Prepare the access-engine repository coordinate without applying the rename.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m16s

FLEX-WP-0020 T01-T03: fresh preflight is zero-blocker, repository-only
scope is FLEX-DEC-2026-013, concurrent work is FLEX-DEC-2026-014.
T04 handoff requests are posted; owner work-records are still required.
T06 stays behind the exact human confirm string and a post-commit preflight.

Assistant: grok
Assistant-Session: 01a0a6cb-0334-72c0-83b0-2df57474a0f6
This commit is contained in:
tegwick 2026-09-15 23:38:48 +02:00
parent 0e020b2d8c
commit dcda1e603f
5 changed files with 166 additions and 7 deletions

View file

@ -0,0 +1,47 @@
# FLEX-WP-0020-T01 — identity baseline (2026-09-15)
Private preflight file is `/tmp/flex-auth-rename-preflight-0020.json` (mode 0600).
It is not committed. Token material stays there.
| Field | Value |
| --- | --- |
| State Hub UUID | `fda8ad85-a7d7-4055-8f21-902a533e59df` |
| Forge repository ID | `42` |
| Forge full name | `coulomb/flex-auth` |
| Default branch | `main` |
| Local path | `/home/worsch/flex-auth` |
| Remote | `forgejo-remote:coulomb/flex-auth.git` |
| Clone URL | `https://forgejo.coulomb.social/coulomb/flex-auth.git` |
| Host paths | railiance01 `/home/tegwick/flex-auth`; `bnt-lap001` `/home/worsch/flex-auth` |
| Protected/current aliases | `flex-auth` (canonical) |
| Target slug | `access-engine` (Forge reports none yet; available) |
| Preflight `safe_to_apply` | `true` |
| Blockers | none |
| Queued edge writes | none |
| Warning | `active_work_present` (15 tasks / 8 workplans) |
| Report checksum (this capture) | `4b930464e0b92137902481d39cd89b1b2458a8ea88ad08c7ac0c86f2427e7c76` |
| Signing | no longer the August 29 `preflight_signing_unavailable` blocker |
Captured `HEAD` at inspection was `6fd3a0cbc400b9128132497fca69d0096259800c`.
A later commit on this workplan requires a fresh T05 preflight before
`forge-renamed`.
## Active-work disposition (FLEX-DEC-2026-014)
- `FLEX-WP-0017` and `FLEX-WP-0019` are finished (the August 29 snapshot is stale).
- `FLEX-WP-0027-T03` remains `wait` — human review, not a source-identity change.
- `FLEX-WP-0022` T01/T02 remain open; T03 is fixture-only. Coordinate rename
must not cancel them.
- `FLEX-WP-0020` itself is the cutover plan.
Working tree at inspection: branch `main`, tracking `origin/main`, clean
before this workplan's source edits.
## Proposed mutations (from preflight)
1. Forgejo `name`: `flex-auth``access-engine` (`forge-renamed`)
2. State Hub `managed_repos.slug`: `flex-auth``access-engine` (`statehub-rebound`)
3. State Hub `managed_repos.remote_url`: `forgejo-remote:coulomb/flex-auth.git``https://forgejo.coulomb.social/coulomb/access-engine.git`
4. Slug registry: `flex-auth:canonical``flex-auth:alias, access-engine:canonical`
No runtime Deployment, image, or policy-package mutation is in this list.

View file

@ -0,0 +1,49 @@
# FLEX-WP-0020-T04 — consumer inventory and handoff requests
Status: requests sent. Owner work-record IDs are not invented here.
Handoff JSON cannot be schema-valid until each owner creates a live
workplan/task; those IDs fill `handoff_id` / `owning_work_record`.
Do not mark external work done from this repository.
Shared identity for every request:
- renamed_repository_id: `fda8ad85-a7d7-4055-8f21-902a533e59df`
- old_slug: `flex-auth`
- new_slug: `access-engine`
- Forge ID stays `42`
- runtime/product names stay `flex-auth` (FLEX-DEC-2026-013)
| Owner | Surface | Required change / verification | Owner work-record |
| --- | --- | --- | --- |
| `railiance-fabric` | fabric-projection | Update `registry/local-repos.yaml`, `registry/railiance-repos.yaml`, live `fabric/**` `repo: flex-auth`; re-ingest; keep `flex-auth.*` runtime graph IDs | pending |
| `ops-warden` | credential-route | Review `registry/routing/catalog.yaml` owner repository field; routing must still resolve; no secret in the reply | pending |
| `reuse-surface` | other | Update federation source URL/path, re-ingest, verify capability continuity | pending |
| `policy-nexus` | other | Update `source-inventory.config.json` remote URL; re-ingest same publication lineage | pending |
| `user-engine` | documentation | Update `wiki/ArchitectureBlueprint.md` absolute source path; adapter/runtime vocabulary stays `flex-auth` | pending |
| `net-kingdom` | deployment | Verify three live `flex-auth-*` Deployments and `sso-mfa/k8s/**`; no runtime rename | pending |
| `tenant-engine` | consumer | Verify docs/client config keep the retained product/runtime contract | pending |
| `sbom-nexus` | sbom | Re-ingest new canonical checkout; snapshots remain related to the UUID above | pending |
| `repo-manager` | other | Reconcile new canonical path; do not rewrite archived UUID-migration evidence | pending |
| `railiance-platform`, `markitect-tool`, `gate-house`, `approval-engine`, `secrets-engine`, `zone-engine` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | pending |
| `flex-auth` + Forgejo operator | ci / package | `.forgejo/workflows/image.yaml`, charts, deploy, releases, packages, hooks, Actions, deploy keys, branch protection, redirects, clone URLs. Only repository coordinates change. Image name stays `coulomb/flex-auth`. | this plan |
Request message IDs (not owner work-records):
| Owner | Message ID |
| --- | --- |
| tenant-engine (T01 question) | `e8ba6a53-0093-4dc0-ad70-01f6b8c8e76b` |
| tenant-engine (0020 verify) | `08b3edfa-c478-45c9-9b2f-4c0fcdf471e7` |
| railiance-fabric | `10d4b1a2-8976-42a5-8d76-6fc1ce54fe87` |
| ops-warden | `0a1956c5-9fd2-4e52-837e-5bfa8e47e83d` |
| reuse-surface | `08919217-1d82-4600-a2e8-e3d9949fabab` |
| policy-nexus | `d861dc4f-11b5-4c73-a98c-8d261e65d65e` |
| user-engine | `94fd6ef0-28b5-4481-a207-2adabab93893` |
| net-kingdom | `3bc95c76-abac-4f20-95ff-a74dcc1d6fd9` |
| sbom-nexus | `08540a29-ecd4-47bc-a87c-7eecf80f166a` |
| repo-manager | `0a4b1825-99b1-4e1e-a4a0-448b0347b744` |
| railiance-platform | `b55a40cb-eb03-4972-a9bc-aac6e131a63e` |
| markitect-tool | `0dd0d6af-12fd-4b3e-af4e-1f294d615039` |
| gate-house | `231460c6-0235-4c22-9f7d-cff3959496ed` |
| approval-engine | `2523510b-79d6-4123-b550-6386dae4d464` |
| secrets-engine | `15cf351a-bad8-4259-9b6f-b21d183a20ab` |
| zone-engine | `40adbd61-0155-44f8-b6a7-621ff1629c46` |