railiance-infra/workplans/RAIL-HO-WP-0013-host-utc-timesyncd.md
codex b3a9520fc3
Some checks are pending
CI Smoke / source-contract (push) Waiting to run
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Classify open workplans with flavor (CUST-WP-0072).
Set flavor on open workplans from origin/prose/status. Copy existing
depends_on aliases only. Do not promote residuals.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-14 15:52:21 +02:00

3 KiB

id type title domain repo status flavor owner topic_slug origin origin_ref created updated related state_hub_workstream_id
RAIL-HO-WP-0013 workplan Declare systemd-timesyncd as the S1 host UTC daemon financials railiance-infra proposed residual codex railiance residual RCLK-WP-0005 2026-09-14 2026-09-14
RAIL-HO-WP-0011
RCLK-WP-0005
RCLK-WP-0002
788a005b-f6d4-5db9-8866-21251951fa0b

Residual from RCLK-WP-0005-T01. railiance01 already runs a single systemd-timesyncd against Ubuntu default NTP, UTC, synchronized. That unit is not in S1 IaC. railiance-hosts is superseded; do not duplicate the tree there.

Wait for RCLK-WP-0002's UTC/leap/quality contract before choosing servers or holdover. Do not install chrony alongside timesyncd.

Declare the adopted daemon

id: RAIL-HO-WP-0013-T01
status: wait
flavor: residual
priority: medium
state_hub_task_id: "9e5db140-0642-58de-8a9c-1c5a3cfd7b6e"

Version systemd-timesyncd (not chrony) in railiance-infra: enabled unit, NTP/FallbackNTP, restricted listeners, health export. Lint/render only until RCLK-WP-0002 and RCLK-WP-0005-T02 authorize live apply. No second daemon.

Canonical S1 ownership: railiance-master ADR-0004 and docs/reef-first-wave-source-map.md. Repeatable read-only evidence lives in railiance-clock at docs/evidence/2026-09-14-railiance01-clock-inventory.json and tools/observe_host_clock.py. The synchronized flag does not establish an independent UTC error bound. Current distro fallback is observed, not an approved independent source set. Review upstream/leap/holdover policy with RCLK-WP-0002.

Use an opt-in Ansible role and narrow playbook; bootstrap calls that same role. Guard against competing daemons and unsupported hosts. Export explicit unusable health states; the application must never acquire clock-write privileges.

Prove IaC convergence, drift and recovery before live rollout

id: RAIL-HO-WP-0013-T02
status: wait
priority: high
state_hub_task_id: "75f17ffa-b781-549d-82ce-d19d431c2618"

Depends on T01. Lint/render and disposable VM convergence; second apply must be no-op. Detect intentional disposable drift, verify reboot persistence and source outage/recovery, and prove source-based rollback. Measure health reporting limits. Record exact source revision/target/config checksum and no unrelated changes. A mocked systemctl result or container-only check is not host synchronization proof.

Apply the reviewed source and return steady-state handoff

id: RAIL-HO-WP-0013-T03
status: wait
priority: high
state_hub_task_id: "c9d142b0-9c8d-5abf-82d9-099a772da5ec"

Depends on T02 and normal reviewed live-host authorization. Produce the exact railiance01 diff and clock-step/credential-consumer impact plan, then use owner IaC to apply/read back. Reverify usable host health and no extra listener/daemon; record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure. No corporate workstation time settings or app-clock trust adoption in this plan.