Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
140 lines
6.5 KiB
Markdown
140 lines
6.5 KiB
Markdown
---
|
||
id: RAIL-HO-WP-0013
|
||
type: workplan
|
||
title: "Declare and verify the Railiance host UTC baseline"
|
||
domain: financials
|
||
repo: railiance-infra
|
||
status: blocked
|
||
flavor: planning
|
||
owner: codex
|
||
topic_slug: railiance
|
||
created: "2026-09-14"
|
||
updated: "2026-09-27"
|
||
related_workplans:
|
||
- RCLK-WP-0005
|
||
- RCLK-WP-0002
|
||
- RAIL-HO-WP-0011
|
||
state_hub_workstream_id: "788a005b-f6d4-5db9-8866-21251951fa0b"
|
||
---
|
||
|
||
Owner work record for RCLK-WP-0005-T01/T02. Canonical S1 ownership is already
|
||
settled by railiance-master ADR-0004 and docs/reef-first-wave-source-map.md.
|
||
Do not create a competing time baseline in railiance-hosts or bootstrap.
|
||
|
||
Read-only railiance01 observation on 2026-09-14: Ubuntu 24.04.4 LTS/KVM,
|
||
systemd-timesyncd active/enabled, UTC, synchronized flag yes, distro fallback
|
||
ntp.ubuntu.com, no local drop-in, no UDP/123 listener in the observed namespace.
|
||
The inspected sample reported offset -634us, root distance 3.432ms and normal
|
||
leap state. This is operational metadata, not an independent UTC error proof.
|
||
Receipt and repeatable collector: railiance-clock/docs/evidence/2026-09-14-railiance01-clock-inventory.json
|
||
and tools/observe_host_clock.py. No configuration or clock change was made.
|
||
|
||
## Adopt the existing daemon and review a versioned UTC policy
|
||
|
||
```task
|
||
id: RAIL-HO-WP-0013-T01
|
||
status: wait
|
||
priority: high
|
||
state_hub_task_id: "9e5db140-0642-58de-8a9c-1c5a3cfd7b6e"
|
||
```
|
||
|
||
Retain systemd-timesyncd as the baseline candidate; do not install chrony/ntpd
|
||
as a second daemon. Join RCLK-WP-0002's upstream independence, leap convention,
|
||
health/error/holdover and consumer-bound review. Specify inventory opt-in, exact
|
||
server/fallback list, boot/poll policy, health export and rollback. The current
|
||
single-provider distro fallback is evidence, not a reviewed independent source set.
|
||
Define what source health can honestly claim before exposing it to the clock app.
|
||
|
||
## Implement one declarative host role and verification entry point
|
||
|
||
```task
|
||
id: RAIL-HO-WP-0013-T02
|
||
status: wait
|
||
priority: high
|
||
state_hub_task_id: "75f17ffa-b781-549d-82ce-d19d431c2618"
|
||
```
|
||
|
||
Depends on T01 policy review. Add opt-in Ansible role under ansible/roles/ and a
|
||
narrow playbook that manages only the reviewed time-service drop-in and service
|
||
state. Integrate bootstrap.yaml through the same role, not copied tasks. Guard
|
||
against other active time daemons and unsupported host platforms. Add health
|
||
verification to the owner baseline/Goss handoff with explicit unusable states.
|
||
No CAP_SYS_TIME or clock write operation for the application time service; that
|
||
capability belongs only to the admitted host daemon. No public UDP/123 ingress.
|
||
|
||
## Prove IaC convergence, drift and recovery before live rollout
|
||
|
||
```task
|
||
id: RAIL-HO-WP-0013-T03
|
||
status: wait
|
||
priority: high
|
||
state_hub_task_id: "c9d142b0-9c8d-5abf-82d9-099a772da5ec"
|
||
```
|
||
|
||
Depends on T02. Lint/render and disposable VM convergence; second apply must be
|
||
no-op. Detect intentional disposable drift, verify reboot persistence and source
|
||
outage/recovery, and prove source-based rollback. Measure health reporting limits.
