railiance-infra/.custodian-brief.md

51 lines
2.1 KiB
Markdown
Raw Normal View History

<!-- custodian-brief: generated by fix-consistency — do not edit manually -->
# Custodian Brief — railiance-infra
**Domain:** financials
**Last synced:** 2026-09-29 19:39 UTC
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
## Active Workstreams
### Declare and verify the Railiance host UTC baseline
Progress: 0/4 done | workplan_id: `788a005b-f6d4-5db9-8866-21251951fa0b`
**Open tasks:**
- ! Adopt the existing daemon and review a versioned UTC policy `9e5db140`
*(wait: Joins RCLK-WP-0002's upstream independence, leap and health review.)*
- ! Implement one declarative host role and verification entry point `75f17ffa`
*(wait: Depends on the T01 policy review.)*
- ! Prove IaC convergence, drift and recovery before live rollout `c9d142b0`
*(wait: Depends on T02.)*
- ! Apply the reviewed source and return steady-state handoff `9adae3a6`
*(wait: Depends on T03 and reviewed live-host authorization.)*
### Close the encrypted S1 backup and recovery loop
Progress: 4/6 done | workplan_id: `5ea28f8f-376c-5230-8bb7-ca871c1a75f4`
**Open tasks:**
- ! T05 — Integrate the governed write-only off-host lane `783dff8b`
*(wait: Offsite upload goes through railiance-platform's railiance-backup-offsite-lane (CCR-2026-0004); credentials must be provisioned there.)*
- ! T06 — Perform an attended isolated restore drill `2ae6feab`
*(wait: Restore drill needs a fresh off-host artifact from T05.)*
### Make the S1 declaration reproducible and the handoff verifiably green
Progress: 6/8 done | workplan_id: `5738f113-1c4e-5d27-95b2-b6655e0b7279`
**Open tasks:**
- ! T08 — Automate bounded SOPS recipient rotation `920f869a`
*(wait: Live recipient removal or credential replacement requires explicit operator approval after the dry run.)*
- · T05 — Provide a fresh green S1 handoff gate `ba526585`
## Inbox Hygiene
**Missing thread_id:** 1 unread message(s) lack supersession chains.
---
## MCP Orientation (when available)
If the state-hub MCP server is reachable, call:
`get_domain_summary("financials")`
This provides richer cross-domain context.
If the MCP call fails, use this file as your orientation source.