2026-07-25 10:41:51 +02:00
|
|
|
---
|
2026-08-25 22:58:35 +02:00
|
|
|
id: RPF-WP-0006
|
2026-07-25 10:41:51 +02:00
|
|
|
type: workplan
|
|
|
|
|
title: "rapp-openbao extraction boundary"
|
|
|
|
|
domain: financials
|
|
|
|
|
repo: railiance-platform
|
2026-07-26 10:39:40 +02:00
|
|
|
status: finished
|
2026-07-25 10:41:51 +02:00
|
|
|
owner: codex
|
|
|
|
|
topic_slug: railiance
|
|
|
|
|
created: "2026-07-25"
|
2026-07-26 10:39:40 +02:00
|
|
|
updated: "2026-07-26"
|
2026-08-25 22:58:35 +02:00
|
|
|
state_hub_workstream_id: "8d292bab-76dd-5ac3-b39d-6bc460ce27d7"
|
2026-07-25 10:41:51 +02:00
|
|
|
---
|
|
|
|
|
|
2026-08-25 22:58:35 +02:00
|
|
|
# RPF-WP-0006 - rapp-openbao extraction boundary
|
2026-07-25 10:41:51 +02:00
|
|
|
|
|
|
|
|
## Goal
|
|
|
|
|
|
|
|
|
|
Prepare the first `rapp-*` extraction by separating the OpenBao workload package
|
|
|
|
|
surface from the broader S3 platform ownership in `railiance-platform`.
|
|
|
|
|
|
|
|
|
|
This workplan follows the first-wave `rapp-*` order defined in
|
|
|
|
|
`/home/worsch/railiance-master/docs/rapp-first-wave-candidates.md`.
|
|
|
|
|
|
|
|
|
|
## Boundaries
|
|
|
|
|
|
|
|
|
|
This workplan may:
|
|
|
|
|
|
|
|
|
|
- identify which OpenBao assets belong to a future `rapp-openbao`
|
|
|
|
|
- record which OpenBao-related concerns remain platform-owned
|
|
|
|
|
- prepare the handoff contract between the future wrapper and S3 platform policy
|
|
|
|
|
|
|
|
|
|
It must not:
|
|
|
|
|
|
|
|
|
|
- weaken `railiance-platform` as the owner of secrets custody and policy
|
|
|
|
|
- move shared credential lane or approval machinery into the workload wrapper
|
|
|
|
|
- require a repo rename or live deployment change before the package boundary is clear
|
|
|
|
|
|
|
|
|
|
## T01 - Separate package assets from platform-governance assets
|
|
|
|
|
|
|
|
|
|
```task
|
2026-08-25 22:58:35 +02:00
|
|
|
id: RPF-WP-0006-T01
|
2026-07-25 11:22:50 +02:00
|
|
|
status: done
|
2026-07-25 10:41:51 +02:00
|
|
|
priority: high
|
2026-08-25 22:58:35 +02:00
|
|
|
state_hub_task_id: "5c0e5411-e47a-5a90-9005-b01762351c0a"
|
2026-07-25 10:41:51 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Classify the current OpenBao-related files into:
|
|
|
|
|
|
|
|
|
|
- workload package assets for `rapp-openbao`
|
|
|
|
|
- shared platform governance and policy that stays in `railiance-platform`
|
|
|
|
|
|
|
|
|
|
Done when the distinction is written against real file paths and current usage.
|
|
|
|
|
|
2026-07-25 11:22:50 +02:00
|
|
|
2026-07-25: Added `docs/rapp-openbao-boundary.md` with file-path classification
|
|
|
|
|
for OpenBao package assets, split-before-move assets, and retained S3
|
|
|
|
|
governance material.
|
|
|
|
|
|
2026-07-25 10:41:51 +02:00
|
|
|
## T02 - Define the first `rapp-openbao` move set
|
|
|
|
|
|
|
|
|
|
```task
|
2026-08-25 22:58:35 +02:00
|
|
|
id: RPF-WP-0006-T02
|
2026-07-25 11:22:50 +02:00
|
|
|
status: done
|
2026-07-25 10:41:51 +02:00
|
|
|
priority: high
|
2026-08-25 22:58:35 +02:00
|
|
|
state_hub_task_id: "3e5f8893-d440-5ce5-a436-3f84edad2e7b"
|
2026-07-25 10:41:51 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Prepare the first move set for the wrapper, including likely candidates such as:
|
|
|
|
|
|
|
|
|
|
- Helm values and middleware for the OpenBao workload
|
|
|
|
|
- UI overlay wrapper assets
|
|
|
|
|
- workload-specific deploy/verify scripts
|
|
|
|
|
- workload-health and recovery runbooks
|
|
|
|
|
|
|
|
|
|
Done when the future wrapper has a concrete first file inventory.
