railiance-platform/.custodian-brief.md
custodian-sync 164131a7a9
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-28:
  - update .custodian-brief.md for railiance-platform

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 237582@bnt-lap001
Assistant-Session: f2b3d9f1-8fb9-4b9c-bc2b-837ec5dfc826
2026-09-28 23:42:34 +02:00

7.5 KiB

Custodian Brief — railiance-platform

Domain: financials
Last synced: 2026-09-28 21:42 UTC
State Hub: http://127.0.0.1:8000 (adjust if running on a remote machine)

Active Workstreams

ArgoCD phase B: adopt the four existing Applications on railiance01

Progress: 2/8 done | workplan_id: 98140775-3b9a-5cf9-9af6-722502d487dc

Open tasks:

  • ! Adopt openbao-secretstore (lowest risk) 6d5fc801 (wait: Adopted 2026-09-21; the follow-on step (issue-core adoption, then automation) waits on the founder's go-ahead.)
  • ! Adopt issue-core (from rapp-issue-core) 0e619658 (wait: Founder go-ahead plus rapp-issue-core's agreement (hub message) that ArgoCD owns production and make deploy stops being a production path.)
  • ! Adopt target-revenue d418068a (wait: Adopted 2026-09-21; remaining preconditions and the next step wait on the founder's go-ahead.)
  • ! Adopt external-secrets (highest risk) 4ca54868 (wait: Founder go-ahead for the ESO adoption after adding CRD Prune=false,Delete=false and re-running the diff.)
  • ! Turn the root back to the production lane 844ff115 (wait: Founder go-ahead to restore automated prune/selfHeal on railiance-apps-root once T03-T06 are proven.)
  • ! Plan phase C: retire coulombcore's ArgoCD 55d1382f (wait: Planning only; needs an operator read-only check of coulombcore's ArgoCD, outside agent session scope.)

Close Forgejo primary backup coverage on Scaleway

Progress: 3/4 done | workplan_id: 7beec1a7-aa82-5a36-9a66-6b60008a2455

Open tasks:

  • ! Establish primary full-archive delivery and application recovery a4807df0 (wait: Operator chooses the independent archive prefix and confirms retention/caller contract and bounded worker credential delivery before the primary archive retrieval.)

Coordinate audit-core temporary custody and recovery exercises

Progress: 2/4 done | workplan_id: f4640325-e89c-591d-b58e-ec6b087900ac

Open tasks:

  • ! T02 — Define the runtime database lease recovery exercise fda4262a (wait: Value-safe lease revoke/expire exercise must be coordinated with rapp-postgres and audit-core.)
  • ! T03 — Define the coordinated railiance01 reboot exercise ba729d18 (wait: Single-node outage exercise needs operator access and a declared restart order coordinated with railiance-infra, railiance-cluster, audit-core and the OpenBao package owner.)

Onboard rapp-policy-nexus to the ArgoCD production lane

Progress: 2/5 done | workplan_id: ec41a4bd-df18-5b07-9b63-ccb80d9f001c

Open tasks:

  • ! Prepare the Application and the dry-run evidence 2afb1aac (wait: Draft the Application only after the tenant decision in T02.)
  • ! Adopt policy-nexus (live, founder go-ahead) 8638fa73 (wait: Founder go-ahead: the merge is a live production change (CONSTRUCT @ railiance-platform, activation=APPROVED); also needs the root automation restored in RPF-WP-0044-T07.)
  • ! Agree where policy-nexus's manifests live 49143c5e (wait: rapp-policy-nexus owns the tenant repository and decides manifest placement itself (RAPP-POLICY-NEXUS-WP-0002).)

Close S3 service assurance and ownership gaps

Progress: 4/7 done | workplan_id: ca639c3d-3a87-5fa4-ad13-6f2e014b0c84

Open tasks:

  • ! Produce S3 signals and prove their delivery to the evidence owner 5351e0e4 (wait: Needs a concrete receiving contract from railiance-telemetry (RTEL-WP-0002) before health transport is accepted; unmonitored state retained meanwhile.)
  • ! Obtain acceptance for compatibility assets and derived-record cleanup 3b74f79c (wait: Owner-ready handoffs to railiance-forge, rapp-openbao and the ArgoCD bootstrap owner await acceptance; S3 custody contracts stay here until then.)
  • ! Make backup freshness and recurring recovery evidence checkable d64446fb

Adopt activity-core application runtime into railiance01 GitOps

Progress: 2/3 done | workplan_id: b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54

Open tasks:

  • ! Observe adoption and enforce bounded promotion readiness 63b44949 (wait: 24h soak after adoption, then founder confirmation of the scoped identity and checks before automated sync; ACTIVITY-WP-0041 owns publication and the promotion guard.)

Coordinate KeyCape live Secret exposure recovery

Progress: 4/6 done | workplan_id: b2c25a01-4a80-55c1-90cf-8538000f7e0e

Open tasks:

  • ! T03 — Collect exact owner acknowledgements 714ae011 (wait: Attended resolver run: postchecks outstanding; NetKingdom asked to package the complete sequence as one receipt-producing command for the next attended session.)
  • ! T06 — Publish the Railiance/OpenBao custody handoff 3b9748c4 (wait: Platform/OpenBao owner must publish the non-secret routing receipt for both lanes through the attended handoff; values are never inferred.)

Implement reviewed credential lanes with separate owner gates

Progress: 3/8 done | workplan_id: 975db491-5412-5e27-8e34-14a2417bb039

Open tasks:

  • ! Accept and provision secrets-engine service JWT login e0c82ea9 (wait: Attended platform provisioning of the exact JWT mount/role/policy; KeyCape issuer/JWKS and service registration under KEY-WP-0009.)
  • ! Implement the platform operator-write CCR contract and Fluid lane f47e5bc5 (wait: Attended platform policy/schema apply after MASON-WP-0005 construction coordination confirms the capability schema.)
  • ! Admit the separate approval client-side readers 68bff751 (wait: Scoped delivery proof pending; human approval follows INFD-WP-0001-T07/T08; front door stays non-resolvable.)
  • ! Dispose of the ungoverned whynot-design npm duplicate 0dd7c9a5 (wait: Founder HOLD (2026-09-21) on the legacy whynot-design npm pointer; custody disposition is an attended decision.)
  • ! Admit the two factory audit-sender custody lanes 0ef52c26 (wait: Attended first-provision via factory_audit_custody.py after consuming AUDIT-WP-0009-T09/T11 declarations.)

Coordinate KeyCape live Secret exposure recovery

Progress: 4/6 done | workplan_id: 038bc3c0-4492-5b91-95eb-ae515ca205df

Open tasks:

  • ! T03 — Collect exact owner acknowledgements e019c166 (wait: Canonical RPF-WP-0027-T03: complete platform custody acknowledgements remain missing.)
  • ! T06 — Publish the Railiance/OpenBao custody handoff 69326850 (wait: Canonical RPF-WP-0027-T06: complete field/auth/expiry/handoff contract absent; September 15 operator block remains in force.)

Coordinate audit-core temporary custody and recovery exercises

Progress: 2/4 done | workplan_id: 88c4ef7f-0af8-580e-90dc-a2bae2675a4d

Open tasks:

  • ! T02 — Define the runtime database lease recovery exercise caba7fcd (wait: Canonical RPF-WP-0015-T02: approved sender identity, fresh bounded attended window, named abort operator and live recovery receipt required.)
  • ! T03 — Define the coordinated railiance01 reboot exercise 09cf4065 (wait: Canonical RPF-WP-0015-T03: fresh outage approval, off-host snapshot, quorum/access evidence and owner execution required.)

Retract public OpenBao listener behind operator-only access

Progress: 2/3 done | workplan_id: 6f8a6cbc-c076-5f0a-ade2-281a7ec71360

Open tasks:

  • ! T03 — Complete the attended operator cutover 99f8b41f

MCP Orientation (when available)

If the state-hub MCP server is reachable, call: get_domain_summary("financials") This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.