`ADHOC-YYYY-MM-DD` is unique per date but not per repository, so any two repos
opening an ad-hoc on the same day collide. The 2026-08-26 fleet projection
reset refused 9 records for exactly this reason.
Canon (work-record-types_v0.1, CUST-WP-0066) settled the form as
`{PREFIX}-WP-ADHOC-YYYY-MM-DD`, filename unchanged, and grandfathered existing
ids on the condition they are never *silently* re-derived. This is the explicit
migration that clause allows for.
The hub id is derived from the record id, so a changed id is a different
record: stale state_hub_*_id fields are dropped and fix-consistency re-derives.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
|
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| .githooks | ||
| ansible | ||
| capabilities/playbooks | ||
| cloudinit | ||
| contrib | ||
| docs | ||
| goss | ||
| history | ||
| hosteurope | ||
| infra/forgejo-restore-drill | ||
| inventory | ||
| keys | ||
| registry | ||
| reports | ||
| reviews | ||
| schemas | ||
| scripts | ||
| secrets | ||
| spec | ||
| state-hub-inbox | ||
| terraform/hetzner | ||
| tests | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| sbom-tools.yaml | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
railiance-infra
Tagline: Git-driven automation for secure, self-reliant servers.
railiance-infra is the canonical S1 ownership repo for the Railiance
infrastructure substrate. It manages two adopted Host Europe servers through
source-backed inventory, Ansible convergence, and recurring Goss
verification. A separate Terraform and cloud-init path provisions only
records explicitly declared as provider-managed Hetzner resources. Selected
provider material lives in-repo encrypted with SOPS/age; host convergence
does not distribute the private age key.
Future reef-* repos will model purpose-bound substrate boundaries such as
reef-railiance or reef-ops-workstations, but the source-backed S1
inventory, hardening baseline, and OS convergence facts stay here.
Quickstart
- Clone Repo: clone the repo
- Prerequisites: terraform >= 1.7, ansible >= 2.16, age, sops.
- Secrets Management: Generate master key (age), provide it to sops and provide your SSH key.
- Setup Provider: Create account, select payment option, establish API token.
- Provisioning: Validate inventory; plan/apply only provider-managed Hetzner records. Adopted Host Europe records are never Terraform resources.
- Convergence: Setup security and tooling with ansible.
🚀 0. Clone Repo
First, clone this repository to your workstation:
git clone https://<your-gitea-host>/coulomb/railiance-infra.git
cd railiance-infra
📦 1. Prerequisites
To use railiance-infra, make sure you have the following tools installed on
your workstation:
- Git → for version control
- age → for key management and encryption (Install guide)
- SOPS → for managing encrypted secrets (SOPS GitHub)
- Terraform → for provisioning infrastructure (Terraform Downloads)
- Ansible → for server configuration (Ansible Installation Guide)
- Make → to run the included
Makefiletasks
Example installation (Ubuntu/Debian)
# System tools
sudo apt update
sudo apt install -y git make ansible
# Terraform
sudo apt install -y wget unzip
wget https://releases.hashicorp.com/terraform/1.9.5/terraform_1.9.5_linux_amd64.zip
unzip terraform_1.9.5_linux_amd64.zip
sudo mv terraform /usr/local/bin/
# age
sudo apt install age
# SOPS Get the latest release (example: v3.10.2 — check GitHub for updates)
wget https://github.com/getsops/sops/releases/download/v3.10.2/sops_3.10.2_amd64.deb
sudo apt install ./sops_3.10.2_amd64.deb
🔑 2. Secrets Management
Generate Age Masterkey and establish SOPS
This project uses SOPS with age for secret encryption.
To set up your own key and configure SOPS, follow the guide here:
SSH Access Preparations
Learn how to add your SSH key and test connectivity after provisioning:
➡️ SSH Access & Connectivity Test
TL;DR
- put your public key into keys/admin_ssh.pub
💻 3. Setup Provider
You need register an account and set it up for API access:
- register
- choose payment method
- generate api-key
- store api-key in secrets safely
🚀 4. Provisioning
How to declare hosts and bring them up on Hetzner:
TL;DR
- Run
make validate-inventoryafter editinginventory/servers.yaml. - Put Hetzner-only fields under
provisioningon alifecycle_mode: provider-managedrecord. - Review
make tf-plan; an apply additionally requiresAPPROVE_TF_APPLY=YES. - One-shot helper: scripts/hcloud_new_server.sh --type ... --region ....
💻 5. Convergence
For adopted or newly provisioned servers, railiance-infra uses
Ansible to converge hosts into a secure,
baseline state.
This includes admin user setup, SSH hardening, firewall rules, essential tooling, and secret handling.
📖 See the full guide here: Convergence Documentation
Routine make verify and make s1-handoff runs are read-only on managed
hosts. Updating the installed Goss surface is deliberately separate and
requires an exact APPROVE_VERIFY_REFRESH value; see
Server Verification.