Commit graph

274 commits

Author SHA1 Message Date
custodian-sync
a1f948564f chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 11:12:20 +02:00
codex
b17a9f8bff Publish S3 platform-service rapp pattern; route family proposals
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
T01: docs/rapp-platform-service-pattern.md generalizes the ownership split
already drawn in the rapp-openbao and rapp-postgres boundary docs into a
reusable four-question test, a reference rapp.yaml for platform services, the
grouped-rapp member rule, and the credential-lane position. It deliberately
does not restate the four-axis model, which railiance-master owns.

T03/T04/T05: proposals routed to the repos that own the model rather than
authored here - reef-railiance (bound_rapps lists 1 of 3 live rapps, and should
be derived rather than hand-listed), railiance-master (rapp.schema.json plus a
family declaration validator, grouped-rapp members field, wave-2 candidate
refresh), the-custodian (canon promotion of the four-axis model, which also
closes the open C-31 multi-segment prefix failures).

T02 is held until the schema settles so the platform rapps and the schema do
not converge on different answers.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:11:57 +02:00
custodian-sync
20d9a599f5 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for railiance-platform
2026-08-11 11:09:19 +02:00
codex
b876a9b5ba Open RAILIANCE-WP-0015: platform rapp consistency
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Survey of the four-axis repo family model against the live cluster and all six
family repos found the concepts sound but unenforced: rapp.yaml has no schema
and has drifted three ways across the three existing rapps, the reef binding
registry lists 1 of 3 live rapps, the rapp population diverged from the
first-wave plan of record, and the model is not in custodian canon so
fix-consistency cannot check it.

Operator decisions recorded in the workplan: grouped-by-bounded-context rapp
granularity, S3 owns only its own rapps and routes schema/canon changes to the
repos that own them, canonize the model now, and build the missing wave-1
user-facing exemplar.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:08:44 +02:00
codex
b7aef386d5 Stabilize credential-change test suite (RAILIANCE-WP-0014)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Five failures in full credential test discovery, none of them broker
regressions:

- CCR-2026-0009 referenced a policy file that was never added, and used a
  schema-invalid access_frontdoor.readiness value. Add the least-privilege
  workload-kv-read-qonto-assistant.hcl (read-only on tenants/binky/qonto-api)
  and set readiness to pending-review. The lane stays proposed and
  non-resolvable.

- Three refusal tests used the live CCR-2026-0002 file as their "unapproved
  CCR" fixture. That lane is now approved, applied and active, so the gates
  correctly permitted it and the tests failed; applier-apply then walked into
  its interactive confirmation prompt and raised EOFError under a
  non-interactive runner. Add an unapproved_ccr() helper that materializes a
  normalized temp copy so approval state is no longer read off a mutable
  production artifact.

- The approve/unconfirmed-claim test demoted an active CCR to approved while
  leaving resolvable=true, tripping a correct validation rule. Build it from
  the same helper.

No gate, blocker, validation rule, or grant semantic was changed. Verified:
credential discovery 52/52 and full discovery 61/61 pass non-interactively,
make credential-change-validate passes all nine CCRs, the grant catalog
validates, and both audit-core openbao-database-credential grants retain
exec-env-only delivery and revoke-on-exec-exit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 10:28:10 +02:00
codex
9f6bdffec4 Broker audit-core dynamic database credentials
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 19:36:30 +02:00
codex
d140e829eb Document live apps-pg consumers including coulomb-social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
apps-pg bootstrapped on cluster; coulomb_social role and database
reserved and applied. Consumer table records vergabe and coulomb-social.
2026-08-09 02:18:21 +02:00
codex
7e70b8d6a1 Reserve apps-pg role and database for coulomb-social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Managed role coulomb_social with passwordSecret
coulomb-social-app-credentials; Database CR coulomb_social_db.
Activates when apps-pg cluster is deployed.
2026-08-09 02:11:35 +02:00
codex
79387f1350 Add OpenBao/ESO lane for target-revenue on railiance01
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ClusterSecretStore openbao-target-revenue and read policies for
platform/workloads/target-revenue/runtime-secrets (WP-0011).
2026-08-05 17:56:39 +02:00
codex
2cb3a24d6d Add ArgoCD Application for target-revenue Trust Service
WP-0011: sync coulomb/target-revenue path k8s/railiance into namespace
target-revenue (revenue.coulomb.social). Requires image, OpenBao secrets,
and DNS before a healthy sync — see target-revenue docs/deployment.md.
2026-08-05 16:41:00 +02:00
codex
741f209e33 Move platform secret stores to local OpenBao
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-03 21:36:52 +02:00
codex
33b36e801d Move reuse secrets to local OpenBao
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-03 21:26:05 +02:00
codex
ce5e908011 Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's
preliminary governing license, per target-revenue's
workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full
specialist legal review is deferred until out of beta (target-revenue
SCOPE.md §1). No Phase is yet declared for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 00:54:20 +02:00
codex
14f3516394 Include user-engine in offsite CNPG backups
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-30 00:05:58 +02:00
codex
32ccc83076 Add AppRole-backed Qonto secret store
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
2026-07-27 03:14:07 +02:00
codex
09c6e41caa Document rapp-openbao compatibility handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-26 10:39:40 +02:00
custodian-sync
963b1caceb chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-26:
  - update .custodian-brief.md for railiance-platform
2026-07-26 10:37:58 +02:00
custodian-sync
2e2561eb49 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-26:
  - update .custodian-brief.md for railiance-platform
2026-07-26 10:37:25 +02:00
codex
12903e3bed Cut forgejo package prune over to OpenBao lane
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
2026-07-26 09:32:08 +02:00
custodian-sync
ba767d5edb chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 4s
Updated by fix-consistency on 2026-07-26:
  - update .custodian-brief.md for railiance-platform
2026-07-26 09:17:43 +02:00
codex
482347aebb Define rapp-openbao boundary
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-25 11:22:50 +02:00
custodian-sync
25214d70fd chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-25:
  - update .custodian-brief.md for railiance-platform
2026-07-25 11:21:44 +02:00
codex
dbabac3b85 Repair platform workplan links
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-25 10:54:35 +02:00
custodian-sync
52a1e3bf96 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-25:
  - update .custodian-brief.md for railiance-platform
2026-07-25 10:43:13 +02:00
custodian-sync
6d49061bfc chore(consistency): renormalize lifecycle state [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-25:
  - workplan status: ready → active
2026-07-25 10:42:31 +02:00
custodian-sync
5690372129 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Updated by fix-consistency on 2026-07-25:
  - update .custodian-brief.md for railiance-platform
2026-07-25 10:41:54 +02:00
custodian-sync
6dd362014b chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-25:
  - workplan status: ready → active
2026-07-25 10:41:51 +02:00
custodian-sync
6586cfc41d chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-25:
  - update .custodian-brief.md for railiance-platform
2026-07-25 10:19:39 +02:00
4fd2654516 chore(consistency): add generated WORK-RECORDS.md [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:29:20 +02:00
custodian-sync
a7ddd10ccf chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-24:
  - update .custodian-brief.md for railiance-platform
2026-07-24 00:28:47 +02:00
63818fe498 CCR-2026-0009: propose qonto-assistant workload KV read lane
Some checks failed
CI Smoke / host-smoke (push) Has been cancelled
CI Smoke / container-smoke (push) Has been cancelled
QONTO-WP-0004-T06. Requests a second, workload-scoped access lane into
the existing tenants/binky/qonto-api credential (CCR-2026-0008 is
human/OIDC admin access only, not usable by a running pod). Mirrors
CCR-2026-0003's llm-connect pattern: External Secrets Operator reads
the KV path into a namespace-scoped Kubernetes Secret via a
ClusterSecretStore restricted to the new qonto-assistant namespace;
the pod never touches the OpenBao token directly.

Status: proposed, not approved -- requires platform-operator and
binky-tenant-owner sign-off before the auth role/policy are applied.
Draft ClusterSecretStore manifest included, following the same
"deployed separately, not via this kustomization" pattern as the
existing activity-core/forgejo/reuse stores. Validated against
schemas/credential-change-request.schema.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:24:16 +02:00
ca24dc6507 fix(backup): worker-safe paths and python WebDAV upload fallback
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s
Default cache to /tmp when HOME is unwritable; allow python3 upload when
curl is absent (activity-core worker image).
2026-07-22 20:34:21 +02:00
16a93b8e5c feat(backup): multi-host CNPG Option A CLI for activity-core
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add cnpg-option-a-backup JSON runner, vendored static age, kubectl install
helper, and ESO policy path for offsite lane so railiance01 workers can
upload without workstation OIDC (RAILIANCE-WP-0016).
2026-07-22 19:50:59 +02:00
b11855f64c Document activity-core ESO read of forgejo-admin
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Extend external-secrets-activity-core policy notes with forgejo-admin
paths used by activity-core actcore-forgejo-admin ExternalSecret
(ACTIVITY-WP-0023-T05).
2026-07-21 23:19:10 +02:00
1cbaac7a73 CCR-2026-0008 active: tenants/binky/qonto-api lane live
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Align path and fields (API_KEY, API_USER) with provisioned secret; policy and
OIDC role applied; agent-high-risk-boundary deny on data path. Front door ready.
2026-07-21 21:42:10 +02:00
9f452f25be CCR-2026-0008: Binky Qonto API tenant lane (approved, pending apply)
Policy + OIDC role for tenants/binky/qonto/api; agent-high-risk-boundary
deny on data path. Implements DEC-2026-004 / BINKY-WP-0005 custody; secret
values remain founder Red-lane.
2026-07-21 21:26:25 +02:00
30a6833943 evidence: forgejo package prune apply 2026-07-21 (38 deleted)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ACTIVITY-WP-0020 T06 first apply with multi-cluster live-image protection.
2026-07-21 19:20:42 +02:00
3e19cd25fd evidence: multi-cluster prune dry-run 2026-07-18 — T07 acceptance met
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
34 candidates, 0 errors, no live tag in would_delete. state-hub
main-1cf949b protected via railiance01 live-images export; helm-pinned
and cluster-scanned tags absent from candidates; activity-core's 19
candidates have no live registry consumer (prod runs a locally-imported
image). Token via forgejo-admin-api-token warden lane, no file drops.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 15:25:42 +02:00
ca4e1526bd prune: merge exported live-image files into protection (multi-cluster)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
ACTIVITY-WP-0020-T07: the kubectl scan only sees the prune host's own
cluster. New repeatable --live-images-file merges image refs exported
from other production clusters; missing file surfaces as WARN (reduced
coverage), forgejo-registry tags protected, other registries ignored.
5/5 tests.

Evidence gathered 2026-07-18: activity-core on railiance01 runs a
locally-imported image (activity-core:railiance01-prod), not a forgejo
registry tag — the largest would_delete set has no live registry
consumer. Live forgejo tags: state-hub:main-1cf949b (railiance01),
issue-core:0.2.1 + state-hub:f2e042a + vergabe-teilnahme:064d295
(coulombcore cluster).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:54:13 +02:00
d4c95f78ff feat(openbao): agent-harness forgejo deploy-key read policy
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add workload-kv-read-agent-harness-forgejo and document the harness
deploy-key + mail AppRole lanes provisioned on railiance01.
2026-07-17 23:57:54 +02:00
183647c33a CCR-2026-0007: activate binky IMAP lane after founder provision
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Mark front door ready/resolvable; record capabilities-safe verify evidence.
2026-07-17 00:33:20 +02:00
7d7260ffa3 openbao: grant platform-admin access to tenants/ mount
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
WARDEN-WP-0028 added mount tenants/ for client secrets; platform-admin
only covered platform/* and secret/*, so UI operators could not see
binky paths. Add tenants/* CRUD+list.
2026-07-17 00:31:09 +02:00
86209fa90c CCR-2026-0007: binky IMAP on tenants/ mount + CCR allowlist
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Enable tenant commercial secrets: applier accepts mount tenants/, apply
policy and OIDC role for company-email IMAP (metadata only; values are
founder Red provision). Extend agent-high-risk-boundary for the path.
2026-07-17 00:09:28 +02:00
347226eb36 CCR-2026-0004: capabilities-safe verify + agent high-risk boundary
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record WP-0026 T07 promotion evidence (no secret values), mark the
offsite backup lane front door resolvable/ready, and add OpenBao policy
agent-high-risk-boundary for coding-agent metadata-only access.
2026-07-16 23:26:28 +02:00
e9e631fbf4 feat(forgejo-package-prune): protect image tags running live in the cluster
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Adds collect_live_cluster_versions() — enumerates pod container images via
kubectl and protects any forgejo.coulomb.social/coulomb/<name>:<tag>. Closes the
gap where CI-deployed apps (e.g. state-hub) pin a live tag absent from Helm
values. On by default (--no-protect-live to skip); emits protection_notes +
live_protection in the JSON summary so consumers can detect reduced coverage.
Verified against production: protects state-hub/vergabe/issue-core live tags.

ACTIVITY-WP-0020 T07 (partial — see workplan note re multi-cluster coverage).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:44:03 +02:00
6f7ca31a6d fix(forgejo-package-prune): correct version enumeration + network robustness
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Forgejo has no per-package /versions endpoint — the list endpoint returns one
entry per (name, version). build_delete_plans now groups list results by name
instead of calling a 404ing /versions sub-path. Removed dead list_versions/_paginate.
Added retry + longer timeout to _api_request for slow/large registry listings
(container list was timing out). Updated fixture test to the grouped model.

Dry-run now clean: 29 candidate deletions across 5 container packages, 0 errors
(was 53× HTTP 404). ACTIVITY-WP-0020 T02 fix; enable/apply still gated on
protection-coverage review (T05).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 02:46:15 +02:00
20bf3d5942 chore: gitignore Python bytecode caches
All checks were successful
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / container-smoke (push) Successful in 36s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 10:49:36 +02:00
4a824d72bd Apply CCR-2026-0006 Forgejo admin PAT lane metadata
Record platform-operator approval, delegated policy/OIDC role apply,
negative verification evidence, and add attended PAT provision script.
2026-07-12 16:07:32 +02:00
25fc47e5f2 Add CCR-2026-0006 Forgejo admin PAT OpenBao lane
Establish proposed workload-kv-read custody for the Forgejo site-admin
PAT at platform/workloads/forgejo/forgejo-admin, sibling to forgejo-mailer.
OIDC workstation fetch mirrors the railiance-backup-offsite pattern.
2026-07-12 16:01:53 +02:00
618641c984 fix(forgejo): accept FORGEJO_ADMIN_TOKEN and document PAT setup
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Align prune auth with railiance-apps forgejo tools and explain that
package prune needs a Forgejo PAT, not the OpenBao backup lane.
2026-07-12 11:57:35 +02:00