diff --git a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md index cc1b593..68c539a 100644 --- a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md +++ b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md @@ -90,7 +90,7 @@ was aligned to OpenBao 2.5.4, matching the source. ```task id: RAILIANCE-WP-0020-T03 -status: wait +status: done priority: high state_hub_task_id: "88671108-cf8c-4de6-b1ce-06e99b1c3d70" ``` @@ -112,6 +112,13 @@ Shamir barrier. The remaining semantic and repeated restart/unseal proof needs two of the three existing source shares through the attended custody ceremony; no supported automated custody route exposes those shares. +Completed 2026-08-03. The operator supplied two rotated shares through hidden +prompts. Two restart/unseal cycles passed. The restored cluster became active +with the source cluster ID; inventory counts matched; the existing scoped Qonto +AppRole proved exact-path `read` and sibling `deny`; and declarative file audit +output was non-empty. Machine-readable evidence is in +`docs/evidence/openbao-isolated-restore-2026-08-03.json`. + ## T04 - Restore authoritative state on railiance01 ```task