From 119277ec938023a41c8af49232d08e4dfd5ee821 Mon Sep 17 00:00:00 2001 From: codex Date: Mon, 21 Sep 2026 19:09:41 +0200 Subject: [PATCH] Record RPF-WP-0044 T02 done and T03 adopted (proving period). Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703 --- ...09-21-openbao-secretstore-argocd-adoption.json | 15 +++++++++++++++ ...-argocd-phase-b-adopt-existing-applications.md | 12 ++++++++---- 2 files changed, 23 insertions(+), 4 deletions(-) create mode 100644 docs/evidence/2026-09-21-openbao-secretstore-argocd-adoption.json diff --git a/docs/evidence/2026-09-21-openbao-secretstore-argocd-adoption.json b/docs/evidence/2026-09-21-openbao-secretstore-argocd-adoption.json new file mode 100644 index 0000000..d88a728 --- /dev/null +++ b/docs/evidence/2026-09-21-openbao-secretstore-argocd-adoption.json @@ -0,0 +1,15 @@ +{ + "schema": "railiance-platform.argocd-adoption.v1", + "task": "RPF-WP-0044-T03", + "application": "openbao-secretstore", + "cluster": "railiance01 (92.205.62.239)", + "decided_by": "founder (GOVERN @ estate), 2026-09-21", + "mode": "ADMINISTER @ realm:kubernetes/railiance01, activation=APPROVED", + "performed_by": "the-custodian session", + "source": {"repo": "coulomb/railiance-platform", "path": "argocd/platform-addons/openbao-secretstore", "revision": "d2dbc19c254247652c49fda8721c80d53bca206a"}, + "root": {"application": "railiance-apps-root", "bootstrap_revision": "c3ebd6dddc830373c75144da178f829b47c3e5de", "adoption_merge_revision": "182e78852c9caea477f6c7058bb477075be024e5", "automated": false}, + "pre_sync_diff": {"method": "kubectl diff --server-side of kustomize render at d2dbc19", "rc": 0, "objects": ["ClusterSecretStore/openbao"]}, + "sync": {"strategy": "apply", "prune": false, "phase": "Succeeded", "sync_status": "Synced", "health": "Healthy", "automated": false}, + "live_checks": {"clustersecretstore_openbao": "Valid", "externalsecret_issue-core-runtime": "SecretSynced", "tracking_id": "openbao-secretstore:external-secrets.io/ClusterSecretStore:external-secrets/openbao", "externalsecrets_ready": "32/37 (5 failing pre-existing: expired OpenBao tokens on openbao-activity-core and openbao-email-connect, unrelated)"}, + "next": "24h proving period; selfHeal only with a second founder go-ahead; prune a third step" +} diff --git a/workplans/RPF-WP-0044-argocd-phase-b-adopt-existing-applications.md b/workplans/RPF-WP-0044-argocd-phase-b-adopt-existing-applications.md index e8786d3..5c0c588 100644 --- a/workplans/RPF-WP-0044-argocd-phase-b-adopt-existing-applications.md +++ b/workplans/RPF-WP-0044-argocd-phase-b-adopt-existing-applications.md @@ -111,12 +111,14 @@ Hazard kept as is: `make argocd-bootstrap-deploy` still defaults to ```task id: RPF-WP-0044-T02 -status: wait +status: done priority: high state_hub_task_id: "7d97ee9c-b2fb-520f-8468-3ecf7eea6c01" ``` -**Waits on the founder's go-ahead.** T01 is done. Applies the render of +**Done 2026-09-21** (founder go-ahead; custodian session). 3 AppProjects + `railiance-apps-root` applied from the clean export of `c3ebd6d`; root Synced/Healthy, op Succeeded at `c3ebd6d`, zero children, 0 ArgoCD-managed namespaces. Repo-server reaches Forgejo. One `OrphanedResourceWarning` (project-level, informational). + + Applies the render of `argocd/railiance01/bootstrap` at commit `c3ebd6dddc830373c75144da178f829b47c3e5de`, from a clean export (not the working tree), then syncs the root by hand at that commit. @@ -183,12 +185,14 @@ Rollback: ```task id: RPF-WP-0044-T03 -status: wait +status: progress priority: high state_hub_task_id: "6d5fc801-e361-579b-bcd8-6fe719a82e94" ``` -**Waits on the founder's go-ahead.** Depends on T02. One object, +**Adopted 2026-09-21** (founder go-ahead; custodian session): diff at `d2dbc19` rc=0; child merged in `182e788`; root synced at `182e788`; child manual sync (apply strategy, prune off) Succeeded at `d2dbc19`, Synced/Healthy, automated off. `ClusterSecretStore/openbao` Valid with tracking annotation; `issue-core-runtime` SecretSynced. Status `progress` = in the 24h proving period; `selfHeal` needs a second go-ahead. Evidence: `docs/evidence/2026-09-21-openbao-secretstore-argocd-adoption.json`. + +One object, `ClusterSecretStore/openbao`, zero diff, public source. It is the store issue-core's `ExternalSecret` reads, so adopt it before issue-core. The 24 other ClusterSecretStores on railiance01 are not in the kustomization and stay