diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 6ae667c..90d362f 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -41,7 +41,7 @@ | task | RAILIANCE-WP-0020-T02 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | | task | RAILIANCE-WP-0020-T03 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | | task | RAILIANCE-WP-0020-T04 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | -| task | RAILIANCE-WP-0020-T05 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | -| task | RAILIANCE-WP-0020-T06 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | +| task | RAILIANCE-WP-0020-T05 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | +| task | RAILIANCE-WP-0020-T06 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | | task | RAILIANCE-WP-0020-T07 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | | task | RAILIANCE-WP-0020-T08 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md | diff --git a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md index 753ec6a..f35bbcd 100644 --- a/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md +++ b/workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md @@ -151,7 +151,7 @@ live and no public DNS changed. ```task id: RAILIANCE-WP-0020-T05 -status: progress +status: done priority: high state_hub_task_id: "f0a82e4e-8074-4a22-b1e9-f01ec0ff76a1" ``` @@ -170,11 +170,19 @@ runtime dependency requires the CoulombCore API. forced ExternalSecret refresh completed as SecretSynced/Ready, and the declarative owner change was committed in `railiance-platform@33b36e8`. +Completed 2026-08-03. Activity-core, Qonto, Forgejo, user-engine, and SSO were +moved in separate waves. All six ClusterSecretStores are Valid on the private +service and all nine ExternalSecrets refreshed as SecretSynced/Ready; affected +Knative, application, Forgejo, and identity pods remained healthy. Declarative +changes are in `railiance-platform@741f209` and `net-kingdom@0ec6f8c`. +Transitional tokens/AppRoles remain temporarily available for bounded rollback; +same-cluster Kubernetes identity conversion remains post-cutover hardening. + ## T06 - Cut over public OpenBao DNS and operator access ```task id: RAILIANCE-WP-0020-T06 -status: wait +status: progress priority: high state_hub_task_id: "f458d110-5fdd-465a-8a23-4ada1051fb12" ``` @@ -186,6 +194,13 @@ Keep the source sealed or write-frozen and immediately recoverable. Done when the observation window passes without source traffic or divergence. +2026-08-03: Deployed the rapp-openbao UI overlay gateway, Traefik middleware, +Ingress, and cert-manager Certificate on railiance01. The gateway is Ready. +The ACME HTTP-01 challenge is correctly pending because public DNS still points +to CoulombCore. No automated DNS credential route exists; change the A record +to `92.205.62.239`, then verify certificate, UI/OIDC, API, audit, backup, and +negative access before retiring the source. + ## T07 - Retire CoulombCore OpenBao reversibly ```task