Record Qonto identity and runtime progress

This commit is contained in:
codex 2026-07-27 21:12:26 +02:00
parent 41c250e888
commit 777e63c617

View file

@ -392,6 +392,11 @@ digest-pinned, bounded Knative packaging with scale-to-zero, default-deny
networking, ExternalSecret references, and an explicit unverified FQDN egress networking, ExternalSecret references, and an explicit unverified FQDN egress
gate. Live SLO, identity, failure, and rollback evidence remains outstanding. gate. Live SLO, identity, failure, and rollback evidence remains outstanding.
2026-07-27: Deployed digest-addressed revision `rapp-qonto-00004` on
rail-knative. The fail-closed proxy gate and cluster-local health smoke pass.
Full cold-start timing, audit/idempotency, revocation, dependency-failure, and
previous-revision rollback evidence remains before T09 completion.
## T10 - Automate routing, conformance, reconciliation, and evidence ## T10 - Automate routing, conformance, reconciliation, and evidence
```task ```task
@ -424,6 +429,12 @@ than used for Kubernetes access.
installation and live verification automation. The configured SSH lane installation and live verification automation. The configured SSH lane
provides agent execution while direct public API access remains unnecessary. provides agent execution while direct public API access remains unnecessary.
2026-07-27: KeyCape client credentials are live, their OpenBao custody and
rotation route is published as `rapp-qonto-keycape-client`, and the M3/prod
posture manifest passes. Public `kc.coulomb.social` DNS still targets the
older CoulombCore endpoint; railiance01 verification currently uses direct
TLS-preserving resolution pending routing convergence.
## Exit Criteria ## Exit Criteria
- [x] `rail-knative` has a written boundary against `rail-kubernetes` - [x] `rail-knative` has a written boundary against `rail-kubernetes`