railiance-platform/workplans
codex 32d5cf0211
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Prepare the two approval client-side reader admissions
RPF-WP-0035-T06. Adds CCR-2026-0019 (secrets-engine) and CCR-2026-0020
(approval-engine-operator) with their exact-path read policies, reusing the
existing version-1 custody from the verifier activation. No reseed, rotation,
shared reader or verifier Secret reuse; both requests are in_flight and nothing
is applied.

The two shapes were decided by read-only survey rather than assumed.
secrets-engine consumes its client secret through an operator-run CLI reading a
protected file, and its namespace holds no workload, so reader 1 is an attended
operator-workstation OIDC lane rather than an ESO lane; its one missing input is
the operator group claim, which NetKingdom and KeyCape own. approval-engine is
not deployed and no owner source names who presents the operator client, so
reader 2 records the undetermined actor instead of guessing one for the widest
approval scope in the pair. Both declare openbao.auth missing rather than
carrying a placeholder binding.

T06 moves to wait on those two owner inputs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-09 14:41:01 +02:00
..
archived Review blocked platform obligations and archive completed ESO recovery 2026-09-05 21:16:53 +02:00
.gitkeep chore(init): scaffold railiance-platform (S3 Platform Services) 2026-03-10 00:36:06 +01:00
README.md Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
RPF-WP-0015-audit-core-custody-and-recovery-coordination.md Review blocked platform obligations and archive completed ESO recovery 2026-09-05 21:16:53 +02:00
RPF-WP-0025-openbao-operator-only-access.md Advance blocked assurance and operator callback work 2026-09-06 14:16:49 +02:00
RPF-WP-0027-keycape-live-secret-exposure-recovery.md Consolidate platform workplans and assess intent gaps 2026-09-05 11:14:42 +02:00
RPF-WP-0029-backup-credential-default-removal.md Record successful full offsite Forgejo recovery and remaining custody gate 2026-09-06 01:36:39 +02:00
RPF-WP-0035-credential-lane-implementation.md Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00
RPF-WP-0036-platform-service-assurance.md Track Q2 receiver implementation and live acceptance dependency 2026-09-06 19:18:14 +02:00
RPF-WP-0038-forgejo-scaleway-primary-coverage.md Record archive recovery lifecycle and validate receipt provenance 2026-09-06 14:53:15 +02:00

Current platform work

Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are under archived/; their IDs and UUIDs are preserved. The number of blocked plans is not a count of missing implementations or independent incidents.

Workplan Purpose and next gate S3 boundary
RPF-WP-0027 Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom.
RPF-WP-0029 Backup cutover and full offsite application recovery complete; old share invalidation receipt remains S3 retains custody acceptance; S1 and forge own their backup execution.
RPF-WP-0025 Private OpenBao access; fresh attended callback/login then guarded retraction Coordinate package, issuer, tunnel and DNS owners; keep the window separate.
RPF-WP-0015 Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts.
RPF-WP-0035 Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window.
RPF-WP-0036 Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff Run the assurance commands; live acceptance and external ownership remain gated.
RPF-WP-0038 Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention.

RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining acceptance gates. Treat credential exposure closure as the highest-priority attended work; task order does not combine or waive approvals.

Assessment and disposition of every plan and generated current record index.

Do not recreate completed workplans because an old Hub alias or generated brief still shows them active. Use source IDs, and follow AGENTS.md for verified sync.

Latest closure review

2026-09-05 blocker review: At that review: 12 unfinished tasks across six genuine blocked plans. The September 6 follow-up adds WP-0038 with one remaining full-archive task. All terminal plans have only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived. Three retired Hub aliases still appear open; they are a derived-view defect, not three more workplans. Use this file before the dated generated brief.