railiance-infra/workplans
codex f4a7805cca
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Open RAIL-HO-WP-0009: firewall declared-state integrity and k3s API exposure
Records the security defect found 2026-08-11: this repo declared 6443/tcp open
to Anywhere while the live host was source-restricted by hand, so converging the
base role would have exposed the Kubernetes API to the internet. A hardening run
that de-hardens, undetected because nothing compares declared UFW state to live
UFW state.

T01 (declarative allowlist) is done. T02 converges it - production action,
approval required, and until it runs the host still carries two stale grants to
addresses the ISP may have reassigned. T03 audits the role for the same class of
defect and asks about the undeclared 2224/tcp open to Anywhere. T04 proposes
removing the API from the public internet via the ops-bridge tunnel pattern
already documented for CoulombCore. T05 routes a declared-vs-live conformance
check to the unowned Q7 loop.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 00:01:39 +02:00
..
archived chore: archive finished RAIL-HO-WP-0005 (Forgejo production migration) 2026-07-14 00:33:10 +02:00
RAIL-HO-WP-0006-forgejo-registry-ref-cleanup.md Sync RAIL-HO-WP-0006 State Hub IDs from fix-consistency 2026-07-09 12:00:52 +02:00
RAIL-HO-WP-0007-first-reef-rollout-and-s1-canonicalization.md Rename first home reef target to reef-railiance 2026-07-26 09:00:32 +02:00
RAIL-HO-WP-0008-railiance01-resource-and-commercial-evidence.md Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
RAIL-HO-WP-0009-firewall-declared-state-and-api-exposure.md Open RAIL-HO-WP-0009: firewall declared-state integrity and k3s API exposure 2026-08-12 00:01:39 +02:00