Finish RPF-WP-0018; RPF-WP-0019 repository-complete
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

RPF-WP-0018 closed: all seven tasks done. The provider-declaration finding
was adopted upstream and its canonical form is the provider: block in
tenancy.yaml; adaptive-pricing declined the standing co-signature and
supplied typed tier minima instead, recorded in ADR-0002. Three corrections
against our own output are recorded in the documents rather than edited
away.

RPF-WP-0019 T03 done (ceiling of three, memory binding, apps-pg-2 named as
overflow, enforced by make apps-pg-verify-capacity). T01/T02 are
repository-complete: backup target, retention, per-consumer connection
limits, role timeouts and Burstable resources are declared in source and
published in s3-consumer-interfaces 1.1.0 before rollout. They stay in
progress because no live application, backup success or restore proof
exists, and declared configuration is not a section 13 artifact. T04 waits
on that window.

apps-pg R reason corrected to say the target is declared-not-applied rather
than absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-18 13:35:04 +02:00
parent e52ae26001
commit dc4245361d
20 changed files with 650 additions and 73 deletions

View file

@ -4,11 +4,11 @@ type: workplan
title: "Align S3 with the estate policy surface (Tenancy Posture + policy-nexus)"
domain: financials
repo: railiance-platform
status: active
status: finished
owner: codex
topic_slug: railiance
created: "2026-08-17"
updated: "2026-08-17"
updated: "2026-08-18"
related:
- POLICY-NEXUS-WP-0001
- TEN-WP-0009
@ -297,3 +297,37 @@ this workplan routes the finding and does not build the ingress.
**A declaration that goes stale the day it is written.** Mitigation is the
`reviewed:` date on the vector set and the review interval in the ADR
template — the same currency mechanism `policy-nexus` T05 will read.
## Closed 2026-08-18
All seven tasks done. What the workplan produced, and what it changed
elsewhere:
- `docs/tenancy-posture.md` + `tenancy.yaml` — the vector set, machine-readable
with the human reasoning kept beside it.
- `docs/placement-policy.md` — placement rule, owner per workload, triggers,
retention floor and ceiling.
- `docs/s3-consumer-interfaces.md` `1.1.0` — quota disclosure.
- `docs/adr/` — created from nothing; `ADR-0001`, `ADR-0002`, `ADR-0003`.
**Two findings were adopted upstream.** The provider-declaration proposal (F4,
narrowed) is in the framework and its canonical form is the `provider:` block
in `tenancy.yaml`. `adaptive-pricing` declined the standing co-signature and
supplied a stronger replacement — typed tier minima joined at tier definition —
which draft-8 adopted; `ADR-0002` records the outcome as single ownership plus
a mandatory typed constraint join, not as an absent signature.
**Three corrections were issued against our own output**, all in the same
direction — claiming levels we could not evidence. `openbao A: 2` retracted to
`A: 0`; the provider finding narrowed once §6's `flex-auth` precedent was read;
the §11 summary to `adaptive-pricing` corrected, since §11.2 keeps marketing
vocabulary free and only the *cannot-reach* claim is restricted, to E4. All
three are recorded in the documents rather than edited away.
**What this workplan deliberately did not do:** fix anything. It found that
`apps-pg` had no backup, no per-consumer controls and no isolation probes, and
published those as visible defects. `RPF-WP-0019` closes them.
**Left open, not owned here:** `bao.coulomb.social` still needs confirmation
against live reef state (`railiance-master` `ba477968`), and F1's substrate
split is with `policy-nexus` to act on.