railiance-infra/workplans
codex 3d1bd75b6b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Record two further drift findings in T03
UFW is entirely inactive on CoulombCore - no firewall on a host running ArgoCD,
the registry and databases - while the declared baseline says UFW active with
default deny. Same defect class as the k3s finding but in the opposite
direction: the declaration is stronger than reality, and equally undetected.
Not an emergency (6443 unreachable from outside, 22/443/80 the expected
surface), but converging that host would enable UFW on a frozen production
system and needs its own decision.

Full convergence of Railiance01 carries 11 changes, most unrelated to the
firewall and none ever applied, including a user-slice memory cap that could OOM
running agent workloads. The base role has no tags, so convergence cannot be
scoped - adding tags folded into this task.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 02:00:17 +02:00
..
archived chore: archive finished RAIL-HO-WP-0005 (Forgejo production migration) 2026-07-14 00:33:10 +02:00
RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md Sync RAIL-HO-WP-0006 State Hub IDs from fix-consistency 2026-07-09 12:00:52 +02:00
RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md Rename first home reef target to reef-railiance 2026-07-26 09:00:32 +02:00
RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
RAIL-HO-WP-0009-firewall-declared-state-and-api-exposure.md Record two further drift findings in T03 2026-08-12 02:00:17 +02:00