railiance-infra/WORK-RECORDS.md
codex c84fe7a3de
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Make the k3s API firewall allowlist declarative
The live host restricted 6443/tcp to specific operator addresses, added by hand,
while this role still declared the port open to Anywhere with no source
restriction. The declared config was weaker than reality: running the base role
would have REMOVED the restriction and exposed the Kubernetes API to the
internet. Security was tightened on the host and never fed back into the source
of truth.

Found 2026-08-11 while diagnosing lost cluster access, which turned out to be an
ISP lease rotation (89.244.90.246 -> .236) against a hand-maintained allowlist.

Changes:
- defaults: k3s_api_allowed_sources (empty = 6443 closed to all external
  sources, the safe failure; SSH unaffected so the host stays recoverable) and
  k3s_api_revoked_sources, so rotated addresses are pruned rather than left as
  standing grants to whoever the ISP reassigns them to
- tasks: grant approved sources, then remove any blanket rule, then revoke
  retired ones. Order matters - grants are added before the blanket rule is
  deleted so convergence never opens a window with no API access
- group_vars/all.yaml: the current operator address, plus the two stale grants
  (.246 rotated, 85.132.220.102 historic) marked for revocation
- docs/verification.md: state that 6443 is source-restricted rather than
  listing it as a plainly allowed port

Not yet converged against the live host - the role change is committed but
running it is a production action needing operator approval.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:56:28 +02:00

2.5 KiB

Work Records — railiance-infra

Generated by statehub fix-consistency (CUST-WP-0061-T04, work-record stage 3). Do not edit by hand — edit the source file/block listed for each record and re-run fix-consistency to refresh this index. Archived workplans are omitted; closed decisions/intakes/engagements stay listed so recently-resolved work is still visible. [auto]

Kind ID Status Lane Source
workplan RAIL-HO-WP-0006 finished workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
workplan RAIL-HO-WP-0007 finished workplans/RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md
workplan RAIL-HO-WP-0008 ready workplans/RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md
task RAIL-HO-WP-0006-T01 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T02 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T03 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T04 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T05 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T06 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T07 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T08 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0006-T09 done workplans/RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md
task RAIL-HO-WP-0007-T01 done workplans/RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md
task RAIL-HO-WP-0007-T02 done workplans/RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md
task RAIL-HO-WP-0007-T03 done workplans/RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md
task RAIL-HO-WP-0007-T04 done workplans/RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md
task RAIL-HO-WP-0008-T01 todo workplans/RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md
task RAIL-HO-WP-0008-T02 todo workplans/RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md
task RAIL-HO-WP-0008-T03 todo workplans/RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md