Commit graph

269 commits

Author SHA1 Message Date
codex
34a3123799 Finish RAILIANCE-WP-0017 consumption-mode enforcement
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Read the resource-control open/restricted signal and refuse new orders
that would exceed a restricted entity's published allowance. Open and
missing signals stay unchanged. Safety paths admit with an exception.
2026-08-15 14:56:02 +02:00
codex
bf8c26cd61 chore(consistency): mark architecture RAILIANCE-WP-0016 finished
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-15 14:44:21 +02:00
custodian-sync
00261789ae chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-15:
  - update .custodian-brief.md for railiance-platform
2026-08-15 14:44:17 +02:00
codex
1eb5fa51ed Finish architecture-cleanup RAILIANCE-WP-0016 T05
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Item 13 is the restore RESOURCE-WP-0002 already proved. Item 14 retires
the dead Bitnami postgresql-ha deploy path and gates Valkey until a
consumer exists. Item 17 publishes the versioned S3 consumer-interface
index.
2026-08-15 14:43:44 +02:00
codex
2af19627e1 feat: add r01-platform-pg to the Option A CNPG backup inventory
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 20:47:16 +02:00
codex
625991469a feat: vend platform-pg-backup-s3 via AppRole ESO
Policy and AppRole applied. Store Valid, ExternalSecret SecretSynced.
Prefix empty. WAL not enabled.
2026-08-14 20:00:15 +02:00
codex
cbc6398583 note: backup bucket policy enforces platform-pg/ prefix 2026-08-14 19:55:53 +02:00
codex
2c3504e368 docs: how to add APPLICATION_ID for the backup bucket policy 2026-08-14 19:52:08 +02:00
codex
ddce013cac approve: CCR-2026-0012; verify scoped backup key in OpenBao
Founder put ACCESS_KEY/SECRET_KEY. S3 prefix CRUD works. IAM write
and ESO apply remain gated. WAL not enabled.
2026-08-14 19:34:40 +02:00
codex
94b2f7cc9c retarget: CCR-2026-0012 is the general backup object-store lane
Use IAM application resource-control and policy Scoped backup access.
OpenBao path is platform/workloads/railiance/backup/object-storage.
rapp-postgres keeps Secret platform-pg-backup-s3 as the first projection.
2026-08-14 19:19:56 +02:00
codex
2769258631 feat: propose CCR-2026-0012 for platform-pg Barman key
Workload KV path and ESO drafts for Secret platform-pg-backup-s3.
Founder mints the project-scoped Scaleway application; values stay
out of git.
2026-08-14 19:01:08 +02:00
codex
015f0e43a9 ccr: CCR-2026-0011 waiting on UI replace of placeholders 2026-08-14 17:40:09 +02:00
codex
5a0c2da501 ccr: CCR-2026-0011 Scaleway bootstrap key lane
Reserve platform/workloads/railiance/scaleway/bootstrap for the
WP-0002 bucket create. Founder puts the value; agent does not
accept it in chat.
2026-08-14 16:58:44 +02:00
codex
6e744b0adb docs: cite RMASTER-WP ids for railiance-master workplans 2026-08-14 14:29:19 +02:00
codex
917d3a1687 workplan: RAILIANCE-WP-0017 enforce consumption mode
Residual of resource-control RESOURCE-WP-0005: refuse new orders
that would exceed a restricted entity's published allowance.
2026-08-14 13:15:30 +02:00
custodian-sync
e87a14041a chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for railiance-platform
2026-08-14 13:15:20 +02:00
codex
beed7941af chore(consistency): mark RAILIANCE-WP-0016 apps-pg evidence finished
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 02:06:01 +02:00
custodian-sync
6455540c78 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for railiance-platform
2026-08-14 02:05:58 +02:00
codex
6033ae1aef Finish RAILIANCE-WP-0016 apps-pg resource evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Publish capacity, recovery, labor, and allocation-driver evidence for
resource:railiance:apps-pg so resource-control can forecast and allocate
without reading application data or inventing booked cost.
2026-08-14 02:05:25 +02:00
codex
b5fb44b53e chore(consistency): mark RAILIANCE-WP-0015 finished in work-record index
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 00:48:13 +02:00
custodian-sync
0548712f23 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for railiance-platform
2026-08-14 00:47:53 +02:00
codex
dfa6373985 Close RAILIANCE-WP-0015-T06 rapp credential-lane binding
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Document the one recipe a new rapp uses to acquire runtime secrets:
standing KV secrets bind through a CCR target.rapp, leases through
grant rapp_id. Stamp the existing postgres grants and the qonto
workload CCR. Gate, delivery, and revocation are unchanged.
2026-08-14 00:47:28 +02:00
codex
6ab882cc44 chore(consistency): mark RAILIANCE-WP-0015-T02 done in work-record index
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 00:40:01 +02:00
custodian-sync
b42bb7407b chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for railiance-platform
2026-08-14 00:39:43 +02:00
codex
ccb5972b42 Close RAILIANCE-WP-0015-T02 platform rapp schema convergence
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Converge the S3 platform-service pattern onto ADR-0007, emit the
reef-railiance live deployable inventory for the family coverage
check, and mark T02 done. Declaration edits land in rapp-openbao
and rapp-postgres.
2026-08-14 00:39:06 +02:00
codex
deabcde73c Point openbao-audit-core store at the Mason AppRole 2026-08-13 10:42:59 +02:00
codex
cac9947e3a Add audit-core ESO policy and ClusterSecretStore for railiance01
KV store for the sender registry only. Database leases stay on the
OpenBao database engine and are consumed via VaultDynamicSecret in
audit-core. Not added to the coulombcore ArgoCD kustomization.
2026-08-13 00:58:58 +02:00
codex
c642367d98 Add email-connect transactional SMTP and ingest custody lane.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
CCR-2026-0010, OpenBao read policies, ClusterSecretStore openbao-email-connect,
and workload-kv lane documentation for EMAIL-WP-0004-T03.
2026-08-12 13:32:11 +02:00
codex
b6ad81fe6b Record the 10a outcome: estimate held, check paid for itself on first run
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
32 assertions, 31 pass on Railiance01. The one failure is a real defect the old
loose assertion could never have seen: Flannel VXLAN declared open to Anywhere
with no source restriction, currently absent from the host, so converging would
introduce the exposure rather than correct drift.

