railiance-infra/workplans/RAIL-HO-WP-0013-host-time-baseline.md
codex 0d6cc3ec3b
All checks were successful
CI Smoke / source-contract (push) Successful in 16s
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 6s
Add opt-in Railiance host time and private authority automation
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-15 21:59:29 +02:00

4.2 KiB

id type title domain repo status flavor owner topic_slug created updated related_workplans state_hub_workstream_id
RAIL-HO-WP-0013 workplan Declare and verify the Railiance host UTC baseline financials railiance-infra active planning codex railiance 2026-09-14 2026-09-14
RCLK-WP-0005
RCLK-WP-0002
RAIL-HO-WP-0011
788a005b-f6d4-5db9-8866-21251951fa0b

Owner work record for RCLK-WP-0005-T01/T02. Canonical S1 ownership is already settled by railiance-master ADR-0004 and docs/reef-first-wave-source-map.md. Do not create a competing time baseline in railiance-hosts or bootstrap.

Read-only railiance01 observation on 2026-09-14: Ubuntu 24.04.4 LTS/KVM, systemd-timesyncd active/enabled, UTC, synchronized flag yes, distro fallback ntp.ubuntu.com, no local drop-in, no UDP/123 listener in the observed namespace. The inspected sample reported offset -634us, root distance 3.432ms and normal leap state. This is operational metadata, not an independent UTC error proof. Receipt and repeatable collector: railiance-clock/docs/evidence/2026-09-14-railiance01-clock-inventory.json and tools/observe_host_clock.py. No configuration or clock change was made.

Adopt the existing daemon and review a versioned UTC policy

id: RAIL-HO-WP-0013-T01
status: todo
priority: high
state_hub_task_id: "9e5db140-0642-58de-8a9c-1c5a3cfd7b6e"

Retain systemd-timesyncd as the baseline candidate; do not install chrony/ntpd as a second daemon. Join RCLK-WP-0002's upstream independence, leap convention, health/error/holdover and consumer-bound review. Specify inventory opt-in, exact server/fallback list, boot/poll policy, health export and rollback. The current single-provider distro fallback is evidence, not a reviewed independent source set. Define what source health can honestly claim before exposing it to the clock app.

Implement one declarative host role and verification entry point

id: RAIL-HO-WP-0013-T02
status: progress
priority: high
state_hub_task_id: "75f17ffa-b781-549d-82ce-d19d431c2618"

Depends on T01 policy review. Add opt-in Ansible role under ansible/roles/ and a narrow playbook that manages only the reviewed time-service drop-in and service state. Integrate bootstrap.yaml through the same role, not copied tasks. Guard against other active time daemons and unsupported host platforms. Add health verification to the owner baseline/Goss handoff with explicit unusable states. No CAP_SYS_TIME or clock write operation for the application time service; that capability belongs only to the admitted host daemon. No public UDP/123 ingress.

Prove IaC convergence, drift and recovery before live rollout

id: RAIL-HO-WP-0013-T03
status: wait
priority: high
state_hub_task_id: "c9d142b0-9c8d-5abf-82d9-099a772da5ec"

Depends on T02. Lint/render and disposable VM convergence; second apply must be no-op. Detect intentional disposable drift, verify reboot persistence and source outage/recovery, and prove source-based rollback. Measure health reporting limits. Record exact source revision/target/config checksum and no unrelated changes. A mocked systemctl result or container-only check is not host synchronization proof.

Apply the reviewed source and return steady-state handoff

id: RAIL-HO-WP-0013-T04
status: wait
priority: high
state_hub_task_id: "9adae3a6-8ee6-538b-9bb3-1ee32ed185e1"

Depends on T03 and normal reviewed live-host authorization. Produce the exact railiance01 diff and clock-step/credential-consumer impact plan, then use owner IaC to apply/read back. Reverify usable host health and no extra listener/daemon; record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure. No corporate workstation time settings or app-clock trust adoption in this plan.

2026-09-15: operator requested implementation and consumer use. Added opt-in railiance_clock owner role and host-time playbook; bootstrap invokes the same role. Authority activation requires artifact hash, admission reference and explicit signing-key delivery. Defaults change no clocks and deploy no service. Native convergence, custody and measured UTC policy acceptance remain open.