Retire CoulombCore OpenBao reversibly
This commit is contained in:
parent
99ca9df6c2
commit
f1839a9d95
2 changed files with 25 additions and 4 deletions
|
|
@ -42,6 +42,6 @@
|
|||
| task | RAILIANCE-WP-0020-T03 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T04 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T05 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T06 | progress | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T07 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T06 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T07 | done | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
| task | RAILIANCE-WP-0020-T08 | wait | — | workplans/RAILIANCE-WP-0020-openbao-migration-to-reef-railiance.md |
|
||||
|
|
|
|||
|
|
@ -182,7 +182,7 @@ same-cluster Kubernetes identity conversion remains post-cutover hardening.
|
|||
|
||||
```task
|
||||
id: RAILIANCE-WP-0020-T06
|
||||
status: progress
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "f458d110-5fdd-465a-8a23-4ada1051fb12"
|
||||
```
|
||||
|
|
@ -201,11 +201,19 @@ to CoulombCore. No automated DNS credential route exists; change the A record
|
|||
to `92.205.62.239`, then verify certificate, UI/OIDC, API, audit, backup, and
|
||||
negative access before retiring the source.
|
||||
|
||||
Completed 2026-08-03. All authoritative and sampled public resolvers converged
|
||||
on `92.205.62.239`. The rapp-openbao gateway serves HTTP 200 for UI and health
|
||||
with a valid cert-manager-owned Let's Encrypt certificate. The target remains
|
||||
active/unsealed with the preserved cluster ID; its audit file is growing and
|
||||
all six stores plus nine ExternalSecrets remain Ready. The source OIDC
|
||||
initiation behavior was compared directly and no target-only regression was
|
||||
found.
|
||||
|
||||
## T07 - Retire CoulombCore OpenBao reversibly
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0020-T07
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "db2443e6-bad7-4a71-b45f-d4b81099df15"
|
||||
```
|
||||
|
|
@ -217,6 +225,14 @@ tunnel, catalog entry, or automation still targets the old runtime.
|
|||
|
||||
Done when CoulombCore serves no OpenBao traffic and rollback remains tested.
|
||||
|
||||
Completed 2026-08-03. After more than one DNS TTL and multi-resolver
|
||||
convergence, the old gateway showed only its Kubernetes readiness probes and
|
||||
no external traffic. CoulombCore StatefulSet `openbao` and Deployment
|
||||
`openbao-ui-gateway` were scaled to zero and their pods terminated. Data and
|
||||
audit PVCs, Services, Ingress, TLS and Helm Secrets, manifests, rotated unseal
|
||||
custody, and encrypted final snapshot remain retained for rollback. A
|
||||
post-retirement public probe returned HTTP 200 from railiance01 with valid TLS.
|
||||
|
||||
## T08 - Final cleanup and closure
|
||||
|
||||
```task
|
||||
|
|
@ -234,6 +250,11 @@ runbooks, routing catalog, State Hub, and the CoulombCore retirement plan.
|
|||
Done when reef-railiance is the sole authoritative OpenBao location and all
|
||||
source-backed records agree.
|
||||
|
||||
Retention gate opened 2026-08-03. Do not delete the retained CoulombCore PVCs,
|
||||
Secrets, Helm records, Ingress, or Services before 2026-09-02. Final deletion
|
||||
also requires a successful railiance01 disaster-recovery drill and fresh
|
||||
explicit destructive-cleanup approval.
|
||||
|
||||
## Safety constraints
|
||||
|
||||
- Never initialize or overwrite either OpenBao instance without verified
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue