1.1 KiB
1.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAIL-HO-WP-0010 | workplan | New reefs do not get 80/443 until a substrate grant exists | financials | railiance-infra | ready | codex | railiance | 2026-08-15 | 2026-08-15 |
|
9eed7d88-27a5-4fbe-b405-2a40aae832f3 |
RAIL-HO-WP-0010 — new-reef host ports
Intake from RMASTER-WP-0023-T05.
Goal
Host surface for new reefs: do not open 80/443 until the reef
declaration carries a public substrate grant. 6443 stays operator-only
(RAIL-HO-WP-0009). This is not the rapp admission desk. Nydus 2224
stays a named exception.
T01 — Fail-closed new-reef UFW
id: RAIL-HO-WP-0010-T01
status: todo
priority: high
state_hub_task_id: "f4cc01f8-5b5e-4693-b389-9bd81e26a799"
Bootstrap / inventory for a new reef starts with SSH (and Nydus only if the provider requires it). 80/443 require a cited reef grant. Do not add per-rapp UFW rules on a shared ingress host.
Done when: a new reef playbook cannot open 80/443 without naming the
grant, and 6443 cannot be opened by this path.