Refresh Current State: four-axis model, hosts supersession, open security work
Corrects the '5-repo stack architecture' phrasing, which predates the four-axis repo-family model. Records that railiance-hosts is superseded by this repo with retirement pending in railiance-master, and surfaces RAIL-HO-WP-0009 with the honest status that the declarative allowlist is committed but not yet converged, so the live host still carries two stale grants. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
dffd6c561e
commit
35ddfa5f78
3 changed files with 26 additions and 3 deletions
17
SCOPE.md
17
SCOPE.md
|
|
@ -75,12 +75,23 @@ higher layer (Kubernetes, platform, etc.) can run.
|
|||
|
||||
- Status: maintained / productive
|
||||
- Implementation: HostEurope substrate baseline active for `Railiance01` and
|
||||
`CoulombCore`; server spec + test suite active; 5-repo stack architecture in
|
||||
place; first reef rollout source map now defined
|
||||
`CoulombCore`; server spec + test suite active; first reef rollout source map
|
||||
defined. Railiance is classified along four repo-family axes (`railiance-*`,
|
||||
`rail-*`, `rapp-*`, `reef-*`), of which five `railiance-*` repos cover S1–S5;
|
||||
this file previously said "5-repo stack architecture", which predates that
|
||||
model
|
||||
- Stability: high for the current single-server and transitional two-server
|
||||
substrate reality; proven in production on `92.205.62.239`
|
||||
- Usage: foundation for all Railiance deployments; canonical S1 source for
|
||||
higher-layer and future reef planning
|
||||
higher-layer and future reef planning. `railiance-hosts` is **superseded** by
|
||||
this repo and carries a banner saying so; its retirement is pending in
|
||||
`railiance-master`
|
||||
- **Open security work**: `RAIL-HO-WP-0009` — the base role declared the k3s API
|
||||
open to Anywhere while the live host was source-restricted by hand, so
|
||||
converging would have exposed the Kubernetes API. The allowlist is now
|
||||
declarative (`k3s_api_allowed_sources` / `k3s_api_revoked_sources`) but
|
||||
**has not yet been converged**, so the live host still carries two stale
|
||||
grants to rotated operator addresses
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue