railiance-infra/workplans
codex 4d9e77c968
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN
open to Anywhere, tag the base role so firewall can be scoped, and
schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage
false so a converge cannot enable UFW there. T02 still needs operator
approval for make converge-firewall HOST=Railiance01.
2026-08-15 15:41:59 +02:00
..
archived chore: archive finished RAIL-HO-WP-0005 (Forgejo production migration) 2026-07-14 00:33:10 +02:00
RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md Sync RAIL-HO-WP-0006 State Hub IDs from fix-consistency 2026-07-09 12:00:52 +02:00
RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md docs: point at RMASTER-WP-0017 after master prefix rename 2026-08-14 14:29:19 +02:00
RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
RAIL-HO-WP-0009-firewall-declared-state-and-api-exposure.md Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated 2026-08-15 15:41:59 +02:00