Record CoulombCore cutover inventory
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-28 02:52:14 +02:00
parent fea55461e9
commit ae986c723a
2 changed files with 86 additions and 2 deletions

View file

@ -63,6 +63,14 @@ Hub must be handed to their owning workload cutovers before CoulombCore host
retirement. Local resolver caches may temporarily retain the former
`auth.coulomb.social` address.
The read-only comparison is recorded in
`docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md`. It confirms
matching public KeyCape JWKS fingerprints and matching declared
Authelia/LLDAP/privacyIDEA images, but independent PVCs and divergent LLDAP
database fingerprints. CoulombCore exposes PostgreSQL logical backups but no
matching LLDAP, Authelia, or privacyIDEA backup CronJobs; fresh protected
source backups remain a hard gate.
## T02 - Prove recoverable backups before changing state
```task
@ -158,8 +166,9 @@ window passes without fallback traffic or state divergence.
2026-07-28: authoritative/public recursive DNS now returns railiance01 for
`auth.coulomb.social`; `login.coulomb.social` was added as an Authelia ingress
and certificate alias. LLDAP and both privacyIDEA names remain intentionally
on CoulombCore pending the state and conformance gates above.
and trusted certificate alias. The complete portal → KeyCape → Authelia
redirect reaches railiance01. LLDAP and both privacyIDEA names remain
intentionally on CoulombCore pending the state and conformance gates above.
## T07 - Retire CoulombCore identity workloads reversibly