:45:30 UTC:** the owner separately instructed
`delete GOTT.Sibyla.Legacy` after supplementary archival. Removed exactly
`D:\fileStorage\repos\GOTT.Sibyla.Legacy` (4,606 files, 754,010,947 bytes), after rechecking
all files against the recovery manifest and verifying the base/supplementary ZIP checksums.
The source ZIPs in `legacy/` and restricted additional-files ZIP remain; see `legacy/README.md`.
All 16 remaining protected paths were present, four current endpoints returned HTTP 200 and
the current worker remained Running. Databases remain protected and were not modified.
The inventory below records the earlier application-retirement scope; its checkout-retention
wording is superseded only by this separately authorized and verified deletion.

| Component | Observed state | Proposed action |
|---|---|---|
| `Sibyla.Legacy.Web`, IIS site 6 and same-named pool | Stopped; `C:\SibylaApps\Sibyla` | Remove site/pool and archived application directory |
| `Sibyla.Legacy.Api`, IIS site 7 and same-named pool | Stopped; `C:\SibylaApps\Sibyla.Api` | Remove site/pool and archived application directory |
| `Sibyla.Legacy.Docs`, IIS site 5 and same-named pool | Started; `docs.legacy.gottsolutions.net` returns 200 | Stop and remove site/pool; keep its source under `D:\fileStorage\repos\GOTT.Sibyla.Legacy\docs` |
| `C:\SibylaApps\Sibyla.Worker` | Service already uninstalled; binaries remain | Remove archived application directory |
| `C:\SibylaApps\Sibyla.PdfTextExtractor` | Retired application helper; no current-deployment configuration reference found | Remove archived application directory |
| `Sibyla Documental Acceptance Runner` task | Enabled, demand-only, no time trigger; last result 0 | Unregister this exact task |
| `.\GottSibylaDocumental` | Enabled; no running process or service uses its SID; the task above still names it | Disable after task removal; retain the account, SID and profile |
| `gott_sibyla_legacy` | 110 public tables, 16,275,135 bytes; no other sessions at inventory time | **Retain.** The reuse audit found conflicting data-handover records; absence of sessions does not establish disposal authority. |
| Three legacy win-acme renewals | Each has exactly one legacy hostname and installs to site 5, 6 or 7 | Cancel these exact renewals; retain installed certificates and the shared renewal task |

The acceptance task's script is a 298-byte identity/timestamp marker that writes
`C:\SibylaApps\Documental-agent\evidence\scheduled-runner.log`. It is not the current
extraction acceptance suite. The old account has explicit ACLs on retained document storage,
Cegid keys and `Documental-agent`; deleting/recreating that account would lose its original SID.
Disabling it retires its login while preserving same-host recovery.

Exact renewal IDs (confirmed from their source JSON and installation SiteId):

| Hostname | Renewal ID | Site |
|---|---|---|
| `legacy.gottsolutions.net` | `dQLZoDRkQ0CqdmIXmGuBUg` | 6 |
| `api.legacy.gottsolutions.net` | `nGdBZrmvXk6FAjnpJLLk2w` | 7 |
| `docs.legacy.gottsolutions.net` | `XGzqrSw2bkOZs_WeRYT2Ww` | 5 |

## Recovery archive

Restricted archive: `D:\Backups\SibylaRetirement\20260909-120359`.
Inheritance is disabled; only SYSTEM, Administrators and the preparing Administrator have access.
Its IIS configuration and application files contain credentials and must not be committed or
attached to public reports.

Prepared using `local/Prepare-LegacyRetirement.ps1` and supplemented with live health,
account-process and tree-ACL evidence:

- Five ZIPs: 509 files, 68,637,415 uncompressed bytes. Every ZIP member was SHA-256 checked
  against its source; the source was checked again after archiving. No reparse points were present.
- PostgreSQL 18.4 custom-format dump, including database-creation metadata. `pg_restore --list`
  succeeded and the entire archive was read/decompressed to `NUL` without executing SQL.
  **A database restore rehearsal has not been performed.**
- Full IIS configuration plus isolated legacy site/pool XML, task XML and runner script,
  account SID/state, service inventory, legacy renewal definitions, file manifests and tree ACLs.
- `artifact-hashes.json` records SHA-256 values for the artifacts. Its own digest is recorded
  separately in `legacy-retirement-260909.sha256` beside this plan.

This is a same-host recovery package, not a bare-metal backup: existing machine encryption
keys, installed certificates, the shared database owner role, document storage, account profile
and Cegid key directory are deliberately retained. A rollback must restore only the retired
objects; replacing the entire live IIS configuration would overwrite unrelated current state.

## Retained components and dependency findings

- Current `Sibyla.Web`, `Sibyla.Api`, `Sibyla.Docs`, and `Sibyla.Worker.Documents`, their release
  directories and current databases remain untouched. The worker runs as `.\SibylaWorker`.
- `C:\SibylaApps` is **not** a deletion target. IdentityServer, dashboard, agents, shared
  `Documental-agent` scripts, Postiz, Buzz and all other sibling directories are retained.
- Retain `D:\fileStorage\SibylaDocuments`, `D:\SibylaData\Keys\Cegid`, Nextcloud data,
  the old account profile, source repositories/`legacy/`, historical evidence and recovery backups.
- Retain PostgreSQL itself and the shared `gott` role. No current Main or Preview migration is run.
- No current-deployment JSON/config/PowerShell/Python/YAML file under `C:\Apps\Sibyla`
  referenced the legacy database, old account or old Sibyla application paths in the targeted scan.
  This is a bounded configuration scan, not proof about every possible external client.
- The old account owns no running process and no Windows service. Its one identified scheduled
  task is explicitly included above. All shared scheduled tasks, including win-acme, remain.

Pre-execution baseline: platform `/` 200; API `/health/ready` 200; current Docs `/` 200;
IdentityServer discovery 200; dashboard `/` 302. Legacy Docs `/` still returns 200.
Older probe routes `/pt`, web `/health`, and API `/health/live` return 404 and are not valid
health gates for this release. No production configuration was changed to obtain these results.

## Approved execution sequence (completed)

1. Validate artifact hashes and recheck the exact sites, pool references, application paths,
   account dependencies, renewal hostnames/site IDs and database sessions. Confirm no deployment
   or renewal is running. If legacy source/config/data changed, refresh the recovery package first.
2. Cancel only the three named win-acme renewal IDs (`wacs.exe --cancel --id <id>`).
   Do not revoke or delete certificates, change DNS or disable the shared renewal task.
3. Stop legacy Docs, then delete only the three legacy sites and their unshared same-named pools.
4. Unregister only `\Sibyla Documental Acceptance Runner`; disable `GottSibylaDocumental`.
   Do not delete its SID, profile, retained-data ACLs or any other task/account.
5. **Do not drop `gott_sibyla_legacy`.** Reconcile data-handover decisions and preserved data before
   any future database-retirement proposal. Retain the shared owner role and its dependencies.
6. Resolve and check each of the four C-drive application directories against the literal targets
   above before deletion. Refuse reparse points or drift. Use PowerShell `Remove-Item -LiteralPath`
   on each exact directory; never delete or enumerate-to-delete the `C:\SibylaApps` parent.
7. Verify only the approved retired IIS objects, renewals, task and application directories are absent;
   verify the protected databases and reuse dependencies still exist;
   the old account is disabled; the live worker and baseline endpoints remain healthy.
   Record actual outcomes and sizes. No FDR source data or sync history is changed.

Recovery if execution needs rollback: restore the required ZIPs and their ACLs; recreate only
the archived legacy IIS objects with their original identities/bindings; restore the legacy database
from its custom dump into its original name only after checking that name is absent; restore the
task definition and re-enable the preserved account if needed. Re-register only the cancelled legacy
renewals from their saved settings. Password-bearing configuration stays inside the restricted archive.

The archive and retained historical data have no automatic deletion date. Their eventual disposal
is a separate decision from retiring executable applications and live endpoints.