Also records the sharper finding from wiring it up: verify.yaml was missing the
vars_files the bootstrap play had, so the firewall assertions rendered empty and
silently asserted nothing - worse than having no check at all.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 03:30:34 +02:00
custodian-sync
11db75f899 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-12:
  - update .custodian-brief.md for railiance-platform
2026-08-12 02:02:06 +02:00
codex
efa39587e3 Rescope items 9 and 10; item 10 was badly mis-sized
Some checks are pending
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / host-smoke (push) Successful in 0s
T04 done, and the answer changes the order. Item 10 was scored size 5 as a
greenfield build. It is not. railiance-infra already has a Goss baseline suite,
an ansible runner, a make verify target that runs it against all hosts and
commits TAP reports to git, and an evidence trail in reports/. The mechanism is
built and wired.

Two things are wrong with it and neither is a build. Nothing runs it - the last
TAP report is dated 2026-03-09, five months ago. And its firewall assertion
matches /6443\/tcp.*ALLOW/, which asserts the port is allowed but not from
whom - it passes identically whether 6443 is restricted to one operator address
or open to the internet, which is exactly the drift that went undetected. It
would however have caught the other finding, since it asserts Status: active and
UFW is inactive on CoulombCore.

Rescoped into slices: 10a (run it, tighten the assertion) is size 1-2 and rises
to WSJF 12.0, fourth overall and the highest-value item after the ratifications.
10b (schedule + alert path) is 7.0. Names the shared dependency - 10b and 9b are
the same plumbing, and building either of 9 or 10 without it produces logs
nobody reads.

The lesson recorded: the gap analysis correctly identified no-conformance-loop
as a capability gap, but the capability was two-thirds built and abandoned.
Before sizing a gap as a build, check whether it is actually an abandonment.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 02:01:44 +02:00
custodian-sync
9a55a1615d chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-08-12:
  - update .custodian-brief.md for railiance-platform
2026-08-12 01:36:15 +02:00
codex
681b304c41 Route the cleanup backlog to railiance-master for adoption
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
T03 done: sent as ac73b172 with the recommendation that master takes the eight
ratification and taxonomy items, and including the correction that our earlier
ArgoCD report to them was wrong.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 01:35:04 +02:00
custodian-sync
9b611c1756 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-08-12:
  - update .custodian-brief.md for railiance-platform
2026-08-12 01:34:19 +02:00
codex
e61de17b0d Gap analysis and WSJF-prioritized cleanup backlog
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Compares INTENT (declared aspiration) against SCOPE (declared state) against
verified reality for every railiance-* repo. This was only possible now: a gap
could not be distinguished from a stale document until the architecture was
coherently defined, the SCOPE files described verified rather than assumed
reality, and the INTENT files stated current rather than copied intent.

