railiance-infra/docs/evidence/2026-09-27-loose-ends.md
codex 9886567b40
Some checks failed
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / source-contract (push) Has been cancelled
Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
2026-09-27 18:47:55 +02:00

2.8 KiB

Existing workplan closeout review — 2026-09-27

Reviewed all root and archived workplans. The only unfinished plans are RAIL-HO-WP-0011, 0012 and 0013; all now have state blocked, with eight remaining tasks in wait. No new task or workplan was opened. No residual task has been marked done without its required live acceptance evidence.

Implemented under WP-0011 T06/T08

  • Rotation dry-run output exposes the exact metadata-only review plan.
  • Approval binds each changed ciphertext's SHA-256 as well as recipients/path.
  • Applied receipts retain the original and resulting recipient/hash evidence.
  • Unrelated Make targets no longer eagerly decrypt the Hetzner token or read and export the local age private key.

Validation: 54 Python unit tests pass, including three new rotation regression tests. Inventory, baseline parity, read-only handoff contract, protected secret paths, SOPS recipient metadata and whitespace checks pass. Ansible-core 2.17.13 host-time playbook syntax check passes in a disposable controller environment. No production decryption, recipient rotation or credential retrieval occurred.

Read-only host verification

ansible-playbook playbooks/verify.yaml, Ansible-core 2.17.13, reached both hosts:

Host Checks completed Blocking assertion Changes
CoulombCore Executable and baseline stat /usr/local/bin/goss absent 0
Railiance01 Executable and baseline stat Installed baseline digest differs from source render 0

The initial sandboxed attempt failed writing Ansible's connection cache; the rerun with that access produced the host findings above. Neither attempt is a passing handoff. Host refresh includes installation/configuration and an hourly timer, so the concrete rendered diff must be reviewed before that separate mutation; subsequent baseline failures must also be resolved before T05 closes.

Backup dependency correction

The exact S1 offsite contract remains pending: d150eb3e6a19d658aa76c930b32fc20ef75ffa399558fc193fbde0738551ee62. Warden's route reports unknown execution workload identity. Platform WP-0029's September 15 closure resolves the old upload-share incident, but does not accept this contract or prove S1 transfer/restore. Keep WP-0012 T05/T06 waiting for those specific owner and recovery receipts.

Clock dependency check

The existing railiance-clock collector produced 2026-09-27-railiance01-clock-inventory.json. Read-only dpkg-query -W systemd systemd-timesyncd returned 255.4-1ubuntu8.17 for both. Effective source/poll observations and configuration hashes are recorded in the receipt and WP-0013. RCLK-WP-0002 still lacks completed policy review; no disposable Ubuntu VM is declared here for reboot/outage/rollback testing. The already deployed authority does not close those gates. No clocks or services were changed.