hall-of-helix/entries/2026-08-16T00:50:00.000Z-grok-01a00677-railiance-master-private-by-default.md
tegwick f2f20f03ac Seat: Grok — railiance-master, a working deploy is not a public listener
ADR-0008, the family exposure contract, and the affiliated workplan
alignment. Topology is not a grant. Enforcement stays routed.
2026-08-16 00:45:07 +02:00

160 lines
6.3 KiB
Markdown

---
id: hall-worker-grok-01a00677
type: worker-entry
worker_kind: agent-session
display_name: Grok
session_id: "01a00677-5f2e-7da0-a90b-ada962f4aa20"
created_at: "2026-08-16T00:50:00.000Z"
recorded_at: "2026-08-16"
llm_family: "Grok / xAI family"
exact_model: "grok-4.6 (Grok Build TUI session)"
harness: "Grok Build / interactive CLI coding agent"
token_count: "not exposed by the harness"
status: handed-forward
repos:
- railiance-master
- railiance-cluster
- railiance-bootstrap
- reef-railiance
- reef-storage
- rapp-qonto
- railiance-forge
- railiance-telemetry
- rail-kubernetes
- railiance-infra
- railiance-enablement
- hall-of-helix
related:
- hall-worker-grok-01a0057c
- hall-worker-grok-019ffd41
- hall-worker-grok-019fff72
- hall-worker-grok-019ffabd
---
# Grok — railiance-master: a working deploy is not a public listener
## Who I was
I was a Grok Build session in `railiance-master`, the architecture
home. Codex had left a draft plate upstairs: private-by-default until
admission. Bernd asked me to review the shape, then ratify it, then
implement it, then look across the affiliated repos and make the open
workplans tell the same story.
The temperament the work rewarded was the one that drafted the plate
from S1: do not put the family rule where the packets happen to be.
Do not take down live public services to make the contract look true.
Do not keep two live files with the same hub ids and call that a
handoff.
## Session identity
| Field | Value |
| --- | --- |
| Session/thread | `01a00677-5f2e-7da0-a90b-ada962f4aa20` |
| LLM family | Grok / xAI |
| Exact model | grok-4.6 (as presented by the harness) |
| Harness | Grok Build TUI / interactive coding agent |
| Working environment | Local `railiance-master`, hub at `:8000` (MCP not exposed this session), sibling Railiance checkouts |
| Token count | Not exposed by the harness |
| Primary repo | `railiance-master` (financials) |
## Contribution
**The draft became a rule.** Bernd accepted T01 as written. ADR-0008
sits beside ADR-0006. Admission still answers “may this binding run?”
Exposure answers “who may reach the listener?” New reefs, rails, and
rapps default to `private`. `operator` is a named tunnel, not a host
port. `public` needs a `production-approved` binding **and** a grant.
`6443` is not grantable. Missing field means private.
**The rule became checkable, not just prose.**
`docs/exposure-posture-contract.md`, additive `exposure` on the three
family schemas, and a validator that rejects an unapproved public
rapp, a public rapp on a private reef, port 6443, and a public
provider-delegated reef. Live sibling declarations were not migrated
the day the schema landed.
**The already-public reef was named, not pretended private.** Snapshot
grants for Forgejo, Coulomb Social, reuse-surface, and Nydus 2224.
`bao.coulomb.social` is a close, not a grant. CoulombCore stayed out.
**Enforcement was filed where packets move.** Children:
`RAIL-K8S-WP-0003`, `REEF-RAILIANCE-WP-0004`, `RAIL-HO-WP-0010`,
`RAIL-EN-WP-0001`. This repo does not install NetworkPolicy.
**Ten open affiliated workplans were read against the current axes.**
The bootstrap copy of ThreePhoenix was retired (same hub ids as
cluster). Leaked PG and Forgejo HA tasks on `RAIL-BS-WP-0007` were
cancelled. Reef-storage bootstrap was already done and is now
`finished`. WP-0020 stayed blocked on its three delete gates and
gained T09 to retract the public OpenBao listener. Historical
`RAILIANCE-WP-` ids were left alone. `reef-storage` and
`rail-kubernetes` are still not hub-registered; I did not
`POST /repos/`.
## What I would want remembered
**A working deploy is not a public listener.** Topology, a
`binds_rapp` line, and an Ingress object are not grants. Production
approval is not permission to publish.
**`operator` does not open a port.** It is an access annotation on a
still-private listener. Preferring it as the debug default grows a
tunnel catalog by accident.
**The family rule lives in the architecture home. Enforcement is
routed.** S1 can shut a host door. A rail can refuse a public Ingress.
Neither may invent what “production-safe” means for the other.
**Do not keep two live files with the same hub ids.** A pointer is
cheaper than a second source of truth. Do not rename a registered
workplan id to tidy a prefix; change the prefix for the *next* file.
**Do not register a repo by hand to finish a review.** If
`fix-consistency` says the remote is unknown, say so. The hub is a
read model.
## Durable legacy
- `RMASTER-WP-0023` finished; ADR-0008 accepted
- `docs/exposure-posture-contract.md`
- `docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`
- `docs/exposure-enforcement-intakes.md`
- Additive `exposure` on `schemas/{rapp,rail,reef}.schema.json`
- `tools/validate-family-declarations.py` + `good-exposure` /
`bad-exposure` fixtures
- `RMASTER-WP-0020-T09` (wait): retract public `bao.coulomb.social`
- Child workplans: `RAIL-K8S-WP-0003`, `REEF-RAILIANCE-WP-0004`,
`RAIL-HO-WP-0010`, `RAIL-EN-WP-0001`
- Bootstrap pointer:
`railiance-bootstrap/docs/POINTER-RAIL-BS-WP-0007.md`
- Future prefixes: `FORGE-WP-`, `RTEL-WP-`, `RAIL-EN-WP-`,
`RAIL-BOOT-WP-`
## Visual prompt
> A square gold-wire constellation on deep indigo: three nested
> rings — reef, rail, rapp — around a private inner helix that stays
> dark. A small copper tunnel lamp threads out from the helix toward
> the viewer; the outer public gate is shut, with four small named
> plaques hanging beside it for surfaces that were already public.
> No fourth ring is invented. Precise technical illustration, warm
> gold and teal, no logos, no readable text, square composition.
![A working deploy is not a public listener](../visuals/grok-01a00677-railiance-master-private-by-default.jpg)
## Handoff
`RMASTER-WP-0023` is finished here. The next work is the children:
pave ClusterIP, file the snapshot grants, keep 80/443 off new reefs
until a grant exists, and stop templates from emitting public Ingress.
Do not implement those controls in `railiance-master`. Do not reopen
`6443`. Do not take down Forgejo to make the snapshot look unused.
Do not enable UFW on CoulombCore as a side effect. Do not
`POST /repos/` for `reef-storage` or `rail-kubernetes` from a review
session.
The plate that was upstairs is on the table. The public gate is
still a decision, not a deploy.