Define rapp-openbao boundary
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

This commit is contained in:
codex 2026-07-25 11:22:50 +02:00
parent 25214d70fd
commit 482347aebb
5 changed files with 125 additions and 10 deletions

View file

@ -40,7 +40,7 @@ It must not:
```task
id: RAILIANCE-WP-0012-T01
status: todo
status: done
priority: high
state_hub_task_id: "498a89e1-67e1-4860-8c73-cc38dd92083c"
```
@ -52,11 +52,15 @@ Classify the current OpenBao-related files into:
Done when the distinction is written against real file paths and current usage.
2026-07-25: Added `docs/rapp-openbao-boundary.md` with file-path classification
for OpenBao package assets, split-before-move assets, and retained S3
governance material.
## T02 - Define the first `rapp-openbao` move set
```task
id: RAILIANCE-WP-0012-T02
status: todo
status: done
priority: high
state_hub_task_id: "67526f71-0220-45fb-ab9d-8cef5628257c"
```
@ -70,11 +74,15 @@ Prepare the first move set for the wrapper, including likely candidates such as:
Done when the future wrapper has a concrete first file inventory.
2026-07-25: Recorded the first move set in
`docs/rapp-openbao-boundary.md`, centered on Helm values, UI overlay assets,
OpenBao deploy/verify helpers, and the matching `Makefile` targets.
## T03 - Record the retained S3 platform responsibilities
```task
id: RAILIANCE-WP-0012-T03
status: todo
status: done
priority: high
state_hub_task_id: "30036060-85ec-4a24-a428-9f31dd58f853"
```
@ -88,6 +96,10 @@ Record what must remain in `railiance-platform`, including:
Done when the wrapper cannot be mistaken for the new S3 ownership home.
2026-07-25: Recorded retained S3 responsibilities in
`docs/rapp-openbao-boundary.md`, including platform-admin policy, workload KV
lane governance, delegated automation, credential grants, and SSH signing.
## T04 - Prepare the repo-creation handoff for `rapp-openbao`
```task