rail-knative/workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md
tegwick cd38dba365 Close Knative CPU request handoff with installer evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e396-d089-7653-b0a1-734cac532913
2026-09-27 18:01:25 +02:00

85 lines
3.4 KiB
Markdown

---
id: RAIL-KNATIVE-WP-0002
type: workplan
title: "Declare the Knative substrate CPU requests set live on railiance01"
domain: financials
repo: rail-knative
status: finished
owner: codex
topic_slug: railiance
created: "2026-09-21"
updated: "2026-09-27"
depends_on: []
state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32"
---
# RAIL-KNATIVE-WP-0002 - Declare the Knative substrate CPU requests
On 2026-09-21 the CPU requests of the Serving and Kourier v1.22.0 install on
railiance01 were lowered live (`ADMINISTER @ realm:kubernetes/railiance01`,
activation=APPROVED by the founder). Limits are unchanged. Record:
`the-custodian/docs/kubernetes-change-gate-decision.md`. Runbook:
`docs/substrate-runbook.md`.
## T01 - Declare the requests over the pinned v1.22.0 assets
```task
id: RAIL-KNATIVE-WP-0002-T01
status: done
priority: high
state_hub_task_id: "006d4578-8b64-5f52-a778-96dee5580274"
```
2026-09-21: Added `substrate/v1.22.0/cpu-requests.patch.yaml` and a
kustomization over the staged `core.yaml` and `kourier.yaml`, with offline
tests. Rendered against the checksum-verified upstream assets (hashes from
`railiance-cluster/install/knative/release-lock.env`): the six Deployments
carry exactly the declared CPU requests, with upstream memory and limits.
## T02 - Verify the declaration against live, read-only
```task
id: RAIL-KNATIVE-WP-0002-T02
status: done
priority: high
state_hub_task_id: "d712ad71-df8b-5606-b90c-a78b765a4129"
```
2026-09-21: `kubectl get deploy -o jsonpath` over `ssh railiance01` read
activator 50m, autoscaler 30m, controller 30m, webhook 30m,
net-kourier-controller 30m, 3scale-kourier-gateway 50m; limits 1 (webhook
500m), matching upstream. The namespace version label is 1.22.0. HPAs:
activator 2%/100%, webhook 10%/100%, gateway 10%/100%. Declared equals live.
## T03 - Make the railiance-cluster installer apply the declaration
```task
id: RAIL-KNATIVE-WP-0002-T03
status: done
priority: high
state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da"
```
2026-09-27: Closed after checking railiance-cluster commit
`3a5432270e275e978d6c8a99529fa7f8be6eef57` and its completed
[RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md).
The owner repository's [installer](../../railiance-cluster/install/knative/install.sh)
applies checksum-verified assets rendered through Serving and Kourier overlays
carrying all six declared CPU requests. Its
[verifier](../../railiance-cluster/install/knative/verify.sh) asserts those requests.
The [render tests](../../railiance-cluster/tests/test_knative_render.py) compare
the overlays with this repository's declaration and check that memory requests
and limits remain upstream's.
The owner workplan records read-only live diff evidence from 2026-09-21:
no Deployment changes remain. Re-running the installer is unnecessary for
this closure and was not performed. An apply can still reset runtime-managed
webhook rules before Knative fills them in again; it is not a blanket no-op.
Cluster-scoped installation remains owned by railiance-cluster.
Closure validation, 2026-09-27: `python3 -m pytest -q -p no:cacheprovider tests
/home/worsch/railiance-cluster/tests/test_knative_render.py` passed all nine
tests, including rendering checksum-verified upstream assets (no skips).
`python3 /home/worsch/rail-kubernetes/tools/validate_contracts.py --rail
declarations/rail.yaml` also passed. No open tasks remain in this repository's
two workplans; no new tasks or workplans were created.