fix(workplans): adopt ADR-007 derived identifiers for unregistered records
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

These workplans exist only in the retired local hub. Their random pre-ADR-007
identifiers are refused by C-06 as stale references, so they cannot be
registered. Deriving from the canonical record id takes no identity from
anything: central does not hold them and the old ids die with the cache.

Records central already holds were deliberately left untouched.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
This commit is contained in:
codex 2026-08-25 20:20:45 +02:00
parent 83416e9900
commit ea2e9ec97d
10 changed files with 55 additions and 53 deletions

View file

@ -15,7 +15,7 @@ related_repos:
- reef-railiance
- rapp-openbao
- rapp-postgres
state_hub_workstream_id: "a14fd4d3-2e30-474f-aeea-af560c622394"
state_hub_workstream_id: "1c73af72-fd4b-5ab6-8ff7-a3c302bf55a5"
---
# RAILIANCE-WP-0015 - Platform rapp consistency and deployment-management contract
@ -107,7 +107,7 @@ It must not:
id: RAILIANCE-WP-0015-T01
status: done
priority: high
state_hub_task_id: "53f6a28f-ee10-4695-ab7f-6781b3d35c76"
state_hub_task_id: "37117b07-196d-5095-ba6b-f2123db4bf3b"
```
Publish the S3 platform-service rapp pattern as `docs/rapp-platform-service-pattern.md`:
@ -121,7 +121,7 @@ inventing a third boundary vocabulary.
id: RAILIANCE-WP-0015-T02
status: done
priority: high
state_hub_task_id: "eada3a6f-9f4e-47bc-bfe5-2ec585f5d312"
state_hub_task_id: "a71c1bdd-4bc7-5547-bc00-0cdc7d459a4b"
```
Bring `rapp-openbao/declarations/rapp.yaml` and
@ -137,7 +137,7 @@ not converge on different answers.
id: RAILIANCE-WP-0015-T03
status: done
priority: medium
state_hub_task_id: "493d0ab0-595c-4a14-b3d6-8c396bd7747b"
state_hub_task_id: "b5cc6fe2-a9c2-5f27-bcb7-a2e22e96b04b"
```
Correct the reef binding registry: propose to `reef-railiance` that
@ -150,7 +150,7 @@ since a hand-listed registry is what went stale.
id: RAILIANCE-WP-0015-T04
status: done
priority: high
state_hub_task_id: "30cb0cb2-2ce2-4d27-8d43-c29dc32904a8"
state_hub_task_id: "3bfe6fba-6e7a-52f1-8b7f-906ba1e065cd"
```
Route the schema and validator proposal to `railiance-master`: a
@ -163,7 +163,7 @@ was actually built and the grouped-context wave-2 inventory.
id: RAILIANCE-WP-0015-T05
status: done
priority: medium
state_hub_task_id: "ca661530-5ebd-422b-854d-7b6986f0b3fe"
state_hub_task_id: "d4223b6e-4e46-5c4c-9d1d-94812b2e8bf6"
```
Route the canon promotion proposal to `the-custodian`: a
@ -176,7 +176,7 @@ the open C-31 failures on multi-segment `RAPP-*-WP-` ids.
id: RAILIANCE-WP-0015-T06
status: done
priority: medium
state_hub_task_id: "9ea10522-47a9-4cce-b0d8-cb6f9c7813b8"
state_hub_task_id: "222afddc-1ac9-5045-b369-f3c2a10a9733"
```
Define how a rapp binds to its credential lane: the relationship between

View file

@ -9,7 +9,7 @@ owner: codex
topic_slug: railiance
created: "2026-08-11"
updated: "2026-08-14"
state_hub_workstream_id: "49084fb8-de63-4f32-a4a9-3a42d4e708ac"
state_hub_workstream_id: "857ca302-bb94-5d41-a649-1aa966368df4"
related:
- RAILIANCE-WP-0003
- RESOURCE-WP-0003
@ -29,7 +29,7 @@ utilization, recovery, operations labor, and consumer allocation. Origin:
id: RAILIANCE-WP-0016-T01
status: done
priority: high
state_hub_task_id: "c772bcea-7ae0-4532-b434-31f75c905431"
state_hub_task_id: "475b8930-1e75-580b-a5e4-ce14b038c0ce"
```
Record instance count, CPU/memory requests and observed use, provisioned and
@ -45,7 +45,7 @@ application data or credentials.
id: RAILIANCE-WP-0016-T02
status: done
priority: high
state_hub_task_id: "4eafebd5-0434-42a2-a126-c292c29c1f21"
state_hub_task_id: "a2ca2b69-f089-5ae4-8c97-bc031503f304"
```
Record backup coverage, restore-test results, recovery objectives, upgrade and
@ -61,7 +61,7 @@ storage risk, and platform labor cost.
id: RAILIANCE-WP-0016-T03
status: done
priority: medium
state_hub_task_id: "fc329443-a2fc-4409-b670-dfb103df2794"
state_hub_task_id: "159eefae-d81c-57db-969f-0f9fcecdbc18"
```
Publish candidate consumer drivers such as database storage GB-month,

View file

@ -16,7 +16,7 @@ related_repos:
- railiance-enablement
- railiance-telemetry
- railiance-forge
state_hub_workstream_id: "8611b555-c681-496d-bfba-667198456837"
state_hub_workstream_id: "857ca302-bb94-5d41-a649-1aa966368df4"
---
# RAILIANCE-WP-0016 - Architecture cleanup backlog, WSJF-prioritized
@ -218,7 +218,7 @@ build, check whether it is actually an abandonment.**
id: RAILIANCE-WP-0016-T01
status: done
priority: high
state_hub_task_id: "9fabf938-0479-4282-b1fe-88af0d2fbd36"
state_hub_task_id: "475b8930-1e75-580b-a5e4-ce14b038c0ce"
```
Produce the INTENT/SCOPE gap analysis across all `railiance-*` repos, comparing
@ -233,7 +233,7 @@ while blocking the most.
id: RAILIANCE-WP-0016-T02
status: done
priority: high
state_hub_task_id: "5b4d5f69-40fd-4af0-be23-325864cea48b"
state_hub_task_id: "a2ca2b69-f089-5ae4-8c97-bc031503f304"
```
Score and order the backlog by WSJF, recording owner and reasoning per item so
@ -243,7 +243,7 @@ the ordering can be argued with rather than merely followed.
id: RAILIANCE-WP-0016-T03
status: done
priority: high
state_hub_task_id: "9ede2fe5-5b6c-4792-b141-9c8f140c1a28"
state_hub_task_id: "159eefae-d81c-57db-969f-0f9fcecdbc18"
```
Route the backlog to `railiance-master` for adoption, with the recommendation
@ -254,7 +254,7 @@ items — and that this workplan closes once adopted.
id: RAILIANCE-WP-0016-T04
status: done
priority: medium
state_hub_task_id: "aac02de1-6367-4767-b7ee-c980577e778f"
state_hub_task_id: "cf63809e-f73e-5306-abba-daf8a41ab72d"
```
Rescope items 9 and 10 (telemetry MVP, conformance loop MVP) into deliverable
@ -273,7 +273,7 @@ it.
id: RAILIANCE-WP-0016-T05
status: done
priority: medium
state_hub_task_id: "a40faaf1-77db-43f5-a774-6ab3866d8e1d"
state_hub_task_id: "44c19ca1-a627-561e-88ba-4cf642bd5594"
```
Execute the S3-owned items in WSJF order — 13 (blocked on `9c21c0e0`), 14, 17 —

View file

@ -13,7 +13,7 @@ related:
- RESOURCE-WP-0005
origin: residual
origin_ref: RESOURCE-WP-0005
state_hub_workstream_id: "f33be601-51b5-4bcf-82bf-31f8dba59b9f"
state_hub_workstream_id: "16e8f234-9305-5ff3-af82-4639215a0c54"
---
# RAILIANCE-WP-0017 — enforce consumption mode
@ -44,7 +44,7 @@ Runbook: `resource-control/docs/resource-procurement-facility.md`.
