railiance-apps/docs
tegwick c5546ac729
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
feat(informed-decision): claim decisions.coulomb.social as the approver origin
INFD-WP-0001-T07 has been blocked since 2026-09-08 on an OIDC redirect URI it
cannot publish without a real deployed origin, which in turn blocks key-cape's
KEY-WP-0013-T02. The operator assigned decisions.coulomb.social; DNS already
resolves to the cluster address.

Adds the Ingress + letsencrypt-prod certificate for the host and a placeholder
nginx backend, so the origin answers before the approver UI itself exists
(INFD-WP-0001-T08 is still gated on approval-engine and on intake INFD-IN-0003).
A redirect URI matches byte-exactly at /authorize, so a host that resolves but
does not complete a TLS handshake fails closed at first login and presents as a
rejected approval rather than a registration defect.

The Ingress carries one path rule on purpose: reuse-surface reported on
2026-07-07 that an Exact rule alongside a catch-all Prefix rule on the same host
was swallowed by the catch-all. That trap is worth avoiding on a host whose
entire purpose is exact-match redirect handling.

Dry-run clean against the live API; deliberately not applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EJbh7o7UWF4tQ5jxygnNGu

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2072522@bnt-lap001
Assistant-Session: 46173adf-7302-4ede-99d6-963b61359928
2026-09-10 16:17:48 +02:00
..
evidence RAILIANCE-WP-0016: finish unattended hybrid Option A backups 2026-07-22 20:34:24 +02:00
app-data-backup-restore-handoff.md RAILIANCE-WP-0015: use workstation cron; suspend in-cluster CronJobs 2026-07-22 18:06:06 +02:00
cnpg-backup-topology-inventory.md RAILIANCE-WP-0016: promote active; inventory and activity-core cutover prep 2026-07-22 19:50:59 +02:00
core-hub-on-railiance01.md WP-0013/0014: warden credential routing, CoulombCore kubeconfig, apps-pg backup dry-run 2026-07-10 15:46:02 +02:00
coulomb-social.md Point coulomb-social Helm and ingress at app.coulomb.social 2026-08-09 23:20:31 +02:00
credential-routing-railiance-apps.md RAILIANCE-WP-0015: Option A CNPG logical backup coverage healthy 2026-07-22 18:00:48 +02:00
django-on-railiance.md Implement app deployment improvements 2026-05-22 22:25:40 +02:00
forge-source-of-truth-decision.md Decommission forge compatibility pointers 2026-06-05 17:33:52 +02:00
forgejo-on-railiance01.md Add Forgejo T05 verify, operator bootstrap, and security hardening 2026-07-07 22:09:53 +02:00
forgejo-package-registry.md docs: mark weekly Forgejo package prune as enabled 2026-07-21 19:20:42 +02:00
informed-decision-origin.md feat(informed-decision): claim decisions.coulomb.social as the approver origin 2026-09-10 16:17:48 +02:00
inter-hub-on-railiance01.md Migrate OCI image refs from Gitea to Forgejo registry 2026-07-09 11:38:14 +02:00
manifest-server-dry-run.md Close S5 app readiness workplan 2026-06-05 17:59:35 +02:00
operator-recipes.md Close S5 app readiness workplan 2026-06-05 17:59:35 +02:00
operator-setup.md Handle app deployment guardrail suggestions 2026-06-15 22:07:03 +02:00
policy-nexus-production.md Close policy nexus production rollout 2026-08-18 15:18:44 +02:00
reuse-surface-on-railiance01.md Migrate OCI image refs from Gitea to Forgejo registry 2026-07-09 11:38:14 +02:00
s5-app-onboarding-checklist.md Add reuse service landing page 2026-06-15 15:40:57 +02:00
vergabe-teilnahme.md docs(backup): close RAILIANCE-WP-0013 S5 Phase 1 gate 2026-07-12 11:29:05 +02:00