Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN
open to Anywhere, tag the base role so firewall can be scoped, and
schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage
false so a converge cannot enable UFW there. T02 still needs operator
approval for make converge-firewall HOST=Railiance01.
This commit is contained in:
codex 2026-08-15 15:41:59 +02:00
parent 434121be99
commit 4d9e77c968
29 changed files with 793 additions and 99 deletions

View file

@ -0,0 +1,10 @@
[Unit]
Description=Railiance declared-vs-live Goss baseline
Documentation=file:///etc/goss/baseline.yaml
[Service]
Type=oneshot
ExecStart=/usr/local/sbin/goss-baseline-check
Nice=10
# The wrapper records TAP even when assertions fail.
SuccessExitStatus=0 1

View file

@ -0,0 +1,12 @@
[Unit]
Description=Hourly Railiance Goss baseline (RAIL-HO-WP-0009-T05)
[Timer]
OnBootSec=5min
OnUnitActiveSec=1h
RandomizedDelaySec=5min
Persistent=true
Unit=railiance-goss-baseline.service
[Install]
WantedBy=timers.target