codex
9f6bdffec4
Broker audit-core dynamic database credentials
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 19:36:30 +02:00
codex
d140e829eb
Document live apps-pg consumers including coulomb-social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
apps-pg bootstrapped on cluster; coulomb_social role and database
reserved and applied. Consumer table records vergabe and coulomb-social.
2026-08-09 02:18:21 +02:00
codex
14f3516394
Include user-engine in offsite CNPG backups
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-30 00:05:58 +02:00
codex
09c6e41caa
Document rapp-openbao compatibility handoff
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-26 10:39:40 +02:00
codex
12903e3bed
Cut forgejo package prune over to OpenBao lane
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
2026-07-26 09:32:08 +02:00
codex
482347aebb
Define rapp-openbao boundary
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-25 11:22:50 +02:00
16a93b8e5c
feat(backup): multi-host CNPG Option A CLI for activity-core
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add cnpg-option-a-backup JSON runner, vendored static age, kubectl install
helper, and ESO policy path for offsite lane so railiance01 workers can
upload without workstation OIDC (RAILIANCE-WP-0016).
2026-07-22 19:50:59 +02:00
1cbaac7a73
CCR-2026-0008 active: tenants/binky/qonto-api lane live
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Align path and fields (API_KEY, API_USER) with provisioned secret; policy and
OIDC role applied; agent-high-risk-boundary deny on data path. Front door ready.
2026-07-21 21:42:10 +02:00
9f452f25be
CCR-2026-0008: Binky Qonto API tenant lane (approved, pending apply)
...
Policy + OIDC role for tenants/binky/qonto/api; agent-high-risk-boundary
deny on data path. Implements DEC-2026-004 / BINKY-WP-0005 custody; secret
values remain founder Red-lane.
2026-07-21 21:26:25 +02:00
30a6833943
evidence: forgejo package prune apply 2026-07-21 (38 deleted)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ACTIVITY-WP-0020 T06 first apply with multi-cluster live-image protection.
2026-07-21 19:20:42 +02:00
3e19cd25fd
evidence: multi-cluster prune dry-run 2026-07-18 — T07 acceptance met
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
34 candidates, 0 errors, no live tag in would_delete. state-hub
main-1cf949b protected via railiance01 live-images export; helm-pinned
and cluster-scanned tags absent from candidates; activity-core's 19
candidates have no live registry consumer (prod runs a locally-imported
image). Token via forgejo-admin-api-token warden lane, no file drops.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 15:25:42 +02:00
d4c95f78ff
feat(openbao): agent-harness forgejo deploy-key read policy
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add workload-kv-read-agent-harness-forgejo and document the harness
deploy-key + mail AppRole lanes provisioned on railiance01.
2026-07-17 23:57:54 +02:00
183647c33a
CCR-2026-0007: activate binky IMAP lane after founder provision
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Mark front door ready/resolvable; record capabilities-safe verify evidence.
2026-07-17 00:33:20 +02:00
86209fa90c
CCR-2026-0007: binky IMAP on tenants/ mount + CCR allowlist
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Enable tenant commercial secrets: applier accepts mount tenants/, apply
policy and OIDC role for company-email IMAP (metadata only; values are
founder Red provision). Extend agent-high-risk-boundary for the path.
2026-07-17 00:09:28 +02:00
25fc47e5f2
Add CCR-2026-0006 Forgejo admin PAT OpenBao lane
...
Establish proposed workload-kv-read custody for the Forgejo site-admin
PAT at platform/workloads/forgejo/forgejo-admin, sibling to forgejo-mailer.
OIDC workstation fetch mirrors the railiance-backup-offsite pattern.
2026-07-12 16:01:53 +02:00
618641c984
fix(forgejo): accept FORGEJO_ADMIN_TOKEN and document PAT setup
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Align prune auth with railiance-apps forgejo tools and explain that
package prune needs a Forgejo PAT, not the OpenBao backup lane.
2026-07-12 11:57:35 +02:00
715631dedd
feat(forgejo): add package prune script with retention depth 3
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
List and optionally delete package versions beyond the newest three,
protecting production Helm image tags. Adds Make targets and unit tests
for ACTIVITY-WP-0020.
2026-07-12 11:35:04 +02:00
bfa83de101
Point npm handoff and ArgoCD sourceRepos at Forgejo
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 13s
Forgejo is primary git/OCI source; Gitea URL retained for emergency rollback.
2026-07-09 11:38:14 +02:00
6abf6b56a0
Fix openbao-secretstore ArgoCD health: coulombcore scope only
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Remove interim ClusterSecretStores (forgejo, activity-core, reuse) from
coulombcore ArgoCD kustomization. Those stores target railiance01 namespaces
and are bootstrapped via railiance-apps/activity-core Make targets.
