Finish hub-core credential lane workplan
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
This commit is contained in:
codex 2026-08-22 00:28:18 +02:00
parent 6f4a53543e
commit d40eb3c2a9
3 changed files with 31 additions and 8 deletions

View file

@ -4,11 +4,11 @@ type: workplan
title: "Hub-core candidate credential lanes"
domain: financials
repo: railiance-platform
status: active
status: finished
owner: codex
topic_slug: railiance
created: "2026-08-21"
updated: "2026-08-21"
updated: "2026-08-22"
related:
- CORE-WP-0010
- RAPPCOREHUB-WP-0002
@ -35,7 +35,7 @@ database store, with separate five-minute ExternalSecret projections.
```task
id: RAILIANCE-WP-0023-T02
status: progress
status: done
priority: high
state_hub_task_id: "d15f82db-f1ba-467a-bb69-86eb7c314016"
```
@ -44,9 +44,14 @@ Apply the reviewed policy and projections after rapp-postgres creates the
roles. Verify store validity, SecretSynced status, role separation, and lease
rotation without reading or logging values.
The exact policy, projections, SecretSynced state, role separation, and
production runtime/migration handoff passed on 2026-08-21. Keep this task in
progress for the deliberate lease-rotation observation during stabilization.
Completed 2026-08-22. The exact policy, projections, SecretSynced state, role
separation, and production runtime/migration handoff passed on 2026-08-21. A
subsequent scheduled five-minute reconciliation advanced both target Secret
resource versions. After projected-volume propagation, the candidate watcher
replaced only its application child while the pod UID remained stable,
readiness stayed true, and the container restart count stayed zero. No
credential value was read or logged. Evidence:
`docs/evidence/core-hub-private-shadow-2026-08-21.md`.
## Hand off the private candidate