From b3884a8c2d25af89668d4895c898e0469c8b0066 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Tue, 25 Aug 2026 17:46:22 +0200 Subject: [PATCH] chore(registrar): assign State Hub identifiers Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006 --- WORK-RECORDS.md | 12 ++++++------ ...P-0011-reproducible-s1-declaration-and-handoff.md | 9 +++++++++ workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | 7 +++++++ 3 files changed, 22 insertions(+), 6 deletions(-) diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index f4526cb..a49907c 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -15,7 +15,7 @@ | workplan | RAIL-HO-WP-0009 | finished | — | workplans/RAIL-HO-WP-0009-firewall-declared-state-and-api-exposure.md | | workplan | RAIL-HO-WP-0010 | finished | — | workplans/RAIL-HO-WP-0010-new-reef-ports-need-a-grant.md | | workplan | RAIL-HO-WP-0011 | active | — | workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md | -| workplan | RAIL-HO-WP-0012 | proposed | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| workplan | RAIL-HO-WP-0012 | active | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | | task | ADHOC-2026-08-22-T01 | done | — | workplans/ADHOC-2026-08-22.md | | task | ADHOC-2026-08-22-T02 | done | — | workplans/ADHOC-2026-08-22.md | | task | ADHOC-2026-08-22-T03 | done | — | workplans/ADHOC-2026-08-22.md | @@ -50,9 +50,9 @@ | task | RAIL-HO-WP-0011-T06 | done | — | workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md | | task | RAIL-HO-WP-0011-T07 | done | — | workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md | | task | RAIL-HO-WP-0011-T08 | wait | — | workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md | -| task | RAIL-HO-WP-0012-T01 | todo | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | -| task | RAIL-HO-WP-0012-T02 | todo | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | -| task | RAIL-HO-WP-0012-T03 | todo | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | -| task | RAIL-HO-WP-0012-T04 | todo | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | -| task | RAIL-HO-WP-0012-T05 | wait | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| task | RAIL-HO-WP-0012-T01 | done | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| task | RAIL-HO-WP-0012-T02 | done | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| task | RAIL-HO-WP-0012-T03 | done | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| task | RAIL-HO-WP-0012-T04 | done | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | +| task | RAIL-HO-WP-0012-T05 | progress | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | | task | RAIL-HO-WP-0012-T06 | wait | — | workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md | diff --git a/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md b/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md index 0851e96..f83cd88 100644 --- a/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md +++ b/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md @@ -12,6 +12,7 @@ updated: "2026-08-23" related: - RAIL-HO-WP-0002 - RAIL-HO-WP-0009 +state_hub_workstream_id: "5738f113-1c4e-5d27-95b2-b6655e0b7279" --- # RAIL-HO-WP-0011 — reproducible S1 declaration and handoff @@ -41,6 +42,7 @@ independently. T07 depends on T02 and T05. T08 depends on T06. id: RAIL-HO-WP-0011-T01 status: done priority: high +state_hub_task_id: "5f89e545-ff95-5216-8369-da10e5eec727" ``` Define one explicit inventory contract for common host identity and @@ -72,6 +74,7 @@ unit coverage. id: RAIL-HO-WP-0011-T02 status: done priority: high +state_hub_task_id: "66024380-3afb-50a7-8908-02eadd96925a" ``` Update the Terraform and helper path to consume the T01 contract and exclude @@ -101,6 +104,7 @@ before init without exact approval variables; no provider mutation occurred. id: RAIL-HO-WP-0011-T03 status: done priority: high +state_hub_task_id: "fdfc7974-c491-555d-8fbd-6b2b42dd7ebb" ``` Replace the permanent `CoulombCore` expected failure with an explicit baseline @@ -130,6 +134,7 @@ assertions. No live firewall change occurred. id: RAIL-HO-WP-0011-T04 status: done priority: high +state_hub_task_id: "188321a8-d39e-5e88-9acd-986765699dbd" ``` Add repository tests that fail when the human baseline, convergence roles, and @@ -159,6 +164,7 @@ access or secret. id: RAIL-HO-WP-0011-T05 status: wait priority: high +state_hub_task_id: "ba526585-6141-5df1-9094-a1322394d8b5" ``` Provide one operator-facing, non-ambiguous command that checks inventory and @@ -192,6 +198,7 @@ no host was contacted. id: RAIL-HO-WP-0011-T06 status: done priority: high +state_hub_task_id: "040b5cdb-6e48-588d-b472-f734b99ad4b2" ``` Remove, relocate, or SOPS-encrypt the plaintext @@ -220,6 +227,7 @@ helpers, and Make consistently use `secrets/hetzner-token.yaml` field id: RAIL-HO-WP-0011-T07 status: done priority: medium +state_hub_task_id: "d296b442-83df-5bb8-abed-bbb848477a26" ``` Define a versioned receipt linking inventory and source revisions, provider @@ -247,6 +255,7 @@ verification without host evidence, and a token-shaped field. id: RAIL-HO-WP-0011-T08 status: wait priority: medium +state_hub_task_id: "920f869a-2554-58a9-b0da-8a0bbd7c5ef1" ``` Build a dry-run-first rotation workflow for the repository's SOPS files. It diff --git a/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md b/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md index cd80fea..4916dea 100644 --- a/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md +++ b/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md @@ -11,6 +11,7 @@ created: "2026-08-23" updated: "2026-08-23" related: - RAIL-HO-WP-0011 +state_hub_workstream_id: "5ea28f8f-376c-5230-8bb7-ca871c1a75f4" --- # RAIL-HO-WP-0012 — encrypted S1 backup and recovery loop @@ -49,6 +50,7 @@ tasks and an attended isolated drill. id: RAIL-HO-WP-0012-T01 status: done priority: high +state_hub_task_id: "0823a432-d43d-526f-be28-765dabc8c1ed" ``` Create a machine-readable declaration for included paths, optional paths, @@ -67,6 +69,7 @@ requires neither root nor a decryption key. id: RAIL-HO-WP-0012-T02 status: done priority: high +state_hub_task_id: "689b3c34-acd0-58dd-8705-0ed621f4d9ab" ``` Refactor the backup helper around the T01 declaration. Check privileges before @@ -90,6 +93,7 @@ tests leave no ambiguous success state. id: RAIL-HO-WP-0012-T03 status: done priority: high +state_hub_task_id: "f1c344a2-6609-5900-87ce-0744d651bead" ``` Provide a restore command that defaults to inspection or extraction beneath an @@ -111,6 +115,7 @@ and no default invocation can overwrite a host file. id: RAIL-HO-WP-0012-T04 status: done priority: medium +state_hub_task_id: "867c1959-36d0-5446-88cd-4b71727f320a" ``` Add source-controlled systemd service/timer units and Ansible deployment for a @@ -128,6 +133,7 @@ no timer is installed merely by running a verification command. id: RAIL-HO-WP-0012-T05 status: progress priority: high +state_hub_task_id: "783dff8b-849e-5ed9-a668-af1184be7bdd" ``` Coordinate with `railiance-platform` through the existing @@ -167,6 +173,7 @@ scheduled. id: RAIL-HO-WP-0012-T06 status: wait priority: high +state_hub_task_id: "2ae6feab-3aa3-58e8-a4a9-1bd70a5e30ca" ``` Select a fresh off-host artifact by metadata, retrieve it through the governed