|
|
|
|
|
|
2026-07-25 11:22:50 +02:00
|
|
|
2026-07-25: Recorded the first move set in
|
|
|
|
|
`docs/rapp-openbao-boundary.md`, centered on Helm values, UI overlay assets,
|
|
|
|
|
OpenBao deploy/verify helpers, and the matching `Makefile` targets.
|
|
|
|
|
|
2026-07-25 10:41:51 +02:00
|
|
|
## T03 - Record the retained S3 platform responsibilities
|
|
|
|
|
|
|
|
|
|
```task
|
2026-08-25 22:58:35 +02:00
|
|
|
id: RPF-WP-0006-T03
|
2026-07-25 11:22:50 +02:00
|
|
|
status: done
|
2026-07-25 10:41:51 +02:00
|
|
|
priority: high
|
2026-08-25 22:58:35 +02:00
|
|
|
state_hub_task_id: "9a6a2cd9-9306-5721-9652-85f007043c19"
|
2026-07-25 10:41:51 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Record what must remain in `railiance-platform`, including:
|
|
|
|
|
|
|
|
|
|
- runtime secret custody as a platform capability
|
|
|
|
|
- workload lane policy and approval flows
|
|
|
|
|
- cross-workload secret delivery conventions
|
|
|
|
|
- platform-wide operator guidance that is not OpenBao-package specific
|
|
|
|
|
|
|
|
|
|
Done when the wrapper cannot be mistaken for the new S3 ownership home.
|
|
|
|
|
|
2026-07-25 11:22:50 +02:00
|
|
|
2026-07-25: Recorded retained S3 responsibilities in
|
|
|
|
|
`docs/rapp-openbao-boundary.md`, including platform-admin policy, workload KV
|
|
|
|
|
lane governance, delegated automation, credential grants, and SSH signing.
|
|
|
|
|
|
2026-07-25 10:41:51 +02:00
|
|
|
## T04 - Prepare the repo-creation handoff for `rapp-openbao`
|
|
|
|
|
|
|
|
|
|
```task
|
2026-08-25 22:58:35 +02:00
|
|
|
id: RPF-WP-0006-T04
|
2026-07-26 10:39:40 +02:00
|
|
|
status: done
|
2026-07-25 10:41:51 +02:00
|
|
|
priority: medium
|
2026-08-25 22:58:35 +02:00
|
|
|
state_hub_task_id: "a276f76b-48a7-512c-b0f8-786225d88683"
|
2026-07-25 10:41:51 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Blocked on T01-T03 and the creation of the future `rapp-openbao` repo.
|
|
|
|
|
|
|
|
|
|
Prepare the minimal handoff needed to create the wrapper repo without breaking
|
|
|
|
|
current operators or losing source-of-truth clarity inside `railiance-platform`.
|
|
|
|
|
|
|
|
|
|
Done when the future package extraction can start from a stable boundary.
|
|
|
|
|
|
2026-07-26 10:39:40 +02:00
|
|
|
2026-07-26: Added `docs/rapp-openbao-compatibility-handoff.md` to define the
|
|
|
|
|
current migration-window split: `rapp-openbao` is now the canonical home for
|
|
|
|
|
package-owned deploy/overlay/smoke assets, while `railiance-platform` retains
|
|
|
|
|
bootstrap, policy, credential-lane governance, and authenticated verification.
|
|
|
|
|
`docs/rapp-openbao-boundary.md`, `docs/openbao.md`, and `SCOPE.md` now point to
|
|
|
|
|
that split explicitly, so current operators can keep using temporary platform
|
|
|
|
|
copies without losing source-of-truth clarity.
|
|
|
|
|
|
2026-07-25 10:41:51 +02:00
|
|
|
## Notes
|
|
|
|
|
|
|
|
|
|
This workplan is repo-local. The framework-level sequencing stays in
|
2026-08-14 14:29:19 +02:00
|
|
|
`railiance-master/workplans/RMASTER-WP-0017-rail-rapp-reef-repo-separation.md`.
|