Complete OpenBao consumer migration waves
This commit is contained in:
parent
06f1653ed7
commit
b8ec0059de
2 changed files with 19 additions and 4 deletions
|
|
@ -41,7 +41,7 @@
|
|||
| task | RAILIANCE-WP-0020-T02 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T03 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T04 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T05 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T06 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T05 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T06 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T07 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T08 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
|
|
|
|||
|
|
@ -151,7 +151,7 @@ live and no public DNS changed.
|
|||
|
||||
```task
|
||||
id: RAILIANCE-WP-0020-T05
|
||||
status: progress
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "f0a82e4e-8074-4a22-b1e9-f01ec0ff76a1"
|
||||
```
|
||||
|
|
@ -170,11 +170,19 @@ runtime dependency requires the CoulombCore API.
|
|||
forced ExternalSecret refresh completed as SecretSynced/Ready, and the
|
||||
declarative owner change was committed in `railiance-platform@33b36e8`.
|
||||
|
||||
Completed 2026-08-03. Activity-core, Qonto, Forgejo, user-engine, and SSO were
|
||||
moved in separate waves. All six ClusterSecretStores are Valid on the private
|
||||
service and all nine ExternalSecrets refreshed as SecretSynced/Ready; affected
|
||||
Knative, application, Forgejo, and identity pods remained healthy. Declarative
|
||||
changes are in `railiance-platform@741f209` and `net-kingdom@0ec6f8c`.
|
||||
Transitional tokens/AppRoles remain temporarily available for bounded rollback;
|
||||
same-cluster Kubernetes identity conversion remains post-cutover hardening.
|
||||
|
||||
## T06 - Cut over public OpenBao DNS and operator access
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0020-T06
|
||||
status: wait
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "f458d110-5fdd-465a-8a23-4ada1051fb12"
|
||||
```
|
||||
|
|
@ -186,6 +194,13 @@ Keep the source sealed or write-frozen and immediately recoverable.
|
|||
|
||||
Done when the observation window passes without source traffic or divergence.
|
||||
|
||||
2026-08-03: Deployed the rapp-openbao UI overlay gateway, Traefik middleware,
|
||||
Ingress, and cert-manager Certificate on railiance01. The gateway is Ready.
|
||||
The ACME HTTP-01 challenge is correctly pending because public DNS still points
|
||||
to CoulombCore. No automated DNS credential route exists; change the A record
|
||||
to `92.205.62.239`, then verify certificate, UI/OIDC, API, audit, backup, and
|
||||
negative access before retiring the source.
|
||||
|
||||
## T07 - Retire CoulombCore OpenBao reversibly
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue