Consolidate concurrent host UTC plans into original residual record

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbc-910e-77a0-b336-3130194350b3
This commit is contained in:
tegwick 2026-09-14 12:29:56 +02:00
parent ea7577ece2
commit 6a95cc37bc
2 changed files with 40 additions and 88 deletions

View file

@ -1,88 +0,0 @@
---
id: RAIL-HO-WP-0013
type: workplan
title: "Declare and verify the Railiance host UTC baseline"
domain: financials
repo: railiance-infra
status: ready
owner: codex
topic_slug: railiance
created: "2026-09-14"
updated: "2026-09-14"
related_workplans:
- RCLK-WP-0005
- RCLK-WP-0002
- RAIL-HO-WP-0011
---
Owner work record for RCLK-WP-0005-T01/T02. Canonical S1 ownership is already
settled by railiance-master ADR-0004 and docs/reef-first-wave-source-map.md.
Do not create a competing time baseline in railiance-hosts or bootstrap.
Read-only railiance01 observation on 2026-09-14: Ubuntu 24.04.4 LTS/KVM,
systemd-timesyncd active/enabled, UTC, synchronized flag yes, distro fallback
ntp.ubuntu.com, no local drop-in, no UDP/123 listener in the observed namespace.
The inspected sample reported offset -634us, root distance 3.432ms and normal
leap state. This is operational metadata, not an independent UTC error proof.
Receipt and repeatable collector: railiance-clock/docs/evidence/2026-09-14-railiance01-clock-inventory.json
and tools/observe_host_clock.py. No configuration or clock change was made.
## Adopt the existing daemon and review a versioned UTC policy
```task
id: RAIL-HO-WP-0013-T01
status: todo
priority: high
```
Retain systemd-timesyncd as the baseline candidate; do not install chrony/ntpd
as a second daemon. Join RCLK-WP-0002's upstream independence, leap convention,
health/error/holdover and consumer-bound review. Specify inventory opt-in, exact
server/fallback list, boot/poll policy, health export and rollback. The current
single-provider distro fallback is evidence, not a reviewed independent source set.
Define what source health can honestly claim before exposing it to the clock app.
## Implement one declarative host role and verification entry point
```task
id: RAIL-HO-WP-0013-T02
status: wait
priority: high
```
Depends on T01 policy review. Add opt-in Ansible role under ansible/roles/ and a
narrow playbook that manages only the reviewed time-service drop-in and service
state. Integrate bootstrap.yaml through the same role, not copied tasks. Guard
against other active time daemons and unsupported host platforms. Add health
verification to the owner baseline/Goss handoff with explicit unusable states.
No CAP_SYS_TIME or clock write operation for the application time service; that
capability belongs only to the admitted host daemon. No public UDP/123 ingress.
## Prove IaC convergence, drift and recovery before live rollout
```task
id: RAIL-HO-WP-0013-T03
status: wait
priority: high
```
Depends on T02. Lint/render and disposable VM convergence; second apply must be
no-op. Detect intentional disposable drift, verify reboot persistence and source
outage/recovery, and prove source-based rollback. Measure health reporting limits.
Record exact source revision/target/config checksum and no unrelated changes.
A mocked systemctl result or container-only check is not host synchronization proof.
## Apply the reviewed source and return steady-state handoff
```task
id: RAIL-HO-WP-0013-T04
status: wait
priority: high
```
Depends on T03 and normal reviewed live-host authorization. Produce the exact
railiance01 diff and clock-step/credential-consumer impact plan, then use owner
IaC to apply/read back. Reverify usable host health and no extra listener/daemon;
record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and
railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure.
No corporate workstation time settings or app-clock trust adoption in this plan.

View file

@ -32,3 +32,43 @@ priority: medium
Version systemd-timesyncd (not chrony) in railiance-infra: enabled unit,
NTP/FallbackNTP, restricted listeners, health export. Lint/render only until
RCLK-WP-0002 and RCLK-WP-0005-T02 authorize live apply. No second daemon.
Canonical S1 ownership: railiance-master ADR-0004 and
`docs/reef-first-wave-source-map.md`. Repeatable read-only evidence lives in
railiance-clock at `docs/evidence/2026-09-14-railiance01-clock-inventory.json`
and `tools/observe_host_clock.py`. The synchronized flag does not establish an
independent UTC error bound. Current distro fallback is observed, not an approved
independent source set. Review upstream/leap/holdover policy with RCLK-WP-0002.
Use an opt-in Ansible role and narrow playbook; bootstrap calls that same role.
Guard against competing daemons and unsupported hosts. Export explicit unusable
health states; the application must never acquire clock-write privileges.
## Prove IaC convergence, drift and recovery before live rollout
```task
id: RAIL-HO-WP-0013-T02
status: wait
priority: high
```
Depends on T01. Lint/render and disposable VM convergence; second apply must be
no-op. Detect intentional disposable drift, verify reboot persistence and source
outage/recovery, and prove source-based rollback. Measure health reporting limits.
Record exact source revision/target/config checksum and no unrelated changes.
A mocked systemctl result or container-only check is not host synchronization proof.
## Apply the reviewed source and return steady-state handoff
```task
id: RAIL-HO-WP-0013-T03
status: wait
priority: high
```
Depends on T02 and normal reviewed live-host authorization. Produce the exact
railiance01 diff and clock-step/credential-consumer impact plan, then use owner
IaC to apply/read back. Reverify usable host health and no extra listener/daemon;
record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and
railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure.
No corporate workstation time settings or app-clock trust adoption in this plan.