|
||
Record exact source revision/target/config checksum and no unrelated changes.
|
||
A mocked systemctl result or container-only check is not host synchronization proof.
|
||
|
||
## Apply the reviewed source and return steady-state handoff
|
||
|
||
```task
|
||
id: RAIL-HO-WP-0013-T04
|
||
status: wait
|
||
priority: high
|
||
state_hub_task_id: "9adae3a6-8ee6-538b-9bb3-1ee32ed185e1"
|
||
```
|
||
|
||
Depends on T03 and normal reviewed live-host authorization. Produce the exact
|
||
railiance01 diff and clock-step/credential-consumer impact plan, then use owner
|
||
IaC to apply/read back. Reverify usable host health and no extra listener/daemon;
|
||
record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and
|
||
railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure.
|
||
No corporate workstation time settings or app-clock trust adoption in this plan.
|
||
|
||
|
||
2026-09-15: operator requested implementation and consumer use. Added opt-in
|
||
railiance_clock owner role and host-time playbook; bootstrap invokes the same
|
||
role. Authority activation requires artifact hash, admission reference and
|
||
explicit signing-key delivery. Defaults change no clocks and deploy no service.
|
||
Native convergence, custody and measured UTC policy acceptance remain open.
|
||
|
||
## Live deployment — 2026-09-15
|
||
|
||
CCR-2026-0028 authorizes the systemd authority and attended host-file custody.
|
||
The role now prepares identity independently of key delivery, supports a verified
|
||
preinstalled key, and pins the production wheel in Railiance01 inventory.
|
||
The authority and health timer are active/enabled on loopback 8787. Readiness
|
||
and signed workstation acceptance passed; receipt is in railiance-clock and
|
||
railiance-platform docs/evidence/2026-09-15-railiance-clock-production.json.
|
||
Health collection needs read-only adjtimex; ProtectClock is disabled only on
|
||
that exporter, while both services retain empty capability sets. Disposable
|
||
outage/reboot/rollback rehearsals remain tracked in T03.
|
||
|
||
## Closeout review — 2026-09-27
|
||
|
||
All four residual tasks are `wait`; deployed source alone does not meet their
|
||
acceptance criteria. T01 is blocked on RCLK-WP-0002 source/leap/error-model
|
||
acceptance; that owner's T01–T03 are still in progress and T04 is todo. T02 has
|
||
an implemented opt-in role and passes native Ansible syntax checking, but still
|
||
requires T01's reviewed policy and baseline/Goss health integration. T03 requires
|
||
an admitted disposable Ubuntu VM for convergence/no-op, drift, reboot,
|
||
source-outage/recovery and rollback evidence. No such test target is declared in
|
||
this repository. T04's prior live deployment evidence stands, but its required
|
||
T03 recovery evidence and steady-state handoff remain outstanding.
|
||
|
||
Refreshed read-only inventory:
|
||
`docs/evidence/2026-09-27-railiance01-clock-inventory.json`, collected with the
|
||
existing railiance-clock collector. Installed systemd and systemd-timesyncd:
|
||
`255.4-1ubuntu8.17`. Effective system/fallback source: `ntp.ubuntu.com`;
|
||
per-link and runtime source lists empty. Poll bounds 32–64 seconds, root-distance
|
||
threshold 500ms, observed leap 0. UTC, timesyncd active, synchronization reported,
|
||
no UDP/123 listener and no observed competing daemon. These are diagnostics,
|
||
not independent accuracy or source-independence proof. Configuration hashes are
|
||
in the receipt; no host configuration was changed.
|
||
|
||
The September 14 duplicate-workplan inbox warning is historical: the current
|
||
checkout has one WP-0013 file and already contains consolidation commit
|
||
`c402245`. Preserve its existing task UUIDs. Workplan is `blocked` on the
|
||
remaining review and native recovery prerequisites.
|