docs(RMASTER-WP-0020): refresh closure gates
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a025c2-407a-7a32-b40a-f37a52f03f62
This commit is contained in:
parent
5acc13f426
commit
13557f7d40
1 changed files with 17 additions and 1 deletions
|
|
@ -8,7 +8,7 @@ status: blocked
|
|||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-07-30"
|
||||
updated: "2026-08-18"
|
||||
updated: "2026-08-22"
|
||||
depends_on:
|
||||
- NK-WP-0022
|
||||
related:
|
||||
|
|
@ -272,6 +272,15 @@ not this), and fresh explicit approval for destructive CoulombCore deletion.
|
|||
Do not reopen until those three are true. The 2026-08-17 one-shot may move
|
||||
the workplan to `active`; it still must not delete anything.
|
||||
|
||||
2026-08-22 review: the time-based retention gate has expired, but the other two
|
||||
gates have not. `rapp-openbao` contains the restore-drill validator and an
|
||||
example evidence document, not completed post-cutover disaster-recovery
|
||||
evidence. This session also carries no fresh, explicit authorization to delete
|
||||
the retained CoulombCore PVCs, Secrets, Helm records, Ingress, or Services.
|
||||
T08 therefore remains `wait`; finishing the migration workplan is not itself
|
||||
destructive-cleanup approval. The package-owner evidence request is State Hub
|
||||
message `02ec17ef-14c2-4c91-9768-7e9ac8714325`.
|
||||
|
||||
## T09 - Retract public OpenBao listener
|
||||
|
||||
```task
|
||||
|
|
@ -311,6 +320,13 @@ owning repo to retract the public listener while preserving the ClusterIP and
|
|||
establishing the named operator tunnel. No destructive T08 cleanup is
|
||||
authorized by this ruling.
|
||||
|
||||
2026-08-22 live review: `openbao/openbao-ui-gateway` still publishes
|
||||
`bao.coulomb.social` through a Traefik Ingress at `92.205.62.239`; its gateway
|
||||
pod is running, and the declarative overlay still contains that host. No named
|
||||
operator tunnel replacement is recorded. T09 therefore remains `progress` and
|
||||
the public-listener retraction acceptance criterion is not met. The platform
|
||||
owner follow-up is `800eb865-404f-4b2b-9363-94247f2bbdad`.
|
||||
|
||||
## Safety constraints
|
||||
|
||||
- Never initialize or overwrite either OpenBao instance without verified
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue