From c54de0f3d004dfd517f0ed0316ec6da840956d61 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Fri, 21 Aug 2026 21:39:10 +0200 Subject: [PATCH] chore(registrar): assign State Hub identifiers --- .../RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md | 6 ++++++ ...RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md | 4 ++++ workplans/RPF-WP-0021-core-hub-platform-onboarding.md | 6 ++++++ 3 files changed, 16 insertions(+) diff --git a/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md b/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md index 9f79e7b..f35b266 100644 --- a/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md +++ b/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md @@ -14,6 +14,7 @@ related: - RISK-F-0009 origin: routed origin_ref: "State Hub message 828e4903-30fe-4903-acfd-cd2ecdda437d" +state_hub_workstream_id: "b4701216-b235-48d1-a527-b52b8fb7e6fc" --- # RAILIANCE-WP-0022 — Agent high-risk boundary coverage @@ -39,6 +40,7 @@ establish whether any agent identity actually carries the boundary. id: RAILIANCE-WP-0022-T01 status: done priority: high +state_hub_task_id: "44d1a4bf-70bb-4d50-a40a-2158acc96b36" ``` Run the capabilities-only ops-warden audit against the policy. The 2026-08-21 @@ -51,6 +53,7 @@ and five without a concrete KV address. No credential value was read. id: RAILIANCE-WP-0022-T02 status: done priority: high +state_hub_task_id: "97c73849-716f-45d7-878f-5e1811a594ff" ``` Add deny-data/read-metadata pairs for the six catalog paths: whynot-design npm, @@ -68,6 +71,7 @@ catalog audit reports all 12 catalog entries covered with none uncovered. id: RAILIANCE-WP-0022-T03 status: done priority: high +state_hub_task_id: "9a293b09-dc0c-4575-bdc1-05102fb218a8" ``` Under attended platform authority, upload the reviewed policy, read it back, @@ -89,6 +93,7 @@ it with a workload-read policy. No token was minted and no Secret was read. id: RAILIANCE-WP-0022-T04 status: done priority: medium +state_hub_task_id: "64ddfacf-b3f2-428e-9630-4b9f436f627f" ``` Reply to ops-warden with the deployment evidence and remaining attachment @@ -106,6 +111,7 @@ versioned generated artifact shape. id: RAILIANCE-WP-0022-T05 status: wait priority: high +state_hub_task_id: "47aa5ed9-95c5-4a23-a460-e4bbd3ed6f65" ``` The policy is live but no role attaches it. Do not add the boundary to diff --git a/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md b/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md index 71ad2eb..3c617d4 100644 --- a/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md +++ b/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md @@ -13,6 +13,7 @@ related: - CORE-WP-0010 - RAPPCOREHUB-WP-0002 - RAPP-POSTGRES-WP-0004 +state_hub_workstream_id: "d2adc2d4-6461-4f7b-affc-7248fea49e60" --- # Hub-core candidate credential lanes @@ -23,6 +24,7 @@ related: id: RAILIANCE-WP-0023-T01 status: done priority: high +state_hub_task_id: "37b69d0e-7eac-40e5-b18a-777fa2b5e2da" ``` Add only `database/creds/hub-core-runtime` and @@ -35,6 +37,7 @@ database store, with separate five-minute ExternalSecret projections. id: RAILIANCE-WP-0023-T02 status: progress priority: high +state_hub_task_id: "d15f82db-f1ba-467a-bb69-86eb7c314016" ``` Apply the reviewed policy and projections after rapp-postgres creates the @@ -51,6 +54,7 @@ progress for the deliberate lease-rotation observation during stabilization. id: RAILIANCE-WP-0023-T03 status: done priority: high +state_hub_task_id: "bb2a73fc-3bee-45a6-83f0-3341639aabdf" ``` Confirm both Secret metadata objects are ready, then hand the candidate diff --git a/workplans/RPF-WP-0021-core-hub-platform-onboarding.md b/workplans/RPF-WP-0021-core-hub-platform-onboarding.md index 4dbcc25..dd03f68 100644 --- a/workplans/RPF-WP-0021-core-hub-platform-onboarding.md +++ b/workplans/RPF-WP-0021-core-hub-platform-onboarding.md @@ -15,6 +15,7 @@ related: - RAPP-POSTGRES-WP-0003 origin: request origin_ref: CORE-WP-0011 +state_hub_workstream_id: "5f7ee0a7-8c6c-475c-b9d9-32d9c5ee86e5" --- # RPF-WP-0021 — Core Hub platform onboarding @@ -69,6 +70,7 @@ retirement of the old runtime. Those remain explicit operator gates in id: RPF-WP-0021-T01 status: done priority: high +state_hub_task_id: "451d4664-fbab-40cf-8a2a-4001ca55fc4c" ``` Under an attended `net-kingdom-admins` OIDC login to @@ -110,6 +112,7 @@ State Hub; workplan UUID assignment remains with the production registrar. id: RPF-WP-0021-T02 status: done priority: high +state_hub_task_id: "f0aea438-9376-47f0-83a8-923570a43759" ``` Review `/home/worsch/rapp-core-hub/handoffs/postgres-consumer.yaml` in @@ -156,6 +159,7 @@ deletion, and names `core_hub_owner` as owner. id: RPF-WP-0021-T03 status: done priority: high +state_hub_task_id: "061be612-b660-4d0a-aa4c-8e26b59b0047" ``` Separate the two credential sources before shadow deployment: @@ -199,6 +203,7 @@ refresh interval restored. id: RPF-WP-0021-T04 status: done priority: high +state_hub_task_id: "85c46ea6-dcae-4ce5-8053-a8595b603f40" ``` After T03 fixes the consuming contract: @@ -256,6 +261,7 @@ all passed. `CCR-2026-0013` is verified. id: RPF-WP-0021-T05 status: done priority: high +state_hub_task_id: "998ec349-43b0-4128-b2f4-1af9441e8da6" ``` After T01-T04, support `CORE-WP-0011-T03`: label the namespace for