docs: record hub-core credential handoff
This commit is contained in:
parent
fe40bdb395
commit
4689645621
2 changed files with 10 additions and 2 deletions
|
|
@ -94,7 +94,7 @@
|
|||
| task | RAILIANCE-WP-0022-T05 | wait | — | workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md |
|
||||
| task | RAILIANCE-WP-0023-T01 | done | — | workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md |
|
||||
| task | RAILIANCE-WP-0023-T02 | progress | — | workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md |
|
||||
| task | RAILIANCE-WP-0023-T03 | wait | — | workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md |
|
||||
| task | RAILIANCE-WP-0023-T03 | done | — | workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md |
|
||||
| task | RPF-WP-0018-T01 | done | — | workplans/RPF-WP-0018-policy-surface-alignment.md |
|
||||
| task | RPF-WP-0018-T02 | done | — | workplans/RPF-WP-0018-policy-surface-alignment.md |
|
||||
| task | RPF-WP-0018-T03 | done | — | workplans/RPF-WP-0018-policy-surface-alignment.md |
|
||||
|
|
|
|||
|
|
@ -41,13 +41,21 @@ Apply the reviewed policy and projections after rapp-postgres creates the
|
|||
roles. Verify store validity, SecretSynced status, role separation, and lease
|
||||
rotation without reading or logging values.
|
||||
|
||||
The exact policy, projections, SecretSynced state, role separation, and
|
||||
production runtime/migration handoff passed on 2026-08-21. Keep this task in
|
||||
progress for the deliberate lease-rotation observation during stabilization.
|
||||
|
||||
## Hand off the private candidate
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0023-T03
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Confirm both Secret metadata objects are ready, then hand the candidate
|
||||
migration and rollout gate back to `RAPPCOREHUB-WP-0002-T03`.
|
||||
|
||||
Completed 2026-08-21. Both projected Secret metadata objects were Ready, the
|
||||
migration completed, and the candidate advanced through all route groups to
|
||||
production authority without exposing credential values.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue