From 777e63c6173795c4dc410d9ba99e4f61230fa661 Mon Sep 17 00:00:00 2001 From: codex Date: Mon, 27 Jul 2026 21:12:26 +0200 Subject: [PATCH] Record Qonto identity and runtime progress --- ...WP-0019-knative-qonto-runtime-on-reef-railiance.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md b/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md index 499efaf..ff001c8 100644 --- a/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md +++ b/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md @@ -392,6 +392,11 @@ digest-pinned, bounded Knative packaging with scale-to-zero, default-deny networking, ExternalSecret references, and an explicit unverified FQDN egress gate. Live SLO, identity, failure, and rollback evidence remains outstanding. +2026-07-27: Deployed digest-addressed revision `rapp-qonto-00004` on +rail-knative. The fail-closed proxy gate and cluster-local health smoke pass. +Full cold-start timing, audit/idempotency, revocation, dependency-failure, and +previous-revision rollback evidence remains before T09 completion. + ## T10 - Automate routing, conformance, reconciliation, and evidence ```task @@ -424,6 +429,12 @@ than used for Kubernetes access. installation and live verification automation. The configured SSH lane provides agent execution while direct public API access remains unnecessary. +2026-07-27: KeyCape client credentials are live, their OpenBao custody and +rotation route is published as `rapp-qonto-keycape-client`, and the M3/prod +posture manifest passes. Public `kc.coulomb.social` DNS still targets the +older CoulombCore endpoint; railiance01 verification currently uses direct +TLS-preserving resolution pending routing convergence. + ## Exit Criteria - [x] `rail-knative` has a written boundary against `rail-kubernetes`