--- id: RPF-WP-0048 type: workplan title: "Adopt activity-core application runtime into railiance01 GitOps" domain: financials repo: railiance-platform status: blocked owner: codex topic_slug: railiance created: "2026-09-27" updated: "2026-09-27" state_hub_workstream_id: "b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54" --- User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the frontend-patterns reporting exception. This explicitly authorizes this adoption; it does not widen the earlier one-time exception to unrelated workloads. Authority: CONSTRUCT @ activity-core and railiance-platform; ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap; activation=APPROVED. Existing 24-hour observation requirement remains in force. ## Bootstrap a namespace-scoped project and adopt nine runtime resources ```task id: RPF-WP-0048-T01 status: done priority: high state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370" ``` New project permits only activity-core source, activity-core destination, and ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal, llm-connect, edge relay, storage or cluster-scoped resources enter this Application. Application source is activity-core k8s/gitops at a pinned reviewed commit; no finalizer, automated sync or pruning initially. Root sync must name this child only; unrelated pending applications must not be changed. Verify ArgoCD's diff, health, resource inventory, schedules and original deployment generations. ## Observe adoption and enforce bounded promotion readiness ```task id: RPF-WP-0048-T02 status: wait priority: high state_hub_task_id: "63b44949-39f8-52fd-ab63-e618b67ef992" ``` Keep automated sync off for at least 24 hours after successful adoption. Record start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication, source validation and the promotion/rollback guard. Root-wide automation is outside this workplan. No unattended merge credential or release executor is assumed just because the Application exists. Confirm the scoped identity and checks before activating bounded routine promotion. Destructive pruning remains disabled. ## Make registry retention aware of digest-pinned releases ```task id: RPF-WP-0048-T03 status: done priority: high state_hub_task_id: "6c2650a2-5da8-5999-a6e7-b22eb7c655f4" ``` The package retention parser currently recognizes tags only; digest references must resolve to protected registry versions before routine digest promotion can be unattended. Cover live and rollback digests, preserve fail-closed behavior on incomplete registry/export coverage, and test the resulting deletion plan without deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is implemented, release evidence must include protected tag aliases for each digest. Immediate mitigation verified: all three activity-core baseline tags are present in the additive live-image union and recognized by the existing owner parser. No retention deletion was run. Future releases must not assume a digest line alone provides package protection. ## Adoption evidence — 2026-09-27 AppProject bootstrapped; root selectively synced only activity-core. Initial nine-resource adoption changed tracking metadata only. Then the child pinned 12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled frontend reporting smoke completed; all three recurring definitions stay enabled. See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to healthy observation. T02 stays waiting for this window and authenticated narrowly bound release-identity/rollback proof. Automation and pruning remain disabled. Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d. ## Digest retention implementation — 2026-09-27 Implemented conservative package-wide protection for live/exported sha256 refs, including tag@digest and retained rollback references. This avoids unsafe alias mapping assumptions; storage retention increases for those packages. Malformed references and incomplete cluster/package inventory refuse apply before deletion. Sixteen focused tests pass. Live tool installation/readback remains required; existing baseline aliases continue protecting production in the meantime. Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad operator token was copied or delegated. Its concrete executor contract is in `docs/activity-core-release-admission.md`. The production worker currently mounts an older platform checkout's script (SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870). Deploy the new script as a pinned GitOps projection, verify worker readback and a non-destructive planner fixture, then close T03. Do not silently overwrite the host checkout: it is outside the newly adopted nine-resource projection. Current baseline aliases remain protected; no prune was executed during verification. ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker that restricts both the platform child revision update and Kubernetes Application sync operation; resource-name RBAC alone cannot restrict patch fields. This is concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a reason to ask the founder to approve each release. Tests in the owner checkout: 20 passed across retention and additive inventory suites. ## Retention deployed and verified — 2026-09-27 T03 complete. Supersedes the earlier pending host-copy installation: the script is now pinned by source commit and SHA256 in activity-core's existing ConfigMap, projected read-only over the worker tool path, and reconciled through ArgoCD. No host checkout mutation, new resource adoption or manual prune was needed. The pod annotation changes with the script hash to refresh subPath mounts. CI verifies source bytes against the platform commit. Live worker hash matches; real additive inventory protects activity-core as a whole package. A synthetic rollback version is protected by the planner. No registry requests or deletion were made by this probe. See docs/evidence/2026-09-27-digest-retention-release.json. New healthy observation start is 2026-09-27T14:06:22Z after worker rollout; earliest eligibility is September 28 at 16:06:22 Europe/Berlin. Automation remains off. T02 still owns the scoped broker/admission and observation requirements. ## Loose-end review — 2026-09-27 The workplan is blocked on T02. Current activity-core remains Synced/Healthy at a12f1169f9d130058ce767f5b26de0606997916c, with health transition 2026-09-27T14:06:22Z. Earliest observation eligibility remains September 28 at 16:06:22 Europe/Berlin. The authenticated bounded broker/admission and rollback proof remain owned jointly with ACTIVITY-WP-0041-T03. Elapsed time is not release-identity admission. T01/T03 remain done; no root automation, pruning or credential delegation was enabled.