diff --git a/workplans/RAILIANCE-WP-0005-credential-request-and-lease-broker.md b/workplans/RPF-WP-0001-credential-request-and-lease-broker.md similarity index 95% rename from workplans/RAILIANCE-WP-0005-credential-request-and-lease-broker.md rename to workplans/RPF-WP-0001-credential-request-and-lease-broker.md index e830319..f15f5ab 100644 --- a/workplans/RAILIANCE-WP-0005-credential-request-and-lease-broker.md +++ b/workplans/RPF-WP-0001-credential-request-and-lease-broker.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0005 +id: RPF-WP-0001 type: workplan title: "Credential Request and Lease Broker" domain: financials @@ -13,10 +13,10 @@ created: "2026-06-24" updated: "2026-07-02" depends_on_workplans: - RAIL-PL-WP-0002 -state_hub_workstream_id: "2731fece-6c49-45b8-ab8a-4ea6c04ac603" +state_hub_workstream_id: "bcc11cf9-d008-5e42-8fff-e2b33a1d0ff2" --- -# RAILIANCE-WP-0005 - Credential Request and Lease Broker +# RPF-WP-0001 - Credential Request and Lease Broker ## Goal @@ -100,10 +100,10 @@ Mitigations required by this workplan: ## T01 - Record ownership and architecture decision ```task -id: RAILIANCE-WP-0005-T01 +id: RPF-WP-0001-T01 status: done priority: high -state_hub_task_id: "cd680de8-a483-40d6-84fa-369bad60e7c7" +state_hub_task_id: "19795f6b-bd41-54cb-a782-846814417704" ``` Write an ADR or docs section confirming railiance-platform as the owner for @@ -121,10 +121,10 @@ Acceptance: ## T02 - Define credential grant catalog ```task -id: RAILIANCE-WP-0005-T02 +id: RPF-WP-0001-T02 status: done priority: high -state_hub_task_id: "6b64ad4b-90cd-475b-aaa9-73997c6b011b" +state_hub_task_id: "ce3913d6-ab7d-56e0-a067-7c5b6d4d5850" ``` Add a non-secret grant catalog schema and initial grant entries. @@ -151,10 +151,10 @@ Acceptance: ## T03 - Configure bounded OpenBao token roles and policies ```task -id: RAILIANCE-WP-0005-T03 +id: RPF-WP-0001-T03 status: done priority: high -state_hub_task_id: "d8498e3b-b2fb-47b7-ab88-cd6592c1807e" +state_hub_task_id: "98819394-390d-5a1b-8fe6-cf80f471cffc" ``` Create idempotent scripts/manifests for OpenBao token roles or equivalent lease @@ -194,10 +194,10 @@ configured. T03 is `done`. ## T04 - Build credential helper MVP ```task -id: RAILIANCE-WP-0005-T04 +id: RPF-WP-0001-T04 status: done priority: high -state_hub_task_id: "0c543cb3-36cb-4b25-9a58-de8efc1216c9" +state_hub_task_id: "a339fdb2-c593-5b9e-9080-d08b3061dab9" ``` Build a small CLI/helper in this repo first, for example credential or @@ -237,10 +237,10 @@ and completed without manual token paste. T04 is `done`. ## T05 - Implement secure delivery modes ```task -id: RAILIANCE-WP-0005-T05 +id: RPF-WP-0001-T05 status: done priority: high -state_hub_task_id: "66f3cd6d-7520-4584-90b8-672866ef3490" +state_hub_task_id: "f4299d05-5365-5903-a1db-982356fc2791" ``` Support safe delivery modes for different runtime contexts. @@ -283,10 +283,10 @@ T05 is `done`. ## T06 - Integrate KeyCape identity and agent subject binding ```task -id: RAILIANCE-WP-0005-T06 +id: RPF-WP-0001-T06 status: done priority: medium -state_hub_task_id: "e1dd5973-bf2b-4aa9-842e-9f530afa1ab6" +state_hub_task_id: "affee57b-4bb8-5ca0-bf62-33acbbcaaf4a" ``` Define how humans and agents authenticate to request grants. @@ -306,10 +306,10 @@ actor type against the grant catalog. T06 is done source-side. ## T07 - Add flex-auth preflight authorization and State Hub request metadata ```task -id: RAILIANCE-WP-0005-T07 +id: RPF-WP-0001-T07 status: done priority: medium -state_hub_task_id: "1269bb58-0699-43ef-aa4f-43bc49c61a49" +state_hub_task_id: "9c415813-a842-5f50-8990-7d0a4f85931f" ``` Before issuing a lease, optionally call flex-auth with actor, subject, grant, @@ -356,10 +356,10 @@ flex-auth. ## T08 - Integrate ops-warden smoke and routing catalog ```task -id: RAILIANCE-WP-0005-T08 +id: RPF-WP-0001-T08 status: done priority: high -state_hub_task_id: "4571d4c9-d4de-4ee9-97e0-ff03e49e65ec" +state_hub_task_id: "39ba556f-59d9-5696-8295-91b347b8a82c" ``` Replace the manual VAULT_TOKEN step in ops-warden smoke docs with the credential @@ -390,10 +390,10 @@ now ranks the broker lane first. Live smoke already proven via ## T09 - Verification, audit, and red-team checks ```task -id: RAILIANCE-WP-0005-T09 +id: RPF-WP-0001-T09 status: done priority: high -state_hub_task_id: "78d1db83-12fb-4ac2-95eb-54c91ac125b5" +state_hub_task_id: "17d02492-6f0e-52c9-8747-03c2131d03e3" ``` Add tests and operator verification for the complete flow. @@ -428,10 +428,10 @@ items are met. ## T10 - Rollout and migration ```task -id: RAILIANCE-WP-0005-T10 +id: RPF-WP-0001-T10 status: done priority: medium -state_hub_task_id: "44ce4082-fa8f-44d0-8f86-172d14ecfb0e" +state_hub_task_id: "678b105d-1b3e-5f91-86c5-a5e6960814bd" ``` Roll out in phases. diff --git a/workplans/RAILIANCE-WP-0008-openbao-approved-automation-delegation.md b/workplans/RPF-WP-0002-openbao-approved-automation-delegation.md similarity index 95% rename from workplans/RAILIANCE-WP-0008-openbao-approved-automation-delegation.md rename to workplans/RPF-WP-0002-openbao-approved-automation-delegation.md index 8cf9a33..b331371 100644 --- a/workplans/RAILIANCE-WP-0008-openbao-approved-automation-delegation.md +++ b/workplans/RPF-WP-0002-openbao-approved-automation-delegation.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0008 +id: RPF-WP-0002 type: workplan title: "OpenBao Approved Automation Delegation" domain: financials @@ -16,10 +16,10 @@ depends_on_workplans: - RAILIANCE-WP-0005 - RAILIANCE-WP-0006 - RAILIANCE-WP-0007 -state_hub_workstream_id: "671898ef-2378-4814-b8f6-066148cdad46" +state_hub_workstream_id: "c69cb4e7-15c8-5858-aebd-73a6e46f0f21" --- -# RAILIANCE-WP-0008 - OpenBao Approved Automation Delegation +# RPF-WP-0002 - OpenBao Approved Automation Delegation ## Goal @@ -113,10 +113,10 @@ and the local applier script. ## T01 - Specify delegated applier policy boundaries ```task -id: RAILIANCE-WP-0008-T01 +id: RPF-WP-0002-T01 status: done priority: high -state_hub_task_id: "d19fdfc5-addb-4813-8086-3aca2e948cea" +state_hub_task_id: "914a31ae-9fbf-5c8d-a5df-cc5a3c4633e3" ``` Define build, test, and production applier capabilities, including exact @@ -141,10 +141,10 @@ grant secret value reads or writes. ## T02 - Implement a CCR-aware applier dry-run ```task -id: RAILIANCE-WP-0008-T02 +id: RPF-WP-0002-T02 status: done priority: high -state_hub_task_id: "2613f40d-fbd9-44f3-a864-85ec1d54e8f7" +state_hub_task_id: "d02dd668-e75d-59b3-a1db-5c0e5b8ce301" ``` Extend the credential-change tooling so a proposed applier can validate a CCR, @@ -172,10 +172,10 @@ credential-tests` passed with 28 tests. ## T03 - Add non-production applier role first ```task -id: RAILIANCE-WP-0008-T03 +id: RPF-WP-0002-T03 status: done priority: medium -state_hub_task_id: "ff927a19-50fb-4351-8db1-c60a0cce0995" +state_hub_task_id: "945a2847-ceaa-5bba-ab2b-29b4d90abac7" ``` Create a build/test applier identity and prove it can apply approved metadata in @@ -217,10 +217,10 @@ until a non-production lane apply and denial probe are recorded. ## T04 - Add production metadata applier with human approval gate ```task -id: RAILIANCE-WP-0008-T04 +id: RPF-WP-0002-T04 status: done priority: high -state_hub_task_id: "414abd65-22d3-420f-994d-f7fdd1302db5" +state_hub_task_id: "493744db-445d-546f-82ea-2dee4bc72214" ``` Create the production metadata applier path and require a resolved CCR/State Hub @@ -269,10 +269,10 @@ run wrote the workload KV policy and OIDC role metadata without ## T05 - Close the whynot-design pilot ```task -id: RAILIANCE-WP-0008-T05 +id: RPF-WP-0002-T05 status: done priority: high -state_hub_task_id: "18f34c95-4d2b-4a08-a5ad-5ab700ff9dfe" +state_hub_task_id: "b5959c20-7ac7-53a8-ba0d-ee569c122a4f" ``` Use the delegated production metadata applier to finish the whynot-design npm diff --git a/workplans/RAILIANCE-WP-0009-issue-core-runtime-ingestion-key-lane.md b/workplans/RPF-WP-0003-issue-core-runtime-ingestion-key-lane.md similarity index 93% rename from workplans/RAILIANCE-WP-0009-issue-core-runtime-ingestion-key-lane.md rename to workplans/RPF-WP-0003-issue-core-runtime-ingestion-key-lane.md index 18e8bc1..be6bf5b 100644 --- a/workplans/RAILIANCE-WP-0009-issue-core-runtime-ingestion-key-lane.md +++ b/workplans/RPF-WP-0003-issue-core-runtime-ingestion-key-lane.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0009 +id: RPF-WP-0003 type: workplan title: "Issue-Core Runtime Ingestion Credential Lane" domain: financials @@ -20,10 +20,10 @@ related_state_hub_messages: - "f76d3a9e-a98f-4081-885d-b79d94312699" related_ccrs: - CCR-2026-0002 -state_hub_workstream_id: "b059c81d-96f1-451f-896f-a05cd73744a1" +state_hub_workstream_id: "5fb6b6a7-3a40-5658-9804-21c0928c6dd9" --- -# RAILIANCE-WP-0009 - Issue-Core Runtime Ingestion Credential Lane +# RPF-WP-0003 - Issue-Core Runtime Ingestion Credential Lane ## Goal @@ -94,10 +94,10 @@ from the CCR before approval if issue-core no longer needs it in this lane. ## T01 - Review CCR scope and field set ```task -id: RAILIANCE-WP-0009-T01 +id: RPF-WP-0003-T01 status: done priority: high -state_hub_task_id: "64d85288-38fb-4374-b889-fd0d136d3bdf" +state_hub_task_id: "a4675954-898a-5b9c-b549-06c5a4bb2afe" ``` Review `CCR-2026-0002` with the platform operator and issue-core owner before @@ -125,10 +125,10 @@ not approval to apply. ## T02 - Confirm Kubernetes auth and External Secrets binding ```task -id: RAILIANCE-WP-0009-T02 +id: RPF-WP-0003-T02 status: done priority: high -state_hub_task_id: "7f4a8317-13f0-4be3-948c-a2e2f90447cf" +state_hub_task_id: "8c938e3e-3302-5f1f-a422-03dd7eca7ed1" ``` Confirm the exact Kubernetes service account, namespace, and External Secrets @@ -156,10 +156,10 @@ applier-dry-run CCR-2026-0002` now blocks only because the CCR is still ## T03 - Apply or confirm least-privilege OpenBao metadata ```task -id: RAILIANCE-WP-0009-T03 +id: RPF-WP-0003-T03 status: done priority: high -state_hub_task_id: "e8566cf4-bb74-4515-b434-7cbf60f9f684" +state_hub_task_id: "b0fd87d6-9150-5607-8102-411d0a373e1b" ``` Apply the read policy and Kubernetes auth role only after review and binding @@ -180,10 +180,10 @@ Acceptance: ## T04 - Provision values through approved custody ```task -id: RAILIANCE-WP-0009-T04 +id: RPF-WP-0003-T04 status: done priority: high -state_hub_task_id: "4990fe6a-ae84-4720-bc8d-e026d73a304b" +state_hub_task_id: "8b2d803d-7165-58c4-b9ce-95d45273b8fb" ``` Have an approved operator create or confirm the OpenBao KV entry and fields. @@ -201,10 +201,10 @@ Acceptance: ## T05 - Verify positive and negative access ```task -id: RAILIANCE-WP-0009-T05 +id: RPF-WP-0003-T05 status: done priority: high -state_hub_task_id: "65e83572-2e46-4196-8f4d-4ab35ba8d1a6" +state_hub_task_id: "83c98191-b9eb-5189-9aa7-06cb58424f95" ``` Prove that the approved issue-core identity can consume the lane and that other @@ -225,10 +225,10 @@ Acceptance: ## T06 - Activate ops-warden catalog front door ```task -id: RAILIANCE-WP-0009-T06 +id: RPF-WP-0003-T06 status: done priority: medium -state_hub_task_id: "0d9a02da-c032-43d5-8019-61ab4d87b40b" +state_hub_task_id: "f8a321d1-e898-5a96-b4c5-b025739e5d9c" ``` Send ops-warden the non-secret pointers needed to promote @@ -259,10 +259,10 @@ ops-warden proxies reads as the caller and holds no secret value. ## T07 - Record lifecycle operations ```task -id: RAILIANCE-WP-0009-T07 +id: RPF-WP-0003-T07 status: done priority: medium -state_hub_task_id: "c85d1139-1f7d-4ed4-a2fc-5ea4ecbdf0c6" +state_hub_task_id: "cac50ef4-7236-5218-8882-c9e5cc1f772f" ``` Document how to deactivate, rotate, and respond to compromise for this lane. diff --git a/workplans/RAILIANCE-WP-0010-llm-connect-openrouter-provider-key-lane.md b/workplans/RPF-WP-0004-llm-connect-openrouter-provider-key-lane.md similarity index 95% rename from workplans/RAILIANCE-WP-0010-llm-connect-openrouter-provider-key-lane.md rename to workplans/RPF-WP-0004-llm-connect-openrouter-provider-key-lane.md index 36d2597..f5716fe 100644 --- a/workplans/RAILIANCE-WP-0010-llm-connect-openrouter-provider-key-lane.md +++ b/workplans/RPF-WP-0004-llm-connect-openrouter-provider-key-lane.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0010 +id: RPF-WP-0004 type: workplan title: "llm-connect OpenRouter Provider Key Lane" domain: financials @@ -20,10 +20,10 @@ related_state_hub_messages: - "f76d3a9e-a98f-4081-885d-b79d94312699" related_ccrs: - CCR-2026-0003 -state_hub_workstream_id: "f364d405-a85d-4b89-b600-1964ab436cad" +state_hub_workstream_id: "afc66064-7ba4-5f11-b61f-d76890244b7e" --- -# RAILIANCE-WP-0010 - llm-connect OpenRouter Provider Key Lane +# RPF-WP-0004 - llm-connect OpenRouter Provider Key Lane ## Goal @@ -96,10 +96,10 @@ The plan supports these `INTENT.md` principles: ## T01 - Review CCR scope and selector naming ```task -id: RAILIANCE-WP-0010-T01 +id: RPF-WP-0004-T01 status: done priority: high -state_hub_task_id: "307b75a6-a3a8-473b-b171-7379d2848698" +state_hub_task_id: "b635b254-e24d-5f34-b5d9-06ca167765e8" ``` Review `CCR-2026-0003` with the platform operator and activity-core owner @@ -134,10 +134,10 @@ the CCR out of `proposed`. ## T02 - Confirm Kubernetes auth and External Secrets binding ```task -id: RAILIANCE-WP-0010-T02 +id: RPF-WP-0004-T02 status: done priority: high -state_hub_task_id: "829192f5-4502-44e0-8020-656d74d5282a" +state_hub_task_id: "c692c020-6705-55c4-9a80-358f83fc67f8" ``` Confirm the exact Kubernetes service account, namespace, and External Secrets @@ -169,10 +169,10 @@ CCR is still `proposed`. ## T03 - Apply or confirm least-privilege OpenBao metadata ```task -id: RAILIANCE-WP-0010-T03 +id: RPF-WP-0004-T03 status: done priority: high -state_hub_task_id: "42796ef5-c4a0-45a7-ae41-0ebdeccdb01d" +state_hub_task_id: "55abf986-bc9c-5025-9513-36ca0f2861d3" ``` Apply the read policy and Kubernetes auth role only after review and binding @@ -193,10 +193,10 @@ Acceptance: ## T04 - Provision the provider key through approved custody ```task -id: RAILIANCE-WP-0010-T04 +id: RPF-WP-0004-T04 status: done priority: high -state_hub_task_id: "651f6ec8-b7d6-45e6-9fef-08646ff737c2" +state_hub_task_id: "cb1272ca-9cbc-5ca6-bf3c-af0c2c18c887" ``` Have an approved operator create or confirm the OpenBao KV entry and @@ -215,10 +215,10 @@ Acceptance: ## T05 - Verify positive and negative access ```task -id: RAILIANCE-WP-0010-T05 +id: RPF-WP-0004-T05 status: done priority: high -state_hub_task_id: "d538cfc0-bf68-4889-a5b3-ed94c1679856" +state_hub_task_id: "cdc65efd-a733-5a13-b439-85bc24712143" ``` Prove that