The preflight token is deliberately not stored in this workplan. Generate a
fresh private mode-0600 preflight file immediately before execution.
Local `HEAD`, `origin/main`, and the Forge snapshot all matched the captured
source commit. The State Hub Forge identity was verified through the supported
API at `2026-08-29T15:46:39Z`; it was not inferred from Git or a redirect.
## Preflight risk register
Every blocker, warning, and external handoff from the captured snapshot is
retained here. T05 must reconcile every row; unknown ownership is a blocker.
| Severity | Code | Captured detail |
| --- | --- | --- |
| blocker | `preflight_signing_unavailable` | `{"code":"preflight_signing_unavailable","message":"Repository rename preflight signing is not configured"}` |
| external-handoff | `fabric-graph-projections` | `Owning repository must be recorded during inventory` |
| external-handoff | `interface-change-consumers` | `Owning repository must be recorded during inventory` |
| warning | `active_work_present` | `{"code":"active_work_present","message":"Active work must be quiesced or explicitly coordinated during cutover","task_count":8,"workplan_count":7}` |
The signing blocker is owned jointly by `state-hub` (runtime contract) and
`railiance-platform` (OpenBao-backed secret delivery). No generated or live
preflight can authorize mutation until that owner-controlled path is present.
## Active-work coordination snapshot
- workplan `flex-wp-0001` / `4dbefd19-bb7d-405c-9a50-e7dbd11cf4d9` is `done`
- workplan `flex-wp-0002` / `aa60e183-9a87-4e03-99b0-15786bfa11ae` is `completed`
- workplan `flex-wp-0003` / `c0a6c9f6-bb6b-416d-b537-f30504c63d75` is `completed`
- workplan `flex-wp-0004` / `99a82976-d376-42b0-89cc-c44e01c0bec6` is `completed`
- workplan `flex-wp-0005` / `e37d42a9-0018-4a67-a672-ff4e9716b338` is `done`
- workplan `flex-wp-0017` / `d75b7256-8b3d-5797-911c-96c3199b8baa` is `active`
- workplan `flex-wp-0019` / `84b9dc5a-71f2-5c70-ace6-78242b13d0f1` is `ready`
- task `7a980074-8488-5ab1-9202-60878adb261d` / `7a980074-8488-5ab1-9202-60878adb261d` is `todo`
- task `FLEX-WP-0017-T03` / `82d39961-8140-5a7f-9bd8-5164dd1742e5` is `wait`
- task `FLEX-WP-0017-T05` / `8c3fc0a2-0855-5ac9-afa5-d03b8b1f0bf9` is `wait`
- task `9d9c0e7a-56e2-5c71-9110-cea973243c22` / `9d9c0e7a-56e2-5c71-9110-cea973243c22` is `todo`
- task `bc109ee3-14b0-5603-a655-0d7376c2a41c` / `bc109ee3-14b0-5603-a655-0d7376c2a41c` is `todo`
- task `d5917b24-2efb-503e-9a9d-837702cafc1c` / `d5917b24-2efb-503e-9a9d-837702cafc1c` is `todo`
- task `f72b1305-114e-5ba2-b84c-f6cc0b524178` / `f72b1305-114e-5ba2-b84c-f6cc0b524178` is `todo`
- task `f7f501d7-6862-5542-88f7-78b704524706` / `f7f501d7-6862-5542-88f7-78b704524706` is `todo`
Only `FLEX-WP-0017` is active and `FLEX-WP-0019` is ready. The preflight also
returned five historical workplans whose terminal `done`/`completed` status is
not concurrent work. T05 must take a fresh snapshot and explicitly coordinate
the two live workplans; it must not silently cancel or rewrite them.
## External ownership ledger
| Effect | Owning repository | What this plan may claim |
| --- | --- | --- |
| State Hub identity and aliases | `state-hub` | Record operation phase/evidence only; State Hub owns the mutation. |
| Preflight signing delivery | `railiance-platform` + `state-hub` | Require a non-secret provisioning receipt and zero-blocker preflight; never store the signing value here. |
| Forge-derived fabric projection | `railiance-fabric` | Record a handoff ID; only that repository closes its source change. |
| Credential-route catalog | `ops-warden` | Record route-review handoff; never request or store a secret here. |
| SBOM projection | `sbom-nexus` | Record re-ingestion evidence; SBOM Nexus owns its projection. |
| Repository CI and Forge-owned settings | `flex-auth` + Forgejo operator | Verify Actions, hooks, deploy keys, releases, redirects, and clone coordinates; keep package `coulomb/flex-auth`. |
| NetKingdom deployment sources and three live workloads | `net-kingdom` | Verify `sso-mfa/k8s/**` and all live `flex-auth-*` workloads remain healthy and intentionally retain runtime names/images. |
| Federation source URL and local roster | `reuse-surface` | Update `registry/federation/**`, re-ingest, and return owner evidence. |
| Forge repository name, canonical clone/web/raw URLs, local checkout, and current repository metadata | Rename to `access-engine` in the phased sequence. |
| Workplan/task prefix and all State Hub UUID fields | Retain `FLEX-WP-` and every existing UUID. |
| Go module/import path `github.com/netkingdom/flex-auth`, binary/CLI, and `FLEX_AUTH_*` variables | Retain. |
| Container package `forgejo.coulomb.social/coulomb/flex-auth`, immutable digests, and current CI `IMAGE_NAME` | Retain and verify publication after the repository rename. |
| Policy/API vocabulary, audiences, dashboards, alerts, and telemetry service labels | Retain. |
| Broader product rename | Defer to a separately reviewed workplan after soak; not authorized here. |
Any change to a `retain` row expands the blast radius and returns this plan to
`proposed` until the affected owner workplans, compatibility window, and
rollback limits are reviewed.
Gate: every item has a decision record and independently deployable changes
have their own workplan or residual handoff.
## 4. Inventory consumers and create owned handoffs
authorization and NetKingdom policy consumers, fabric sources, SBOM scans,
docs, badges, webhooks, mirrors, caches, dashboards, alerts, and local clones.
- Start from the concrete owners and paths below. For each required source
change, create a live residual/intake/workplan in that owner before T05.
- Record each external work-record ID here and attach a
`state-hub.repository-rename-handoff.v1` payload following
`state-hub/docs/schemas/repository-rename-handoff-v1.schema.json`. It names
the source repository, old/new slug, affected paths or graph IDs, required
re-ingest and verification, owning workplan/task, and non-secret evidence.
- Do not mark that external work done from this repository; completion evidence
must come from its owner.
- Include every row in the preflight risk register, even when it is only a
warning or currently zero-count projection.
Gate: every discovered external change has one named owning repository and
durable handoff ID; unknown ownership blocks the live rename.
Reviewed inventory baseline:
| Owner | Required source/verification surface |
| --- | --- |
| `railiance-fabric` | `registry/local-repos.yaml`, `registry/railiance-repos.yaml`, and live `fabric/**` declarations with `repo: flex-auth`; re-ingest repository/path graph nodes while retaining `flex-auth.*` runtime graph IDs. Historical discovery snapshots are evidence and are not rewritten. |
| `ops-warden` | `registry/routing/catalog.yaml` owner repository field; verify credential routing still resolves without exposing or rotating a credential. |
| `reuse-surface` | `registry/federation/sources.yaml`, `registry/federation/local-repo-roster.yaml`, and generated `registry/indexes/federated.yaml`; update raw URL/path, re-ingest, verify capability continuity. |
| `policy-nexus` | `source-inventory.config.json` remote URL; re-ingest and verify the same publication lineage. |
| `user-engine` | `wiki/ArchitectureBlueprint.md` absolute source path; separately verify its adapter and environment vocabulary remains `flex-auth`. |
| `net-kingdom` | Three ready live Deployments (`flex-auth-ops-warden`, `flex-auth-tenant-engine`, `flex-auth-user-engine`) and `sso-mfa/k8s/**`; no runtime rename, image-coordinate change, or rollout is authorized. |
| `tenant-engine` | Verify documentation and client configuration continue to use the retained product/runtime contract; no repository-coordinate source was found in the reviewed live paths. |
| `sbom-nexus` | Re-ingest the new canonical checkout and prove historical/current snapshots remain related to State Hub UUID `fda8ad85-a7d7-4055-8f21-902a533e59df`. |
| `repo-manager` | Reconcile the new canonical path and preserve file-backed identifiers; do not rewrite archived UUID-migration evidence. |
| `railiance-platform`, `markitect-tool`, `gate-house`, `approval-engine`, `secrets-engine`, `zone-engine` | Named verification owners for semantic consumers found in the estate scan; confirm no live repository URL/path remains and retain product/runtime terminology. |