id: RAILIANCE-WP-0017-T01
status: done
priority: high
state_hub_task_id: "1c872918-0872-4b2a-8596-89b106239e54"
state_hub_task_id: "ac487f39-5c2f-5d9a-b95f-e59f0262bd26"
```
Define how platform procurement and admission read the latest

View file

@ -14,7 +14,7 @@ related:
- RISK-F-0009
origin: routed
origin_ref: "State Hub message 828e4903-30fe-4903-acfd-cd2ecdda437d"
state_hub_workstream_id: "b4701216-b235-48d1-a527-b52b8fb7e6fc"
state_hub_workstream_id: "a7977cbf-ab43-56b7-b7a9-ceb52382b341"
---
# RAILIANCE-WP-0022 — Agent high-risk boundary coverage
@ -40,7 +40,7 @@ establish whether any agent identity actually carries the boundary.
id: RAILIANCE-WP-0022-T01
status: done
priority: high
state_hub_task_id: "44d1a4bf-70bb-4d50-a40a-2158acc96b36"
state_hub_task_id: "15cc7f31-4385-500c-9cf9-b356674d8c89"
```
Run the capabilities-only ops-warden audit against the policy. The initial
@ -55,7 +55,7 @@ No credential value was read.
id: RAILIANCE-WP-0022-T02
status: done
priority: high
state_hub_task_id: "97c73849-716f-45d7-878f-5e1811a594ff"
state_hub_task_id: "08041e2d-c65e-5977-a4db-82c85ab17d02"
```
Add deny-data/read-metadata pairs for the six catalog paths: whynot-design npm,
@ -74,7 +74,7 @@ catalog entries covered with none uncovered.
id: RAILIANCE-WP-0022-T03
status: done
priority: high
state_hub_task_id: "9a293b09-dc0c-4575-bdc1-05102fb218a8"
state_hub_task_id: "021b5c1a-a3fe-510a-93d9-89cd0adb632e"
```
Under attended platform authority, upload the reviewed policy, read it back,
@ -94,7 +94,7 @@ lanes without a concrete address. No Secret value was read.
id: RAILIANCE-WP-0022-T04
status: done
priority: medium
state_hub_task_id: "64ddfacf-b3f2-428e-9630-4b9f436f627f"
state_hub_task_id: "96952dd8-0aa7-5498-82a9-b35d47d94694"
```
Reply to ops-warden with the deployment evidence and remaining attachment
@ -116,7 +116,7 @@ repeatable upstream-equality plus policy-coverage command.
id: RAILIANCE-WP-0022-T05
status: done
priority: high
state_hub_task_id: "47aa5ed9-95c5-4a23-a460-e4bbd3ed6f65"
state_hub_task_id: "6f034ee3-bbf0-5cbb-bbd2-bb5e9eea6d5d"
```
The policy is live but no role attaches it. Do not add the boundary to
@ -143,8 +143,10 @@ not a blocker to the active AppRole boundary.
id: RAILIANCE-WP-0022-T06
status: done
priority: high
state_hub_task_id: "3e7bf3f0-10b9-55f8-8393-54158b88542f"
```
Consume ops-warden's versioned `high-risk-data-paths.yaml` as a policy-check
input, add the two newly regraded issue-core and reuse-surface paths, and rerun
source plus live coverage. The input remains ops-warden's risk statement, not

View file

@ -13,7 +13,7 @@ related:
- CORE-WP-0010
- RAPPCOREHUB-WP-0002
- RAPP-POSTGRES-WP-0004
state_hub_workstream_id: "d2adc2d4-6461-4f7b-affc-7248fea49e60"
state_hub_workstream_id: "ec52fbe6-571b-570e-884b-c7a32ff7bcc8"
---
# Hub-core candidate credential lanes
@ -24,7 +24,7 @@ state_hub_workstream_id: "d2adc2d4-6461-4f7b-affc-7248fea49e60"
id: RAILIANCE-WP-0023-T01
status: done
priority: high
state_hub_task_id: "37b69d0e-7eac-40e5-b18a-777fa2b5e2da"
state_hub_task_id: "d3d45d08-3e95-5669-b321-c1e8474d2eb0"
```
Add only `database/creds/hub-core-runtime` and
@ -37,7 +37,7 @@ database store, with separate five-minute ExternalSecret projections.
