Land RPF-WP-0039 third apps-pg consumer source.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Admit vergabe_demo_company as the third declared consumer, track
the bounded provisioner and scoped controls, and refresh admission
occupancy to 3/3. Overflow remains apps-pg-2 before any fourth.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 01:29:38 +02:00
parent 0178ec3c6d
commit f05ef49c69
18 changed files with 446 additions and 19 deletions

View file

@ -0,0 +1,71 @@
---
id: RPF-WP-0039
type: workplan
title: "Provision the isolated Vergabe demo-company database consumer"
domain: financials
repo: railiance-platform
status: finished
owner: the-custodian
topic_slug: railiance
created: "2026-09-12"
updated: "2026-09-15"
related: [RAPPS-WP-0014, VERGABE-WP-0019, CUST-WP-0071]
state_hub_workstream_id: "fc52be19-470c-572e-92a6-661e054db50a"
---
The operator selected a fresh demo tenant, accepted the 60m application request,
and supplied the product DNS record. The platform-owned apps-pg lane permits
controlled provisioning until end-to-end OpenBao onboarding exists. This consumer
is the third of the declared maximum three; no bootstrap or historical consumer
credential is reused. No additional OpenBao control-plane login is needed for
this existing Kubernetes/CNPG lane.
## Provision the fresh database and contained runtime custody
```task
id: RPF-WP-0039-T01
status: done
priority: high
state_hub_task_id: "de793b19-b509-5de5-b816-5ca54246e901"
```
Bind only Railiance01 UID a553c742-0115-43d4-99a4-a5ca56fe0786, databases/apps-pg,
role/database vergabe_demo_company, databases/vergabe-demo-company-credentials,
and vergabe-demo-company/vergabe-demo-env. Generate new credentials in memory,
transport only through captured child stdin/stdout, and print metadata only.
Refuse existing conflicting objects, unmanaged matching database/role, changed
cluster revision, more than three consumers and unrelated configuration changes.
Apply the managed role and Database declaration, 20-connection ceiling and
15-second role timeouts; revoke PUBLIC database access. Preserve vergabe_db and
coulomb_social_db. Record the delivery and actual consumer connection evidence.
## Hand application recovery and measured sizing to their existing owners
```task
id: RPF-WP-0039-T02
status: done
priority: high
state_hub_task_id: "152a50e1-da02-5a18-a796-0919edeb2b46"
```
Verify CNPG application and role isolation and current apps-pg backup metadata.
RAPPS-WP-0014-T03 owns the consistent database/media/issue-state recovery point
and isolated restore, VERGABE-WP-0019-T06 owns identity handoff, and CUST-WP-0071
owns demand measurement and weekly resource review. Keep these records live;
provisioning success alone does not admit customer data or complete recovery.
Completed 2026-09-12. Six synthetic custody/guard tests, server dry-run and the
capacity checker pass (apps-pg 3/3). Initial Cluster UID
834d8a5e-ea2c-4b12-ad97-5561af348953/resourceVersion 59692221 guarded the append.
The Database CR reports applied, all fresh migrations completed, and actual
application connection reports database/role vergabe_demo_company. SQL readback
confirms non-privileged role, limits/timeouts, own-database CONNECT true and
historical/bootstrap database CONNECT false. No bootstrap credential was read.
The latest base backup is 2026-09-11T02:15:11Z and predates this new database;
continuous archival and that receipt are not a coherent demo recovery proof.
Residuals remain live before this plan is finished: RAPPS-WP-0014-T03 for matched
backup/restart/isolated restore, VERGABE-WP-0019-T06 for welcome/identity mapping,
and CUST-WP-0071 for measured demand and final weekly review. The prototype keeps
its approved 60m request; no fourth apps-pg consumer is admitted.