railiance-infra/docs/evidence/2026-09-27-loose-ends.md
codex 9886567b40
Some checks failed
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / source-contract (push) Has been cancelled
Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
2026-09-27 18:47:55 +02:00

54 lines
2.8 KiB
Markdown

# Existing workplan closeout review — 2026-09-27
Reviewed all root and archived workplans. The only unfinished plans are
RAIL-HO-WP-0011, 0012 and 0013; all now have state `blocked`, with eight
remaining tasks in `wait`. No new task or workplan was opened. No residual task
has been marked done without its required live acceptance evidence.
## Implemented under WP-0011 T06/T08
- Rotation dry-run output exposes the exact metadata-only review plan.
- Approval binds each changed ciphertext's SHA-256 as well as recipients/path.
- Applied receipts retain the original and resulting recipient/hash evidence.
- Unrelated Make targets no longer eagerly decrypt the Hetzner token or read
and export the local age private key.
Validation: 54 Python unit tests pass, including three new rotation regression
tests. Inventory, baseline parity, read-only handoff contract, protected secret
paths, SOPS recipient metadata and whitespace checks pass. Ansible-core 2.17.13
host-time playbook syntax check passes in a disposable controller environment.
No production decryption, recipient rotation or credential retrieval occurred.
## Read-only host verification
`ansible-playbook playbooks/verify.yaml`, Ansible-core 2.17.13, reached both hosts:
| Host | Checks completed | Blocking assertion | Changes |
| --- | --- | --- | --- |
| CoulombCore | Executable and baseline stat | `/usr/local/bin/goss` absent | 0 |
| Railiance01 | Executable and baseline stat | Installed baseline digest differs from source render | 0 |
The initial sandboxed attempt failed writing Ansible's connection cache; the
rerun with that access produced the host findings above. Neither attempt is a
passing handoff. Host refresh includes installation/configuration and an hourly
timer, so the concrete rendered diff must be reviewed before that separate
mutation; subsequent baseline failures must also be resolved before T05 closes.
## Backup dependency correction
The exact S1 offsite contract remains pending:
`d150eb3e6a19d658aa76c930b32fc20ef75ffa399558fc193fbde0738551ee62`.
Warden's route reports unknown execution workload identity. Platform WP-0029's
September 15 closure resolves the old upload-share incident, but does not accept
this contract or prove S1 transfer/restore. Keep WP-0012 T05/T06 waiting for those
specific owner and recovery receipts.
## Clock dependency check
The existing railiance-clock collector produced
`2026-09-27-railiance01-clock-inventory.json`. Read-only `dpkg-query -W systemd
systemd-timesyncd` returned `255.4-1ubuntu8.17` for both. Effective source/poll
observations and configuration hashes are recorded in the receipt and WP-0013.
RCLK-WP-0002 still lacks completed policy review; no disposable Ubuntu VM is
declared here for reboot/outage/rollback testing. The already deployed authority
does not close those gates. No clocks or services were changed.