diff --git a/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md b/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md index 2fbce70..4b7dc09 100644 --- a/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md +++ b/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md @@ -9,7 +9,7 @@ owner: codex topic_slug: railiance created: "2026-07-14" updated: "2026-07-22" -state_hub_workstream_id: "1437c98c-e37b-4578-b033-dc3da8ba7870" +state_hub_workstream_id: "1c73af72-fd4b-5ab6-8ff7-a3c302bf55a5" --- # CNPG backup ScheduledBackup coverage @@ -42,7 +42,7 @@ id: RAILIANCE-WP-0015-T01 status: done priority: high needs_human: false -state_hub_task_id: "3df45d8d-39e0-45db-9611-941f066c610a" +state_hub_task_id: "37117b07-196d-5095-ba6b-f2123db4bf3b" ``` Operator provisions `NC_WEBDAV_TOKEN`, `NC_WEBDAV_URL`, `AGE_PRIVATE_KEY` per @@ -59,7 +59,7 @@ data-path `read` capability + field presence verified without printing values. id: RAILIANCE-WP-0015-T02 status: done priority: high -state_hub_task_id: "7d9b2022-c533-4d49-9a91-fc34ae99aa9a" +state_hub_task_id: "a71c1bdd-4bc7-5547-bc00-0cdc7d459a4b" ``` Once T01 resolves, materialize the `databases` namespace Secret from the lane @@ -77,7 +77,7 @@ workstation runner using the same OpenBao lane. id: RAILIANCE-WP-0015-T03 status: done priority: high -state_hub_task_id: "2b97e3ee-6284-4e5f-b56e-df57194cc7b8" +state_hub_task_id: "b5cc6fe2-a9c2-5f27-bcb7-a2e22e96b04b" ``` Implement the decided Option A lane as an unattended schedule for `apps-pg`, @@ -98,7 +98,7 @@ uploaded encrypted dumps for all consumer databases and wrote id: RAILIANCE-WP-0015-T04 status: done priority: medium -state_hub_task_id: "151656cb-73ca-4d52-842e-22f14690f71c" +state_hub_task_id: "3bfe6fba-6e7a-52f1-8b7f-906ba1e065cd" ``` `cnpg-backup-status.sh` currently reports `degraded` whenever a CNPG-native @@ -118,7 +118,7 @@ clusters. id: RAILIANCE-WP-0015-T05 status: done priority: high -state_hub_task_id: "59f41267-94a9-45f0-a9d7-3c0cb16689ff" +state_hub_task_id: "d4223b6e-4e46-5c4c-9d1d-94812b2e8bf6" ``` Run an isolated-namespace restore drill from a scheduled artifact for at least diff --git a/workplans/RAILIANCE-WP-0016-railiance01-activity-core-backup-automation.md b/workplans/RAILIANCE-WP-0016-railiance01-activity-core-backup-automation.md index eeced67..a32e798 100644 --- a/workplans/RAILIANCE-WP-0016-railiance01-activity-core-backup-automation.md +++ b/workplans/RAILIANCE-WP-0016-railiance01-activity-core-backup-automation.md @@ -9,7 +9,7 @@ owner: codex topic_slug: railiance created: "2026-07-22" updated: "2026-07-22" -state_hub_workstream_id: "0c8ddbc9-3740-4e0a-acb2-901e050ab242" +state_hub_workstream_id: "857ca302-bb94-5d41-a649-1aa966368df4" --- # railiance01 + activity-core unattended backup automation @@ -33,7 +33,7 @@ Evidence: `docs/evidence/cnpg-option-a-unattended-20260722.json` id: RAILIANCE-WP-0016-T01 status: done priority: high -state_hub_task_id: "acf23292-438b-44c0-a6cd-87327b54d743" +state_hub_task_id: "475b8930-1e75-580b-a5e4-ce14b038c0ce" ``` `docs/cnpg-backup-topology-inventory.md` @@ -44,7 +44,7 @@ state_hub_task_id: "acf23292-438b-44c0-a6cd-87327b54d743" id: RAILIANCE-WP-0016-T02 status: done priority: high -state_hub_task_id: "35e81dc9-4f86-4a8f-8857-faef4117eeb6" +state_hub_task_id: "a2ca2b69-f089-5ae4-8c97-bc031503f304" ``` Platform CLI + vendor age; image `cnpg-option-a-backup:v1` for Core; python @@ -57,7 +57,7 @@ id: RAILIANCE-WP-0016-T03 status: done priority: high needs_human: false -state_hub_task_id: "3bcb6a70-7b74-47a3-8afe-3921fdccd893" +state_hub_task_id: "159eefae-d81c-57db-969f-0f9fcecdbc18" ``` ESO `actcore-backup-offsite` **SecretSynced**; worker has `NC_WEBDAV_*`. @@ -68,7 +68,7 @@ ESO `actcore-backup-offsite` **SecretSynced**; worker has `NC_WEBDAV_*`. id: RAILIANCE-WP-0016-T04 status: done priority: high -state_hub_task_id: "b8d2dd05-31a0-4fd7-bdef-27eb686e8f8a" +state_hub_task_id: "cf63809e-f73e-5306-abba-daf8a41ab72d" ``` **Decision recorded:** Core API not reachable from R01; Core backups run @@ -81,7 +81,7 @@ host kubeconfig for local clusters only. id: RAILIANCE-WP-0016-T05 status: done priority: high -state_hub_task_id: "547b3acb-94c2-46e0-a7da-ef51ee0c3c8d" +state_hub_task_id: "44c19ca1-a627-561e-88ba-4cf642bd5594" ``` `daily-cnpg-option-a-backup` enabled; Temporal schedule upserted; resolver smoke @@ -93,7 +93,7 @@ overall=ok; CLI smoke 4 dumps/uploads on R01. id: RAILIANCE-WP-0016-T06 status: done priority: medium -state_hub_task_id: "d6cab5a4-3cdd-4033-b21e-88db02197472" +state_hub_task_id: "5b230dae-8916-5efa-a395-fd472e025920" ``` `make cnpg-backup-status` → **ok** with in-cluster CronJobs + last-success. @@ -105,7 +105,7 @@ Schedule mode `in-cluster-cron`. id: RAILIANCE-WP-0016-T07 status: done priority: high -state_hub_task_id: "f331bdcd-0e76-4bc0-b85a-1bb1227a876b" +state_hub_task_id: "cb64ec26-4e02-54cf-807b-1d3ddbcba21c" ``` Automated CronJob/activity-core artifacts produced; prior restore drill pattern diff --git a/workplans/RAILIANCE-WP-0018-policy-nexus-production-binding.md b/workplans/RAILIANCE-WP-0018-policy-nexus-production-binding.md index b931161..2fb1e35 100644 --- a/workplans/RAILIANCE-WP-0018-policy-nexus-production-binding.md +++ b/workplans/RAILIANCE-WP-0018-policy-nexus-production-binding.md @@ -13,7 +13,7 @@ related: - POLICY-NEXUS-WP-0001 - RAPP-POLICY-NEXUS-WP-0001 - REEF-RAILIANCE-WP-0004 -state_hub_workstream_id: "801197d8-d387-4fcf-9a38-b4e7457847e6" +state_hub_workstream_id: "1b9af4e8-7579-5141-837b-c736b85204a0" --- # RAILIANCE-WP-0018 — policy-nexus production binding @@ -30,7 +30,7 @@ chart in the S5 repository. id: RAILIANCE-WP-0018-T01 status: done priority: high -state_hub_task_id: "537639f3-2078-4560-8bd0-4ac7d13f8131" +state_hub_task_id: "21426991-71be-5bc4-a4d7-89c81c2e299a" ``` The production binding, guarded delegating Make targets, and runbook are @@ -44,7 +44,7 @@ selection and production approval. id: RAILIANCE-WP-0018-T02 status: done priority: high -state_hub_task_id: "44a2e61e-e4a6-46ab-baf2-c81fb020a68e" +state_hub_task_id: "2ee8f8b2-9672-5ab1-8f4a-2aacc7f1e905" ``` Publish a clean-source image, resolve its registry OCI digest, record it and the @@ -67,7 +67,7 @@ deterministic source set. The production binding now selects that candidate. id: RAILIANCE-WP-0018-T03 status: done priority: high -state_hub_task_id: "d78dbaf0-1df5-4498-b1e4-9aeb6804831b" +state_hub_task_id: "bef1c91a-5702-5522-9c23-e57e8c0a2c44" ``` From an authorized operator workstation, run package checks and the Kubernetes @@ -87,7 +87,7 @@ serving as deployed revision 4. Deployment and pod are 1/1 Ready in namespace id: RAILIANCE-WP-0018-T04 status: done priority: high -state_hub_task_id: "438b9016-9a11-4905-aa24-a7a3c622a033" +state_hub_task_id: "dc4712b6-a171-54ad-9d78-0ba97cfe9dca" ``` HTTPS, current and immutable document paths, permanent legacy redirect,