Implement S3 service assurance and admission checks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 11:43:55 +02:00
parent 8f828c7609
commit 234b1b559f
21 changed files with 1728 additions and 30 deletions

View file

@ -0,0 +1,95 @@
{
"schema": "railiance-platform.admission.v1",
"basis": "source-declarations",
"cells": {
"apps-pg": {
"consumers": [
"coulomb_social",
"vergabe"
],
"ceiling": 3,
"retention_days": 30,
"instances": 1,
"memory_limit": "1Gi",
"max_connections": 100,
"service_classes": {
"coulomb_social": "interactive",
"vergabe": "interactive"
},
"connection_limits": {
"vergabe": 20,
"coulomb_social": 20
},
"owners": {
"coulomb_social": "coulomb-social",
"vergabe": "vergabe-teilnahme"
}
},
"apps-pg-2": {
"consumers": [],
"ceiling": 3,
"retention_days": 30,
"instances": 1,
"memory_limit": "1Gi",
"max_connections": 100,
"service_classes": {},
"connection_limits": {},
"owners": {}
},
"platform-pg": {
"consumers": [
"audit-core",
"core-hub",
"isolation-probe",
"tenant-engine"
],
"ceiling": 4,
"retention_days": 30,
"instances": 1,
"memory_limit": "1Gi",
"max_connections": 100,
"service_classes": {
"audit-core": "batch",
"core-hub": "latency-critical",
"isolation-probe": "interactive",
"tenant-engine": "latency-critical"
},
"owners": {
"audit-core": "audit-core",
"core-hub": "core-hub",
"isolation-probe": "rapp-postgres",
"tenant-engine": "tenant-engine"
}
},
"platform-pg-2": {
"consumers": [
"sbom-nexus"
],
"ceiling": 4,
"retention_days": 30,
"instances": 1,
"memory_limit": "1Gi",
"max_connections": 100,
"service_classes": {
"sbom-nexus": "interactive"
},
"owners": {
"sbom-nexus": "sbom-nexus"
}
}
},
"sources": {
"railiance-platform/helm/apps-pg-cluster.yaml": "9885c81338e1c3bdb0558839552315720068c5d355819e4a1320fbd677d0ffcf",
"railiance-platform/helm/apps-pg-2-cluster.yaml": "e9e615a0b5de8597a5501b2d8740a763ba3622cbebb765ce651236c2175de942",
"rapp-postgres/consumers/audit-core.yaml": "a2db53f901df056546b2c028f287f8fc50486e6e6cd81026b9e926b6b64272b3",
"rapp-postgres/consumers/core-hub.yaml": "8fe3e8b4488548b2f5e01f1d46edd9fd5fe4f0e4f65a3821f172adbfb5ae1d84",
"rapp-postgres/consumers/isolation-probe.yaml": "8ea24d3bd04ab683b47ceff2586932ea4fdb0d45c49896167bb5b352a67a5cfb",
"rapp-postgres/consumers/sbom-nexus.yaml": "0b21d05fe7b9d21cbc9eb761f455329739ceb71f8dd3d1200971426962c11236",
"rapp-postgres/consumers/tenant-engine.yaml": "92f36d587f001c86ff401aedd25cb49fa171d49e000b0a6ab551e182e5c11448",
"railiance-platform/tools/verify_apps_pg_capacity.py": "b571ec63b0a7501dabba37a84af9d2cfcb7737ed891a7ea2ab05c54010b1893e",
"railiance-platform/assurance/placement-owners.json": "b9a52f755552dc4bb83536dca8aadca691a4f8bc47089e9e1962902abcec7aa2",
"rapp-postgres/scripts/render_consumers.py": "2dcfd68f94a3d6c7e1072c4a55a497b1697eab30acaecae53865c9b1a596773a",
"rapp-postgres/helm/platform-pg-cluster.yaml": "461da0d43e61a4ddca29d6e98080b8b1642bd3303f3395da1b0beb28775c2c5c",
"rapp-postgres/helm/platform-pg-2-cluster.yaml": "06b92a76189b1a33d1eee3f5c835a3e94269ad7b040383c04e8028c2c3fe766a"
}
}

View file

@ -0,0 +1,131 @@
{
"schema": "railiance-platform.ownership-handoffs.v1",
"reviewed": "2026-09-05",
"decision": "retain existing operational entry points through review; no bulk move",
"records": [
{
"surface": "forge-runtime",
"proposed_accepting_owner": "railiance-forge",
"status": "retained-pending-acceptance",
"review_due": "2026-10-05",
"callers_to_verify": "activity-core command definitions and railiance-apps compatibility callers",
"source_files": [
{
"path": "tools/cmd/forgejo-backup",
"sha256": "a20f0aebb22f0978c0f45f74e4ac55a927b080910844296acabec10f45110cb6"
},
{
"path": "tools/cmd/forgejo-package-prune",
"sha256": "66bababca54931115831aa42b7ad95bb4ee348d4057b5bfd1f5a6ae13cfa8ea3"
},
{
"path": "scripts/forgejo_package_prune.py",
"sha256": "63ba4df1c937a0067ea3bb4b1efbe4cfa47205f34e80f337ca71e4a0e6a31db4"
},
{
"path": "tools/cmd/refresh-live-images",
"sha256": "341676396e2c2a85f4585fcbf5c7e085805c9228eae8961740e19960ef2ba5ea"
},
{
"path": "scripts/refresh_live_images.py",
"sha256": "d1bcd88f3b757d98fa4cfa033329fe7b230f7bf1c6b466fc9cccc6804edf12b6"
},
{
"path": "docs/forgejo-backup.md",
"sha256": "69f6f38de902b80c6de161087b1d5738d1dea7ea35b3d49816d2ea67a1a5329b"
},
{
"path": "docs/forgejo-package-prune.md",
"sha256": "4f389876f52ba273f6a43c2d7d721a64c520ed9620e4a04899a423775224572a"
}
],
"acceptance": "Owner names canonical replacements; update all callers and prove dry-run/smoke and rollback before source removal. No external acceptance asserted."
},
{
"surface": "openbao-package",
"proposed_accepting_owner": "rapp-openbao",
"status": "retained-pending-acceptance",
"review_due": "2026-10-05",
"callers_to_verify": "Makefile package dispatch and existing operator entry points",
"source_files": [
{
"path": "scripts/openbao-verify.sh",
"sha256": "1e118570c8682619a46413f55fa4690482db342f6b6c83e6644c908aa7a667ee"
},
{
"path": "scripts/openbao-verify-login-overlay.sh",
"sha256": "57438714f1b7aac0c37b8bdf525c5387f812a6d30532bb98b395e5db5208ad6d"
},
{
"path": "docs/rapp-openbao-compatibility-handoff.md",
"sha256": "65ff0b39ee7312c8a242d24cf3434f9d0636a830e841f1a70de560c96cd8d57f"
}
],
"acceptance": "Owner names canonical replacements; update all callers and prove dry-run/smoke and rollback before source removal. No external acceptance asserted."
},
{
"surface": "gitops-bootstrap",
"proposed_accepting_owner": "railiance-cluster / railiance-enablement",
"status": "retained-pending-acceptance",
"review_due": "2026-10-05",
"callers_to_verify": "cluster bootstrap and generic GitOps entry points",
"source_files": [
{
"path": "argocd/bootstrap/00-railiance-bootstrap-project.yaml",
"sha256": "1fcdff98b1870e8867df65deeabd759e1357f0359af50ac6229f12ea3ec695ea"
},
{
"path": "argocd/bootstrap/01-railiance-tenants-project.yaml",
"sha256": "cf1823ed2294b874730de6d908c0f471d9b67f9ac07bb51a1456de6f77154d07"
},
{
"path": "argocd/bootstrap/02-railiance-platform-addons-project.yaml",
"sha256": "10b4596dcf6ac369329794612b2f43469a6f4ea1fa99759f92d1d66a50841cf8"
},
{
"path": "argocd/bootstrap/10-railiance-apps-root.application.yaml",
"sha256": "0eadd51880488442b6c8ed31470fa27c123637b97d66c56a2489d06a03a3c0ba"
},
{
"path": "argocd/bootstrap/kustomization.yaml",
"sha256": "5eaa17dc142ad134ef044fa9914eaea3ecaa5572b705be8e89660ecdb8a15b99"
}
],
"acceptance": "Owner names canonical replacements; update all callers and prove dry-run/smoke and rollback before source removal. No external acceptance asserted."
},
{
"surface": "application-releases",
"proposed_accepting_owner": "railiance-apps / individual package owners",
"status": "retained-pending-acceptance",
"review_due": "2026-10-05",
"callers_to_verify": "ArgoCD application reconciliation",
"source_files": [
{
"path": "argocd/applications/target-revenue.application.yaml",
"sha256": "c59ff45f7cf5dae47cf39c32fbcde3a614aa79be6a9edb07079f833cde1fa38b"
},
{
"path": "argocd/applications/external-secrets.application.yaml",
"sha256": "545d560c35ab1515f444099847730d7e9d8b7bd14beb30878ebc2f4bd99a5080"
},
{
"path": "argocd/applications/openbao-secretstore.application.yaml",
"sha256": "01ca88f200be6c23926b0ccf17ef7a3ab0d247044469edd92e9571820119943b"
},
{
"path": "argocd/applications/issue-core.application.yaml",
"sha256": "079fdb118996eed8e579f6a658dc11a153c8fc20998daf6379533d30eb339654"
}
],
"acceptance": "Owner names canonical replacements; update all callers and prove dry-run/smoke and rollback before source removal. No external acceptance asserted."
},
{
"surface": "derived-record-aliases",
"proposed_accepting_owner": "repo-manager / state-hub",
"status": "retained-pending-owner-repair",
"review_due": "2026-10-05",
"source_ref": "history/2026-09-05-platform-intent-workplan-assessment.md#derived-state-caveat",
"acceptance": "Scoped legacy alias retirement and generated brief agree with canonical source; no UUID edits or blanket retirement."
}
]
}

View file

@ -0,0 +1,9 @@
{
"vergabe": {"owner": "vergabe-teilnahme", "cell": "apps-pg", "service_class": "interactive", "evidence": "docs/evidence/RPF-WP-0019-isolation-2026-08-20.md"},
"coulomb_social": {"owner": "coulomb-social", "cell": "apps-pg", "service_class": "interactive", "evidence": "docs/evidence/RPF-WP-0019-isolation-2026-08-20.md"},
"audit-core": {"owner": "audit-core", "cell": "platform-pg", "evidence": "rapp-postgres/consumers/audit-core.yaml"},
"tenant-engine": {"owner": "tenant-engine", "cell": "platform-pg", "evidence": "rapp-postgres/docs/evidence/tenant-engine-postgres-cutover-2026-08-21.md"},
"core-hub": {"owner": "core-hub", "cell": "platform-pg", "evidence": "docs/evidence/core-hub-postgres-capacity-admission-2026-08-20.md"},
"isolation-probe": {"owner": "rapp-postgres", "cell": "platform-pg", "evidence": "rapp-postgres/consumers/isolation-probe.yaml"},
"sbom-nexus": {"owner": "sbom-nexus", "cell": "platform-pg-2", "evidence": "rapp-postgres/docs/evidence/RAPP-POSTGRES-WP-0005-T04-boundary-restore-2026-08-22.md"}
}

View file

@ -0,0 +1,96 @@
{
"schema": "railiance-platform.assurance-contract.v1",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"capture_max_age_seconds": 900,
"threshold_status": "local-diagnostic-only",
"signals": {
"apps-pg.ready": {
"owner": "railiance-platform",
"max_age_seconds": 900
},
"apps-pg.backup": {
"owner": "railiance-platform",
"max_age_seconds": 129600
},
"apps-pg.wal": {
"owner": "railiance-platform",
"max_age_seconds": 900
},
"apps-pg.restore": {
"owner": "railiance-platform",
"max_age_seconds": 2592000
},
"apps-pg.headroom": {
"owner": "railiance-platform",
"max_age_seconds": 900
},
"platform-pg.ready": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"platform-pg.backup": {
"owner": "rapp-postgres",
"max_age_seconds": 129600
},
"platform-pg.wal": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"platform-pg.restore": {
"owner": "rapp-postgres",
"max_age_seconds": 2592000
},
"platform-pg.headroom": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"platform-pg-2.ready": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"platform-pg-2.backup": {
"owner": "rapp-postgres",
"max_age_seconds": 129600
},
"platform-pg-2.wal": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"platform-pg-2.restore": {
"owner": "rapp-postgres",
"max_age_seconds": 2592000
},
"platform-pg-2.headroom": {
"owner": "rapp-postgres",
"max_age_seconds": 900
},
"openbao.seal": {
"owner": "railiance-platform",
"max_age_seconds": 900
},
"openbao.snapshot": {
"owner": "railiance-platform",
"max_age_seconds": 129600
},
"openbao.restore": {
"owner": "railiance-platform",
"max_age_seconds": 2592000
},
"offsite.upload": {
"owner": "railiance-platform",
"max_age_seconds": 129600
},
"offsite.restore": {
"owner": "railiance-platform",
"max_age_seconds": 2592000
},
"eso.ready": {
"owner": "railiance-platform",
"max_age_seconds": 900
},
"eso.refresh": {
"owner": "railiance-platform",
"max_age_seconds": 3600
}
}
}

View file

@ -0,0 +1,198 @@
{
"schema": "railiance-platform.service-records.v1",
"reviewed": "2026-09-05",
"review_owner": "railiance-platform",
"review_scope": "S3 disclosure of unsupported guarantees; not external package approval",
"services": [
{
"service": "apps-pg",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-platform",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"vergabe",
"coulomb_social"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"retention": "30 days",
"existing_evidence": "docs/evidence/RPF-WP-0019-backup-restore-2026-08-20.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "platform-pg",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-postgres",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"audit-core",
"tenant-engine",
"core-hub",
"isolation-probe"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"retention": "30 days",
"existing_evidence": "rapp-postgres/docs/evidence/backup-restore-2026-08-13.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "platform-pg-2",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-postgres",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"sbom-nexus"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"retention": "30 days",
"existing_evidence": "rapp-postgres/docs/evidence/RAPP-POSTGRES-WP-0005-T04-boundary-restore-2026-08-22.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "openbao",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-openbao",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"approved credential lanes"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"retention": "KV history/audit/snapshot retention not accepted",
"existing_evidence": "reviews/WARDEN-WP-0027-T02-DRILL-20260822-01-openbao-snapshot-receipt.json",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "forgejo-backup",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-forge",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"forgejo"
],
"failure_domain": "source host plus separately encrypted Nextcloud copy",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"retention": "14 daily + 4 weekly target; local 7/type",
"existing_evidence": "docs/forgejo-backup.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "cnpg-option-a",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-platform",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"production-of-record CNPG logical dumps"
],
"failure_domain": "source host plus separately encrypted Nextcloud copy",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"retention": "offsite retention not accepted",
"existing_evidence": "docs/cnpg-option-a-backup.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
}
]
}