`ADHOC-YYYY-MM-DD` is unique per date but not per repository, so any two repos
opening an ad-hoc on the same day collide. The 2026-08-26 fleet projection
reset refused 9 records for exactly this reason.
Canon (work-record-types_v0.1, CUST-WP-0066) settled the form as
`{PREFIX}-WP-ADHOC-YYYY-MM-DD`, filename unchanged, and grandfathered existing
ids on the condition they are never *silently* re-derived. This is the explicit
migration that clause allows for.
The hub id is derived from the record id, so a changed id is a different
record: stale state_hub_*_id fields are dropped and fix-consistency re-derives.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
921 B
921 B
| id | type | title | domain | repo | status | owner | topic_slug | created | updated |
|---|---|---|---|---|---|---|---|---|---|
| RAIL-BS-RCLUSTER-WP-ADHOC-2026-07-27 | workplan | Knative fail-closed init-container support | financials | railiance-cluster | finished | codex | railiance | 2026-07-27 | 2026-07-27 |
RAIL-BS-RCLUSTER-WP-ADHOC-2026-07-27
Enable and verify Knative init containers
id: RAIL-BS-RCLUSTER-WP-ADHOC-2026-07-27-T01
status: done
priority: high
Enable only kubernetes.podspec-init-containers in Knative
config-features, persist the idempotent installer patch, and assert it in
the verifier. This supports fail-closed workload admission after asynchronous
NetworkPolicy reconciliation.
2026-07-27: Enabled the feature on railiance01 and validated a
rapp-qonto Knative Service containing a restricted init container through
the live admission webhook. A disposable same-policy pod proved
gate=passed before application=admitted.