id: RAILIANCE-WP-0023-T02
status: done
priority: high
state_hub_task_id: "d15f82db-f1ba-467a-bb69-86eb7c314016"
state_hub_task_id: "c6e180b5-b3e6-500f-8d28-449092780946"
```
Apply the reviewed policy and projections after rapp-postgres creates the
@ -59,7 +59,7 @@ credential value was read or logged. Evidence:
id: RAILIANCE-WP-0023-T03
status: done
priority: high
state_hub_task_id: "bb2a73fc-3bee-45a6-83f0-3341639aabdf"
state_hub_task_id: "58b852a9-98fe-55aa-b3de-316f4d6c4c59"
```
Confirm both Secret metadata objects are ready, then hand the candidate

View file

@ -15,7 +15,7 @@ related:
- RAPP-POSTGRES-WP-0002
origin: routed
origin_ref: "net-kingdom/canon/standards/tenancy-posture_v0.1.md §19.2, §20"
state_hub_workstream_id: "d40827cb-bb48-4cdd-9b41-8dfae116d705"
state_hub_workstream_id: "4fcb6026-2630-59a3-b5de-15f54efcf59d"
---
# RPF-WP-0018 — policy surface alignment
@ -181,7 +181,7 @@ repo's `docs/adr/README.md` is one repo's answer to it.
id: RPF-WP-0018-T01
status: done
priority: high
state_hub_task_id: "ff392a23-e72a-4442-843f-929f218404ae"
state_hub_task_id: "88d1342b-5093-5fbc-aa84-1608d163b979"
```
**Publish the S3 posture vector set.** Write `docs/tenancy-posture.md`:
one vector per service under S3 custody (`openbao`, `apps-pg`, and the
@ -194,7 +194,7 @@ Route F4 to `net-kingdom` with the vector set as the evidence.
id: RPF-WP-0018-T02
status: done
priority: high
state_hub_task_id: "962fc494-bb9b-4f67-8e5b-2ed88a670945"
state_hub_task_id: "03f0a5bd-7876-5784-bf02-11cbcdf005bb"
```
**Accept placement ownership, scoped.** Write `docs/placement-policy.md`:
adopt the P0P4 ladder by reference (do not restate it — the canon copy is
@ -208,7 +208,7 @@ either way.
id: RPF-WP-0018-T03
status: done
priority: medium
state_hub_task_id: "f6f30233-3f6e-44a0-a644-7268f9d88f3c"
state_hub_task_id: "b602226f-8eb5-5609-995f-94f9074b0895"
```
**Make triggers monitorable or honestly unmonitored.** For each of the five
§8 triggers, record in `docs/placement-policy.md` what signal would fire it,
@ -222,7 +222,7 @@ report which service classes are co-resident. Today that is
id: RPF-WP-0018-T04
status: done
priority: medium
state_hub_task_id: "8a3ce90b-8af2-4dcd-9a35-77025d2123f2"
state_hub_task_id: "92ce14f6-afee-50f6-abd4-197c4724a589"
```
**Disclose quotas to consumers (§10.2).** Extend
`docs/s3-consumer-interfaces.md` to `1.1.0` — additive under its own
@ -235,7 +235,7 @@ these is announced to bound consumers, not discovered by them.
id: RPF-WP-0018-T05
status: done
priority: medium
state_hub_task_id: "a6da631d-fa4e-4c2b-acc3-d3cf53cfb57f"
state_hub_task_id: "58ef22f8-7f1b-5647-babd-eeb817b3ae31"
```
**Create the ADR surface (F2).** Create `docs/adr/` with an ADR template
carrying the frontmatter `policy-nexus` T02/T05 consume: title, status,
@ -250,7 +250,7 @@ only home for a decision.
