RPF-WP-0044: T01 done; exact T02/T03 commands pinned to c3ebd6d.
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
codex 2026-09-21 19:05:56 +02:00
parent c3ebd6dddc
commit 4ca88a14f0
2 changed files with 82 additions and 32 deletions

View file

@ -83,6 +83,14 @@ neutralises automated sync, then adopts one application at a time, each with
its own founder go-ahead. Read-only diff evidence: its own founder go-ahead. Read-only diff evidence:
`docs/evidence/argocd-phase-b-adoption-diff-2026-09-21.json`. `docs/evidence/argocd-phase-b-adoption-diff-2026-09-21.json`.
**railiance01 uses its own path (founder's Option A, RPF-WP-0044-T01).**
`argocd/railiance01/bootstrap/` declares the railiance01 AppProjects and a root
app with no `automated` block, reading `argocd/railiance01/applications/`
(empty until an adoption task). Child drafts wait in
`argocd/railiance01/drafts/`, which no root syncs. Never apply
`argocd/bootstrap/` (coulombcore's, automated) on railiance01; it and
`argocd/applications/` stay unchanged for coulombcore until phase C.
## Bootstrap Layout ## Bootstrap Layout
```text ```text

View file

@ -68,37 +68,44 @@ Application resource. Not verified: repo-server egress to Forgejo and
```task ```task
id: RPF-WP-0044-T01 id: RPF-WP-0044-T01
status: wait status: done
priority: high priority: high
state_hub_task_id: "2d7230f5-50c8-5eee-a050-1501ce5af62a" state_hub_task_id: "2d7230f5-50c8-5eee-a050-1501ce5af62a"
``` ```
**Waits on the founder's choice of layout.** Repository-only; applying **Done 2026-09-21, commit `c3ebd6d`.** The founder chose **Option A**
nothing. But coulombcore's ArgoCD still syncs `argocd/applications/` on (`GOVERN @ estate`): a railiance01-only source path. Repository-only; nothing
`main`, so an edit there is a live change on coulombcore. applied. `argocd/applications/` and `argocd/bootstrap/` are untouched, because
coulombcore's ArgoCD still reads `argocd/applications/` on `main` and its
bootstrap may be re-applied from `argocd/bootstrap/`. coulombcore could not be
read in this session, so the railiance01 bootstrap has its own path.
- **Option A (recommended):** a railiance01-only source path, Declared (all under `argocd/railiance01/`):
`argocd/railiance01/applications/`, starting empty, and the railiance01 root
pointing at it. `argocd/applications/` is left untouched for coulombcore
until phase C. No commit in this plan then reaches coulombcore.
- **Option B:** edit `argocd/applications/` in place. Every change also lands
on coulombcore's ArgoCD; needs its own go-ahead and a coulombcore read first.
Declared changes (Option A): 1. `bootstrap/`: the three AppProjects and `railiance-apps-root` with **no
`automated` block**, path `argocd/railiance01/applications`,
`targetRevision: main` (each sync pins its revision in the operation).
2. `bootstrap/01-railiance-tenants-project.yaml`: `postgresql.cnpg.io/Cluster`
added to `namespaceResourceWhitelist`. The other two AppProjects are copies
of `argocd/bootstrap/`.
3. `applications/` holds only `README.md`. A placeholder **is** needed: git does
not keep an empty directory and a missing path is a `ComparisonError`.
ArgoCD's directory source reads only `*.yaml`/`*.yml`/`*.json`, so it renders
zero children (confirmed live by T02).
4. `drafts/`: the four children, no `automated`, no finalizer, pinned:
openbao-secretstore `d2dbc19` (railiance-platform), issue-core `a78f38c`
(`rapp-issue-core.git`, path `manifests`), target-revenue `f1109d5`,
external-secrets chart `0.16.1`. No root syncs `drafts/`.
5. `argocd/repositories/rapp-issue-core.repository.sops.yaml.template` (no
value); `issue-core.repository.sops.yaml.template` marked obsolete.
1. Root app for railiance01 with **no `automated` block** and path Offline proof: `kubectl kustomize argocd/railiance01/bootstrap` renders exactly
`argocd/railiance01/applications`. 3 AppProjects and 1 Application with no `automated` field;
2. `railiance-tenants`: add `postgresql.cnpg.io/Cluster` to `ssh railiance01 'kubectl apply --dry-run=server -f -'` of that render
`namespaceResourceWhitelist` (target-revenue). returned rc=0 (all four "created (server dry run)").
3. Child Application drafts kept in this workplan until their task; each
without `automated`, without finalizers, with `targetRevision` pinned to a
commit or chart version.
4. `issue-core` draft repointed to `rapp-issue-core.git`, path `manifests`.
5. Add `argocd/repositories/rapp-issue-core.repository.sops.yaml.template`
(no value). Mark `issue-core.repository.sops.yaml.template` obsolete.
AppProjects and the root are applied by hand (T02), not synced by the root, Hazard kept as is: `make argocd-bootstrap-deploy` still defaults to
so these edits change nothing live until T02. `argocd/bootstrap` (automated root). Do not run it on railiance01.
## Apply the AppProjects and the root app, automated sync off (live) ## Apply the AppProjects and the root app, automated sync off (live)
@ -109,18 +116,26 @@ priority: high
state_hub_task_id: "7d97ee9c-b2fb-520f-8468-3ecf7eea6c01" state_hub_task_id: "7d97ee9c-b2fb-520f-8468-3ecf7eea6c01"
``` ```
**Waits on the founder's go-ahead.** Depends on T01. **Waits on the founder's go-ahead.** T01 is done. Applies the render of
`argocd/railiance01/bootstrap` at commit `c3ebd6dddc830373c75144da178f829b47c3e5de`, from a clean export (not
the working tree), then syncs the root by hand at that commit.
```bash ```bash
ssh railiance01 'kubectl apply --dry-run=server -f -' < <(kubectl kustomize argocd/bootstrap) cd ~/railiance-platform && git fetch origin && git merge-base --is-ancestor c3ebd6dddc830373c75144da178f829b47c3e5de origin/main && echo pinned-commit-on-main
ssh railiance01 'kubectl apply -f -' < <(kubectl kustomize argocd/bootstrap) R=$(mktemp -d) && git -C ~/railiance-platform archive c3ebd6dddc830373c75144da178f829b47c3e5de argocd/railiance01/bootstrap | tar -x -C "$R"
kubectl kustomize "$R/argocd/railiance01/bootstrap" > "$R/bootstrap.yaml" && grep -c '^kind: AppProject' "$R/bootstrap.yaml" && grep -c automated "$R/bootstrap.yaml" # expect 3 and 0
ssh railiance01 'kubectl apply --dry-run=server -f -' < "$R/bootstrap.yaml"
ssh railiance01 'kubectl apply -f -' < "$R/bootstrap.yaml"
ssh railiance01 'kubectl -n argocd patch application railiance-apps-root --type merge -p "{\"operation\":{\"initiatedBy\":{\"username\":\"founder-approved\"},\"sync\":{\"revision\":\"c3ebd6dddc830373c75144da178f829b47c3e5de\",\"prune\":false}}}"'
ssh railiance01 'kubectl -n argocd get appprojects,applications' ssh railiance01 'kubectl -n argocd get appprojects,applications'
ssh railiance01 'kubectl -n argocd get application railiance-apps-root -o jsonpath="{.status.sync.status} {.status.operationState.phase} {.status.operationState.syncResult.revision} resources={.status.resources}{\"\n\"}"'
``` ```
Expect three AppProjects and `railiance-apps-root` Synced with zero children Expect three AppProjects and `railiance-apps-root` `Synced`, operation
(the path is empty). A `ComparisonError` means the repo-server cannot reach `Succeeded` at `c3ebd6d`, and no resources (zero children). A
Forgejo: stop and fix egress before any app task. No repository Secret is `ComparisonError` means the repo-server cannot reach Forgejo: stop and fix
needed; `coulomb/railiance-platform` is public. egress before any app task. No repository Secret is needed;
`coulomb/railiance-platform` is public.
Rollback: `kubectl -n argocd delete application railiance-apps-root` (no Rollback: `kubectl -n argocd delete application railiance-apps-root` (no
finalizer, no children), then delete the three AppProjects. Nothing else is finalizer, no children), then delete the three AppProjects. Nothing else is
@ -133,8 +148,8 @@ Every adoption task follows the same steps. `<app>` and `<sha>` vary.
1. **Diff.** Re-run the evidence render and `kubectl diff --server-side` at 1. **Diff.** Re-run the evidence render and `kubectl diff --server-side` at
the commit or chart version being pinned. Any spec change, any missing the commit or chart version being pinned. Any spec change, any missing
whitelist kind, or a different image: stop. whitelist kind, or a different image: stop.
