Record Qonto identity and runtime progress

This commit is contained in:
codex 2026-07-27 21:12:26 +02:00
parent 41c250e888
commit 777e63c617

View file

@ -392,6 +392,11 @@ digest-pinned, bounded Knative packaging with scale-to-zero, default-deny
networking, ExternalSecret references, and an explicit unverified FQDN egress
gate. Live SLO, identity, failure, and rollback evidence remains outstanding.
2026-07-27: Deployed digest-addressed revision `rapp-qonto-00004` on
rail-knative. The fail-closed proxy gate and cluster-local health smoke pass.
Full cold-start timing, audit/idempotency, revocation, dependency-failure, and
previous-revision rollback evidence remains before T09 completion.
## T10 - Automate routing, conformance, reconciliation, and evidence
```task
@ -424,6 +429,12 @@ than used for Kubernetes access.
installation and live verification automation. The configured SSH lane
provides agent execution while direct public API access remains unnecessary.
2026-07-27: KeyCape client credentials are live, their OpenBao custody and
rotation route is published as `rapp-qonto-keycape-client`, and the M3/prod
posture manifest passes. Public `kc.coulomb.social` DNS still targets the
older CoulombCore endpoint; railiance01 verification currently uses direct
TLS-preserving resolution pending routing convergence.
## Exit Criteria
- [x] `rail-knative` has a written boundary against `rail-kubernetes`