Track second-wave implementation evidence

This commit is contained in:
codex 2026-07-26 14:14:31 +02:00
parent ffbd4178ce
commit 2e8378012e

View file

@ -356,6 +356,10 @@ Acceptance:
- Qonto's single-server/shared-control-plane residual risk is explicit
- mixed-rail split triggers are represented
2026-07-26: Added a reusable, secret-free substrate preflight in
`railiance-cluster` and recorded the failed API reachability result as reef
evidence with `block_installation`. Declared topology was not promoted.
## T09 - Establish Qonto SLO, threat, rollback, and fallback evidence
```task
@ -378,6 +382,11 @@ Acceptance:
- rollback prefers a verified Knative revision; direct Kubernetes fallback is
time-bounded and exceptional
2026-07-26: `rapp-qonto` now has offline-validated, cluster-local,
digest-pinned, bounded Knative packaging with scale-to-zero, default-deny
networking, ExternalSecret references, and an explicit unverified FQDN egress
gate. Live SLO, identity, failure, and rollback evidence remains outstanding.
## T10 - Automate routing, conformance, reconciliation, and evidence
```task
@ -401,6 +410,11 @@ Acceptance:
- human steps are limited to named authority or residual-risk decisions and
have an automation follow-up path
2026-07-26: Generic Knative and Qonto conformance is executable offline. The
cluster preflight is idempotent and read-only. Credential routing was attempted
first; its unrelated Forgejo match is tracked as a catalog-quality gap rather
than used for Kubernetes access.
## Exit Criteria
- [x] `rail-knative` has a written boundary against `rail-kubernetes`