audit-core/deploy
tegwick 5b5196eea7
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
feat(AUDIT-WP-0008): admit governed E2 probe ingress
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a025c2-407a-7a32-b40a-f37a52f03f62
2026-08-22 09:37:30 +02:00
..
audit-core.yaml Close AUDIT-WP-0007 after live chain attestation. 2026-08-16 01:23:54 +02:00
clustersecretstore.yaml Read mounted DB credentials from a Kubernetes snapshot 2026-08-13 12:25:32 +02:00
externalsecret-senders.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
externalsecrets.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
migrate-job.yaml Close AUDIT-WP-0007 after live chain attestation. 2026-08-16 01:23:54 +02:00
networkpolicies.yaml feat(AUDIT-WP-0008): admit governed E2 probe ingress 2026-08-22 09:37:30 +02:00
README.md Close AUDIT-WP-0007 after live chain attestation. 2026-08-16 01:23:54 +02:00
senders-scope.json Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
senders-scope.yaml Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00

railiance01 package

Target: railiance01 only. The workstation kubeconfig that talks to that API is the k3s-api-railiance01 tunnel (local port 16444). ~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite the server port or export a copy before applying.

Apply order is documented in docs/operator-runbook.md. Do not apply the Deployment until:

  1. The image digest is pinned (currently sha256:7febc28e… from commit 5fd04e2).
  2. Secrets audit-core-database, audit-core-database-migrate, and audit-core-senders exist. ConfigMap audit-core-senders-scope is applied (deploy/senders-scope.yaml) before the Deployment mounts it.
  3. Job audit-core-migrate has completed.
make image-build
make deploy-dry-run