From d5772d2a1aabd19fd85955f94b99a912c8c28f55 Mon Sep 17 00:00:00 2001 From: tegwick Date: Wed, 22 Jul 2026 17:53:35 +0200 Subject: [PATCH] RAILIANCE-WP-0015: activate workplan; close T01 offsite credentials MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CCR-2026-0004 / railiance-backup-offsite-lane is resolvable; mark T01 done and move T02–T04 into progress for Option A schedule implementation. --- ...15-cnpg-backup-scheduledbackup-coverage.md | 53 +++++++++---------- 1 file changed, 24 insertions(+), 29 deletions(-) diff --git a/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md b/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md index 0381f43..d811592 100644 --- a/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md +++ b/workplans/RAILIANCE-WP-0015-cnpg-backup-scheduledbackup-coverage.md @@ -4,11 +4,11 @@ type: workplan title: "CNPG backup ScheduledBackup coverage — drive cnpg-backup-status to healthy" domain: financials repo: railiance-apps -status: ready +status: active owner: codex topic_slug: railiance created: "2026-07-14" -updated: "2026-07-14" +updated: "2026-07-22" state_hub_workstream_id: "1437c98c-e37b-4578-b033-dc3da8ba7870" --- @@ -23,38 +23,27 @@ residual **DB-backup operational hardening**, not a migration blocker. Drive `make cnpg-backup-status` (railiance-apps) from **degraded → healthy**: scheduled, unattended, encrypted, off-cluster backups with a passing restore drill for all four production CNPG clusters — `apps-pg`, `gitea-db`, -`net-kingdom-pg`, `state-hub-db`. +`net-kingdom-pg`, `state-hub-db` (CoulombCore `databases` namespace). -## Current state (2026-07-14) +## Current state (2026-07-22) -- `cnpg-backup-status`: **degraded — 4 clusters lack ScheduledBackup coverage** - (all show `backup spec = null`, `ScheduledBackup = none`; clusters otherwise - healthy, 1 instance each). -- Decided approach (RAIL-HO-WP-0005 Key Decision 5, Option A, 2026-07-09): - daily **age-encrypted `pg_dump`/`forgejo dump` → Nextcloud WebDAV**, 14 daily + - 4 weekly retention, RPO 24h / RTO 4h. A one-off encrypted `forgejo-db` dump was - produced + restore-drilled (RAILIANCE-WP-0013, finished 2026-07-11). -- Tooling already present: `tools/cnpg-backup-status.sh`, `manifests/cnpg-backup-readiness.yaml` - (commented template), `make apps-pg-backup-dry-run`, `platform forgejo-backup`, - `docs/app-data-backup-restore-handoff.md`. - -## Blocking gate (human / operator) - -The offsite credential lane **`CCR-2026-0004`** (railiance-backup-offsite-lane) -is `status: active`, `decision: approved`, but **`resolvable: false`** -(`readiness: applied-pending-verify`). No backup Secret exists in the `databases` -namespace. Provisioning `NC_WEBDAV_TOKEN` / `NC_WEBDAV_URL` / `AGE_PRIVATE_KEY` -into OpenBao (making `warden access railiance-backup-offsite-lane --fetch …` -resolve) is an **operator/OpenBao action** — out of scope for agent credential -handling per credential-routing. Everything downstream is gated on it. +- T01 (CCR-2026-0004 offsite credentials) is **done**: catalog + `railiance-backup-offsite-lane` is `resolvable: true` / `readiness: ready`; + OpenBao path holds `NC_WEBDAV_TOKEN`, `NC_WEBDAV_URL`, `AGE_PRIVATE_KEY`; + OIDC role `railiance-backup-workload-kv-read` grants `read` on the data path + (verified 2026-07-22, capabilities-safe / key inventory only). +- `cnpg-backup-status` still reports degraded under the old barman + `ScheduledBackup` definition; Option A logical-dump schedules are the target. +- Phase 1 evidence for `apps-pg`/`vergabe_db` exists (RAILIANCE-WP-0013); this + workplan generalizes to all four clusters with unattended coverage. ## Task: Provision CCR-2026-0004 offsite credentials (operator) ```task id: RAILIANCE-WP-0015-T01 -status: wait +status: done priority: high -needs_human: true +needs_human: false state_hub_task_id: "3df45d8d-39e0-45db-9611-941f066c610a" ``` @@ -63,11 +52,17 @@ Operator provisions `NC_WEBDAV_TOKEN`, `NC_WEBDAV_URL`, `AGE_PRIVATE_KEY` per `warden access railiance-backup-offsite-lane --fetch NC_WEBDAV_TOKEN` succeeds and the CCR flips to `resolvable: true`. +**Closed 2026-07-22:** CCR `resolvable: true`, `readiness: ready`; OIDC login + +data-path `read` capability + field presence verified without printing values. +Note: OIDC token cannot `auth/token/create` (403 expected); verify with +`bao token capabilities` on the current token and/or key inventory, not child +token minting. + ## Task: Create offsite backup Secret in databases namespace ```task id: RAILIANCE-WP-0015-T02 -status: wait +status: progress priority: high state_hub_task_id: "7d9b2022-c533-4d49-9a91-fc34ae99aa9a" ``` @@ -80,7 +75,7 @@ Secret exists and `pg_dump`/WebDAV upload authenticates. ```task id: RAILIANCE-WP-0015-T03 -status: wait +status: progress priority: high state_hub_task_id: "2b97e3ee-6284-4e5f-b56e-df57194cc7b8" ``` @@ -96,7 +91,7 @@ artifacts without manual intervention. ```task id: RAILIANCE-WP-0015-T04 -status: wait +status: progress priority: medium state_hub_task_id: "151656cb-73ca-4d52-842e-22f14690f71c" ```