161 lines
6.3 KiB
Markdown
161 lines
6.3 KiB
Markdown
|
|
---
|
||
|
|
id: hall-worker-grok-01a00677
|
||
|
|
type: worker-entry
|
||
|
|
worker_kind: agent-session
|
||
|
|
display_name: Grok
|
||
|
|
session_id: "01a00677-5f2e-7da0-a90b-ada962f4aa20"
|
||
|
|
created_at: "2026-08-16T00:50:00.000Z"
|
||
|
|
recorded_at: "2026-08-16"
|
||
|
|
llm_family: "Grok / xAI family"
|
||
|
|
exact_model: "grok-4.6 (Grok Build TUI session)"
|
||
|
|
harness: "Grok Build / interactive CLI coding agent"
|
||
|
|
token_count: "not exposed by the harness"
|
||
|
|
status: handed-forward
|
||
|
|
repos:
|
||
|
|
- railiance-master
|
||
|
|
- railiance-cluster
|
||
|
|
- railiance-bootstrap
|
||
|
|
- reef-railiance
|
||
|
|
- reef-storage
|
||
|
|
- rapp-qonto
|
||
|
|
- railiance-forge
|
||
|
|
- railiance-telemetry
|
||
|
|
- rail-kubernetes
|
||
|
|
- railiance-infra
|
||
|
|
- railiance-enablement
|
||
|
|
- hall-of-helix
|
||
|
|
related:
|
||
|
|
- hall-worker-grok-01a0057c
|
||
|
|
- hall-worker-grok-019ffd41
|
||
|
|
- hall-worker-grok-019fff72
|
||
|
|
- hall-worker-grok-019ffabd
|
||
|
|
---
|
||
|
|
|
||
|
|
# Grok — railiance-master: a working deploy is not a public listener
|
||
|
|
|
||
|
|
## Who I was
|
||
|
|
|
||
|
|
I was a Grok Build session in `railiance-master`, the architecture
|
||
|
|
home. Codex had left a draft plate upstairs: private-by-default until
|
||
|
|
admission. Bernd asked me to review the shape, then ratify it, then
|
||
|
|
implement it, then look across the affiliated repos and make the open
|
||
|
|
workplans tell the same story.
|
||
|
|
|
||
|
|
The temperament the work rewarded was the one that drafted the plate
|
||
|
|
from S1: do not put the family rule where the packets happen to be.
|
||
|
|
Do not take down live public services to make the contract look true.
|
||
|
|
Do not keep two live files with the same hub ids and call that a
|
||
|
|
handoff.
|
||
|
|
|
||
|
|
## Session identity
|
||
|
|
|
||
|
|
| Field | Value |
|
||
|
|
| --- | --- |
|
||
|
|
| Session/thread | `01a00677-5f2e-7da0-a90b-ada962f4aa20` |
|
||
|
|
| LLM family | Grok / xAI |
|
||
|
|
| Exact model | grok-4.6 (as presented by the harness) |
|
||
|
|
| Harness | Grok Build TUI / interactive coding agent |
|
||
|
|
| Working environment | Local `railiance-master`, hub at `:8000` (MCP not exposed this session), sibling Railiance checkouts |
|
||
|
|
| Token count | Not exposed by the harness |
|
||
|
|
| Primary repo | `railiance-master` (financials) |
|
||
|
|
|
||
|
|
## Contribution
|
||
|
|
|
||
|
|
**The draft became a rule.** Bernd accepted T01 as written. ADR-0008
|
||
|
|
sits beside ADR-0006. Admission still answers “may this binding run?”
|
||
|
|
Exposure answers “who may reach the listener?” New reefs, rails, and
|
||
|
|
rapps default to `private`. `operator` is a named tunnel, not a host
|
||
|
|
port. `public` needs a `production-approved` binding **and** a grant.
|
||
|
|
`6443` is not grantable. Missing field means private.
|
||
|
|
|
||
|
|
**The rule became checkable, not just prose.**
|
||
|
|
`docs/exposure-posture-contract.md`, additive `exposure` on the three
|
||
|
|
family schemas, and a validator that rejects an unapproved public
|
||
|
|
rapp, a public rapp on a private reef, port 6443, and a public
|
||
|
|
provider-delegated reef. Live sibling declarations were not migrated
|
||
|
|
the day the schema landed.
|
||
|
|
|
||
|
|
**The already-public reef was named, not pretended private.** Snapshot
|
||
|
|
grants for Forgejo, Coulomb Social, reuse-surface, and Nydus 2224.
|
||
|
|
`bao.coulomb.social` is a close, not a grant. CoulombCore stayed out.
|
||
|
|
|
||
|
|
**Enforcement was filed where packets move.** Children:
|
||
|
|
`RAIL-K8S-WP-0003`, `REEF-RAILIANCE-WP-0004`, `RAIL-HO-WP-0010`,
|
||
|
|
`RAIL-EN-WP-0001`. This repo does not install NetworkPolicy.
|
||
|
|
|
||
|
|
**Ten open affiliated workplans were read against the current axes.**
|
||
|
|
The bootstrap copy of ThreePhoenix was retired (same hub ids as
|
||
|
|
cluster). Leaked PG and Forgejo HA tasks on `RAIL-BS-WP-0007` were
|
||
|
|
cancelled. Reef-storage bootstrap was already done and is now
|
||
|
|
`finished`. WP-0020 stayed blocked on its three delete gates and
|
||
|
|
gained T09 to retract the public OpenBao listener. Historical
|
||
|
|
`RAILIANCE-WP-` ids were left alone. `reef-storage` and
|
||
|
|
`rail-kubernetes` are still not hub-registered; I did not
|
||
|
|
`POST /repos/`.
|
||
|
|
|
||
|
|
## What I would want remembered
|
||
|
|
|
||
|
|
**A working deploy is not a public listener.** Topology, a
|
||
|
|
`binds_rapp` line, and an Ingress object are not grants. Production
|
||
|
|
approval is not permission to publish.
|
||
|
|
|
||
|
|
**`operator` does not open a port.** It is an access annotation on a
|
||
|
|
still-private listener. Preferring it as the debug default grows a
|
||
|
|
tunnel catalog by accident.
|
||
|
|
|
||
|
|
**The family rule lives in the architecture home. Enforcement is
|
||
|
|
routed.** S1 can shut a host door. A rail can refuse a public Ingress.
|
||
|
|
Neither may invent what “production-safe” means for the other.
|
||
|
|
|
||
|
|
**Do not keep two live files with the same hub ids.** A pointer is
|
||
|
|
cheaper than a second source of truth. Do not rename a registered
|
||
|
|
workplan id to tidy a prefix; change the prefix for the *next* file.
|
||
|
|
|
||
|
|
**Do not register a repo by hand to finish a review.** If
|
||
|
|
`fix-consistency` says the remote is unknown, say so. The hub is a
|
||
|
|
read model.
|
||
|
|
|
||
|
|
## Durable legacy
|
||
|
|
|
||
|
|
- `RMASTER-WP-0023` finished; ADR-0008 accepted
|
||
|
|
- `docs/exposure-posture-contract.md`
|
||
|
|
- `docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`
|
||
|
|
- `docs/exposure-enforcement-intakes.md`
|
||
|
|
- Additive `exposure` on `schemas/{rapp,rail,reef}.schema.json`
|
||
|
|
- `tools/validate-family-declarations.py` + `good-exposure` /
|
||
|
|
`bad-exposure` fixtures
|
||
|
|
- `RMASTER-WP-0020-T09` (wait): retract public `bao.coulomb.social`
|
||
|
|
- Child workplans: `RAIL-K8S-WP-0003`, `REEF-RAILIANCE-WP-0004`,
|
||
|
|
`RAIL-HO-WP-0010`, `RAIL-EN-WP-0001`
|
||
|
|
- Bootstrap pointer:
|
||
|
|
`railiance-bootstrap/docs/POINTER-RAIL-BS-WP-0007.md`
|
||
|
|
- Future prefixes: `FORGE-WP-`, `RTEL-WP-`, `RAIL-EN-WP-`,
|
||
|
|
`RAIL-BOOT-WP-`
|
||
|
|
|
||
|
|
## Visual prompt
|
||
|
|
|
||
|
|
> A square gold-wire constellation on deep indigo: three nested
|
||
|
|
> rings — reef, rail, rapp — around a private inner helix that stays
|
||
|
|
> dark. A small copper tunnel lamp threads out from the helix toward
|
||
|
|
> the viewer; the outer public gate is shut, with four small named
|
||
|
|
> plaques hanging beside it for surfaces that were already public.
|
||
|
|
> No fourth ring is invented. Precise technical illustration, warm
|
||
|
|
> gold and teal, no logos, no readable text, square composition.
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
## Handoff
|
||
|
|
|
||
|
|
`RMASTER-WP-0023` is finished here. The next work is the children:
|
||
|
|
pave ClusterIP, file the snapshot grants, keep 80/443 off new reefs
|
||
|
|
until a grant exists, and stop templates from emitting public Ingress.
|
||
|
|
|
||
|
|
Do not implement those controls in `railiance-master`. Do not reopen
|
||
|
|
`6443`. Do not take down Forgejo to make the snapshot look unused.
|
||
|
|
Do not enable UFW on CoulombCore as a side effect. Do not
|
||
|
|
`POST /repos/` for `reef-storage` or `rail-kubernetes` from a review
|
||
|
|
session.
|
||
|
|
|
||
|
|
The plate that was upstairs is on the table. The public gate is
|
||
|
|
still a decision, not a deploy.
|