Consolidate platform workplans and assess intent gaps

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 11:14:42 +02:00
parent 9d958f8e09
commit 9f83e426c7
40 changed files with 2985 additions and 295 deletions

View file

@ -4,14 +4,15 @@ Reviewed against local owner source on 2026-09-05. These are proposed designs,
not approvals or executable CCRs. No live credentials or OpenBao objects were
created. Files here are deliberately outside the production CCR/policy scan.
| Design | Owning platform workplan | Consumer dependency | Main unresolved input |
| Design | Design workplan / current implementation task | Consumer dependency | Main unresolved input |
| --- | --- | --- | --- |
| [Secrets-engine service JWT](secrets-engine-service-jwt.md) | RPF-WP-0032 | SECRETS-WP-0008-T06; SECRETS-WP-0007-T04 | Actual issuer/JWKS, live registration and scoped execution authority |
| [Fluid-telegram operator KV](fluid-telegram-operator-kv.md) | RPF-WP-0033 | MASON-WP-0005; FT-WP-0002 | Tenant acceptance, actual OIDC group, write-capable CCR support |
| [State Hub preflight signing](state-hub-preflight-signing.md) | RPF-WP-0034 | STATE-WP-0085-T09 | Deployment binding, owner-approved custody and rotation window |
| [Secrets-engine service JWT](secrets-engine-service-jwt.md) | RPF-WP-0032 (finished) / RPF-WP-0035-T02 | SECRETS-WP-0008-T06; SECRETS-WP-0007-T04 | Actual issuer/JWKS, live registration and scoped execution authority |
| [Fluid-telegram operator KV](fluid-telegram-operator-kv.md) | RPF-WP-0033 (finished) / RPF-WP-0035-T03 | MASON-WP-0005; FT-WP-0002 | Tenant acceptance, actual OIDC group, write-capable CCR support |
| [State Hub preflight signing](state-hub-preflight-signing.md) | RPF-WP-0034 (finished) / RPF-WP-0035-T04 | FLEX-WP-0020-T05; STATE-WP-0085-T09 delivered | Deployment binding, owner-approved custody and rotation window |
Each workplan separates completed design work from the owner review,
implementation, and live acceptance still required. Proposed object names can
The completed design workplans are archived. RPF-WP-0035 is the canonical
queue for owner review, implementation, and live acceptance still required.
State Hub retirement requires revalidating the signing demand before provisioning. Proposed object names can
be reviewed now; none represents a surveyed or active object. Before any secret
or access request, use `warden route find` / `warden route show` as required by
AGENTS.md. Keep values, bearer tokens and signing/preflight tokens out of Git,

View file

@ -102,3 +102,13 @@ For a non-compromise failed deployment, keep operations fenced and restore the
prior chart/key version only with owner approval, then verify all replicas.
Keep protected historical KV versions until the retention decision; no automatic
destroy, provider rename, or weakening of preflight checks is part of this lane.
## Demand review — 2026-09-05
STATE-WP-0085-T09 completed its adoption-plan deliverable on 2026-08-31.
The still-proposed FLEX-WP-0020-T05 cutover carries the signing prerequisite.
State Hub is now explicitly transitional in its INTENT; State Hub/repo-manager
and the migration owner must confirm the target runtime and continued need
before provisioning this design. RPF-WP-0035-T04 is the current platform task;
RPF-WP-0034 is the archived design record. No demand withdrawal or activation
is inferred from retirement planning alone.