railiance-enablement/docs/private-by-default-template-contract.md
tegwick 27ac54b32d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Enforce private-by-default enablement templates
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 12:34:25 +02:00

868 B

Private-by-default template contract

Railiance enablement templates produce build and promotion evidence; they do not create a public listener. ADR-0008 is enforced by the execution rail:

  • Kubernetes workload scaffolding is owned by rail-kubernetes.
  • Its default Service is ClusterIP, its generated ingress policy is default-deny, and its Stage 2 values do not enable Ingress.
  • A public Ingress requires matching rapp and reef declarations at the rail's deploy gate. An Ingress object or successful deployment is not a grant.
  • Operator access uses the named tunnel documented by the owning rail or rapp.

make check rejects enablement workflow templates that embed Ingress, LoadBalancer, NodePort, or direct Kubernetes/Helm deployment commands. This keeps reusable build workflows from becoming an accidental application or cluster deployment owner.