the approved llm-connect identity can consume the lane and that @@ -239,10 +239,10 @@ Acceptance: ## T06 - Activate ops-warden catalog front door ```task -id: RAILIANCE-WP-0010-T06 +id: RPF-WP-0004-T06 status: done priority: medium -state_hub_task_id: "376de3fe-ef9c-4b57-b238-1ba21ac8bb1c" +state_hub_task_id: "83f6801c-1355-5b0f-95ba-c35f45175fff" ``` Send ops-warden the non-secret pointers needed to promote the agreed @@ -273,10 +273,10 @@ positive/negative verification. ## T07 - Record lifecycle operations ```task -id: RAILIANCE-WP-0010-T07 +id: RPF-WP-0004-T07 status: done priority: medium -state_hub_task_id: "130155a5-e0f9-49f8-ba27-b48098746f02" +state_hub_task_id: "d9386de3-5b68-5ed2-a44b-3b21705b720f" ``` Document how to deactivate, rotate, and respond to compromise for this lane. @@ -293,7 +293,7 @@ Acceptance: ## T08 - Reconcile the railiance01 consumer after provider 401 ```task -id: RAILIANCE-WP-0010-T08 +id: RPF-WP-0004-T08 status: cancel priority: high ``` diff --git a/workplans/RAILIANCE-WP-0011-reuse-surface-runtime-secrets-openbao-lane.md b/workplans/RPF-WP-0005-reuse-surface-runtime-secrets-openbao-lane.md similarity index 91% rename from workplans/RAILIANCE-WP-0011-reuse-surface-runtime-secrets-openbao-lane.md rename to workplans/RPF-WP-0005-reuse-surface-runtime-secrets-openbao-lane.md index da41254..db75d93 100644 --- a/workplans/RAILIANCE-WP-0011-reuse-surface-runtime-secrets-openbao-lane.md +++ b/workplans/RPF-WP-0005-reuse-surface-runtime-secrets-openbao-lane.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0011 +id: RPF-WP-0005 type: workplan title: "reuse-surface Runtime Secrets OpenBao Lane" domain: financials @@ -16,10 +16,10 @@ related_repos: - railiance-apps - reuse-surface - ops-warden -state_hub_workstream_id: "46760f03-a08d-490b-b14b-b16012ccc6e7" +state_hub_workstream_id: "7fe172fe-d987-52a0-aa36-67d6a1dd5a7c" --- -# RAILIANCE-WP-0011 — reuse-surface Runtime Secrets OpenBao Lane +# RPF-WP-0005 — reuse-surface Runtime Secrets OpenBao Lane ## Goal @@ -63,10 +63,10 @@ and keep `make reuse-forgejo-webhook` idempotent. ## Draft OpenBao + ESO Lane ```task -id: RAILIANCE-WP-0011-T01 +id: RPF-WP-0005-T01 status: done priority: medium -state_hub_task_id: "ed5d785d-aef9-4afc-a22f-64d8c5db10f9" +state_hub_task_id: "4e7f5200-37a5-5208-b01e-a9633fb056df" ``` - Draft CCR for the lane (path, fields, policy, k8s role, ESO target) @@ -83,10 +83,10 @@ T02 blocked on platform-operator and reuse-surface-owner approval. ## Platform Apply And Verification ```task -id: RAILIANCE-WP-0011-T02 +id: RPF-WP-0005-T02 status: done priority: medium -state_hub_task_id: "5c27ccc2-222a-4b2c-a3b6-5a72ded18dfd" +state_hub_task_id: "01b661a1-315b-566c-ad15-00cb71640f5a" ``` Blocked on CCR-2026-0005 approval. @@ -106,10 +106,10 @@ path. CCR status `verified`. T03 catalog migration remains open. ## Consumer Handoff And Catalog Migration ```task -id: RAILIANCE-WP-0011-T03 +id: RPF-WP-0005-T03 status: done priority: low -state_hub_task_id: "096fae4b-00f2-452c-ab36-8777329e273c" +state_hub_task_id: "a521036b-2858-5a42-9d23-6f142137ee6d" ``` Blocked on T02 verification. @@ -129,10 +129,10 @@ documented as break-glass only. CCR-2026-0005 front door `ready`/`resolvable=tru ## Forgejo Webhook Rotation Runbook ```task -id: RAILIANCE-WP-0011-T04 +id: RPF-WP-0005-T04 status: done priority: low -state_hub_task_id: "2ac325df-4882-478b-9ac8-aa4b1e9fa541" +state_hub_task_id: "cf1f198e-2af2-5f62-8e3b-1edfc9f537c8" ``` Blocked on T03. diff --git a/workplans/RAILIANCE-WP-0012-rapp-openbao-extraction-boundary.md b/workplans/RPF-WP-0006-rapp-openbao-extraction-boundary.md similarity index 89% rename from workplans/RAILIANCE-WP-0012-rapp-openbao-extraction-boundary.md rename to workplans/RPF-WP-0006-rapp-openbao-extraction-boundary.md index 76c86dc..f84dec3 100644 --- a/workplans/RAILIANCE-WP-0012-rapp-openbao-extraction-boundary.md +++ b/workplans/RPF-WP-0006-rapp-openbao-extraction-boundary.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0012 +id: RPF-WP-0006 type: workplan title: "rapp-openbao extraction boundary" domain: financials @@ -9,10 +9,10 @@ owner: codex topic_slug: railiance created: "2026-07-25" updated: "2026-07-26" -state_hub_workstream_id: "6ec5f317-e6c6-48e8-a7d4-850c13541641" +state_hub_workstream_id: "8d292bab-76dd-5ac3-b39d-6bc460ce27d7" --- -# RAILIANCE-WP-0012 - rapp-openbao extraction boundary +# RPF-WP-0006 - rapp-openbao extraction boundary ## Goal @@ -39,10 +39,10 @@ It must not: ## T01 - Separate package assets from platform-governance assets ```task -id: RAILIANCE-WP-0012-T01 +id: RPF-WP-0006-T01 status: done priority: high -state_hub_task_id: "498a89e1-67e1-4860-8c73-cc38dd92083c" +state_hub_task_id: "5c0e5411-e47a-5a90-9005-b01762351c0a" ``` Classify the current OpenBao-related files into: @@ -59,10 +59,10 @@ governance material. ## T02 - Define the first `rapp-openbao` move set ```task -id: RAILIANCE-WP-0012-T02 +id: RPF-WP-0006-T02 status: done priority: high -state_hub_task_id: "67526f71-0220-45fb-ab9d-8cef5628257c" +state_hub_task_id: "3e5f8893-d440-5ce5-a436-3f84edad2e7b" ``` Prepare the first move set for the wrapper, including likely candidates such as: @@ -81,10 +81,10 @@ OpenBao deploy/verify helpers, and the matching `Makefile` targets. ## T03 - Record the retained S3 platform responsibilities ```task -id: RAILIANCE-WP-0012-T03 +id: RPF-WP-0006-T03 status: done priority: high -state_hub_task_id: "30036060-85ec-4a24-a428-9f31dd58f853" +state_hub_task_id: "9a6a2cd9-9306-5721-9652-85f007043c19" ``` Record what must remain in `railiance-platform`, including: @@ -103,10 +103,10 @@ lane governance, delegated automation, credential grants, and SSH signing. ## T04 - Prepare the repo-creation handoff for `rapp-openbao` ```task -id: RAILIANCE-WP-0012-T04 +id: RPF-WP-0006-T04 status: done priority: medium -state_hub_task_id: "25bf2d11-4a85-4259-9027-79768a23a06c" +state_hub_task_id: "a276f76b-48a7-512c-b0f8-786225d88683" ``` Blocked on T01-T03 and the creation of the future `rapp-openbao` repo. diff --git a/workplans/RAILIANCE-WP-0013-forgejo-admin-pat-openbao-cutover.md b/workplans/RPF-WP-0007-forgejo-admin-pat-openbao-cutover.md similarity index 90% rename from workplans/RAILIANCE-WP-0013-forgejo-admin-pat-openbao-cutover.md rename to workplans/RPF-WP-0007-forgejo-admin-pat-openbao-cutover.md index 6982106..d15cae2 100644 --- a/workplans/RAILIANCE-WP-0013-forgejo-admin-pat-openbao-cutover.md +++ b/workplans/RPF-WP-0007-forgejo-admin-pat-openbao-cutover.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0013 +id: RPF-WP-0007 type: workplan title: "Forgejo admin PAT OpenBao consumer cutover" domain: financials @@ -12,10 +12,10 @@ updated: "2026-07-26" related_repos: - activity-core - ops-warden -state_hub_workstream_id: "38fa254d-cd56-498a-8385-f9673ec005ac" +state_hub_workstream_id: "f4fd52ba-4e84-52e7-a8d7-667b72d3cc1b" --- -# RAILIANCE-WP-0013 - Forgejo admin PAT OpenBao consumer cutover +# RPF-WP-0007 - Forgejo admin PAT OpenBao consumer cutover ## Goal @@ -44,10 +44,10 @@ It must not: ## T01 - Inventory current consumer and fallback paths ```task -id: RAILIANCE-WP-0013-T01 +id: RPF-WP-0007-T01 status: done priority: medium -state_hub_task_id: "68131f3b-cb97-4aa9-abbb-cddb1e395703" +state_hub_task_id: "3e8ee5f4-cdca-5803-8a15-86156faf5673" ``` Record where the current Forgejo admin PAT is consumed and documented, including: @@ -67,10 +67,10 @@ approved lane reference already lived in `CCR-2026-0006` and ## T02 - Implement the approved non-file fallback path ```task -id: RAILIANCE-WP-0013-T02 +id: RPF-WP-0007-T02 status: done priority: high -state_hub_task_id: "f67a58e5-d780-4226-97a8-4c669b47e4a4" +state_hub_task_id: "2684056f-39a9-503a-91df-36f287fe4654" ``` Change the package-prune consumer so that, when `FORGEJO_TOKEN` and @@ -90,10 +90,10 @@ break-glass handoffs, and `/tmp/forgejo-tegwick-api-token` only works when ## T03 - Update operator guidance and lane references ```task -id: RAILIANCE-WP-0013-T03 +id: RPF-WP-0007-T03 status: done priority: medium -state_hub_task_id: "ed5f791c-5beb-43bd-844b-4188b604bc3f" +state_hub_task_id: "34ecd9c9-486f-5509-bb74-6836d3515100" ``` Refresh the operator docs so they align with `CCR-2026-0006`, the routing @@ -110,10 +110,10 @@ break-glass env/file overrides kept for attended sessions. ## T04 - Verify prune workflow and close the inbox request ```task -id: RAILIANCE-WP-0013-T04 +id: RPF-WP-0007-T04 status: done priority: medium -state_hub_task_id: "1fc2af0f-b4ff-4694-b072-23af0254377e" +state_hub_task_id: "90355dee-66dd-593f-9444-a42ff15f2398" ``` Blocked on T01-T03. diff --git a/workplans/RAILIANCE-WP-0014-credential-change-suite-stabilization.md b/workplans/RPF-WP-0008-credential-change-suite-stabilization.md similarity index 90% rename from workplans/RAILIANCE-WP-0014-credential-change-suite-stabilization.md rename to workplans/RPF-WP-0008-credential-change-suite-stabilization.md index f60838a..bfac8dd 100644 --- a/workplans/RAILIANCE-WP-0014-credential-change-suite-stabilization.md +++ b/workplans/RPF-WP-0008-credential-change-suite-stabilization.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0014 +id: RPF-WP-0008 type: workplan title: "Credential-change test suite stabilization" domain: financials @@ -12,10 +12,10 @@ updated: "2026-08-11" related_repos: - rapp-postgres - ops-warden -state_hub_workstream_id: "4dea40b7-43f5-499a-8919-79221623aa79" +state_hub_workstream_id: "ec6b9fe2-5aae-5eb0-ba05-c1be241eda6b" --- -# RAILIANCE-WP-0014 - Credential-change test suite stabilization +# RPF-WP-0008 - Credential-change test suite stabilization ## Goal @@ -60,10 +60,10 @@ It must not: ## Tasks ```task -id: RAILIANCE-WP-0014-T01 +id: RPF-WP-0008-T01 status: done priority: high -state_hub_task_id: "18d3358b-2cd6-4fe0-aab6-602f85d8cccd" +state_hub_task_id: "300632b3-f89c-523e-a31f-b9bc98c8df30" ``` Repair `CCR-2026-0009` (qonto-assistant workload KV read lane) so it validates: @@ -78,10 +78,10 @@ The CCR stays `status: proposed` with `resolvable: false` — this task adds the missing source artifact, it does not advance the lane. ```task -id: RAILIANCE-WP-0014-T02 +id: RPF-WP-0008-T02 status: done priority: high -state_hub_task_id: "4705a142-4168-41a8-aba0-691d8fc3c6bd" +state_hub_task_id: "9533e97b-06dc-58d5-8249-fe299bad438d" ``` Stop the refusal tests depending on live CCR lifecycle state. Add a @@ -99,10 +99,10 @@ confirmation prompt. The gate ordering in `scripts/credential-change.py` was already correct and was left untouched. ```task -id: RAILIANCE-WP-0014-T03 +id: RPF-WP-0008-T03 status: done priority: medium -state_hub_task_id: "dd34d578-97e5-4c26-aef8-faafc994c387" +state_hub_task_id: "1b417fe7-6703-5663-9f3c-3a040ce1fe6f" ``` Fix `test_approve_records_comment_but_unconfirmed_claim_still_blocks_apply`, @@ -113,10 +113,10 @@ which demoted an active CCR to `approved` while leaving test actually wants. The validation rule is correct and unchanged. ```task -id: RAILIANCE-WP-0014-T04 +id: RPF-WP-0008-T04 status: done priority: high -state_hub_task_id: "457053f2-261f-4c80-92d4-c084e6236e88" +state_hub_task_id: "83a4e8da-5ebb-5006-8aa8-2fe02169f9ba" ``` Confirm acceptance against the requested criteria: diff --git a/workplans/RAILIANCE-WP-0015-platform-rapp-consistency.md b/workplans/RPF-WP-0009-platform-rapp-consistency.md similarity index 92% rename from workplans/RAILIANCE-WP-0015-platform-rapp-consistency.md rename to workplans/RPF-WP-0009-platform-rapp-consistency.md index f892631..a8dc368 100644 --- a/workplans/RAILIANCE-WP-0015-platform-rapp-consistency.md +++ b/workplans/RPF-WP-0009-platform-rapp-consistency.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0015 +id: RPF-WP-0009 type: workplan title: "Platform rapp consistency and deployment-management contract" domain: financials @@ -15,10 +15,10 @@ related_repos: - reef-railiance - rapp-openbao - rapp-postgres -state_hub_workstream_id: "1c73af72-fd4b-5ab6-8ff7-a3c302bf55a5" +state_hub_workstream_id: "cd85bf28-7050-59a7-9af2-a7455b3df0fb" --- -# RAILIANCE-WP-0015 - Platform rapp consistency and deployment-management contract +# RPF-WP-0009 - Platform rapp consistency and deployment-management contract ## Goal @@ -104,10 +104,10 @@ It must not: ## Tasks ```task -id: RAILIANCE-WP-0015-T01 +id: RPF-WP-0009-T01 status: done priority: high -state_hub_task_id: "37117b07-196d-5095-ba6b-f2123db4bf3b" +state_hub_task_id: "512adfef-a561-5b60-b4f3-f60e67696ef9" ``` Publish the S3 platform-service rapp pattern as `docs/rapp-platform-service-pattern.md`: @@ -118,10 +118,10 @@ credential-lane binding. Generalize from the existing inventing a third boundary vocabulary. ```task -id: RAILIANCE-WP-0015-T02 +id: RPF-WP-0009-T02 status: done priority: high -state_hub_task_id: "a71c1bdd-4bc7-5547-bc00-0cdc7d459a4b" +state_hub_task_id: "29b55ae5-74e2-5110-892c-ebb2b0cbf550" ``` Bring `rapp-openbao/declarations/rapp.yaml` and @@ -134,10 +134,10 @@ with the `railiance-master` schema proposal (T04) before editing, so the two do not converge on different answers. ```task -id: RAILIANCE-WP-0015-T03 +id: RPF-WP-0009-T03 status: done priority: medium -state_hub_task_id: "b5cc6fe2-a9c2-5f27-bcb7-a2e22e96b04b" +state_hub_task_id: "53cb32e3-5cdc-5664-b7be-c46828849c56" ``` Correct the reef binding registry: propose to `reef-railiance` that @@ -147,10 +147,10 @@ declaration. Ask that the binding be derived or checked rather than hand-listed, since a hand-listed registry is what went stale. ```task -id: RAILIANCE-WP-0015-T04 +id: RPF-WP-0009-T04 status: done priority: high -state_hub_task_id: "3bfe6fba-6e7a-52f1-8b7f-906ba1e065cd" +state_hub_task_id: "b157de50-ff34-57aa-800e-d2d79e65a731" ``` Route the schema and validator proposal to `railiance-master`: a @@ -160,10 +160,10 @@ member field, and a refresh of `rapp-first-wave-candidates.md` to reflect what was actually built and the grouped-context wave-2 inventory. ```task -id: RAILIANCE-WP-0015-T05 +id: RPF-WP-0009-T05 status: done priority: medium -state_hub_task_id: "d4223b6e-4e46-5c4c-9d1d-94812b2e8bf6" +state_hub_task_id: "57ed22c9-94b9-526d-beb0-0a090eeaac3a" ``` Route the canon promotion proposal to `the-custodian`: a @@ -173,10 +173,10 @@ and admission of the `rail-`/`rapp-`/`reef-` prefixes into the open C-31 failures on multi-segment `RAPP-*-WP-` ids. ```task -id: RAILIANCE-WP-0015-T06 +id: RPF-WP-0009-T06 status: done priority: medium -state_hub_task_id: "222afddc-1ac9-5045-b369-f3c2a10a9733" +state_hub_task_id: "4423fa37-7e0d-5e2d-ac39-f6b505c60243" ``` Define how a rapp binds to its credential lane: the relationship between diff --git a/workplans/RAILIANCE-WP-0016-apps-pg-resource-evidence.md b/workplans/RPF-WP-0010-apps-pg-resource-evidence.md similarity index 81% rename from workplans/RAILIANCE-WP-0016-apps-pg-resource-evidence.md rename to workplans/RPF-WP-0010-apps-pg-resource-evidence.md index 6243325..d5e6697 100644 --- a/workplans/RAILIANCE-WP-0016-apps-pg-resource-evidence.md +++ b/workplans/RPF-WP-0010-apps-pg-resource-evidence.