2026-07-08 15:41:04 +02:00
6076d57218
Repoint ArgoCD GitOps to Forgejo (RAIL-HO-WP-0005 T11)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Switch bootstrap AppProjects, root application, openbao-secretstore, and
repository template URLs from gitea.coulomb.social to forgejo.coulomb.social.
2026-07-08 15:35:28 +02:00
e36694648a
Support activity-core ISSUE_CORE_API_KEY ExternalSecret on railiance01
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Switch openbao-activity-core ClusterSecretStore to interim coulombcore
token auth like forgejo/reuse, broaden the activity-core ESO policy to
include the shared issue-core runtime path, and document ESO-managed rotation.
2026-07-08 00:04:59 +02:00
839a4418a9
Add reuse-surface secrets rotation runbook (RAILIANCE-WP-0011-T04)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Document OpenBao patch, ESO force-sync, hub rollout, and Forgejo webhook
reconcile; extend credential-lane lifecycle for CCR-2026-0005; finish workplan.
2026-07-08 00:01:21 +02:00
31a5de81d0
Complete RAILIANCE-WP-0011-T03 catalog migration for CCR-2026-0005
...
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Activate CCR front door, document reuse-surface lane in workload-kv-access-lanes,
and mark consumer handoff task done.
2026-07-07 22:38:45 +02:00
074e7f8441
Add Forgejo daily backup automation (T04/T09 Option A)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
make forgejo-backup runs forgejo dump + pg_dump, age-encrypts, uploads to
Nextcloud forgejo/ prefix. Includes dry-run, status, and operator docs.
2026-07-07 17:19:19 +02:00
0055e8f3f7
Establish railiance backup credentials in OpenBao (CCR-2026-0004).
...
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Add workload KV lane for Nextcloud WebDAV token, URL, and age recovery
escrow at platform/workloads/railiance/backup/offsite-lane. Apply read
policy and OIDC role railiance-backup-workload-kv-read; wire forgejo-backup
to load credentials from OpenBao when env is unset.
2026-07-07 17:16:30 +02:00
06844c2669
NET-WP-0020 T4: prepared transit auto-unseal seal stanza (disabled by default)
...
Commented seal "transit" stanza in the OpenBao server config plus an
'Auto-Unseal via Transit Seal' doc section covering provisioning, seal
migration, pod-restart proof, and the net-kingdom console evidence flags.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 22:08:47 +02:00
38c6b11103
RAILIANCE-WP-0009/0010 T07: credential lane lifecycle runbook
...
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 14:52:08 +02:00
38936d8fd6
Close delegated prod applier pilot
2026-07-01 23:34:13 +02:00
8321e14b46
Unblock credential broker warden-sign pilot
2026-07-01 23:10:38 +02:00
a95236d2e5
Add credential-change delegated applier flow
2026-07-01 20:07:26 +02:00
8f617fcbf4
Activate whynot npm credential lane
2026-06-29 00:13:09 +02:00
1e769c75a0
Record whynot positive fetch verification
2026-06-28 17:26:10 +02:00
2c1e76efca
Record whynot identity group evidence
2026-06-28 16:05:17 +02:00
3527bc1cae
Request groups scope for whynot OIDC role
2026-06-28 13:23:14 +02:00
adf865611c
Mark whynot lane applied pending verification
2026-06-28 12:53:39 +02:00
271aa94642
Record whynot OpenBao lane apply evidence
2026-06-28 12:41:39 +02:00
53f3f4ca10
Document OpenBao Browser CLI limits
2026-06-28 09:18:36 +02:00
f630d5135e
Fix OpenBao role payload handoff
2026-06-28 02:33:42 +02:00
e3147b7fd5
Prepare whynot npm token handoff
2026-06-28 01:43:06 +02:00
eb24e04b71
Correct whynot credential tenant path
2026-06-28 01:00:12 +02:00
0e3ea30c75
Propose OpenBao automation delegation
2026-06-28 00:44:23 +02:00
248bc58b6a
Add credential CCR operator handoff
2026-06-28 00:21:02 +02:00
3706ff703e
Link CCR approval to State Hub decision
2026-06-28 00:00:02 +02:00
52687d8b3e
Confirm whynot credential binding
2026-06-27 23:45:31 +02:00
aee0dcefad
Add credential lane readiness proposals
2026-06-27 23:30:29 +02:00
815b124ab1
Implement credential change request review flow
2026-06-27 22:57:21 +02:00
85a4278a55
Add credential approval workflow plan
2026-06-27 22:48:24 +02:00
673ec46e25
feat: complete credential broker source flow
2026-06-27 00:29:53 +02:00
752cfd6f00
feat: add credential broker token helper
2026-06-27 00:06:03 +02:00
c7393d94ab
feat: add credential grant catalog foundation
2026-06-26 17:49:40 +02:00