diff --git a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md index 9083208..6212114 100644 --- a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md +++ b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md @@ -8,7 +8,7 @@ status: active owner: codex topic_slug: railiance created: "2026-07-30" -updated: "2026-08-03" +updated: "2026-08-04" depends_on: - NK-WP-0022 state_hub_workstream_id: "0616a297-18c5-4c4e-a4fc-69135b3f9a15" @@ -220,7 +220,7 @@ state_hub_task_id: "db2443e6-bad7-4a71-b45f-d4b81099df15" Scale the CoulombCore OpenBao and UI gateway to zero after successful cutover. Retain manifests, encrypted final snapshot, PVCs, Secrets, TLS material, and -documented rollback for at least 30 days. Confirm no DNS, monitor, client, +documented rollback for at least 14 days. Confirm no DNS, monitor, client, tunnel, catalog entry, or automation still targets the old runtime. Done when CoulombCore serves no OpenBao traffic and rollback remains tested. @@ -251,10 +251,16 @@ Done when reef-railiance is the sole authoritative OpenBao location and all source-backed records agree. Retention gate opened 2026-08-03. Do not delete the retained CoulombCore PVCs, -Secrets, Helm records, Ingress, or Services before 2026-09-02. Final deletion +Secrets, Helm records, Ingress, or Services before 2026-08-17. Final deletion also requires a successful railiance01 disaster-recovery drill and fresh explicit destructive-cleanup approval. +2026-08-04: The workplan moved to backlog for the shortened retention window. +Activity Core one-shot definition +`activity-definitions/openbao-retention-closeout.md` reactivates T08 at 08:00 +Europe/Berlin on 2026-08-17 by emitting a claimable ops run. The schedule never +performs destructive cleanup itself. + ## Safety constraints - Never initialize or overwrite either OpenBao instance without verified