diff --git a/README.md b/README.md index ae8a32d..0d1e450 100644 --- a/README.md +++ b/README.md @@ -6,5 +6,9 @@ This rail inherits the versioned `rail-kubernetes` common workload contract and owns only Knative-specific activation, scale-to-zero, revision, traffic, cold-start, and rollback semantics. -The repo is currently at `declared` readiness. It does not claim that Knative -is installed or production-approved on any reef. +The [declaration](declarations/rail.yaml) records `verified` readiness, backed by +the [2026-07-26 lifecycle evidence](../reef-railiance/evidence/verification/rail-knative-v1.22.0-2026-07-26.json) +on reef-railiance. This is not production approval. + +The [substrate runbook](docs/substrate-runbook.md) describes the declared CPU +requests consumed by the railiance-cluster installer. diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 001fa66..1ba7632 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -9,11 +9,11 @@ | Kind | ID | Status | Lane | Source | | --- | --- | --- | --- | --- | | workplan | RAIL-KNATIVE-WP-0001 | finished | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | -| workplan | RAIL-KNATIVE-WP-0002 | active | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | +| workplan | RAIL-KNATIVE-WP-0002 | finished | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | task | RAIL-KNATIVE-WP-0001-T01 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T02 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T03 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T04 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0002-T01 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | task | RAIL-KNATIVE-WP-0002-T02 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | -| task | RAIL-KNATIVE-WP-0002-T03 | wait | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | +| task | RAIL-KNATIVE-WP-0002-T03 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | diff --git a/docs/substrate-runbook.md b/docs/substrate-runbook.md index 82609e8..a3eb8ee 100644 --- a/docs/substrate-runbook.md +++ b/docs/substrate-runbook.md @@ -22,10 +22,16 @@ upstream's. These values were set live on 2026-09-21 as because the node had 100% of its allocatable CPU requested and backups could not be scheduled. Record: `the-custodian/docs/kubernetes-change-gate-decision.md`. -A plain re-apply or upgrade of the upstream manifests restores the upstream -column. Every apply or upgrade must apply these patches afterwards, and an -upgrade to a new version needs a new `substrate//` with container -names re-checked against that release. +The owner installer now renders these requests into the manifests before apply, +using separate Serving and Kourier overlays. Its verifier checks all six values. +Implementation and read-only live diff evidence are recorded in +[RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md), +implemented by railiance-cluster commit `3a5432270e275e978d6c8a99529fa7f8be6eef57`. + +A plain re-apply of unpatched upstream manifests restores the upstream column. +Every apply or upgrade must preserve these patches, and an upgrade to a new +version needs a new `substrate//` with container names re-checked +against that release. ## Lessons diff --git a/workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md b/workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md index 053148a..f2b8495 100644 --- a/workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md +++ b/workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md @@ -4,11 +4,11 @@ type: workplan title: "Declare the Knative substrate CPU requests set live on railiance01" domain: financials repo: rail-knative -status: active +status: finished owner: codex topic_slug: railiance created: "2026-09-21" -updated: "2026-09-21" +updated: "2026-09-27" depends_on: [] state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32" --- @@ -55,19 +55,31 @@ activator 2%/100%, webhook 10%/100%, gateway 10%/100%. Declared equals live. ```task id: RAIL-KNATIVE-WP-0002-T03 -status: wait +status: done priority: high state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da" ``` -Waits on railiance-cluster, which owns the install (`install/knative/`). -rail-knative does not edit that repository. The installer must apply -`substrate/v1.22.0/cpu-requests.patch.yaml` after each upstream apply, for -example by building the kustomization over its staged files, or by running -`kubectl patch deployment -n --type strategic --patch-file ` -per document; `verify.sh` should assert the six requests. +2026-09-27: Closed after checking railiance-cluster commit +`3a5432270e275e978d6c8a99529fa7f8be6eef57` and its completed +[RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md). +The owner repository's [installer](../../railiance-cluster/install/knative/install.sh) +applies checksum-verified assets rendered through Serving and Kourier overlays +carrying all six declared CPU requests. Its +[verifier](../../railiance-cluster/install/knative/verify.sh) asserts those requests. +The [render tests](../../railiance-cluster/tests/test_knative_render.py) compare +the overlays with this repository's declaration and check that memory requests +and limits remain upstream's. -Because the values are already live, re-running the patched installer changes -no running state. Running the *unpatched* installer before this lands reverts -the requests and should not be done. Rollback of the installer change is a -revert of its commit; the live values need no rollback. +The owner workplan records read-only live diff evidence from 2026-09-21: +no Deployment changes remain. Re-running the installer is unnecessary for +this closure and was not performed. An apply can still reset runtime-managed +webhook rules before Knative fills them in again; it is not a blanket no-op. +Cluster-scoped installation remains owned by railiance-cluster. + +Closure validation, 2026-09-27: `python3 -m pytest -q -p no:cacheprovider tests +/home/worsch/railiance-cluster/tests/test_knative_render.py` passed all nine +tests, including rendering checksum-verified upstream assets (no skips). +`python3 /home/worsch/rail-kubernetes/tools/validate_contracts.py --rail +declarations/rail.yaml` also passed. No open tasks remain in this repository's +two workplans; no new tasks or workplans were created.