Commit graph

39 commits

Author SHA1 Message Date
codex
44c39e5708 docs: record policy publication handoff 2026-08-18 17:59:21 +02:00
codex
7d32673812 docs: align master with canon and policy publication 2026-08-18 17:00:07 +02:00
codex
190fa7b0dc docs(openbao): progress public listener retraction 2026-08-18 15:30:34 +02:00
codex
668ef2699f chore(consistency): write back WP-0020 T09 hub id 2026-08-15 20:56:47 +02:00
codex
c465d36ead chore: align WP-0020 with ADR-0008 and note 0023 children
Route public bao.coulomb.social as a close, not a grant. Record the
filed child workplans for private-by-default enforcement.
2026-08-15 20:52:04 +02:00
codex
4a664533d3 feat: implement RMASTER-WP-0023 private-by-default exposure
Add the exposure contract, additive family schema fields, validator
checks and fixtures, the reef-railiance exception snapshot, and
routed intakes. Enforcement stays in the owning repos.
2026-08-15 20:08:37 +02:00
codex
b3e9980321 feat: accept ADR-0008 private-by-default exposure (WP-0023 T01)
Operator ratified the recommended table. Record the sibling ADR,
point ADR-0006 at it, and open T02.
2026-08-15 19:50:46 +02:00
codex
567682c902 chore(consistency): register RMASTER-WP-0023 hub ids
Write back the State Hub workstream and task IDs and refresh
WORK-RECORDS.md after fix-consistency created the workplan.
2026-08-15 19:35:38 +02:00
codex
fb1b7dae73 workplan: refine RMASTER-WP-0023 after review
Accept the workplan home and tighten scope: exposure sits
beside ADR-0006 as ADR-0008, public keys off binding
admission, T04 is a reef-railiance snapshot, enforcement
is routed, and Q7 / provider APIs stay out.
2026-08-15 19:34:48 +02:00
codex
48dba891b5 Propose RMASTER-WP-0023: private-by-default exposure until admission
Draft family workplan for review. Default reefs, rails, and rapps stay
off the public internet until production-approved plus an explicit
grant. Implementation is routed, not done here.
2026-08-15 19:19:07 +02:00
codex
137f0f3b9f Block RMASTER-WP-0020 until T08 cleanup gates open
Park the OpenBao migration workplan as blocked and T08 as wait. Retention,
the post-cutover disaster-recovery drill, and explicit destructive-deletion
approval are all still closed; do not reopen before 2026-08-17.
2026-08-14 20:33:22 +02:00
codex
654bbe891b feat: allow provider-delegated reefs with no rail
Object-storage reefs omit primary_rail and hosted_rails. Scaleway
operates S3; reef-storage only names the boundary. Finish
RMASTER-WP-0022.
2026-08-14 15:53:30 +02:00
codex
82b7b7295d workplan: RMASTER-WP-0022 establish reef-storage
Plan a storage reef for Scaleway object storage, distinct from
reef-railiance. Backup attributes will live there; the reef schema
must allow a substrate with no compute rail.
2026-08-14 15:44:44 +02:00
codex
4864b7852d chore: use RMASTER-WP prefix for master workplans
Rename RAILIANCE-WP-0017..0021 to RMASTER-WP-* so railiance-master
IDs no longer collide with railiance-platform's RAILIANCE-WP series.
Hub UUIDs are unchanged.
2026-08-14 14:29:18 +02:00
codex
3cc0dc31d6 Finish RAILIANCE-WP-0021: family schemas, validator, and ADR-0007
Add rail and reef schemas, derive reef bound_rapps from rapp.bound_reefs,
and ship a standalone family-declaration validator with an inventory-fed
coverage check. Point the bootstrap contract at the schemas, record the
dimension and cardinality decisions in ADR-0007, correct the first-wave
candidates document, and release the shape to downstream repos.
2026-08-13 15:29:07 +02:00
custodian-sync
bd7227202f chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-11:
  - workplan status: ready → active
2026-08-11 22:56:40 +02:00
codex
28cbba1025 Add rapp declaration schema with composition block (WP-0021 T02, T03)
schemas/rapp.schema.json defines one normative shape for the rollout, smoke and
rollback contracts in place of the three mutually unreadable variants found
across the live rapps, promotes contract_version, readiness_state,
data_classification and criticality to required, and forbids the rapp- prefix
on workload_identity.name.

composition replaces the flat members list per amendment f88f938d: purpose,
member_repos with deployables, and pinned upstream_components. Repos are
many:many with rapps; deployables are 1:1, which is what makes the T06 coverage
check well-formed.

ownership_repo left permissive pending an architecture-owner call; the tighter
alternative is written up in schemas/README.md.

Validated against all three live declarations: openbao 10 errors, postgres 10,
qonto 4 — precisely the reported drift and nothing else.

Also found: three further rapp-* repos (secrets-engine, tenant-engine,
user-engine) carry no declarations at all, which the routed survey missed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 22:56:22 +02:00
codex
8fc92bd7d2 Sync RAILIANCE-WP-0021 hub ids and tidy T01 completion note
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 20:41:17 +02:00
codex
f3c44c7a80 Open RAILIANCE-WP-0021 for the rapp declaration schema
railiance-platform surveyed the four-axis model against the live cluster and
all six family repos and routed the findings here (messages 04c776c4 and
f88f938d): rapp.yaml has no schema and has drifted three ways, reef bound_rapps
is a stale hand-maintained list, and ~17 live workloads sit against 3 rapps.

Takes ownership of the schema, the composition block with its two cardinalities
(repos many:many with rapps, deployables 1:1), and a validator over all three
family declaration files. Migration stays with the owning repos.

T01 done: both messages acknowledged, ownership confirmed to railiance-platform.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 20:40:40 +02:00
codex
a89019eae1 Schedule OpenBao retention closeout 2026-08-04 00:53:34 +02:00
custodian-sync
1c2f9af732 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-04:
  - workplan status: backlog → active
2026-08-04 00:33:52 +02:00
codex
f1839a9d95 Retire CoulombCore OpenBao reversibly 2026-08-04 00:19:26 +02:00
codex
b8ec0059de Complete OpenBao consumer migration waves 2026-08-03 21:40:29 +02:00
codex
cb428442eb Advance OpenBao migration to consumer waves 2026-08-03 21:30:17 +02:00
custodian-sync
9a1fcd9699 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-03:
  - RAILIANCE-WP-0020-T04: progress → wait
2026-08-03 20:35:53 +02:00
codex
ceed081c8d Prepare OpenBao authority migration 2026-08-03 18:50:13 +02:00
codex
a2c4ebfcd8 Plan OpenBao migration and restore Forgejo metadata 2026-07-30 15:38:18 +02:00
codex
4c4028ff05 Finish Knative Qonto framework workplan 2026-07-29 23:13:51 +02:00
codex
777e63c617 Record Qonto identity and runtime progress 2026-07-27 21:12:26 +02:00
codex
41c250e888 Advance Knative runtime workplan 2026-07-26 20:16:33 +02:00
codex
2e8378012e Track second-wave implementation evidence 2026-07-26 14:14:31 +02:00
codex
ffbd4178ce Launch second-wave implementation workplans 2026-07-26 13:39:49 +02:00
codex
8901ae4b15 Define derived rail and Qonto readiness architecture 2026-07-26 11:45:07 +02:00
codex
b6c24a7195 Finish first repo-family materialization wave 2026-07-26 08:51:13 +02:00
codex
bb04b71b49 Record rail-kubernetes remote reconciliation 2026-07-25 22:24:07 +02:00
codex
7d8478ee8f Record rail-kubernetes doc import progress 2026-07-25 19:40:40 +02:00
codex
3a7e53d09e Record first rail-kubernetes materialization progress 2026-07-25 18:58:29 +02:00
codex
f8200b269c Launch first repo-family materialization wave 2026-07-25 18:14:06 +02:00
codex
8022665b35 Establish Railiance architecture home 2026-07-25 10:54:37 +02:00