Close verified incident task and finish local workplan loose ends
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3c3-621b-7350-9f77-50a8d3ee7657
This commit is contained in:
codex 2026-09-27 19:04:54 +02:00
parent 5781d34b3b
commit debf981097
22 changed files with 1210 additions and 62 deletions

View file

@ -1,37 +1,25 @@
# Current platform work
Reviewed 2026-09-15. Open workplans below; RPF-WP-0029 finished on predecessor
unshare. Completed designs and implementations are under `archived/`; their IDs
and UUIDs are preserved. The number of blocked plans is not a count of missing
implementations or independent incidents.
Reviewed September 27, 2026. Eight workplans remain blocked with 23 waiting
tasks. No active, ready or proposed source workplan remains. Completed work
retains its IDs and managed UUIDs, including plans under `archived/`.
| Workplan | Purpose and next gate | S3 boundary |
| Workplan | Remaining tasks | Next dependency |
| --- | --- | --- |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | T02/T03 | Fresh recovery windows, synthetic sender/abort owner and snapshot/quorum/access evidence |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | T03/T06 | Complete historical resolver custody/routing contract; T05 closed from September 23 operator disposition and owner receipt |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | T02/T03/T06/T07/T08 | Exact service registration/custody, human memo acceptance, reader/disablement returns, governed npm migration and formerly-valid audit-bearer revocation proof |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | T03/T04/T06 | Current recovery/cadence/custody evidence, Q2 production delivery and owner/projection acceptance; local archive adapter implemented |
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | T04 | Durable scheduled caller, canonical verified inventory and quota/retention gates; September 15 cutover/expiration hold persists |
| [RPF-WP-0043](RPF-WP-0043-policy-nexus-argocd-onboarding.md) | T02/T03/T04 | Cross-owner chart/values agreement, committed values and source access, zero-diff proof and adoption |
| [RPF-WP-0044](RPF-WP-0044-argocd-phase-b-adopt-existing-applications.md) | T03–T08 | Per-app promotion gates, issue-core credentials/ownership, target-revenue hook acceptance, ESO adoption/observation and readable old-controller inventory |
| [RPF-WP-0048](RPF-WP-0048-activity-core-gitops-adoption.md) | T02 | Healthy observation through September 28 at 16:06:22 Berlin plus bounded authenticated release broker/admission and rollback proof |
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
| [RPF-WP-0043](RPF-WP-0043-policy-nexus-argocd-onboarding.md) | Onboard production-approved rapp-policy-nexus to the ArgoCD lane by 2026-12-21; T01 confirms ArgoCD reconciles on railiance01 (unverified) | Plan only; adoption waits on the founder's go-ahead and rapp-policy-nexus's manifest decision. |
Latest [review and evidence](../history/2026-09-27-loose-end-review.md).
No new task or workplan was created. Existing completed credential reviews,
delivery, retention projection and rotations are not reopened by these waits.
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
acceptance gates. Treat credential exposure closure as the highest-priority attended
work; task order does not combine or waive approvals.
[Assessment and disposition of every plan](../history/2026-09-05-platform-intent-workplan-assessment.md)
and [generated current record index](../WORK-RECORDS.md).
Do not recreate completed workplans because an old Hub alias or generated brief
still shows them active. Use source IDs, and follow AGENTS.md for verified sync.
## Latest closure review
[2026-09-05 blocker review](../history/2026-09-05-blocked-workplan-closure-review.md):
At that review: 12 unfinished tasks across six genuine blocked plans.
The September 6 follow-up adds WP-0038 with one remaining full-archive task. All terminal plans have
only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived.
Three retired Hub aliases still appear open; they are a derived-view defect,
not three more workplans. Use this file before the dated generated brief.
Source files are authoritative. The generated brief still contains retired
aliases and stale statuses; do not recreate work from it. Routine synchronization
uses the exact-commit Repo Manager receipt described in AGENTS.md. Legacy alias
repair remains the scoped owner dependency in WP-0036-T06.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-22"
updated: "2026-09-05"
updated: "2026-09-27"
related:
- AUDIT-WP-0008
- WH-ENG-20260822-AUDIT-E2-01
@ -348,3 +348,7 @@ is no longer missing. T02 waits on its separately approved sender identity,
fresh bounded window, abort operator and live recovery receipt. Local driver
success does not prove lease revocation/ESO recovery. T03 remains a separate
outage exercise; no historical window or terminal NO-GO may be reused.
## Loose-end review — 2026-09-27
T02/T03 remain waiting on fresh attended execution windows, named abort operators, current custody/quorum evidence and owner execution. The implemented load driver and prior procedure approvals do not supply a fresh live recovery receipt. No expired window was reused.

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-09-15"
updated: "2026-09-27"
related:
- KEY-WP-0011
origin: routed
@ -110,7 +110,7 @@ and all T03 acknowledgements. No value may enter captured output.
```task
id: RPF-WP-0027-T05
status: wait
status: done
priority: high
state_hub_task_id: "9cb5fa67-012a-58cf-bafb-e7c7d4f9782d"
```
@ -172,3 +172,7 @@ and acceptable disposition. Overall incident closure remains open.
No new owner acceptance or coordination message is asserted by this review.
Keep this incident separate from the new-lane queue; broad lane approval cannot
close an exposure.
## Loose-end review — 2026-09-27
T05 is now done by the newer owner record: NK-WP-0033 accepted the operator ruling on 2026-09-23 and recorded the green attended read-only resolver/MFA/health/cleanup receipt. Predecessor denial remains explicitly NOT-PROVEN, with the unavailable-predecessor disposition accepted by Bernd Worsch; it is not relabelled as a successful negative test. KEY-WP-0011 already closes the other credential-class rotation/recovery evidence. See `docs/evidence/2026-09-27-keycape-incident-owner-return.json`. T03/T06 still wait for the complete platform custody/routing handoff. The owner names operators/lldap/admin and operators/privacyidea/pi-admin, but does not supply the complete field/auth/expiry/handoff contract required by T06. The September 15 instruction to leave historical routing lanes blocked remains in force. No repeat rotation or predecessor recovery was attempted.

View file

@ -415,7 +415,7 @@ into this client-identity grant.
```task
id: RPF-WP-0035-T08
status: progress
status: wait
priority: high
assignee: railiance-platform
needs_human: false
@ -696,3 +696,7 @@ T07 consumed the confirmed legacy consumer return. The stale value-comparison
ask is removed. WARDEN-WP-0037-T03's no-rotation hold stays in force until the
governed native migration is evidenced. Legacy destruction follows migration;
neither source reconciliation nor the historical pilot is that evidence.
## Loose-end review — 2026-09-27
T08 now explicitly waits for formerly-valid audit-bearer revocation acceptance from AUDIT-WP-0009-T09/T11. Native delivery, producer checks and independent readback already passed; do not reopen login, seed or review gates. T02/T03/T06/T07 retain their latest exact service registration, signed-in human acceptance, owner delivery/disposition and governed-consumer migration dependencies. No credential value was read or changed.

View file

@ -8,7 +8,7 @@ status: blocked
flavor: implementation
owner: codex
created: "2026-09-05"
updated: "2026-09-06"
updated: "2026-09-27"
state_hub_workstream_id: "ca639c3d-3a87-5fa4-ad13-6f2e014b0c84"
---
@ -314,3 +314,7 @@ RTEL-WP-0002-T04: accepted package/runtime, authenticated execution, actual
operator recipient, cadence/storage/retention and independent receiver watchdog,
then acknowledged controlled delivery. Local test-inbox visibility is not that
live receipt; S3 remains unmonitored until acceptance.
## Loose-end review — 2026-09-27
Completed the local full-primary archive assurance adapter under T03. It validates ordered transfer/decryption/restore receipts, exact provenance hashes, full profile, version-pinned verified download and application/database/repository/package/cleanup proof; historical undated receipts remain ineligible. Updated producer profile propagation and assurance documentation. Fresh live metadata reports 18 healthy signals, five missing recovery/upload signals and one stale OpenBao snapshot; transport remains unmonitored. T03/T04/T06 remain waiting on current recovery/cadence/custody proof, Q2 production delivery acceptance and owner/derived-record acceptance respectively. RTEL-WP-0002-T04 already selects rapp-telemetry; the stale claim that no receiver implementation/package exists is superseded. See `history/2026-09-27-loose-end-review.md`.

View file

@ -4,11 +4,11 @@ type: workplan
title: "Close Forgejo primary backup coverage on Scaleway"
domain: financials
repo: railiance-platform
status: active
status: blocked
flavor: implementation
owner: codex
created: "2026-09-06"
updated: "2026-09-15"
updated: "2026-09-27"
state_hub_workstream_id: "7beec1a7-aa82-5a36-9a66-6b60008a2455"
---
@ -72,7 +72,7 @@ removed. Evidence: `docs/evidence/forgejo-scaleway-restore-2026-09-06.json`.
```task
id: RPF-WP-0038-T04
status: progress
status: wait
priority: high
state_hub_task_id: "a4807df0-ec96-58f1-9cbd-42b1dcde0d6f"
```
@ -118,3 +118,7 @@ the existing durable caller, inventory, quota and retention gates.
**Operator decision, 2026-09-15:** do not expire retained backups or cut over
scheduled secondary delivery. The planner and attended executor stay idle until
durable caller/inventory/quota gates are closed.
## Loose-end review — 2026-09-27
T04 now explicitly waits. Primary and essentials manual recovery are already proven. Durable scheduled caller/dependency binding, canonical verified inventory, quota/retention gates and owner activation are still absent. September 15 prohibits expiration and scheduled secondary cutover until those gates close; no retained backups or schedules were changed. New primary transfer receipts preserve archive_profile for the assurance adapter in WP-0036-T03.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Onboard rapp-policy-nexus to the ArgoCD production lane"
domain: financials
repo: railiance-platform
status: active
status: blocked
flavor: planning
owner: railiance-platform
topic_slug: railiance
created: "2026-09-21"
updated: "2026-09-22"
updated: "2026-09-27"
due: "2026-12-21"
related: [RPF-WP-0022]
state_hub_workstream_id: "ec41a4bd-df18-5b07-9b63-ccb80d9f001c"
@ -231,3 +231,7 @@ the inventory.
- **T05 done.** Gap declared and inventoried in
`docs/direct-apply-gap-inventory.md`, with a per-group proposal for the
founder. No target changed.
## Loose-end review — 2026-09-27
The workplan is blocked on the source-owner agreement and its downstream adoption gates. RAPP-POLICY-NEXUS-WP-0002 proposes a multi-source Application: chart in rapp-policy-nexus and release values in railiance-apps. This supersedes the earlier platform-only suggestion to put production values in the package repository. The platform accepts that shape and the helm/policy-nexus path exception in principle; it still needs railiance-apps acceptance, an actual committed values path/revision, source access and a zero-diff render before T02/T03 can close. No owner acceptance or cross-repository change is inferred. T01 remains proven by current railiance01 Synced/Healthy evidence.

View file

@ -4,12 +4,12 @@ type: workplan
title: "ArgoCD phase B: adopt the four existing Applications on railiance01"
domain: financials
repo: railiance-platform
status: active
status: blocked
flavor: planning
owner: railiance-platform
topic_slug: railiance
created: "2026-09-21"
updated: "2026-09-21"
updated: "2026-09-27"
related: [RPF-WP-0043, RPF-WP-0022]
state_hub_workstream_id: "98140775-3b9a-5cf9-9af6-722502d487dc"
---
@ -185,7 +185,7 @@ Rollback:
```task
id: RPF-WP-0044-T03
status: progress
status: wait
priority: high
state_hub_task_id: "6d5fc801-e361-579b-bcd8-6fe719a82e94"
```
@ -256,7 +256,7 @@ whitelist. Live check: `rapp-issue-core make verify-live`. Workload restore:
```task
id: RPF-WP-0044-T05
status: progress
status: wait
priority: medium
state_hub_task_id: "d418068a-6fb0-5416-aac5-d23c93924d9c"
```
@ -317,7 +317,7 @@ railiance01 path is a live production change, and `RPF-WP-0043-T04`
```task
id: RPF-WP-0044-T08
status: todo
status: wait
priority: low
state_hub_task_id: "55d1382f-5862-5321-a1c9-96767764ba43"
```
@ -326,3 +326,7 @@ Planning only. Needs a read-only check of coulombcore's ArgoCD, outside this
session's scope. Under Option A, retiring it also removes `argocd/applications/`.
Also hand back to the cluster layer: the phase A install is not declared in
any repository and its pods have no resource requests (BestEffort).
## Loose-end review — 2026-09-27
T03/T05 passed their elapsed healthy observation gate: current ArgoCD status is Synced/Healthy with last healthy transitions on September 21; openbao is Valid and issue-core-runtime is SecretSynced. They now wait on the remaining automation go-aheads and, for target-revenue, hook-owner acceptance. T06 local preparation is complete: the inactive ESO draft protects all 20 CRDs from prune/delete. The pinned 0.16.1 chart renders 39 objects; server-side diff is exactly the 20 protective metadata annotations, with no spec changes. All 25 ClusterSecretStores are Valid. T04 still needs the repository credential/production-owner contract; T07 depends on the per-app gates. T08 has a concrete retirement procedure at `docs/argocd-coulombcore-retirement.md`, but its required live inventory is blocked: SSH works and Kubernetes rejects both default and explicit local k3s kubeconfigs. No controller or workload was changed. Evidence: `docs/evidence/2026-09-27-argocd-loose-end-status.json` and `docs/evidence/2026-09-27-eso-adoption-preparation.json`.

View file

@ -4,7 +4,7 @@ type: workplan
title: "Adopt activity-core application runtime into railiance01 GitOps"
domain: financials
repo: railiance-platform
status: active
status: blocked
owner: codex
topic_slug: railiance
created: "2026-09-27"
@ -130,3 +130,7 @@ were made by this probe. See docs/evidence/2026-09-27-digest-retention-release.j
New healthy observation start is 2026-09-27T14:06:22Z after worker rollout;
earliest eligibility is September 28 at 16:06:22 Europe/Berlin. Automation remains
off. T02 still owns the scoped broker/admission and observation requirements.
## Loose-end review — 2026-09-27
The workplan is blocked on T02. Current activity-core remains Synced/Healthy at a12f1169f9d130058ce767f5b26de0606997916c, with health transition 2026-09-27T14:06:22Z. Earliest observation eligibility remains September 28 at 16:06:22 Europe/Berlin. The authenticated bounded broker/admission and rollback proof remain owned jointly with ACTIVITY-WP-0041-T03. Elapsed time is not release-identity admission. T01/T03 remain done; no root automation, pruning or credential delegation was enabled.