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0016 +id: RPF-WP-0010 type: workplan title: "Publish apps-pg resource and recovery evidence" domain: financials @@ -9,13 +9,13 @@ owner: codex topic_slug: railiance created: "2026-08-11" updated: "2026-08-14" -state_hub_workstream_id: "857ca302-bb94-5d41-a649-1aa966368df4" +state_hub_workstream_id: "ee4a867f-eae2-5e85-b0b1-9802a3f31f10" related: - RAILIANCE-WP-0003 - RESOURCE-WP-0003 --- -# RAILIANCE-WP-0016 — apps-pg resource evidence +# RPF-WP-0010 — apps-pg resource evidence ## Goal @@ -26,10 +26,10 @@ utilization, recovery, operations labor, and consumer allocation. Origin: ## T01 — Publish database capacity and utilization ```task -id: RAILIANCE-WP-0016-T01 +id: RPF-WP-0010-T01 status: done priority: high -state_hub_task_id: "475b8930-1e75-580b-a5e4-ce14b038c0ce" +state_hub_task_id: "4cba1304-9a5d-5a26-8706-fe1df7ca5d4e" ``` Record instance count, CPU/memory requests and observed use, provisioned and @@ -42,10 +42,10 @@ application data or credentials. ## T02 — Publish recovery and operational evidence ```task -id: RAILIANCE-WP-0016-T02 +id: RPF-WP-0010-T02 status: done priority: high -state_hub_task_id: "a2ca2b69-f089-5ae4-8c97-bc031503f304" +state_hub_task_id: "382751c3-b05c-51d1-9a9c-d64363978851" ``` Record backup coverage, restore-test results, recovery objectives, upgrade and @@ -58,10 +58,10 @@ storage risk, and platform labor cost. ## T03 — Define shared database allocation drivers ```task -id: RAILIANCE-WP-0016-T03 +id: RPF-WP-0010-T03 status: done priority: medium -state_hub_task_id: "159eefae-d81c-57db-969f-0f9fcecdbc18" +state_hub_task_id: "01148c0f-9d21-5c64-be99-cb5f42697274" ``` Publish candidate consumer drivers such as database storage GB-month, @@ -74,8 +74,8 @@ making railiance-platform a financial ledger. ## Outcome Published 2026-08-14. Observation -`docs/evidence/RAILIANCE-WP-0016-apps-pg-observation.json` and narrative -`docs/evidence/RAILIANCE-WP-0016-apps-pg-resource-evidence.md`. +`docs/evidence/RPF-WP-0010-apps-pg-observation.json` and narrative +`docs/evidence/RPF-WP-0010-apps-pg-resource-evidence.md`. - T01: 1/1 instance, 10Gi local-path, 590 MiB PGDATA, no CPU/memory requests, two consumer catalogs (~16.6 MiB), `vergabe_db` unused. diff --git a/workplans/RAILIANCE-WP-0016-architecture-cleanup-backlog.md b/workplans/RPF-WP-0011-architecture-cleanup-backlog.md similarity index 95% rename from workplans/RAILIANCE-WP-0016-architecture-cleanup-backlog.md rename to workplans/RPF-WP-0011-architecture-cleanup-backlog.md index 20a54f1..1dbb317 100644 --- a/workplans/RAILIANCE-WP-0016-architecture-cleanup-backlog.md +++ b/workplans/RPF-WP-0011-architecture-cleanup-backlog.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0016 +id: RPF-WP-0011 type: workplan title: "Architecture cleanup backlog, WSJF-prioritized" domain: financials @@ -16,10 +16,10 @@ related_repos: - railiance-enablement - railiance-telemetry - railiance-forge -state_hub_workstream_id: "857ca302-bb94-5d41-a649-1aa966368df4" +state_hub_workstream_id: "b3026cdc-ba4c-5da0-8e69-086e1691fca7" --- -# RAILIANCE-WP-0016 - Architecture cleanup backlog, WSJF-prioritized +# RPF-WP-0011 - Architecture cleanup backlog, WSJF-prioritized ## Goal @@ -97,7 +97,7 @@ ratifications** at WSJF 12.0. **Item 13 is done, not blocked.** `RESOURCE-WP-0002` finished 2026-08-15. Barman is live on `platform-pg`; T05 recorded full restore and PITR on 2026-08-14; daily backups have completed since. Pointer: -`docs/evidence/RAILIANCE-WP-0016-item13-restore-2026-08-15.md`. +`docs/evidence/RPF-WP-0011-item13-restore-2026-08-15.md`. **Item 19 is last and that is deliberate.** S4 build-out is the widest gap in the family, but it is large, and item 12 gives S4 a smaller first @@ -215,10 +215,10 @@ build, check whether it is actually an abandonment.** ## Tasks ```task -id: RAILIANCE-WP-0016-T01 +id: RPF-WP-0011-T01 status: done priority: high -state_hub_task_id: "475b8930-1e75-580b-a5e4-ce14b038c0ce" +state_hub_task_id: "d18ea91e-439b-57b4-a1b1-c39ede985579" ``` Produce the INTENT/SCOPE gap analysis across all `railiance-*` repos, comparing @@ -230,20 +230,20 @@ undeclared*, or *decided but unmoved*, and the third kind is cheapest to clear while blocking the most. ```task -id: RAILIANCE-WP-0016-T02 +id: RPF-WP-0011-T02 status: done priority: high -state_hub_task_id: "a2ca2b69-f089-5ae4-8c97-bc031503f304" +state_hub_task_id: "bc7e49aa-b4a0-5f25-a6ba-a738dad0b3be" ``` Score and order the backlog by WSJF, recording owner and reasoning per item so the ordering can be argued with rather than merely followed. ```task -id: RAILIANCE-WP-0016-T03 +id: RPF-WP-0011-T03 status: done priority: high -state_hub_task_id: "159eefae-d81c-57db-969f-0f9fcecdbc18" +state_hub_task_id: "80c39586-8c2a-59b8-ab7a-578d479d45c7" ``` Route the backlog to `railiance-master` for adoption, with the recommendation @@ -251,10 +251,10 @@ that it takes items 2, 3, 4, 6, 7, 8, 16 and 18 — the ratification and taxonom items — and that this workplan closes once adopted. ```task -id: RAILIANCE-WP-0016-T04 +id: RPF-WP-0011-T04 status: done priority: medium -state_hub_task_id: "cf63809e-f73e-5306-abba-daf8a41ab72d" +state_hub_task_id: "302c718a-133c-544d-8b79-3b876fd25fb5" ``` Rescope items 9 and 10 (telemetry MVP, conformance loop MVP) into deliverable @@ -270,10 +270,10 @@ to build a loop; it is to run what exists, tighten two assertions, and schedule it. ```task -id: RAILIANCE-WP-0016-T05 +id: RPF-WP-0011-T05 status: done priority: medium -state_hub_task_id: "44c19ca1-a627-561e-88ba-4cf642bd5594" +state_hub_task_id: "d3568127-b2b2-5806-84f5-e482a41ccf55" ``` Execute the S3-owned items in WSJF order — 13 (blocked on `9c21c0e0`), 14, 17 — diff --git a/workplans/RAILIANCE-WP-0017-consumption-mode-enforcement.md b/workplans/RPF-WP-0012-consumption-mode-enforcement.md similarity index 89% rename from workplans/RAILIANCE-WP-0017-consumption-mode-enforcement.md rename to workplans/RPF-WP-0012-consumption-mode-enforcement.md index 325de3b..e362293 100644 --- a/workplans/RAILIANCE-WP-0017-consumption-mode-enforcement.md +++ b/workplans/RPF-WP-0012-consumption-mode-enforcement.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0017 +id: RPF-WP-0012 type: workplan title: "Enforce resource-control consumption mode" domain: financials @@ -13,10 +13,10 @@ related: - RESOURCE-WP-0005 origin: residual origin_ref: RESOURCE-WP-0005 -state_hub_workstream_id: "16e8f234-9305-5ff3-af82-4639215a0c54" +state_hub_workstream_id: "519e512d-bef0-54ca-85f0-6912a5219ed5" --- -# RAILIANCE-WP-0017 — enforce consumption mode +# RPF-WP-0012 — enforce consumption mode ## Goal @@ -41,10 +41,10 @@ Runbook: `resource-control/docs/resource-procurement-facility.md`. ## T01 — Subscribe to the consumption-mode signal ```task -id: RAILIANCE-WP-0017-T01 +id: RPF-WP-0012-T01 status: done priority: high -state_hub_task_id: "ac487f39-5c2f-5d9a-b95f-e59f0262bd26" +state_hub_task_id: "c758776c-bd2a-5d38-a9b7-94db66fc0568" ``` Define how platform procurement and admission read the latest diff --git a/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md b/workplans/RPF-WP-0013-agent-high-risk-boundary-coverage.md similarity index 90% rename from workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md rename to workplans/RPF-WP-0013-agent-high-risk-boundary-coverage.md index 115df6e..e696934 100644 --- a/workplans/RAILIANCE-WP-0022-agent-high-risk-boundary-coverage.md +++ b/workplans/RPF-WP-0013-agent-high-risk-boundary-coverage.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0022 +id: RPF-WP-0013 type: workplan title: "Close agent high-risk OpenBao boundary coverage" domain: financials @@ -14,10 +14,10 @@ related: - RISK-F-0009 origin: routed origin_ref: "State Hub message 828e4903-30fe-4903-acfd-cd2ecdda437d" -state_hub_workstream_id: "a7977cbf-ab43-56b7-b7a9-ceb52382b341" +state_hub_workstream_id: "25c0b1c9-a1b7-5844-bd39-9db165fe196c" --- -# RAILIANCE-WP-0022 — Agent high-risk boundary coverage +# RPF-WP-0013 — Agent high-risk boundary coverage ## Goal @@ -37,10 +37,10 @@ establish whether any agent identity actually carries the boundary. ## T01 — Reconcile catalog coverage ```task -id: RAILIANCE-WP-0022-T01 +id: RPF-WP-0013-T01 status: done priority: high -state_hub_task_id: "15cc7f31-4385-500c-9cf9-b356674d8c89" +state_hub_task_id: "35855316-3282-52d2-922e-43af1c4495c0" ``` Run the capabilities-only ops-warden audit against the policy. The initial @@ -52,10 +52,10 @@ No credential value was read. ## T02 — Close the concrete deny gaps ```task -id: RAILIANCE-WP-0022-T02 +id: RPF-WP-0013-T02 status: done priority: high -state_hub_task_id: "08041e2d-c65e-5977-a4db-82c85ab17d02" +state_hub_task_id: "9f2a6ffc-5f48-5e45-b636-76dff7d41743" ``` Add deny-data/read-metadata pairs for the six catalog paths: whynot-design npm, @@ -71,10 +71,10 @@ catalog entries covered with none uncovered. ## T03 — Apply and verify live ```task -id: RAILIANCE-WP-0022-T03 +id: RPF-WP-0013-T03 status: done priority: high -state_hub_task_id: "021b5c1a-a3fe-510a-93d9-89cd0adb632e" +state_hub_task_id: "92b4b531-986d-54b4-a18b-cd8785dca5ce" ``` Under attended platform authority, upload the reviewed policy, read it back, @@ -91,10 +91,10 @@ lanes without a concrete address. No Secret value was read. ## T04 — Route the result ```task -id: RAILIANCE-WP-0022-T04 +id: RPF-WP-0013-T04 status: done priority: medium -state_hub_task_id: "96952dd8-0aa7-5498-82a9-b35d47d94694" +state_hub_task_id: "d394fcb7-1477-5dfe-9e4b-65bd14f08346" ``` Reply to ops-warden with the deployment evidence and remaining attachment @@ -113,10 +113,10 @@ repeatable upstream-equality plus policy-coverage command. ## T05 — Establish a distinct coding-agent identity ```task -id: RAILIANCE-WP-0022-T05 +id: RPF-WP-0013-T05 status: done priority: high -state_hub_task_id: "6f034ee3-bbf0-5cbb-bbd2-bb5e9eea6d5d" +state_hub_task_id: "6805ef60-bd20-5549-b955-cee94eb69dad" ``` The policy is live but no role attaches it. Do not add the boundary to @@ -140,10 +140,10 @@ not a blocker to the active AppRole boundary. ## T06 — Consume the generated catalog artifact ```task -id: RAILIANCE-WP-0022-T06 +id: RPF-WP-0013-T06 status: done priority: high -state_hub_task_id: "3e7bf3f0-10b9-55f8-8393-54158b88542f" +state_hub_task_id: "1b0c4f03-0ec7-5fcc-908d-beed236e4865" ``` diff --git a/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md b/workplans/RPF-WP-0014-hub-core-candidate-credential-lanes.md similarity index 84% rename from workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md rename to workplans/RPF-WP-0014-hub-core-candidate-credential-lanes.md index 6b51c1b..86f9b74 100644 --- a/workplans/RAILIANCE-WP-0023-hub-core-candidate-credential-lanes.md +++ b/workplans/RPF-WP-0014-hub-core-candidate-credential-lanes.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0023 +id: RPF-WP-0014 type: workplan title: "Hub-core candidate credential lanes" domain: financials @@ -13,7 +13,7 @@ related: - CORE-WP-0010 - RAPPCOREHUB-WP-0002 - RAPP-POSTGRES-WP-0004 -state_hub_workstream_id: "ec52fbe6-571b-570e-884b-c7a32ff7bcc8" +state_hub_workstream_id: "ab1c2145-528b-50af-b36e-161f28325848" --- # Hub-core candidate credential lanes @@ -21,10 +21,10 @@ state_hub_workstream_id: "ec52fbe6-571b-570e-884b-c7a32ff7bcc8" ## Extend exact-scope policy and projections ```task -id: RAILIANCE-WP-0023-T01 +id: RPF-WP-0014-T01 status: done priority: high -state_hub_task_id: "d3d45d08-3e95-5669-b321-c1e8474d2eb0" +state_hub_task_id: "b30ba596-14c8-54c2-92fc-530bbbc965a8" ``` Add only `database/creds/hub-core-runtime` and @@ -34,10 +34,10 @@ database store, with separate five-minute ExternalSecret projections. ## Activate and verify production lanes ```task -id: RAILIANCE-WP-0023-T02 +id: RPF-WP-0014-T02 status: done priority: high -state_hub_task_id: "c6e180b5-b3e6-500f-8d28-449092780946" +state_hub_task_id: "68766bac-d032-57f9-84cd-a8725cbe0ada" ``` Apply the reviewed policy and projections after rapp-postgres creates the @@ -56,10 +56,10 @@ credential value was read or logged. Evidence: ## Hand off the private candidate ```task -id: RAILIANCE-WP-0023-T03 +id: RPF-WP-0014-T03 status: done priority: high -state_hub_task_id: "58b852a9-98fe-55aa-b3de-316f4d6c4c59" +state_hub_task_id: "0af38f5b-7f59-5e14-8046-646c6fe526cd" ``` Confirm both Secret metadata objects are ready, then hand the candidate diff --git a/workplans/RAILIANCE-WP-0024-audit-core-custody-and-recovery-coordination.md b/workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md similarity index 96% rename from workplans/RAILIANCE-WP-0024-audit-core-custody-and-recovery-coordination.md rename to workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md index dfdca0c..da961bb 100644 --- a/workplans/RAILIANCE-WP-0024-audit-core-custody-and-recovery-coordination.md +++ b/workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0024 +id: RPF-WP-0015 type: workplan title: "Coordinate audit-core temporary custody and recovery exercises" domain: financials @@ -16,10 +16,10 @@ related: - RAILIANCE-WP-0025 origin: routed origin_ref: "State Hub messages 10f80080-4c83-42ba-8590-f23c582d9f05 and a93fa88f-a9c5-4539-93ae-0c8f8490f53d" -state_hub_workstream_id: "88c4ef7f-0af8-580e-90dc-a2bae2675a4d" +state_hub_workstream_id: "f4640325-e89c-591d-b58e-ec6b087900ac" --- -# RAILIANCE-WP-0024 — audit-core custody and recovery coordination +# RPF-WP-0015 — audit-core custody and recovery coordination ## Goal @@ -47,10 +47,10 @@ lease revocation, firewall change, or host reboot. ## T01 — Define the Whitehat E2 temporary sender lane ```task -id: RAILIANCE-WP-0024-T01 +id: RPF-WP-0015-T01 status: done priority: high -state_hub_task_id: "c4da371a-f35d-5377-9f6a-d34e274c98d0" +state_hub_task_id: "1d0cd97e-bc65-5dfe-b57a-97649419a118" ``` Define the reviewed path for exactly two distinct bearer values with an @@ -118,10 +118,10 @@ copied for another engagement. ## T02 — Define the runtime database lease recovery exercise ```task -id: RAILIANCE-WP-0024-T02 +id: RPF-WP-0015-T02 status: progress priority: high -state_hub_task_id: "caba7fcd-014e-5253-87f7-6993731cb0c4" +state_hub_task_id: "fda4262a-56f6-5f06-a070-8fe7e1297209" ``` Coordinate with `rapp-postgres` and audit-core on a value-safe exercise for @@ -174,10 +174,10 @@ live window after the Whitehat engagement cleanup. ## T03 — Define the coordinated railiance01 reboot exercise ```task -id: RAILIANCE-WP-0024-T03 +id: RPF-WP-0015-T03 status: progress priority: high -state_hub_task_id: "09cf4065-4f8a-5b5f-beec-17f623efb56f" +state_hub_task_id: "ba729d18-f053-539f-86ef-5cb8ad4cce45" ``` Coordinate the single-node outage with `railiance-infra`, @@ -264,10 +264,10 @@ followed by fresh owner receipts and a fresh human decision. ## T04 — Route the contracts and approval gates ```task -id: RAILIANCE-WP-0024-T04 +id: RPF-WP-0015-T04 status: done priority: medium -state_hub_task_id: "22f5011f-aa43-54d0-9c68-66b1b7a2d140" +state_hub_task_id: "52f37fac-2449-5e65-ab5b-8c4889caee48" ``` Route the reviewed procedures to audit-core, `rapp-postgres`, @@ -295,7 +295,7 @@ procedure paths, responsibility boundary, stop conditions, passing automated preflight state, and explicit statement that no live mutation was requested. **Direct review interface (2026-08-22):** -`interfaces/RAILIANCE-WP-0024-owner-reviews.json` and +`interfaces/RPF-WP-0015-owner-reviews.json` and `scripts/wp0024-owner-review.py` replace follow-up prose-to-task translation with owner-executable `show`, `verify`, `approve`, `request-changes`, and aggregate `status` operations. Approvals are valid only for the canonical diff --git a/workplans/RAILIANCE-WP-0025-versioned-ephemeral-custody-lifecycle.md b/workplans/RPF-WP-0016-versioned-ephemeral-custody-lifecycle.md similarity index 91% rename from workplans/RAILIANCE-WP-0025-versioned-ephemeral-custody-lifecycle.md rename to workplans/RPF-WP-0016-versioned-ephemeral-custody-lifecycle.md index 3d2705a..859e999 100644 --- a/workplans/RAILIANCE-WP-0025-versioned-ephemeral-custody-lifecycle.md +++ b/workplans/RPF-WP-0016-versioned-ephemeral-custody-lifecycle.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0025 +id: RPF-WP-0016 type: workplan title: "Version ephemeral custody projection and broker handoff" domain: financials @@ -15,10 +15,10 @@ related: - AUDIT-WP-0008 origin: run-review origin_ref: "WH-ENG-20260822-AUDIT-E2-02 terminal clean admission abort" -state_hub_workstream_id: "2422d4e7-2125-591e-8e95-80ecc6e09da0" +state_hub_workstream_id: "26165dd5-dca5-5261-b4bf-183d186aad27" --- -# RAILIANCE-WP-0025 — Version ephemeral custody projection and broker handoff +# RPF-WP-0016 — Version ephemeral custody projection and broker handoff ## Goal @@ -36,10 +36,10 @@ unattended cleanup controller. ## T01 — Define projection, broker-readiness, and cleanup receipts ```task -id: RAILIANCE-WP-0025-T01 +id: RPF-WP-0016-T01 status: done priority: high -state_hub_task_id: "b3a27c15-5717-5c9a-a530-b592dfa4b6f3" +state_hub_task_id: "3d95a854-1c54-58c9-90d2-971b9a9ec5c6" ``` Publish versioned JSON Schemas and canonical validation for the projection @@ -60,10 +60,10 @@ Broker approvals also pin the current hashes of all four interface schemas. ## T02 — Implement a data-driven custody lifecycle ```task -id: RAILIANCE-WP-0025-T02 +id: RPF-WP-0016-T02 status: done priority: high -state_hub_task_id: "b549638b-cd39-57b1-a103-6ceea2a025e1" +state_hub_task_id: "783f74b8-d4a6-5ac5-9300-62acfedc53c6" ``` Replace copied per-engagement code and static manifests with one lifecycle that @@ -84,10 +84,10 @@ engagement-id digest rather than a copied run suffix. ## T03 — Gate projection on a direct broker capability receipt ```task -id: RAILIANCE-WP-0025-T03 +id: RPF-WP-0016-T03 status: done priority: high -state_hub_task_id: "dde2d93a-729d-50ba-88ce-fe0fb12f2c1e" +state_hub_task_id: "e2cced83-5beb-5fb1-919a-72bd6cb49dcf" ``` Provide a direct owner interface for `whitehat-security` to inspect, verify, @@ -110,10 +110,10 @@ adapter must pass the interface itself. ## T04 — Harden execution and transactional cleanup ```task -id: RAILIANCE-WP-0025-T04 +id: RPF-WP-0016-T04 status: done priority: high -state_hub_task_id: "8b85184e-c5c1-56af-920b-b2bd3b6eb4ff" +state_hub_task_id: "a14cb95b-6ef4-5872-a4ec-c7b51577cef1" ``` Centralize remote argv quoting, test shell-hostile arguments, and inject @@ -134,10 +134,10 @@ UID differs from the receipt. ## T05 — Add an approval-ready expired-lease cleanup entry point ```task -id: RAILIANCE-WP-0025-T05 +id: RPF-WP-0016-T05 status: done priority: medium -state_hub_task_id: "af0a0de5-4753-52b9-aa2e-8e052c5254bf" +state_hub_task_id: "8e2840d1-b8e3-5f0f-8c94-f5019fff4e72" ``` Add a fail-closed `cleanup-expired` interface that accepts only a valid @@ -166,10 +166,10 @@ was deployed; those remain a separate owner decision. ## T06 — Export the broker receipt consumed by admission ```task -id: RAILIANCE-WP-0025-T06 +id: RPF-WP-0016-T06 status: done priority: high -state_hub_task_id: "e3a3ee1d-3b6e-5217-bf65-d2a449c45719" +state_hub_task_id: "d815e1b9-73fe-527c-85c9-c20e37cf510f" ``` The first fresh-run setup review found that `approve` posted the canonical diff --git a/workplans/RAILIANCE-WP-0026-attended-login-output-containment.md b/workplans/RPF-WP-0017-attended-login-output-containment.md similarity index 95% rename from workplans/RAILIANCE-WP-0026-attended-login-output-containment.md rename to workplans/RPF-WP-0017-attended-login-output-containment.md index 6e0b853..be9d81b 100644 --- a/workplans/RAILIANCE-WP-0026-attended-login-output-containment.md +++ b/workplans/RPF-WP-0017-attended-login-output-containment.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0026 +id: RPF-WP-0017 type: workplan title: "Contain attended OpenBao login output before authentication" domain: financials @@ -15,10 +15,10 @@ related: - WARDEN-WP-0027-T02-DRILL-20260822-01 origin: routed origin_ref: "State Hub message b3f34c2d-941f-4ddd-b15d-e28075446021" -state_hub_workstream_id: "73878f8d-d8bb-5845-8a5c-91cdd83c1066" +state_hub_workstream_id: "b27975a7-e1bf-595e-8412-de03e167c9ed" --- -# RAILIANCE-WP-0026 — attended OpenBao login output containment +# RPF-WP-0017 — attended OpenBao login output containment ## Goal @@ -50,10 +50,10 @@ seal/unseal ceremony, or reuse of the terminal drill scenario. ## T01 — Harden the attended-login adapter and prove failure containment ```task -id: RAILIANCE-WP-0026-T01 +id: RPF-WP-0017-T01 status: done priority: high -state_hub_task_id: "3c302542-f637-5130-9cd1-5c55fbf109eb" +state_hub_task_id: "e2448d67-8585-5d99-9c00-20c06f1186dd" ``` Implement the fix in `ops-warden` and return one value-safe owner receipt to diff --git a/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md b/workplans/RPF-WP-0018-openbao-operator-only-access.md similarity index 87% rename from workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md rename to workplans/RPF-WP-0018-openbao-operator-only-access.md index c9292aa..e69574a 100644 --- a/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md +++ b/workplans/RPF-WP-0018-openbao-operator-only-access.