Names the pattern that organizes the work: every gap is declared-but-unbuilt
(telemetry, S4, conformance loop), built-but-undeclared (the firewall
restriction, Q1 custody, the Plane dimension), or decided-but-unmoved (forge
placement, hosts retirement, rapp schema). The third kind is cheapest to clear
and blocks the most; the second is most dangerous, because it stays invisible
until something breaks - the firewall case was found by accident.

RAILIANCE-WP-0016 orders 19 items by WSJF with owner and reasoning per item.
Top three are nearly free and all decided-but-unmoved. Item 1, converging the
firewall allowlist, is a live exposure: two standing grants point at addresses
the ISP has reassigned. Item 2, five pending ratifications in railiance-master,
blocks a quarter of the backlog for a day of decisions.

Flags honestly that the size scores for telemetry and the conformance loop are
guesses, that item 13 is blocked rather than deprioritized, and that this
backlog belongs to railiance-master rather than S3 - it lives here only because
the analysis was done here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 01:33:03 +02:00
codex
28f445fa89 Reopen the ArgoCD question on corrected evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
The 2026-08-11 decision to keep ArgoCD rested on a claim that turned out to be
wrong. Verified against both clusters once API access was restored: ArgoCD is
not on railiance01, it runs on CoulombCore, its Applications target CoulombCore
in-cluster, nothing on railiance01 is ArgoCD-managed, and the live S3 workloads
- target-revenue, openbao, external-secrets - deploy outside GitOps. Two
Applications are Degraded and one is OutOfSync/Missing.

The earlier claim that removing ArgoCD documentation would describe a system
that does not exist was backwards: the documentation already describes a
deployment path that is largely not in effect. Restates the question with three
real options - adopt properly on railiance01, retire, or relocate to Helix Forge
- and notes that doing nothing is the option with a cost.

Same defect class as RAIL-HO-WP-0009: declared and live state diverged, and
nothing detected it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 00:05:14 +02:00
codex
21db3d9b50 Name S3's Quality-dimension responsibilities in INTENT
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
S3 has carried Q1 Security and Compliance for months - approval gates,
delegated apply, revocation semantics, front-door readiness - without the
dimension ever being named. Naming it does not change what this layer does; it
makes the responsibility legible to the rest of the fleet.

Also draws the line the other way: observability is Q2 and belongs to
railiance-telemetry, so S3's obligation is to emit through the standard contract
rather than build its own monitoring. The recoverability half is Q3 and remains
unowned.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:20:13 +02:00
codex
0d26b5d21b Establish all six OAS dimensions as a working model
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Populates each canonical dimension with Railiance's actual position, canon's
sub-levels, owners where they exist, and honest status.

Findings from doing it:
- Q1 Security and Compliance is already implemented in S3 to a mature standard
  (approval gates, delegated apply, revocation, front-door readiness) and was
  never named as a dimension. Evidence the dimensions describe real structure
  rather than impose vocabulary.
- Plane is operated in full and declared nowhere. P1 workload, P2 control
  (ArgoCD, CNPG, ESO, cert-manager), P3 management (State Hub, master,
  workplans). Likely to clarify the rail/rapp relationship, since a rail is
  essentially a P1 contract.
- Intelligence is already referenced in practice - qonto-assistant cites an I1
  isolation profile - and the whole agent operating model is I4-I5. Leaving it
  unmodelled understates what this fleet actually is.
- Q3 Operability and Q7 Governance remain unowned; Q5 unaddressed.