id: RPF-WP-0018-T06
status: done
priority: low
state_hub_task_id: "99f2a4d8-b20c-4c43-8c94-0bc469bfcc46"
state_hub_task_id: "49c682a0-a9b7-59f0-ad65-79b4fb9bb79c"
```
**Answer §19.9 — retention floor and ceiling.** Decide whether
`backupRetentionDays` gets a platform minimum (so a consumer asking for one
@ -264,7 +264,7 @@ maximum declared across co-residents, so a shorter horizon is a P2 trigger.
id: RPF-WP-0018-T07
status: done
priority: high
state_hub_task_id: "b021fda3-23bd-4843-8d1b-983b6ec582b5"
state_hub_task_id: "ad7a159b-a395-50e0-a517-d605a1d70108"
```
**Route the findings.** Reply to `rapp-postgres` and `tenant-engine` with
T01/T02 outcomes and F3/F4. Reply to `policy-nexus` with F1 (substrate

View file

@ -13,7 +13,7 @@ related:
- RPF-WP-0018
origin: residual
origin_ref: RPF-WP-0018
state_hub_workstream_id: "160e226d-27b0-4c94-9e99-331f4354dd12"
state_hub_workstream_id: "6ded9d76-e3a8-5d52-9221-2c7935f3b364"
---
# RPF-WP-0019 — apps-pg recoverability and per-consumer controls
@ -144,7 +144,7 @@ T02 are complete. T04 subsequently passed 14/14 and the workplan is finished.
id: RPF-WP-0019-T01
status: done
priority: high
state_hub_task_id: "0f5175c7-bde3-46a0-87a8-b50b5eeac32c"
state_hub_task_id: "9f0c7e4f-6351-51c1-8c5e-39f770668605"
```
**Establish a backup target for `apps-pg`.** Confirm the state of the
`resource-control` bucket and the `platform-pg-backup-s3` OpenBao Secret; if
@ -169,7 +169,7 @@ seconds. See `docs/evidence/RPF-WP-0019-backup-restore-2026-08-20.md`.
id: RPF-WP-0019-T02
status: done
priority: high
state_hub_task_id: "c5b0b2ac-b9f5-42fb-8e75-2fac2ab1e852"
state_hub_task_id: "8c95e2b5-884c-5504-9998-5bdd8ae64b5d"
```
**Declare and enforce per-consumer controls.** Per-consumer connection
allowance, `statement_timeout`, `idle_in_transaction_session_timeout`, and
@ -194,7 +194,7 @@ parameters were also verified live.
id: RPF-WP-0019-T03
status: done
priority: medium
state_hub_task_id: "736cbc11-1992-4f1b-9ff0-cb4622ff39a5"
state_hub_task_id: "9d8c534d-72b7-5cac-ada1-72273fb3ab01"
```
**Declare the ceiling and overflow target.** Owed under this repo's own
Rule P-4.1 before `apps-pg`'s third consumer; it is at two. Name the binding
@ -211,7 +211,7 @@ intentionally remains absent until a fourth consumer is approved.
id: RPF-WP-0019-T04
status: done
priority: medium
state_hub_task_id: "2fccdd26-c9c6-43cb-b069-27ed5668afac"
state_hub_task_id: "88ef2973-98cd-508a-9b10-73efcf6dce14"
```
**Isolation probes, after T02.** Consumer-boundary probes on the
`rapp-postgres` model, then the §13 noisy-neighbour artifact: per-consumer

View file

@ -13,7 +13,7 @@ related:
- RPF-WP-0014
origin: residual
origin_ref: RPF-WP-0019
state_hub_workstream_id: "e2da7c94-0693-40fa-a339-1873b7dd061a"
state_hub_workstream_id: "99bdb617-b577-5de3-a9d8-4990ac676e28"
---
# RPF-WP-0020 — CCR schema drift
@ -78,7 +78,7 @@ draft and a real gap produce identical output.
