Fix rotation review evidence and reconcile blocked S1 workplans
Some checks failed
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / source-contract (push) Has been cancelled

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
This commit is contained in:
codex 2026-09-27 18:47:55 +02:00
parent 41f25fe42d
commit 9886567b40
10 changed files with 255 additions and 18 deletions

View file

@ -4,12 +4,12 @@ type: workplan
title: "Make the S1 declaration reproducible and the handoff verifiably green"
domain: financials
repo: railiance-infra
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-08-23"
updated: "2026-09-27"
related:
- RAIL-HO-WP-0002
- RAIL-HO-WP-0009
@ -313,3 +313,27 @@ Current evidence (2026-08-23):
- Forgejo Actions run 79 is green for revision `4f2312a` across all three jobs.
- Pending before finish: an attended fresh all-host handoff receipt and an
attended non-printing SOPS decryption receipt.
## Closeout review — 2026-09-27
T08 source gaps repaired: the default metadata-only output now includes exact
file paths, ciphertext hashes and before/after recipient sets; approval binds
the ciphertext hash; applied receipts preserve the reviewed original recipients
and hash alongside the resulting hash. Three regression tests cover these cases.
Unrelated Make targets no longer decrypt the provider token or read/export the
private age key during Makefile evaluation. No credential was rotated.
T05 remains `wait`: a read-only Ansible 2.17.13 run reached both hosts with
`changed=0`. CoulombCore lacks `/usr/local/bin/goss`; Railiance01's installed
baseline checksum differs from the source-rendered profile. The next step is a
reviewed Goss refresh for each host, followed by remediation of any actual
baseline failures and a clean-revision all-host handoff. A failed surface check
is not green host evidence. See `docs/evidence/2026-09-27-loose-ends.md`.
T08 remains `wait`: source tests and metadata checks pass, but this workstation
has no SOPS executable or approved decryption session for the repository's
recipient. The existing attended non-printing decryption receipt is still
required; mock tests do not substitute for it. The host having SOPS installed
does not establish approved recovery-key custody.
Workplan is `blocked` until those live verification prerequisites are met.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Close the encrypted S1 backup and recovery loop"
domain: financials
repo: railiance-infra
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-08-23"
updated: "2026-09-27"
related:
- RAIL-HO-WP-0011
state_hub_workstream_id: "5ea28f8f-376c-5230-8bb7-ca871c1a75f4"
@ -132,7 +132,7 @@ no timer is installed merely by running a verification command.
```task
id: RAIL-HO-WP-0012-T05
status: progress
status: wait
priority: high
state_hub_task_id: "783dff8b-849e-5ed9-a668-af1184be7bdd"
```
@ -216,3 +216,21 @@ decrypted configuration.
- T05 is source-prepared and pending owner acceptance; T06 remains `wait`. No
off-host write, retained-artifact deletion, private-key access, or live-host
restore occurred.
## Closeout review — 2026-09-27
T05 is `wait`, not ongoing implementation. The exact S1 acceptance file remains
`pending`; no owner decision accepts this envelope/projection. Route lookup still
reports unknown workload identity. Source upload/collision/redirect/retention
and isolated fixture recovery tests pass, but no approved live S1 transfer or
owner retrieval receipt exists. T06 consequently remains `wait` for that copy
and attended recovery-key custody and isolated restore.
The older upload-credential incident is no longer a blocker: platform
`RPF-WP-0029` closed on 2026-09-15 with predecessor-share invalidation attestation
and replacement transport/application recovery evidence. That evidence concerns
the platform's archive, not this S1 bundle, and does not accept the S1 contract.
Historical recovery-key exposure remains separately recorded by the owner.
Workplan is `blocked` on exact owner acceptance, controlled S1 transfer and an
attended S1 restore drill. No new task or workplan was created.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Declare and verify the Railiance host UTC baseline"
domain: financials
repo: railiance-infra
status: active
status: blocked
flavor: planning
owner: codex
topic_slug: railiance
created: "2026-09-14"
updated: "2026-09-15"
updated: "2026-09-27"
related_workplans:
- RCLK-WP-0005
- RCLK-WP-0002
@ -33,7 +33,7 @@ and tools/observe_host_clock.py. No configuration or clock change was made.
```task
id: RAIL-HO-WP-0013-T01
status: todo
status: wait
priority: high
state_hub_task_id: "9e5db140-0642-58de-8a9c-1c5a3cfd7b6e"
```
@ -49,7 +49,7 @@ Define what source health can honestly claim before exposing it to the clock app
```task
id: RAIL-HO-WP-0013-T02
status: progress
status: wait
priority: high
state_hub_task_id: "75f17ffa-b781-549d-82ce-d19d431c2618"
```
@ -81,7 +81,7 @@ A mocked systemctl result or container-only check is not host synchronization pr
```task
id: RAIL-HO-WP-0013-T04
status: progress
status: wait
priority: high
state_hub_task_id: "9adae3a6-8ee6-538b-9bb3-1ee32ed185e1"
```
@ -111,3 +111,30 @@ railiance-platform docs/evidence/2026-09-15-railiance-clock-production.json.
Health collection needs read-only adjtimex; ProtectClock is disabled only on
that exporter, while both services retain empty capability sets. Disposable
outage/reboot/rollback rehearsals remain tracked in T03.
## Closeout review — 2026-09-27
All four residual tasks are `wait`; deployed source alone does not meet their
acceptance criteria. T01 is blocked on RCLK-WP-0002 source/leap/error-model
acceptance; that owner's T01–T03 are still in progress and T04 is todo. T02 has
an implemented opt-in role and passes native Ansible syntax checking, but still
requires T01's reviewed policy and baseline/Goss health integration. T03 requires
an admitted disposable Ubuntu VM for convergence/no-op, drift, reboot,
source-outage/recovery and rollback evidence. No such test target is declared in
this repository. T04's prior live deployment evidence stands, but its required
T03 recovery evidence and steady-state handoff remain outstanding.
Refreshed read-only inventory:
`docs/evidence/2026-09-27-railiance01-clock-inventory.json`, collected with the
existing railiance-clock collector. Installed systemd and systemd-timesyncd:
`255.4-1ubuntu8.17`. Effective system/fallback source: `ntp.ubuntu.com`;
per-link and runtime source lists empty. Poll bounds 32–64 seconds, root-distance
threshold 500ms, observed leap 0. UTC, timesyncd active, synchronization reported,
no UDP/123 listener and no observed competing daemon. These are diagnostics,
not independent accuracy or source-independence proof. Configuration hashes are
in the receipt; no host configuration was changed.
The September 14 duplicate-workplan inbox warning is historical: the current
checkout has one WP-0013 file and already contains consolidation commit
`c402245`. Preserve its existing task UUIDs. Workplan is `blocked` on the
remaining review and native recovery prerequisites.