Declare scoped activity-core ArgoCD adoption

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 14:01:47 +02:00
parent c9bf8c90c9
commit f3f2b82d0c
4 changed files with 97 additions and 0 deletions

View file

@ -0,0 +1,50 @@
---
id: RPF-WP-0048
type: workplan
title: "Adopt activity-core application runtime into railiance01 GitOps"
domain: financials
repo: railiance-platform
status: active
owner: codex
topic_slug: railiance
created: "2026-09-27"
updated: "2026-09-27"
---
User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the
frontend-patterns reporting exception. This explicitly authorizes this adoption;
it does not widen the earlier one-time exception to unrelated workloads.
Authority: CONSTRUCT @ activity-core and railiance-platform;
ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap;
activation=APPROVED. Existing 24-hour observation requirement remains in force.
## Bootstrap a namespace-scoped project and adopt nine runtime resources
```task
id: RPF-WP-0048-T01
status: progress
priority: high
```
New project permits only activity-core source, activity-core destination, and
ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal,
llm-connect, edge relay, storage or cluster-scoped resources enter this Application.
Application source is activity-core k8s/gitops at a pinned reviewed commit; no
finalizer, automated sync or pruning initially. Root sync must name this child
only; unrelated pending applications must not be changed. Verify ArgoCD's diff,
health, resource inventory, schedules and original deployment generations.
## Observe adoption and enforce bounded promotion readiness
```task
id: RPF-WP-0048-T02
status: wait
priority: high
```
Keep automated sync off for at least 24 hours after successful adoption. Record
start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication,
source validation and the promotion/rollback guard. Root-wide automation is outside
this workplan. No unattended merge credential or release executor is assumed just
because the Application exists. Confirm the scoped identity and checks before
activating bounded routine promotion. Destructive pruning remains disabled.