2. **Merge** the child Application (no `automated`) into the railiance01 2. **Merge** the child Application (no `automated`) from
path, then sync the root by hand so it creates the child object only: `argocd/railiance01/drafts/` into `argocd/railiance01/applications/`, then sync the root by hand so it creates the child object only:
```bash ```bash
ssh railiance01 'kubectl -n argocd patch application railiance-apps-root --type merge -p "{\"operation\":{\"initiatedBy\":{\"username\":\"founder-approved\"},\"sync\":{\"revision\":\"<sha>\",\"prune\":false}}}"' ssh railiance01 'kubectl -n argocd patch application railiance-apps-root --type merge -p "{\"operation\":{\"initiatedBy\":{\"username\":\"founder-approved\"},\"sync\":{\"revision\":\"<sha>\",\"prune\":false}}}"'
``` ```
@ -182,6 +197,33 @@ untracked (declared gap, RPF-WP-0043-T05). Live check:
`externalsecret/issue-core-runtime` stays `SecretSynced`. Workload restore: `externalsecret/issue-core-runtime` stays `SecretSynced`. Workload restore:
`kubectl apply -f argocd/platform-addons/openbao-secretstore/openbao.clustersecretstore.yaml`. `kubectl apply -f argocd/platform-addons/openbao-secretstore/openbao.clustersecretstore.yaml`.
Exact commands (the root sync pins the merge commit `$SHA`; the child is
pinned to `d2dbc19`, the last commit touching its source path):
```bash
# 1. Diff at the pinned source commit (expect no output, rc=0)
cd ~/railiance-platform && git fetch origin && git checkout main && git pull --ff-only
R=$(mktemp -d) && git archive d2dbc19c254247652c49fda8721c80d53bca206a argocd/platform-addons/openbao-secretstore | tar -x -C "$R"
ssh railiance01 'kubectl diff --server-side -f -' < <(kubectl kustomize "$R/argocd/platform-addons/openbao-secretstore"); echo rc=$?
# 2. Merge the child (drop the 3-line DRAFT header), push, sync the root at that commit
sed '1,3d' argocd/railiance01/drafts/openbao-secretstore.application.yaml > argocd/railiance01/applications/openbao-secretstore.application.yaml
git rm -q argocd/railiance01/drafts/openbao-secretstore.application.yaml
git add argocd/railiance01/applications/openbao-secretstore.application.yaml
git commit -m "Adopt openbao-secretstore on railiance01 (RPF-WP-0044-T03)" && git push origin main
SHA=$(git rev-parse HEAD) && echo "$SHA"
ssh railiance01 "kubectl -n argocd patch application railiance-apps-root --type merge -p '{\"operation\":{\"initiatedBy\":{\"username\":\"founder-approved\"},\"sync\":{\"revision\":\"$SHA\",\"prune\":false}}}'"
# 3. ArgoCD's own diff (expect OutOfSync or Synced, one resource ClusterSecretStore/openbao, metadata-only)
ssh railiance01 'kubectl -n argocd get application openbao-secretstore -o jsonpath="{.status.sync.status} {.status.health.status} {.status.resources}{\"\n\"}"'
# 4. Manual sync, prune off, apply strategy (hooks skipped)
ssh railiance01 'kubectl -n argocd patch application openbao-secretstore --type merge -p "{\"operation\":{\"initiatedBy\":{\"username\":\"founder-approved\"},\"sync\":{\"revision\":\"d2dbc19c254247652c49fda8721c80d53bca206a\",\"prune\":false,\"syncStrategy\":{\"apply\":{}}}}}"'
ssh railiance01 'kubectl -n argocd get application openbao-secretstore -o jsonpath="{.status.sync.status} {.status.health.status} {.status.operationState.phase}{\"\n\"}"'
ssh railiance01 'kubectl get clustersecretstore openbao; kubectl -n issue-core get externalsecret issue-core-runtime'
```
Rollback (R1): `git revert` the merge commit and push, then
`ssh railiance01 'kubectl -n argocd delete application openbao-secretstore'`
(no finalizer; the ClusterSecretStore keeps running).
## Adopt issue-core (from rapp-issue-core) ## Adopt issue-core (from rapp-issue-core)
```task ```task