railiance-platform/.custodian-brief.md
custodian-sync 0873e5b804
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-28:
  - update .custodian-brief.md for railiance-platform

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 237582@bnt-lap001
Assistant-Session: f2b3d9f1-8fb9-4b9c-bc2b-837ec5dfc826
2026-09-28 23:39:27 +02:00

5.9 KiB

Custodian Brief — railiance-platform

Domain: financials
Last synced: 2026-09-28 21:39 UTC
State Hub: http://127.0.0.1:8000 (adjust if running on a remote machine)

Active Workstreams

ArgoCD phase B: adopt the four existing Applications on railiance01

Progress: 2/8 done | workplan_id: 98140775-3b9a-5cf9-9af6-722502d487dc

Open tasks:

  • ! Adopt openbao-secretstore (lowest risk) 6d5fc801
  • ! Adopt issue-core (from rapp-issue-core) 0e619658
  • ! Adopt target-revenue d418068a
  • ! Adopt external-secrets (highest risk) 4ca54868
  • ! Turn the root back to the production lane 844ff115
  • ! Plan phase C: retire coulombcore's ArgoCD 55d1382f

Onboard rapp-policy-nexus to the ArgoCD production lane

Progress: 2/5 done | workplan_id: ec41a4bd-df18-5b07-9b63-ccb80d9f001c

Open tasks:

  • ! Agree where policy-nexus's manifests live 49143c5e
  • ! Prepare the Application and the dry-run evidence 2afb1aac
  • ! Adopt policy-nexus (live, founder go-ahead) 8638fa73

Close Forgejo primary backup coverage on Scaleway

Progress: 3/4 done | workplan_id: 7beec1a7-aa82-5a36-9a66-6b60008a2455

Open tasks:

  • ! Establish primary full-archive delivery and application recovery a4807df0 (wait: Operator chooses the independent archive prefix and confirms retention/caller contract and bounded worker credential delivery before the primary archive retrieval.)

Close S3 service assurance and ownership gaps

Progress: 4/7 done | workplan_id: ca639c3d-3a87-5fa4-ad13-6f2e014b0c84

Open tasks:

  • ! Produce S3 signals and prove their delivery to the evidence owner 5351e0e4
  • ! Obtain acceptance for compatibility assets and derived-record cleanup 3b74f79c
  • ! Make backup freshness and recurring recovery evidence checkable d64446fb

Implement reviewed credential lanes with separate owner gates

Progress: 3/8 done | workplan_id: 975db491-5412-5e27-8e34-14a2417bb039

Open tasks:

  • ! Accept and provision secrets-engine service JWT login e0c82ea9 (wait: Attended platform provisioning of the exact JWT mount/role/policy; KeyCape issuer/JWKS and service registration under KEY-WP-0009.)
  • ! Implement the platform operator-write CCR contract and Fluid lane f47e5bc5 (wait: Attended platform policy/schema apply after MASON-WP-0005 construction coordination confirms the capability schema.)
  • ! Admit the separate approval client-side readers 68bff751 (wait: Scoped delivery proof pending; human approval follows INFD-WP-0001-T07/T08; front door stays non-resolvable.)
  • ! Dispose of the ungoverned whynot-design npm duplicate 0dd7c9a5 (wait: Founder HOLD (2026-09-21) on the legacy whynot-design npm pointer; custody disposition is an attended decision.)
  • ! Admit the two factory audit-sender custody lanes 0ef52c26 (wait: Attended first-provision via factory_audit_custody.py after consuming AUDIT-WP-0009-T09/T11 declarations.)

Coordinate KeyCape live Secret exposure recovery

Progress: 4/6 done | workplan_id: b2c25a01-4a80-55c1-90cf-8538000f7e0e

Open tasks:

  • ! T03 — Collect exact owner acknowledgements 714ae011 (wait: Attended resolver run: postchecks outstanding; NetKingdom asked to package the complete sequence as one receipt-producing command for the next attended session.)
  • ! T06 — Publish the Railiance/OpenBao custody handoff 3b9748c4 (wait: Platform/OpenBao owner must publish the non-secret routing receipt for both lanes through the attended handoff; values are never inferred.)

Coordinate audit-core temporary custody and recovery exercises

Progress: 2/4 done | workplan_id: f4640325-e89c-591d-b58e-ec6b087900ac

Open tasks:

  • ! T02 — Define the runtime database lease recovery exercise fda4262a (wait: Value-safe lease revoke/expire exercise must be coordinated with rapp-postgres and audit-core.)
  • ! T03 — Define the coordinated railiance01 reboot exercise ba729d18 (wait: Single-node outage exercise needs operator access and a declared restart order coordinated with railiance-infra, railiance-cluster, audit-core and the OpenBao package owner.)

Adopt activity-core application runtime into railiance01 GitOps

Progress: 2/3 done | workplan_id: b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54

Open tasks:

  • ! Observe adoption and enforce bounded promotion readiness 63b44949

Coordinate KeyCape live Secret exposure recovery

Progress: 4/6 done | workplan_id: 038bc3c0-4492-5b91-95eb-ae515ca205df

Open tasks:

  • ! T03 — Collect exact owner acknowledgements e019c166 (wait: Canonical RPF-WP-0027-T03: complete platform custody acknowledgements remain missing.)
  • ! T06 — Publish the Railiance/OpenBao custody handoff 69326850 (wait: Canonical RPF-WP-0027-T06: complete field/auth/expiry/handoff contract absent; September 15 operator block remains in force.)

Coordinate audit-core temporary custody and recovery exercises

Progress: 2/4 done | workplan_id: 88c4ef7f-0af8-580e-90dc-a2bae2675a4d

Open tasks:

  • ! T02 — Define the runtime database lease recovery exercise caba7fcd (wait: Canonical RPF-WP-0015-T02: approved sender identity, fresh bounded attended window, named abort operator and live recovery receipt required.)
  • ! T03 — Define the coordinated railiance01 reboot exercise 09cf4065 (wait: Canonical RPF-WP-0015-T03: fresh outage approval, off-host snapshot, quorum/access evidence and owner execution required.)

Retract public OpenBao listener behind operator-only access

Progress: 2/3 done | workplan_id: 6f8a6cbc-c076-5f0a-ade2-281a7ec71360

Open tasks:

  • ! T03 — Complete the attended operator cutover 99f8b41f

MCP Orientation (when available)

If the state-hub MCP server is reachable, call: get_domain_summary("financials") This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.