chore: align WP-0020 with ADR-0008 and note 0023 children
Route public bao.coulomb.social as a close, not a grant. Record the filed child workplans for private-by-default enforcement.
This commit is contained in:
parent
132bfb838a
commit
c465d36ead
2 changed files with 36 additions and 7 deletions
|
|
@ -8,16 +8,20 @@ status: blocked
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: railiance
|
topic_slug: railiance
|
||||||
created: "2026-07-30"
|
created: "2026-07-30"
|
||||||
updated: "2026-08-14"
|
updated: "2026-08-15"
|
||||||
depends_on:
|
depends_on:
|
||||||
- NK-WP-0022
|
- NK-WP-0022
|
||||||
|
related:
|
||||||
|
- ADR-0008
|
||||||
|
- RMASTER-WP-0023
|
||||||
state_hub_workstream_id: "0616a297-18c5-4c4e-a4fc-69135b3f9a15"
|
state_hub_workstream_id: "0616a297-18c5-4c4e-a4fc-69135b3f9a15"
|
||||||
---
|
---
|
||||||
|
|
||||||
# RMASTER-WP-0020 - OpenBao migration to reef-railiance
|
# RMASTER-WP-0020 - OpenBao migration to reef-railiance
|
||||||
|
|
||||||
Move the authoritative OpenBao runtime from CoulombCore to the default
|
Move the authoritative OpenBao runtime from CoulombCore onto
|
||||||
`rail-kubernetes` platform path on `reef-railiance`, preserving every secret,
|
`rail-kubernetes` **hosted by** `reef-railiance` (`rapp-openbao`),
|
||||||
|
preserving every secret,
|
||||||
policy, auth method, identity, lease-relevant contract, audit record, and
|
policy, auth method, identity, lease-relevant contract, audit record, and
|
||||||
recovery capability. This is a stateful security control plane and must never
|
recovery capability. This is a stateful security control plane and must never
|
||||||
run on scale-to-zero Knative.
|
run on scale-to-zero Knative.
|
||||||
|
|
@ -268,6 +272,32 @@ not this), and fresh explicit approval for destructive CoulombCore deletion.
|
||||||
Do not reopen until those three are true. The 2026-08-17 one-shot may move
|
Do not reopen until those three are true. The 2026-08-17 one-shot may move
|
||||||
the workplan to `active`; it still must not delete anything.
|
the workplan to `active`; it still must not delete anything.
|
||||||
|
|
||||||
|
## T09 - Retract public OpenBao listener
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: RMASTER-WP-0020-T09
|
||||||
|
status: wait
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Depends on T08 remaining blocked until its three gates open; this task
|
||||||
|
can be routed sooner.
|
||||||
|
|
||||||
|
T06 published `bao.coulomb.social` on Railiance01 for DNS continuity.
|
||||||
|
ADR-0008 later split admission from exposure. The 2026-08-15 snapshot
|
||||||
|
lists that name as a **routed close, not a grant**. Target inventory is
|
||||||
|
`public_ingress: false`. Consumers already use
|
||||||
|
`openbao.openbao.svc:8200`.
|
||||||
|
|
||||||
|
Route to `rapp-openbao` / `railiance-platform`: drop public Ingress,
|
||||||
|
keep ClusterIP, set `exposure.posture: operator` with a named
|
||||||
|
ops-bridge tunnel for the UI. Do not implement NetworkPolicy here.
|
||||||
|
|
||||||
|
**Done when:** `bao.coulomb.social` is not a public listener we publish,
|
||||||
|
the runbook no longer treats public DNS as the steady state, and the
|
||||||
|
declaration carries `operator` (or `private`) rather than an implicit
|
||||||
|
public grant.
|
||||||
|
|
||||||
## Safety constraints
|
## Safety constraints
|
||||||
|
|
||||||
- Never initialize or overwrite either OpenBao instance without verified
|
- Never initialize or overwrite either OpenBao instance without verified
|
||||||
|
|
|
||||||
|
|
@ -334,10 +334,9 @@ there from this repo.
|
||||||
with a back-link to this ID.
|
with a back-link to this ID.
|
||||||
|
|
||||||
Completed 2026-08-15: intakes in
|
Completed 2026-08-15: intakes in
|
||||||
`docs/exposure-enforcement-intakes.md`. State Hub messages sent to
|
`docs/exposure-enforcement-intakes.md`. Child workplans filed:
|
||||||
`rail-kubernetes`, `railiance-cluster`, `reef-railiance`,
|
`RAIL-K8S-WP-0003`, `REEF-RAILIANCE-WP-0004`, `RAIL-HO-WP-0010`,
|
||||||
`railiance-infra`, and `railiance-enablement`. Owning-repo agents file
|
`RAIL-EN-WP-0001`.
|
||||||
the workplans.
|
|
||||||
|
|
||||||
## Suggested review order
|
## Suggested review order
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue