Record CoulombCore cutover inventory
This commit is contained in:
parent
fea55461e9
commit
ae986c723a
2 changed files with 86 additions and 2 deletions
|
|
@ -63,6 +63,14 @@ Hub must be handed to their owning workload cutovers before CoulombCore host
|
|||
retirement. Local resolver caches may temporarily retain the former
|
||||
`auth.coulomb.social` address.
|
||||
|
||||
The read-only comparison is recorded in
|
||||
`docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md`. It confirms
|
||||
matching public KeyCape JWKS fingerprints and matching declared
|
||||
Authelia/LLDAP/privacyIDEA images, but independent PVCs and divergent LLDAP
|
||||
database fingerprints. CoulombCore exposes PostgreSQL logical backups but no
|
||||
matching LLDAP, Authelia, or privacyIDEA backup CronJobs; fresh protected
|
||||
source backups remain a hard gate.
|
||||
|
||||
## T02 - Prove recoverable backups before changing state
|
||||
|
||||
```task
|
||||
|
|
@ -158,8 +166,9 @@ window passes without fallback traffic or state divergence.
|
|||
|
||||
2026-07-28: authoritative/public recursive DNS now returns railiance01 for
|
||||
`auth.coulomb.social`; `login.coulomb.social` was added as an Authelia ingress
|
||||
and certificate alias. LLDAP and both privacyIDEA names remain intentionally
|
||||
on CoulombCore pending the state and conformance gates above.
|
||||
and trusted certificate alias. The complete portal → KeyCape → Authelia
|
||||
redirect reaches railiance01. LLDAP and both privacyIDEA names remain
|
||||
intentionally on CoulombCore pending the state and conformance gates above.
|
||||
|
||||
## T07 - Retire CoulombCore identity workloads reversibly
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue