--- id: RAIL-FAB-WP-0028 type: workplan title: "Host and operate the financial Fabric authority" domain: financials repo: railiance-fabric status: proposed owner: codex topic_slug: railiance created: "2026-08-31" updated: "2026-08-31" --- # RAIL-FAB-WP-0028 - Hosted financial Fabric authority ## Goal Turn the local registry-backed authority proven by FIN-WP-0003 and STATE-WP-0079-D2 into a durable production owner surface. State Hub can retain an immutable projection during the strangler window, but retirement must not depend on a workstation process or a workstation-owned SQLite database. Origin: residual from `STATE-WP-0079-T04` after the 2026-08-31 D2 parity and rollback rehearsal. ## T01 - Decide runtime and persistence ownership ```task id: RAIL-FAB-WP-0028-T01 status: todo priority: high ``` Select the production runtime, persistent registry store, backup/restore boundary, authentication policy, and deployment repository. Preserve accepted snapshot history and deterministic snapshot-set provenance. ## T02 - Deploy the authority service ```task id: RAIL-FAB-WP-0028-T02 status: wait priority: high ``` Package and deploy the registry service with health/readiness checks and stable owner endpoints for `/exports/financial`, `/graph/summary`, and `/graph/edges`. Do not expose mutation endpoints without the authorization selected in T01. ## T03 - Automate freshness and recovery ```task id: RAIL-FAB-WP-0028-T03 status: wait priority: high ``` Run a reviewed accepted-snapshot refresh loop, surface stale/error state, and prove backup/restore without changing the deterministic export for an unchanged accepted snapshot set. ## T04 - Cut direct consumers over ```task id: RAIL-FAB-WP-0028-T04 status: wait priority: high ``` Run the fin-hub consumer gate against the hosted owner endpoint, inventory and switch any real callers, exercise rollback, and hand the receipts back to `STATE-WP-0079-T04` before State Hub's Fabric projection routes retire.