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0027 +id: RPF-WP-0018 type: workplan title: "Retract public OpenBao listener behind operator-only access" domain: financials @@ -12,10 +12,10 @@ updated: "2026-08-23" related: - RMASTER-WP-0020-T09 - RAPP-OPENBAO-WP-0002 -state_hub_workstream_id: "6f8a6cbc-c076-5f0a-ade2-281a7ec71360" +state_hub_workstream_id: "4fcb6026-2630-59a3-b5de-15f54efcf59d" --- -# RAILIANCE-WP-0027 — OpenBao operator-only access +# RPF-WP-0018 — OpenBao operator-only access ## Goal @@ -25,10 +25,10 @@ destructive CoulombCore cleanup. ## T01 — Align the retained compatibility source ```task -id: RAILIANCE-WP-0027-T01 +id: RPF-WP-0018-T01 status: done priority: high -state_hub_task_id: "d84fb3fd-2166-58a0-81d9-2141ca55a67d" +state_hub_task_id: "88d1342b-5093-5fbc-aa84-1608d163b979" ``` The retained platform manifest now matches the canonical package posture: @@ -39,10 +39,10 @@ rollback artifact. ## T02 — Add guarded retraction and rollback ```task -id: RAILIANCE-WP-0027-T02 +id: RPF-WP-0018-T02 status: done priority: high -state_hub_task_id: "149fdec9-6735-514e-aad1-0c2daf72d27a" +state_hub_task_id: "03f0a5bd-7876-5784-bf02-11cbcdf005bb" ``` `scripts/openbao-public-listener-transition.sh` pins the cluster UID, verifies @@ -53,10 +53,10 @@ It deletes only the Ingress and provides an exact rollback path. ## T03 — Complete the attended operator cutover ```task -id: RAILIANCE-WP-0027-T03 +id: RPF-WP-0018-T03 status: wait priority: high -state_hub_task_id: "99f8b41f-e9db-579d-a6fb-b71337048afc" +state_hub_task_id: "b602226f-8eb5-5609-995f-94f9074b0895" ``` KeyCape revision `d150be1` now admits exactly diff --git a/workplans/RAILIANCE-WP-0028-flex-auth-credential-grant-integration.md b/workplans/RPF-WP-0019-flex-auth-credential-grant-integration.md similarity index 83% rename from workplans/RAILIANCE-WP-0028-flex-auth-credential-grant-integration.md rename to workplans/RPF-WP-0019-flex-auth-credential-grant-integration.md index 43a74bb..6ac0778 100644 --- a/workplans/RAILIANCE-WP-0028-flex-auth-credential-grant-integration.md +++ b/workplans/RPF-WP-0019-flex-auth-credential-grant-integration.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0028 +id: RPF-WP-0019 type: workplan title: "Adopt canonical flex-auth credential-grant checks" domain: financials @@ -13,10 +13,10 @@ related: - FLEX-WP-0012 origin: routed origin_ref: "State Hub decision 1f9f257d-c9f2-4a5e-a018-8058a3f2a51a" -state_hub_workstream_id: "022dda1f-8772-57ad-862e-672924455f11" +state_hub_workstream_id: "6ded9d76-e3a8-5d52-9221-2c7935f3b364" --- -# RAILIANCE-WP-0028 — canonical flex-auth credential-grant checks +# RPF-WP-0019 — canonical flex-auth credential-grant checks ## Goal @@ -27,10 +27,10 @@ consumer-specific flex-auth endpoint. ## T01 — Resolve translation ownership ```task -id: RAILIANCE-WP-0028-T01 +id: RPF-WP-0019-T01 status: done priority: high -state_hub_task_id: "cfec3a0a-a198-580a-988b-4b2d7bac206c" +state_hub_task_id: "9f0c7e4f-6351-51c1-8c5e-39f770668605" ``` The operator explicitly approved Option A in State Hub decision @@ -41,10 +41,10 @@ normalization belong here, before the flex-auth policy boundary. ## T02 — Implement the canonical request and response ```task -id: RAILIANCE-WP-0028-T02 +id: RPF-WP-0019-T02 status: done priority: high -state_hub_task_id: "971f243a-a6cd-5a3a-965a-8191c51c7577" +state_hub_task_id: "8c95e2b5-884c-5504-9998-5bdd8ae64b5d" ``` Change the helper default to `/v1/check`, emit the coordinated @@ -60,10 +60,10 @@ evaluator provenance, and subject/resource binding back to the request. ## T03 — Verify and route the contract ```task -id: RAILIANCE-WP-0028-T03 +id: RPF-WP-0019-T03 status: done priority: medium -state_hub_task_id: "60725d60-ae38-5fe8-971f-8c714261fd1d" +state_hub_task_id: "9d8c534d-72b7-5cac-ada1-72273fb3ab01" ``` Exercise focused allow and deny tests, validate the complete repository suite, diff --git a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md b/workplans/RPF-WP-0020-keycape-live-secret-exposure-recovery.md similarity index 87% rename from workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md rename to workplans/RPF-WP-0020-keycape-live-secret-exposure-recovery.md index 9f23845..c24f20b 100644 --- a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md +++ b/workplans/RPF-WP-0020-keycape-live-secret-exposure-recovery.md @@ -1,5 +1,5 @@ --- -id: RAILIANCE-WP-0029 +id: RPF-WP-0020 type: workplan title: "Coordinate KeyCape live Secret exposure recovery" domain: financials @@ -13,10 +13,10 @@ related: - KEY-WP-0011 origin: routed origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4" -state_hub_workstream_id: "038bc3c0-4492-5b91-95eb-ae515ca205df" +state_hub_workstream_id: "99bdb617-b577-5de3-a9d8-4990ac676e28" --- -# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery +# RPF-WP-0020 — KeyCape live Secret exposure recovery ## Goal @@ -27,10 +27,10 @@ payload and never treat repository access as live mutation authority. ## T01 — Contain and establish the recovery boundary ```task -id: RAILIANCE-WP-0029-T01 +id: RPF-WP-0020-T01 status: done priority: high -state_hub_task_id: "62976143-33f1-5544-b7bb-174aed47e09b" +state_hub_task_id: "4763622c-78aa-556a-ba8e-9b556a2e78fc" ``` Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection, @@ -41,10 +41,10 @@ the public JWKS digest/kid. The legacy value-printing rotation helper is banned. ## T02 — Publish the governed bundle cutover ```task -id: RAILIANCE-WP-0029-T02 +id: RPF-WP-0020-T02 status: done priority: high -state_hub_task_id: "87bedc80-0060-518c-a5f4-3112d3d8d867" +state_hub_task_id: "a897b2f5-b7ae-5dbf-9f51-54b2db5ca6fc" ``` `docs/keycape-live-secret-exposure-recovery.md` defines owners, required @@ -55,10 +55,10 @@ predecessor revocation, and sanitized evidence. ## T03 — Collect exact owner acknowledgements ```task -id: RAILIANCE-WP-0029-T03 +id: RPF-WP-0020-T03 status: progress priority: high -state_hub_task_id: "e019c166-3abb-5edf-81a7-d65f0ea91c93" +state_hub_task_id: "44959415-a917-5dfb-a5ab-80ab166b9096" ``` KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288`, @@ -95,10 +95,10 @@ lane remains unresolved and no credential fetch or retry is authorized. ## T04 — Execute the attended rotation ```task -id: RAILIANCE-WP-0029-T04 +id: RPF-WP-0020-T04 status: wait priority: high -state_hub_task_id: "dbf31617-ff0b-5995-b273-cc0a854221a8" +state_hub_task_id: "d85eeb8a-3147-59e1-bc2a-e84244dde93d" ``` Requires a fresh exact human GO, an at-most-30-minute window, named driver and @@ -108,10 +108,10 @@ and all T03 acknowledgements. No value may enter captured output. ## T05 — Prove predecessor denial and close ```task -id: RAILIANCE-WP-0029-T05 +id: RPF-WP-0020-T05 status: wait priority: high -state_hub_task_id: "c4c23dfb-8762-5017-8d50-5d9c35086736" +state_hub_task_id: "e026d9e6-82d0-5322-a3ef-e69e7f613514" ``` Verify replacement operation and predecessor rejection for the signing key, @@ -122,10 +122,10 @@ status, timestamps, and cleanup receipts. ## T06 — Publish the Railiance/OpenBao custody handoff ```task -id: RAILIANCE-WP-0029-T06 +id: RPF-WP-0020-T06 status: progress priority: high -state_hub_task_id: "69326850-cd3a-556e-a9cc-9d463802545b" +state_hub_task_id: "0b666b58-b73a-5d2e-a4e5-c53769fef85e" ``` The platform/OpenBao owner must publish a non-secret receipt for both routing