audit-core/deploy/README.md
tegwick 5d46723d4e
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Cut over AUDIT-WP-0006 image and add AUDIT-WP-0007.
Live receiver now reports custody_class=operational with a cited
30-day recoverable window (sha256:05fe1c06). Next workplan is
integrity verification so tamper_evidence can become honest.
2026-08-16 00:57:59 +02:00

773 B

railiance01 package

Target: railiance01 only. The workstation kubeconfig that talks to that API is the k3s-api-railiance01 tunnel (local port 16444). ~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite the server port or export a copy before applying.

Apply order is documented in docs/operator-runbook.md. Do not apply the Deployment until:

  1. The image digest is pinned (currently sha256:05fe1c06… from commit 40dcadd).
  2. Secrets audit-core-database, audit-core-database-migrate, and audit-core-senders exist. ConfigMap audit-core-senders-scope is applied (deploy/senders-scope.yaml) before the Deployment mounts it.
  3. Job audit-core-migrate has completed.
make image-build
make deploy-dry-run