Finish RPF-WP-0018; RPF-WP-0019 repository-complete
RPF-WP-0018 closed: all seven tasks done. The provider-declaration finding was adopted upstream and its canonical form is the provider: block in tenancy.yaml; adaptive-pricing declined the standing co-signature and supplied typed tier minima instead, recorded in ADR-0002. Three corrections against our own output are recorded in the documents rather than edited away. RPF-WP-0019 T03 done (ceiling of three, memory binding, apps-pg-2 named as overflow, enforced by make apps-pg-verify-capacity). T01/T02 are repository-complete: backup target, retention, per-consumer connection limits, role timeouts and Burstable resources are declared in source and published in s3-consumer-interfaces 1.1.0 before rollout. They stay in progress because no live application, backup success or restore proof exists, and declared configuration is not a section 13 artifact. T04 waits on that window. apps-pg R reason corrected to say the target is declared-not-applied rather than absent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e52ae26001
commit
dc4245361d
20 changed files with 650 additions and 73 deletions
|
|
@ -4,11 +4,11 @@ type: workplan
|
|||
title: "Align S3 with the estate policy surface (Tenancy Posture + policy-nexus)"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: active
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-08-17"
|
||||
updated: "2026-08-17"
|
||||
updated: "2026-08-18"
|
||||
related:
|
||||
- POLICY-NEXUS-WP-0001
|
||||
- TEN-WP-0009
|
||||
|
|
@ -297,3 +297,37 @@ this workplan routes the finding and does not build the ingress.
|
|||
**A declaration that goes stale the day it is written.** Mitigation is the
|
||||
`reviewed:` date on the vector set and the review interval in the ADR
|
||||
template — the same currency mechanism `policy-nexus` T05 will read.
|
||||
|
||||
## Closed 2026-08-18
|
||||
|
||||
All seven tasks done. What the workplan produced, and what it changed
|
||||
elsewhere:
|
||||
|
||||
- `docs/tenancy-posture.md` + `tenancy.yaml` — the vector set, machine-readable
|
||||
with the human reasoning kept beside it.
|
||||
- `docs/placement-policy.md` — placement rule, owner per workload, triggers,
|
||||
retention floor and ceiling.
|
||||
- `docs/s3-consumer-interfaces.md` `1.1.0` — quota disclosure.
|
||||
- `docs/adr/` — created from nothing; `ADR-0001`, `ADR-0002`, `ADR-0003`.
|
||||
|
||||
**Two findings were adopted upstream.** The provider-declaration proposal (F4,
|
||||
narrowed) is in the framework and its canonical form is the `provider:` block
|
||||
in `tenancy.yaml`. `adaptive-pricing` declined the standing co-signature and
|
||||
supplied a stronger replacement — typed tier minima joined at tier definition —
|
||||
which draft-8 adopted; `ADR-0002` records the outcome as single ownership plus
|
||||
a mandatory typed constraint join, not as an absent signature.
|
||||
|
||||
**Three corrections were issued against our own output**, all in the same
|
||||
direction — claiming levels we could not evidence. `openbao A: 2` retracted to
|
||||
`A: 0`; the provider finding narrowed once §6's `flex-auth` precedent was read;
|
||||
the §11 summary to `adaptive-pricing` corrected, since §11.2 keeps marketing
|
||||
vocabulary free and only the *cannot-reach* claim is restricted, to E4. All
|
||||
three are recorded in the documents rather than edited away.
|
||||
|
||||
**What this workplan deliberately did not do:** fix anything. It found that
|
||||
`apps-pg` had no backup, no per-consumer controls and no isolation probes, and
|
||||
published those as visible defects. `RPF-WP-0019` closes them.
|
||||
|
||||
**Left open, not owned here:** `bao.coulomb.social` still needs confirmation
|
||||
against live reef state (`railiance-master` `ba477968`), and F1's substrate
|
||||
split is with `policy-nexus` to act on.
|
||||
|
|
|
|||
|
|
@ -4,15 +4,16 @@ type: workplan
|
|||
title: "apps-pg: backup, per-consumer controls, and the isolation probes they make possible"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: proposed
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-08-17"
|
||||
updated: "2026-08-17"
|
||||
updated: "2026-08-18"
|
||||
related:
|
||||
- RPF-WP-0018
|
||||
origin: residual
|
||||
origin_ref: RPF-WP-0018
|
||||
state_hub_workstream_id: "160e226d-27b0-4c94-9e99-331f4354dd12"
|
||||
---
|
||||
|
||||
# RPF-WP-0019 — apps-pg recoverability and per-consumer controls
|
||||
|
|
@ -65,12 +66,43 @@ the `platform-pg-backup-s3` credential lane — the same handoff
|
|||
`make postgres-backup-deploy` waits on. Check whether that is now live before
|
||||
assuming this is blocked.
|
||||
|
||||
## Status 2026-08-18 — repository-complete, live-blocked
|
||||
|
||||
Everything this repo can do without touching the cluster is done and
|
||||
committed. What remains on T01, T02 and T04 is a single operator window
|
||||
against a live shared rail, in this order:
|
||||
|
||||
1. `make apps-pg-deploy` — Cluster reconcile: role connection limits,
|
||||
Burstable requests/limits, explicit aggregate parameters.
|
||||
2. Apply `helm/apps-pg-consumer-controls.sql` — the two 15s role timeouts.
|
||||
Idempotent; CNPG 1.28 has no managed-role settings field, so this is
|
||||
operator SQL by necessity, not by preference.
|
||||
3. `make apps-pg-backup-deploy` — the ScheduledBackup, once the governed
|
||||
Secret is confirmed live.
|
||||
4. Capture `LastBackupSucceeded=True` and a scratch restore. **Until both
|
||||
exist, `apps-pg` R stays 0** — declared configuration is not a §13
|
||||
artifact, and this workplan exists because that distinction was missed once
|
||||
already.
|
||||
5. T04's probes, in an announced window, after 1–3 have settled.
|
||||
|
||||
**Blocker as of this session:** the cluster is unreachable from the
|
||||
workstation — `kubectl` returns `Unauthorized` against
|
||||
`config-hosteurope`. Credentials or the tunnel need attention before any of
|
||||
the above runs. This is a session-local access problem, not a defect in the
|
||||
manifests: `make apps-pg-verify-capacity` passes and the capacity tests are
|
||||
green.
|
||||
|
||||
**Do not treat the rollout as evidence.** T04's P1 claim and the R-axis both
|
||||
need artifacts produced *after* application, and `docs/placement-policy.md`
|
||||
§3.1 and `tenancy.yaml` should be updated only then.
|
||||
|
||||
## Tasks
|
||||
|
||||
```task
|
||||
id: RPF-WP-0019-T01
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "0f5175c7-bde3-46a0-87a8-b50b5eeac32c"
|
||||
```
|
||||
**Establish a backup target for `apps-pg`.** Confirm the state of the
|
||||
`resource-control` bucket and the `platform-pg-backup-s3` OpenBao Secret; if
|
||||
|
|
@ -78,10 +110,17 @@ live, configure `barmanObjectStore` and a `retentionPolicy` on the cluster. If
|
|||
not live, record the dependency and say so — do not leave the absence
|
||||
undocumented a second time.
|
||||
|
||||
2026-08-18 repository readiness: the governed Secret exists live and reviewed
|
||||
desired state now carries a distinct `apps-pg/` prefix, 30-day retention,
|
||||
continuous WAL and a daily 02:15 backup. NetworkPolicy admits the DNS/HTTPS
|
||||
path archival needs. The ScheduledBackup is not applied and no successful
|
||||
backup/restore evidence exists, so T01 remains progress.
|
||||
|
||||
```task
|
||||
id: RPF-WP-0019-T02
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "c5b0b2ac-b9f5-42fb-8e75-2fac2ab1e852"
|
||||
```
|
||||
**Declare and enforce per-consumer controls.** Per-consumer connection
|
||||
allowance, `statement_timeout`, `idle_in_transaction_session_timeout`, and
|
||||
|
|
@ -90,20 +129,34 @@ every value in `docs/s3-consumer-interfaces.md` before it takes effect —
|
|||
§10.2 is a disclosure rule, and applying a timeout consumers learn about by
|
||||
hitting it would breach the rule while implementing it.
|
||||
|
||||
2026-08-18 repository readiness: both roles declare a 20-connection limit,
|
||||
the pod has Burstable requests/limits, aggregate/logging parameters are
|
||||
explicit, and controlled operator SQL sets both 15s role timeouts. Every value
|
||||
was published in `docs/s3-consumer-interfaces.md` before application. Live SQL
|
||||
and Cluster reconciliation remain an operator window, so T02 remains progress.
|
||||
|
||||
```task
|
||||
id: RPF-WP-0019-T03
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "736cbc11-1992-4f1b-9ff0-cb4622ff39a5"
|
||||
```
|
||||
**Declare the ceiling and overflow target.** Owed under this repo's own
|
||||
Rule P-4.1 before `apps-pg`'s third consumer; it is at two. Name the binding
|
||||
resource per Rule P-4.2 — memory or connections — and a named overflow
|
||||
substrate per P-4.3.
|
||||
|
||||
Completed 2026-08-18. The declared ceiling is three, memory is the binding
|
||||
constraint, and `apps-pg-2` is a named, source-provisionable overflow cell with
|
||||
a distinct credential and backup prefix. `make apps-pg-verify-capacity`
|
||||
rejects a fourth consumer per cell and unbounded/duplicate roles. The cell
|
||||
intentionally remains absent until a fourth consumer is approved.
|
||||
|
||||
```task
|
||||
id: RPF-WP-0019-T04
|
||||
status: todo
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "2fccdd26-c9c6-43cb-b069-27ed5668afac"
|
||||
```
|
||||
**Isolation probes, after T02.** Consumer-boundary probes on the
|
||||
`rapp-postgres` model, then the §13 noisy-neighbour artifact: per-consumer
|
||||
|
|
@ -112,6 +165,10 @@ judged against each consumer's declared service class. Update
|
|||
`docs/placement-policy.md` §3.1 and `docs/tenancy-posture.md` when the P1
|
||||
claims become evidenced.
|
||||
|
||||
Waiting on T02 live application and an announced probe window. No saturation
|
||||
or destructive recovery experiment is run against the shared production rail
|
||||
as part of repository preparation.
|
||||
|
||||
## Boundaries
|
||||
|
||||
- `apps-pg` only. `platform-pg`'s equivalents are `rapp-postgres`'s.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue