Document rapp-openbao compatibility handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

This commit is contained in:
codex 2026-07-26 10:39:40 +02:00
parent 963b1caceb
commit 09c6e41caa
6 changed files with 131 additions and 19 deletions

View file

@ -1,6 +1,6 @@
# rapp-openbao Boundary
This document records the first-wave boundary for extracting a future
This document records the first-wave boundary for extracting the wave-1
`rapp-openbao` repo out of `railiance-platform`.
The rule is simple:
@ -9,7 +9,7 @@ The rule is simple:
- `railiance-platform` keeps secret custody, policy, lane governance, and
platform-wide operator controls
## Package Assets For Future `rapp-openbao`
## Package Assets For `rapp-openbao`
These files describe or implement the OpenBao workload package itself and are
valid candidates for a dedicated wrapper repo.
@ -58,7 +58,7 @@ These files and concerns stay in S3 even after a wrapper repo exists.
## First Move Set
The first repo-creation handoff for `rapp-openbao` should start with the least
The initial repo-creation handoff for `rapp-openbao` started with the least
coupled package assets:
- `helm/openbao-values.yaml`
@ -75,6 +75,9 @@ coupled package assets:
This first move set is enough to establish a package repo that can render,
deploy, and verify OpenBao without inheriting platform lane governance.
The migration-window compatibility path between `railiance-platform` and
`rapp-openbao` now lives in `docs/rapp-openbao-compatibility-handoff.md`.
## Resulting Rule
`rapp-openbao` may own how OpenBao is packaged, deployed, verified, and skinned