railiance-infra/workplans/RAIL-HO-WP-0010-new-reef-ports-need-a-grant.md
codex dea6c72d54
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
workplan: RAIL-HO-WP-0010 new reefs need a grant for 80/443
Intake from RMASTER-WP-0023. 6443 stays operator-only.
2026-08-15 20:52:04 +02:00

1 KiB

id type title domain repo status owner topic_slug created updated related
RAIL-HO-WP-0010 workplan New reefs do not get 80/443 until a substrate grant exists financials railiance-infra ready codex railiance 2026-08-15 2026-08-15
RMASTER-WP-0023
RAIL-HO-WP-0009
ADR-0008

RAIL-HO-WP-0010 — new-reef host ports

Intake from RMASTER-WP-0023-T05.

Goal

Host surface for new reefs: do not open 80/443 until the reef declaration carries a public substrate grant. 6443 stays operator-only (RAIL-HO-WP-0009). This is not the rapp admission desk. Nydus 2224 stays a named exception.

T01 — Fail-closed new-reef UFW

id: RAIL-HO-WP-0010-T01
status: todo
priority: high

Bootstrap / inventory for a new reef starts with SSH (and Nydus only if the provider requires it). 80/443 require a cited reef grant. Do not add per-rapp UFW rules on a shared ingress host.

Done when: a new reef playbook cannot open 80/443 without naming the grant, and 6443 cannot be opened by this path.