Separate Core Hub onboarding from archived apps-pg identities
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 10:22:29 +02:00
parent 6b74b5e3a9
commit 6b41a43fa3
7 changed files with 29 additions and 22 deletions

View file

@ -1,5 +1,5 @@
{ {
"status": "proposed-requires-exception-to-managed-uuid-rule", "status": "applied-user-approved",
"retain": "workplans/archived/260702-RPF-WP-0021-apps-pg-shared-cluster.md", "retain": "workplans/archived/260702-RPF-WP-0021-apps-pg-shared-cluster.md",
"rename_from": "workplans/RPF-WP-0021-core-hub-platform-onboarding.md", "rename_from": "workplans/RPF-WP-0021-core-hub-platform-onboarding.md",
"rename_to": "workplans/RPF-WP-0030-core-hub-platform-onboarding.md", "rename_to": "workplans/RPF-WP-0030-core-hub-platform-onboarding.md",
@ -42,5 +42,7 @@
"docs/evidence/core-hub-private-shadow-2026-08-21.md", "docs/evidence/core-hub-private-shadow-2026-08-21.md",
"docs/evidence/core-hub-shadow-preflight-2026-08-20.md" "docs/evidence/core-hub-shadow-preflight-2026-08-20.md"
], ],
"hub_action": "Reconcile pushed source using rmgr sync; review further refusals without blindly acknowledging retirements." "hub_action": "Reconcile pushed source using rmgr sync; review further refusals without blindly acknowledging retirements.",
"approved_at": "2026-09-05",
"archived_file_sha256": "4bed0cb17adf20fedb4cca79c3d4bfd3c252b8c3feead6927578ecd915aa23a3"
} }

View file

@ -1,6 +1,6 @@
# Core Hub PostgreSQL capacity admission — 2026-08-20 # Core Hub PostgreSQL capacity admission — 2026-08-20
Workplan: `RPF-WP-0021-T02` Workplan: `RPF-WP-0030-T02`
Target: railiance01 `databases/platform-pg` Target: railiance01 `databases/platform-pg`

View file

@ -1,6 +1,6 @@
# Core Hub PostgreSQL capacity preflight — 2026-08-20 # Core Hub PostgreSQL capacity preflight — 2026-08-20
Workplan: `RPF-WP-0021-T02` Workplan: `RPF-WP-0030-T02`
Target: railiance01 `databases/platform-pg` Target: railiance01 `databases/platform-pg`

View file

@ -3,7 +3,7 @@
## Scope and safety boundary ## Scope and safety boundary
This record covers the private Core Hub relocation shadow on railiance01 for This record covers the private Core Hub relocation shadow on railiance01 for
`RPF-WP-0021`. Public Ingress was absent throughout. The CoulombCore writer, `RPF-WP-0030`. Public Ingress was absent throughout. The CoulombCore writer,
public routing, DNS, and source runtime were not changed or retired. No secret public routing, DNS, and source runtime were not changed or retired. No secret
value is included in this record. value is included in this record.

View file

@ -1,7 +1,7 @@
# Core Hub private-shadow preflight — 2026-08-20 # Core Hub private-shadow preflight — 2026-08-20
This records non-secret source/target metadata gathered for This records non-secret source/target metadata gathered for
`RPF-WP-0021-T05`. It is preparation only: no source data was dumped or `RPF-WP-0030-T05`. It is preparation only: no source data was dumped or
restored because the governed credential projections under T04 are not yet restored because the governed credential projections under T04 are not yet
live. live.