Adds a recommended establishing order for railiance-master to ratify: Quality
first (most unowned concerns), Plane second (cheap, descriptive), Capability
third (blocked on the C1 attribution drift), Intelligence fourth, Logic last or
never if Helix Forge owns functional decomposition.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:09:36 +02:00
codex
cbc961ca09 Coherence review: Railiance uses one of six OAS dimensions
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
The central finding. OAS defines six canonical dimensions and states that each
architecture description MUST use them. Railiance has modelled itself almost
entirely on Stack. Everything that did not fit a stack level was treated as an
anomaly - "unplaced", "beside the stack" - and accumulated as exceptions.

They were never anomalies. They are concerns on dimensions Railiance was not
using, and the Quality dimension's sub-levels map almost one-to-one onto the
capability gaps this review found independently: Q2 Observability is
railiance-telemetry, named in canon in exactly those words; Q7 Governance is
the conformance loop; Q3 is restore proof; Q6 is cost attribution. The
self-evidencing thread across five stack layers is five Stack repos each
independently asking for Q2 and Q7 - what a missing dimension looks like from
inside the one you are using.

Also records four contradictions (C1-C4), of which C1 is actionable here: the
hub attributes ~11 capabilities to this repo including Terraform, Ansible, k3s,
CI/CD and app deployment, which S3 does not own. SCOPE.md declares four, all
correctly S3, and is authoritative.

ArgoCD decision closed: keep it, documentation stays accurate; relocating GitOps
to Helix Forge noted as possible future cleanup.

SCOPE.md: corrects the "five independent repos per OAS Stack layer" claim,
records the ArgoCD deployment path, the telemetry emission relationship, and the
hub capability drift.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 22:53:15 +02:00
codex
0ae7cdab92 Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Gitea has been replaced by Forgejo. Updates prose mentions in docs/ while
deliberately preserving live names that a blind sweep would have broken:
GITEA_BACKEND_TOKEN is a provisioned OpenBao field in CCR-2026-0002, GITEA_URL
is a Makefile variable, and gitea-db is a running cnpg cluster. Capitalisation
discriminates prose from identifiers. Archived workplans are left as historical
record.

Blueprint 5.2: forge placement decided - workload to rapp-forgejo, layer
responsibility to S4 railiance-enablement, which already declares the handoff
contract and gains its first concrete owned responsibility.

Blueprint 5.6: whether Railiance should use ArgoCD at all is recorded as an open
decision rather than acted on by removing mentions. S3 runs four live ArgoCD
Applications plus AppProjects, and the two most recent commits here add more, so
deleting the documentation would describe a system that does not exist. The
question is real; it needs a decision and a migration, not a docs edit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 22:41:30 +02:00
codex
20c5dc831e Add ArchitectureBlueprint.md as the structural backbone
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Consolidates what this session established: the four orthogonal repo-family
axes and the separation rule that keeps Forgejo orgs, State Hub domains and
rapp contexts from being derived from each other; the stack levels plus the
concerns that sit beside the stack; the self-evidencing thread and its two
halves (evidence plane, now owned by railiance-telemetry, and the conformance
loop, still unowned); verified repository status including the two superseded
lineages; and the open placement decisions, each naming railiance-master as
the decider rather than settling them here.

Records that the railiance-forge retirement hypothesis was tested and rejected
- it and helix-forge are different lineages, one operational and one
methodological - so forge should be placed, not retired.

Also notes for tooling that the bootstrap/cluster/hosts/infra repos have
unrelated histories but near-identical content, so fleet inventories must
deduplicate by origin URL rather than by directory.

SCOPE.md gains the telemetry emission relationship and a pointer to the
blueprint.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 21:57:36 +02:00
custodian-sync
3f586cfada chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 21:01:41 +02:00
codex
37216c2d34 Assess the Railiance architecture in aspiration from INTENT files
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Reads all ten local railiance-* INTENT.md files as a statement of intended
architecture, cross-checked against git history, remotes and the live cluster.

Ten repos declare eight distinct intents. The aspiration is coherent and the
handoffs are stated from both sides. Findings: railiance-bootstrap is a second
local clone of railiance-cluster rather than a repo (which means fleet counts
built by scanning ~ overcount, including the 112 figure in the org refactor);
railiance-hosts and railiance-infra are distinct remotes with unrelated
histories and byte-identical INTENT, both claiming S1; railiance-forge is
unplaced in the OAS stack dimension; S4 is aspiration-only at 25 commits and
zero workplans.

The strongest finding is a shared thread nobody named: five layers
independently aspire to be "self-evidencing" or "auditable", and no repo owns
the verification substrate that would evaluate those claims. That is the same
gap as the enforcement control loop, arrived at from the opposite direction.

Also notes missing homes for observability, end-to-end restore proof, and the
cost-attribution interface.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 21:01:21 +02:00
custodian-sync
ba1850951a chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 14:46:53 +02:00
codex
2597fa46da Rapp context is its own grouping dimension
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Operator design review considered binding bounded rapp context to Forgejo orgs
or State Hub domains and rejected both. OAS P1 governs - independent
perspectives must stay in separate dimensions - and cardinality forces it: a
repo has exactly one Forgejo org (a path segment in the clone URL) so org:repo
is 1:many, while rapp:repo is many:many, and a many:many grouping cannot be
derived from a 1:many one.

Records the dimension table, the composition block (first-party member repos
plus pinned upstream components and a stated purpose), and the precision that
makes enforcement well-defined: repos are many:many with rapps but deployables
are 1:1, so the validator can ask whether every live deployable belongs to
exactly one rapp. That is the coverage check that would have caught all three
of this survey's drift findings at once.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:34:51 +02:00
custodian-sync
a1f948564f chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 11:12:20 +02:00
codex
b17a9f8bff Publish S3 platform-service rapp pattern; route family proposals
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
T01: docs/rapp-platform-service-pattern.md generalizes the ownership split
already drawn in the rapp-openbao and rapp-postgres boundary docs into a
reusable four-question test, a reference rapp.yaml for platform services, the
grouped-rapp member rule, and the credential-lane position. It deliberately
does not restate the four-axis model, which railiance-master owns.

T03/T04/T05: proposals routed to the repos that own the model rather than
authored here - reef-railiance (bound_rapps lists 1 of 3 live rapps, and should
be derived rather than hand-listed), railiance-master (rapp.schema.json plus a
family declaration validator, grouped-rapp members field, wave-2 candidate
refresh), the-custodian (canon promotion of the four-axis model, which also
closes the open C-31 multi-segment prefix failures).

T02 is held until the schema settles so the platform rapps and the schema do
not converge on different answers.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:11:57 +02:00
custodian-sync
20d9a599f5 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 11:09:19 +02:00
codex
b876a9b5ba Open RAILIANCE-WP-0015: platform rapp consistency
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Survey of the four-axis repo family model against the live cluster and all six
family repos found the concepts sound but unenforced: rapp.yaml has no schema
and has drifted three ways across the three existing rapps, the reef binding
registry lists 1 of 3 live rapps, the rapp population diverged from the
first-wave plan of record, and the model is not in custodian canon so
fix-consistency cannot check it.

Operator decisions recorded in the workplan: grouped-by-bounded-context rapp
granularity, S3 owns only its own rapps and routes schema/canon changes to the
repos that own them, canonize the model now, and build the missing wave-1
user-facing exemplar.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:08:44 +02:00
codex
b7aef386d5 Stabilize credential-change test suite (RAILIANCE-WP-0014)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Five failures in full credential test discovery, none of them broker
regressions:

- CCR-2026-0009 referenced a policy file that was never added, and used a
  schema-invalid access_frontdoor.readiness value. Add the least-privilege
  workload-kv-read-qonto-assistant.hcl (read-only on tenants/binky/qonto-api)
  and set readiness to pending-review. The lane stays proposed and
  non-resolvable.

- Three refusal tests used the live CCR-2026-0002 file as their "unapproved
  CCR" fixture. That lane is now approved, applied and active, so the gates
  correctly permitted it and the tests failed; applier-apply then walked into
  its interactive confirmation prompt and raised EOFError under a
  non-interactive runner. Add an unapproved_ccr() helper that materializes a
  normalized temp copy so approval state is no longer read off a mutable
  production artifact.

- The approve/unconfirmed-claim test demoted an active CCR to approved while
  leaving resolvable=true, tripping a correct validation rule. Build it from
  the same helper.

No gate, blocker, validation rule, or grant semantic was changed. Verified:
credential discovery 52/52 and full discovery 61/61 pass non-interactively,
make credential-change-validate passes all nine CCRs, the grant catalog
validates, and both audit-core openbao-database-credential grants retain
exec-env-only delivery and revoke-on-exec-exit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 10:28:10 +02:00