diff --git a/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md b/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md index 7afb1ca..d3280dd 100644 --- a/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md +++ b/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md @@ -356,6 +356,10 @@ Acceptance: - Qonto's single-server/shared-control-plane residual risk is explicit - mixed-rail split triggers are represented +2026-07-26: Added a reusable, secret-free substrate preflight in +`railiance-cluster` and recorded the failed API reachability result as reef +evidence with `block_installation`. Declared topology was not promoted. + ## T09 - Establish Qonto SLO, threat, rollback, and fallback evidence ```task @@ -378,6 +382,11 @@ Acceptance: - rollback prefers a verified Knative revision; direct Kubernetes fallback is time-bounded and exceptional +2026-07-26: `rapp-qonto` now has offline-validated, cluster-local, +digest-pinned, bounded Knative packaging with scale-to-zero, default-deny +networking, ExternalSecret references, and an explicit unverified FQDN egress +gate. Live SLO, identity, failure, and rollback evidence remains outstanding. + ## T10 - Automate routing, conformance, reconciliation, and evidence ```task @@ -401,6 +410,11 @@ Acceptance: - human steps are limited to named authority or residual-risk decisions and have an automation follow-up path +2026-07-26: Generic Knative and Qonto conformance is executable offline. The +cluster preflight is idempotent and read-only. Credential routing was attempted +first; its unrelated Forgejo match is tracked as a catalog-quality gap rather +than used for Kubernetes access. + ## Exit Criteria - [x] `rail-knative` has a written boundary against `rail-kubernetes`