feat: prepare scoped State Hub preflight signing custody and rotation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
This commit is contained in:
parent
a46a6d8213
commit
5d288938f7
4 changed files with 117 additions and 8 deletions
|
|
@ -1,6 +1,6 @@
|
|||
# State Hub repository-rename preflight signing lane
|
||||
|
||||
Status: proposed, not provisioned. Owner: railiance-platform, RPF-WP-0034.
|
||||
Status: implementation staged, not provisioned. Owner: railiance-platform, RPF-WP-0035-T04.
|
||||
Demand: State Hub message `cd52ba10-de41-46ce-aa8b-9b44050da8f7`,
|
||||
STATE-WP-0085-T09. Provisioning this lane does not authorize any repository rename.
|
||||
|
||||
|
|
@ -112,3 +112,12 @@ and the migration owner must confirm the target runtime and continued need
|
|||
before provisioning this design. RPF-WP-0035-T04 is the current platform task;
|
||||
RPF-WP-0034 is the archived design record. No demand withdrawal or activation
|
||||
is inferred from retirement planning alone.
|
||||
|
||||
## Implementation preparation — 2026-09-05
|
||||
|
||||
CCR-2026-0015, the exact data-only policy and bounded role, namespace-scoped
|
||||
ESO manifests, silent CAS writer and API-only chart binding are staged.
|
||||
The fresh live fixture has only the signing-unavailable blocker.
|
||||
`state-hub-preflight-activation.md` supplies the controlled-outage rotation
|
||||
fence and recovery sequence. Live acceptance still requires attended OIDC/MFA;
|
||||
the existing operator session returned 403.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue