rail-kubernetes/workplans/RAIL-K8S-WP-0003-private-by-default-networking.md
codex c6b045051f workplan: RAIL-K8S-WP-0003 private-by-default networking
Intake from RMASTER-WP-0023. ClusterIP and default-deny until a grant
exists.
2026-08-15 20:52:04 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated related
RAIL-K8S-WP-0003 workplan Private-by-default networking until an exposure grant exists financials rail-kubernetes ready codex railiance 2026-08-15 2026-08-15
RMASTER-WP-0023
ADR-0008
ADR-0006

RAIL-K8S-WP-0003 — private-by-default networking

Intake from RMASTER-WP-0023-T05. Until this rail owns live networking, railiance-cluster may implement the same controls and back-link here.

Goal

Enforce ADR-0008 on the Kubernetes rail: ClusterIP is the paved Service; default-deny NetworkPolicy; no public Ingress unless the rapp has exposure.posture: public, a grant, binding_admission: production-approved, and the reef has granted a public surface.

Do not define what production-safe means (ADR-0006). Do not open 6443.

T01 — Pave ClusterIP and default-deny

id: RAIL-K8S-WP-0003-T01
status: todo
priority: high

Templates and overlays emit ClusterIP and default-deny NetworkPolicy. Document the operator/tunnel path for debug. Missing exposure means private.

Done when: a new rapp on this rail has no public listener unless a grant exists.

T02 — Gate public Ingress on the grant

id: RAIL-K8S-WP-0003-T02
status: todo
priority: high

A public Ingress class is emitted only when the declaration carries a valid grant. An Ingress object is not itself a grant.

Done when: an ungranted rapp cannot obtain a public Ingress from the paved path.