id: RPF-WP-0020-T01
status: done
priority: high
state_hub_task_id: "3bf8bf9c-ac33-4ce7-8b3f-5b40135b227c"
state_hub_task_id: "4763622c-78aa-556a-ba8e-9b556a2e78fc"
```
**Migrate CCR-2026-0010 to the current schema.** Determine the actual
authentication path for the `email-connect` transactional lane — Kubernetes
@ -101,7 +101,7 @@ out of scope. No Secret value was read.
id: RPF-WP-0020-T02
status: done
priority: medium
state_hub_task_id: "12933d69-82a3-470d-b01c-0c40c28a7984"
state_hub_task_id: "a897b2f5-b7ae-5dbf-9f51-54b2db5ca6fc"
```
**Give the suite a way to express a draft.** Add an explicit in-flight state
so `CCR-2026-0011` is skipped *by declaration* rather than by exception list —
@ -120,7 +120,7 @@ metadata or filling credential placeholders.
id: RPF-WP-0020-T03
status: done
priority: medium
state_hub_task_id: "da52b518-c6fb-40b8-acb9-c64724ca4eee"
state_hub_task_id: "44959415-a917-5dfb-a5ab-80ab166b9096"
```
**Report the drift rather than only fixing it.** If the `openbao.auth`
requirement was added without migrating existing active CCRs, other repos
@ -137,7 +137,7 @@ now documented locally.
id: RPF-WP-0020-T04
status: done
priority: low
state_hub_task_id: "2259ee69-4914-42c4-9175-8c61b2206888"
state_hub_task_id: "d85eeb8a-3147-59e1-bc2a-e84244dde93d"
```
**Make the suite green and keep it that way.** With T01 and T02 done, the full
suite passes. Record in `docs/credential-change-approval.md` that a new

View file

@ -15,7 +15,7 @@ related:
- RAPP-POSTGRES-WP-0003
origin: request
origin_ref: CORE-WP-0011
state_hub_workstream_id: "5f7ee0a7-8c6c-475c-b9d9-32d9c5ee86e5"
state_hub_workstream_id: "aa7fe3ff-a76c-5f26-a1e0-a35e48b28d60"
---
# RPF-WP-0021 — Core Hub platform onboarding
@ -70,7 +70,7 @@ retirement of the old runtime. Those remain explicit operator gates in
id: RPF-WP-0021-T01
status: done
priority: high
state_hub_task_id: "451d4664-fbab-40cf-8a2a-4001ca55fc4c"
state_hub_task_id: "a7cd3fc0-4469-55a6-aed0-a8cacb34c033"
```
Under an attended `net-kingdom-admins` OIDC login to
@ -112,7 +112,7 @@ State Hub; workplan UUID assignment remains with the production registrar.
id: RPF-WP-0021-T02
status: done
priority: high
state_hub_task_id: "f0aea438-9376-47f0-83a8-923570a43759"
state_hub_task_id: "7cac453b-2e85-56d9-abae-d983e382246b"
```
Review `/home/worsch/rapp-core-hub/handoffs/postgres-consumer.yaml` in
@ -159,7 +159,7 @@ deletion, and names `core_hub_owner` as owner.
id: RPF-WP-0021-T03
status: done
priority: high
state_hub_task_id: "061be612-b660-4d0a-aa4c-8e26b59b0047"
state_hub_task_id: "223d5a77-b7c3-5d1a-a93c-4cb9628b457a"
```
Separate the two credential sources before shadow deployment:
@ -203,7 +203,7 @@ refresh interval restored.
id: RPF-WP-0021-T04
status: done
priority: high
state_hub_task_id: "85c46ea6-dcae-4ce5-8053-a8595b603f40"
state_hub_task_id: "50713b54-38a8-543d-8c74-0e3fa186fbb8"
```
After T03 fixes the consuming contract:
@ -261,7 +261,7 @@ all passed. `CCR-2026-0013` is verified.
id: RPF-WP-0021-T05
status: done
priority: high
state_hub_task_id: "998ec349-43b0-4128-b2f4-1af9441e8da6"
state_hub_task_id: "ba4984f9-c6c5-5eb2-b4c4-83cbec59298c"
```
After T01-T04, support `CORE-WP-0011-T03`: label the namespace for