chore(registrar): assign State Hub identifiers
This commit is contained in:
parent
f106ee941c
commit
c54de0f3d0
3 changed files with 16 additions and 0 deletions
|
|
@ -14,6 +14,7 @@ related:
|
|||
- RISK-F-0009
|
||||
origin: routed
|
||||
origin_ref: "State Hub message 828e4903-30fe-4903-acfd-cd2ecdda437d"
|
||||
state_hub_workstream_id: "b4701216-b235-48d1-a527-b52b8fb7e6fc"
|
||||
---
|
||||
|
||||
# RAILIANCE-WP-0022 — Agent high-risk boundary coverage
|
||||
|
|
@ -39,6 +40,7 @@ establish whether any agent identity actually carries the boundary.
|
|||
id: RAILIANCE-WP-0022-T01
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "44d1a4bf-70bb-4d50-a40a-2158acc96b36"
|
||||
```
|
||||
|
||||
Run the capabilities-only ops-warden audit against the policy. The 2026-08-21
|
||||
|
|
@ -51,6 +53,7 @@ and five without a concrete KV address. No credential value was read.
|
|||
id: RAILIANCE-WP-0022-T02
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "97c73849-716f-45d7-878f-5e1811a594ff"
|
||||
```
|
||||
|
||||
Add deny-data/read-metadata pairs for the six catalog paths: whynot-design npm,
|
||||
|
|
@ -68,6 +71,7 @@ catalog audit reports all 12 catalog entries covered with none uncovered.
|
|||
id: RAILIANCE-WP-0022-T03
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "9a293b09-dc0c-4575-bdc1-05102fb218a8"
|
||||
```
|
||||
|
||||
Under attended platform authority, upload the reviewed policy, read it back,
|
||||
|
|
@ -89,6 +93,7 @@ it with a workload-read policy. No token was minted and no Secret was read.
|
|||
id: RAILIANCE-WP-0022-T04
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "64ddfacf-b3f2-428e-9630-4b9f436f627f"
|
||||
```
|
||||
|
||||
Reply to ops-warden with the deployment evidence and remaining attachment
|
||||
|
|
@ -106,6 +111,7 @@ versioned generated artifact shape.
|
|||
id: RAILIANCE-WP-0022-T05
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "47aa5ed9-95c5-4a23-a460-e4bbd3ed6f65"
|
||||
```
|
||||
|
||||
The policy is live but no role attaches it. Do not add the boundary to
|
||||
|
|
|
|||
|
|
@ -13,6 +13,7 @@ related:
|
|||
- CORE-WP-0010
|
||||
- RAPPCOREHUB-WP-0002
|
||||
- RAPP-POSTGRES-WP-0004
|
||||
state_hub_workstream_id: "d2adc2d4-6461-4f7b-affc-7248fea49e60"
|
||||
---
|
||||
|
||||
# Hub-core candidate credential lanes
|
||||
|
|
@ -23,6 +24,7 @@ related:
|
|||
id: RAILIANCE-WP-0023-T01
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "37b69d0e-7eac-40e5-b18a-777fa2b5e2da"
|
||||
```
|
||||
|
||||
Add only `database/creds/hub-core-runtime` and
|
||||
|
|
@ -35,6 +37,7 @@ database store, with separate five-minute ExternalSecret projections.
|
|||
id: RAILIANCE-WP-0023-T02
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "d15f82db-f1ba-467a-bb69-86eb7c314016"
|
||||
```
|
||||
|
||||
Apply the reviewed policy and projections after rapp-postgres creates the
|
||||
|
|
@ -51,6 +54,7 @@ progress for the deliberate lease-rotation observation during stabilization.
|
|||
id: RAILIANCE-WP-0023-T03
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "bb2a73fc-3bee-45a6-83f0-3341639aabdf"
|
||||
```
|
||||
|
||||
Confirm both Secret metadata objects are ready, then hand the candidate
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ related:
|
|||
- RAPP-POSTGRES-WP-0003
|
||||
origin: request
|
||||
origin_ref: CORE-WP-0011
|
||||
state_hub_workstream_id: "5f7ee0a7-8c6c-475c-b9d9-32d9c5ee86e5"
|
||||
---
|
||||
|
||||
# RPF-WP-0021 — Core Hub platform onboarding
|
||||
|
|
@ -69,6 +70,7 @@ retirement of the old runtime. Those remain explicit operator gates in
|
|||
id: RPF-WP-0021-T01
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "451d4664-fbab-40cf-8a2a-4001ca55fc4c"
|
||||
```
|
||||
|
||||
Under an attended `net-kingdom-admins` OIDC login to
|
||||
|
|
@ -110,6 +112,7 @@ State Hub; workplan UUID assignment remains with the production registrar.
|
|||
id: RPF-WP-0021-T02
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "f0aea438-9376-47f0-83a8-923570a43759"
|
||||
```
|
||||
|
||||
Review `/home/worsch/rapp-core-hub/handoffs/postgres-consumer.yaml` in
|
||||
|
|
@ -156,6 +159,7 @@ deletion, and names `core_hub_owner` as owner.
|
|||
id: RPF-WP-0021-T03
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "061be612-b660-4d0a-aa4c-8e26b59b0047"
|
||||
```
|
||||
|
||||
Separate the two credential sources before shadow deployment:
|
||||
|
|
@ -199,6 +203,7 @@ refresh interval restored.
|
|||
id: RPF-WP-0021-T04
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "85c46ea6-dcae-4ce5-8053-a8595b603f40"
|
||||
```
|
||||
|
||||
After T03 fixes the consuming contract:
|
||||
|
|
@ -256,6 +261,7 @@ all passed. `CCR-2026-0013` is verified.
|
|||
id: RPF-WP-0021-T05
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "998ec349-43b0-4128-b2f4-1af9441e8da6"
|
||||
```
|
||||
|
||||
After T01-T04, support `CORE-WP-0011-T03`: label the namespace for
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue