Complete OpenBao consumer migration waves

This commit is contained in:
codex 2026-08-03 21:40:29 +02:00
parent 06f1653ed7
commit b8ec0059de
2 changed files with 19 additions and 4 deletions

View file

@ -41,7 +41,7 @@
| task | RAILIANCE-WP-0020-T02 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T03 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T04 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T05 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T06 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T05 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T06 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T07 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
| task | RAILIANCE-WP-0020-T08 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |

View file

@ -151,7 +151,7 @@ live and no public DNS changed.
```task
id: RAILIANCE-WP-0020-T05
status: progress
status: done
priority: high
state_hub_task_id: "f0a82e4e-8074-4a22-b1e9-f01ec0ff76a1"
```
@ -170,11 +170,19 @@ runtime dependency requires the CoulombCore API.
forced ExternalSecret refresh completed as SecretSynced/Ready, and the
declarative owner change was committed in `railiance-platform@33b36e8`.
Completed 2026-08-03. Activity-core, Qonto, Forgejo, user-engine, and SSO were
moved in separate waves. All six ClusterSecretStores are Valid on the private
service and all nine ExternalSecrets refreshed as SecretSynced/Ready; affected
Knative, application, Forgejo, and identity pods remained healthy. Declarative
changes are in `railiance-platform@741f209` and `net-kingdom@0ec6f8c`.
Transitional tokens/AppRoles remain temporarily available for bounded rollback;
same-cluster Kubernetes identity conversion remains post-cutover hardening.
## T06 - Cut over public OpenBao DNS and operator access
```task
id: RAILIANCE-WP-0020-T06
status: wait
status: progress
priority: high
state_hub_task_id: "f458d110-5fdd-465a-8a23-4ada1051fb12"
```
@ -186,6 +194,13 @@ Keep the source sealed or write-frozen and immediately recoverable.
Done when the observation window passes without source traffic or divergence.
2026-08-03: Deployed the rapp-openbao UI overlay gateway, Traefik middleware,
Ingress, and cert-manager Certificate on railiance01. The gateway is Ready.
The ACME HTTP-01 challenge is correctly pending because public DNS still points
to CoulombCore. No automated DNS credential route exists; change the A record
to `92.205.62.239`, then verify certificate, UI/OIDC, API, audit, backup, and
negative access before retiring the source.
## T07 - Retire CoulombCore OpenBao reversibly
```task