--- id: RAIL-KNATIVE-WP-0002 type: workplan title: "Declare the Knative substrate CPU requests set live on railiance01" domain: financials repo: rail-knative status: finished owner: codex topic_slug: railiance created: "2026-09-21" updated: "2026-09-27" depends_on: [] state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32" --- # RAIL-KNATIVE-WP-0002 - Declare the Knative substrate CPU requests On 2026-09-21 the CPU requests of the Serving and Kourier v1.22.0 install on railiance01 were lowered live (`ADMINISTER @ realm:kubernetes/railiance01`, activation=APPROVED by the founder). Limits are unchanged. Record: `the-custodian/docs/kubernetes-change-gate-decision.md`. Runbook: `docs/substrate-runbook.md`. ## T01 - Declare the requests over the pinned v1.22.0 assets ```task id: RAIL-KNATIVE-WP-0002-T01 status: done priority: high state_hub_task_id: "006d4578-8b64-5f52-a778-96dee5580274" ``` 2026-09-21: Added `substrate/v1.22.0/cpu-requests.patch.yaml` and a kustomization over the staged `core.yaml` and `kourier.yaml`, with offline tests. Rendered against the checksum-verified upstream assets (hashes from `railiance-cluster/install/knative/release-lock.env`): the six Deployments carry exactly the declared CPU requests, with upstream memory and limits. ## T02 - Verify the declaration against live, read-only ```task id: RAIL-KNATIVE-WP-0002-T02 status: done priority: high state_hub_task_id: "d712ad71-df8b-5606-b90c-a78b765a4129" ``` 2026-09-21: `kubectl get deploy -o jsonpath` over `ssh railiance01` read activator 50m, autoscaler 30m, controller 30m, webhook 30m, net-kourier-controller 30m, 3scale-kourier-gateway 50m; limits 1 (webhook 500m), matching upstream. The namespace version label is 1.22.0. HPAs: activator 2%/100%, webhook 10%/100%, gateway 10%/100%. Declared equals live. ## T03 - Make the railiance-cluster installer apply the declaration ```task id: RAIL-KNATIVE-WP-0002-T03 status: done priority: high state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da" ``` 2026-09-27: Closed after checking railiance-cluster commit `3a5432270e275e978d6c8a99529fa7f8be6eef57` and its completed [RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md). The owner repository's [installer](../../railiance-cluster/install/knative/install.sh) applies checksum-verified assets rendered through Serving and Kourier overlays carrying all six declared CPU requests. Its [verifier](../../railiance-cluster/install/knative/verify.sh) asserts those requests. The [render tests](../../railiance-cluster/tests/test_knative_render.py) compare the overlays with this repository's declaration and check that memory requests and limits remain upstream's. The owner workplan records read-only live diff evidence from 2026-09-21: no Deployment changes remain. Re-running the installer is unnecessary for this closure and was not performed. An apply can still reset runtime-managed webhook rules before Knative fills them in again; it is not a blanket no-op. Cluster-scoped installation remains owned by railiance-cluster. Closure validation, 2026-09-27: `python3 -m pytest -q -p no:cacheprovider tests /home/worsch/railiance-cluster/tests/test_knative_render.py` passed all nine tests, including rendering checksum-verified upstream assets (no skips). `python3 /home/worsch/rail-kubernetes/tools/validate_contracts.py --rail declarations/rail.yaml` also passed. No open tasks remain in this repository's two workplans; no new tasks or workplans were created.