View file

@ -1,5 +1,5 @@
--- ---
id: RPF-WP-0021 id: RPF-WP-0030
type: workplan type: workplan
title: "Unblock rapp-core-hub publication and platform onboarding" title: "Unblock rapp-core-hub publication and platform onboarding"
domain: financials domain: financials
@ -8,17 +8,17 @@ status: finished
owner: codex owner: codex
topic_slug: railiance topic_slug: railiance
created: "2026-08-20" created: "2026-08-20"
updated: "2026-08-21" updated: "2026-09-05"
related: related:
- CORE-WP-0011 - CORE-WP-0011
- RAPPCOREHUB-WP-0001 - RAPPCOREHUB-WP-0001
- RAPP-POSTGRES-WP-0003 - RAPP-POSTGRES-WP-0003
origin: request origin: request
origin_ref: CORE-WP-0011 origin_ref: CORE-WP-0011
state_hub_workstream_id: "aa7fe3ff-a76c-5f26-a1e0-a35e48b28d60" state_hub_workstream_id: "f7a13cc2-7b1f-5644-89a8-b4e9a934b018"
--- ---
# RPF-WP-0021 — Core Hub platform onboarding # RPF-WP-0030 — Core Hub platform onboarding
## Goal ## Goal
@ -67,10 +67,10 @@ retirement of the old runtime. Those remain explicit operator gates in
## T01 — Publish and register `rapp-core-hub` ## T01 — Publish and register `rapp-core-hub`
```task ```task
id: RPF-WP-0021-T01 id: RPF-WP-0030-T01
status: done status: done
priority: high priority: high
state_hub_task_id: "a7cd3fc0-4469-55a6-aed0-a8cacb34c033" state_hub_task_id: "b561e71e-213e-506f-8eaf-578eef54977f"
``` ```
Under an attended `net-kingdom-admins` OIDC login to Under an attended `net-kingdom-admins` OIDC login to
@ -109,10 +109,10 @@ State Hub; workplan UUID assignment remains with the production registrar.
## T02 — Accept the Core Hub PostgreSQL consumer ## T02 — Accept the Core Hub PostgreSQL consumer
```task ```task
id: RPF-WP-0021-T02 id: RPF-WP-0030-T02
status: done status: done
priority: high priority: high
state_hub_task_id: "7cac453b-2e85-56d9-abae-d983e382246b" state_hub_task_id: "5ed30960-336c-5650-96c6-9395ea7f2584"
``` ```
Review `/home/worsch/rapp-core-hub/handoffs/postgres-consumer.yaml` in Review `/home/worsch/rapp-core-hub/handoffs/postgres-consumer.yaml` in
@ -156,10 +156,10 @@ deletion, and names `core_hub_owner` as owner.
## T03 — Correct the runtime credential delivery contract ## T03 — Correct the runtime credential delivery contract
```task ```task
id: RPF-WP-0021-T03 id: RPF-WP-0030-T03
status: done status: done
priority: high priority: high
state_hub_task_id: "223d5a77-b7c3-5d1a-a93c-4cb9628b457a" state_hub_task_id: "ad022406-0ae5-58db-9b9d-2e958ab73237"
``` ```
Separate the two credential sources before shadow deployment: Separate the two credential sources before shadow deployment:
@ -200,10 +200,10 @@ refresh interval restored.
## T04 — Declare and apply the OpenBao/ESO lanes ## T04 — Declare and apply the OpenBao/ESO lanes
```task ```task
id: RPF-WP-0021-T04 id: RPF-WP-0030-T04
status: done status: done
priority: high priority: high
state_hub_task_id: "50713b54-38a8-543d-8c74-0e3fa186fbb8" state_hub_task_id: "d4c2d69d-186a-5d0d-9ab7-5a4a48cb1e8d"
``` ```
After T03 fixes the consuming contract: After T03 fixes the consuming contract:
@ -258,10 +258,10 @@ all passed. `CCR-2026-0013` is verified.
## T05 — Support the private shadow restore and verification ## T05 — Support the private shadow restore and verification
```task ```task
id: RPF-WP-0021-T05 id: RPF-WP-0030-T05
status: done status: done
priority: high priority: high
state_hub_task_id: "ba4984f9-c6c5-5eb2-b4c4-83cbec59298c" state_hub_task_id: "1b608d2e-d660-50dd-8765-c429afbcb14c"
``` ```
After T01-T04, support `CORE-WP-0011-T03`: label the namespace for After T01-T04, support `CORE-WP-0011-T03`: label the namespace for

View file

@ -4,7 +4,7 @@ type: workplan
title: "Separate duplicated apps-pg and Core Hub workplan identities" title: "Separate duplicated apps-pg and Core Hub workplan identities"
domain: financials domain: financials
repo: railiance-platform repo: railiance-platform
status: blocked status: active
owner: codex owner: codex
created: "2026-09-05" created: "2026-09-05"
updated: "2026-09-05" updated: "2026-09-05"
@ -37,7 +37,7 @@ updates. Existing source UUIDs have not been changed.
```task ```task
id: RPF-WP-0031-T02 id: RPF-WP-0031-T02
status: wait status: progress
priority: high priority: high
state_hub_task_id: "2990a940-634c-5d76-b74c-740de8c36b16" state_hub_task_id: "2990a940-634c-5d76-b74c-740de8c36b16"
``` ```
@ -49,3 +49,8 @@ After approval, apply the exact proposal, preserve the archived identity and
all completion evidence, check uniqueness across root and archived workplans, all completion evidence, check uniqueness across root and archived workplans,
commit/push, and run `rmgr sync`. Inspect any retirement refusal before proceeding; commit/push, and run `rmgr sync`. Inspect any retirement refusal before proceeding;
never blanket-acknowledge unrelated retirements. never blanket-acknowledge unrelated retirements.
User approved the exact exception on 2026-09-05. Applied the six proposed UUIDs
and four evidence-reference updates; the archived file is byte-for-byte unchanged.
Source uniqueness and authoritative reconciliation are being verified.