# Vergabe binding and loose-end review — 2026-09-27 Reviewed every workplan, including archived files. RAPPS-WP-0014 is the only unfinished workplan; all other task blocks are done. No ready or proposed workplan remains. No new workplan or task was created. ## Binding verification (read-only) | Check | Result | | --- | --- | | Node / cluster | Ready, 92.205.62.239; kube-system UID a553c742-0115-43d4-99a4-a5ca56fe0786 | | Helm | vergabe-demo-company / vergabe-teilnahme, deployed revision 3, chart 0.2.1 | | Deployment | Ready 1/1; image sha256:a26444f59c259698159c69ccb96f73dc648a261ece4c86bb2037a9d977870d91 | | Requests / custody reference | 60m CPU, 256Mi memory; envFrom Secret reference vergabe-demo-env | | Media / issue state | vergabe-teilnahme-media 5Gi and vergabe-teilnahme-app-state 1Gi, both Bound, local-path | | TLS / health | vergabe-demo-tls Ready; HTTPS /demo-company/health/ returned 200 | | Chart regression suite | 8 tests passed | | Helm lint | Passed with admitted values plus SSO overlay | Commands: `kubectl get nodes -o wide`, explicit namespace/deployment field queries, `kubectl -n vergabe-demo-company get deployment,pvc,certificate`, `helm list -n vergabe-demo-company -o json`, HTTPS health request, `python3 -m unittest discover -s tests -p 'test_vergabe_pilot_chart.py'`, and `helm lint charts/vergabe-teilnahme -f helm/vergabe-demo-company-values.proposed.yaml -f helm/vergabe-demo-company-sso.proposed.yaml`. The image/source/CI receipt is [the revision 3 rollout](2026-09-12-account-recovery-live.md). Database/role isolation and initial membership counts retain their dated receipts in [the binding](../vergabe-demo-company-binding.md); no current user list, database contents or Secret values were read for this review. VERGABE-WP-0019 records the September 24 founder sign-in and still waits for the fresh recipient journey and two-user acceptance. T02 can close on its release-binding scope without claiming those separate gates passed. ## Remaining recovery gate [September 25](2026-09-25-vergabe-demo-company-restore.md) proves a database restore and pod restart only. File claims were empty and the encrypted database artifact remained on the workstation. It does not prove populated media/issue state recovery, off-host delivery, restored user workflow or safe rollback. `warden route find` and `warden route show railiance-backup-offsite-lane` identify railiance-platform's OpenBao/Nextcloud lane. With the documented local OpenBao tunnel explicitly selected, `tools/check-backup-lane-auth.sh` confirmed OpenBao is unsealed but returned **no valid caller token**. Bernd Worsch's attended authentication is required for this workstation upload path; no secret was fetched. This does not establish the health of separate unattended jobs. RAPPS-WP-0014-T03 waits for the company workflow, a coherent off-host recovery point for all three stores, isolated restored workflow, rollback evidence and named support/incident ownership. The workplan is blocked. Existing product owner tasks VERGABE-WP-0019-T04/T06 retain human acceptance. No runtime mutation, substitute user login, backup upload or new recovery claim was made. The policy-nexus ArgoCD inbox proposal was read. It belongs to the existing rApp/platform onboarding plans and supplies no unfinished task in this repo; this review does not approve its live adoption or open another plan.