source: repo-manager reason: deterministic projection registration Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
88 lines
3.8 KiB
Markdown
88 lines
3.8 KiB
Markdown
---
|
|
id: RPF-WP-0048
|
|
type: workplan
|
|
title: "Adopt activity-core application runtime into railiance01 GitOps"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: active
|
|
owner: codex
|
|
topic_slug: railiance
|
|
created: "2026-09-27"
|
|
updated: "2026-09-27"
|
|
state_hub_workstream_id: "b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54"
|
|
---
|
|
|
|
User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the
|
|
frontend-patterns reporting exception. This explicitly authorizes this adoption;
|
|
it does not widen the earlier one-time exception to unrelated workloads.
|
|
Authority: CONSTRUCT @ activity-core and railiance-platform;
|
|
ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap;
|
|
activation=APPROVED. Existing 24-hour observation requirement remains in force.
|
|
|
|
## Bootstrap a namespace-scoped project and adopt nine runtime resources
|
|
|
|
```task
|
|
id: RPF-WP-0048-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370"
|
|
```
|
|
|
|
New project permits only activity-core source, activity-core destination, and
|
|
ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal,
|
|
llm-connect, edge relay, storage or cluster-scoped resources enter this Application.
|
|
Application source is activity-core k8s/gitops at a pinned reviewed commit; no
|
|
finalizer, automated sync or pruning initially. Root sync must name this child
|
|
only; unrelated pending applications must not be changed. Verify ArgoCD's diff,
|
|
health, resource inventory, schedules and original deployment generations.
|
|
|
|
## Observe adoption and enforce bounded promotion readiness
|
|
|
|
```task
|
|
id: RPF-WP-0048-T02
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "63b44949-39f8-52fd-ab63-e618b67ef992"
|
|
```
|
|
|
|
Keep automated sync off for at least 24 hours after successful adoption. Record
|
|
start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication,
|
|
source validation and the promotion/rollback guard. Root-wide automation is outside
|
|
this workplan. No unattended merge credential or release executor is assumed just
|
|
because the Application exists. Confirm the scoped identity and checks before
|
|
activating bounded routine promotion. Destructive pruning remains disabled.
|
|
|
|
## Make registry retention aware of digest-pinned releases
|
|
|
|
```task
|
|
id: RPF-WP-0048-T03
|
|
status: todo
|
|
priority: high
|
|
state_hub_task_id: "6c2650a2-5da8-5999-a6e7-b22eb7c655f4"
|
|
```
|
|
|
|
The package retention parser currently recognizes tags only; digest references
|
|
must resolve to protected registry versions before routine digest promotion can
|
|
be unattended. Cover live and rollback digests, preserve fail-closed behavior on
|
|
incomplete registry/export coverage, and test the resulting deletion plan without
|
|
deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is
|
|
implemented, release evidence must include protected tag aliases for each digest.
|
|
|
|
Immediate mitigation verified: all three activity-core baseline tags are present
|
|
in the additive live-image union and recognized by the existing owner parser.
|
|
No retention deletion was run. Future releases must not assume a digest line alone
|
|
provides package protection.
|
|
|
|
## Adoption evidence — 2026-09-27
|
|
|
|
AppProject bootstrapped; root selectively synced only activity-core. Initial
|
|
nine-resource adoption changed tracking metadata only. Then the child pinned
|
|
12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the
|
|
same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled
|
|
frontend reporting smoke completed; all three recurring definitions stay enabled.
|
|
|
|
See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak
|
|
starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to
|
|
healthy observation. T02 stays waiting for this window and authenticated narrowly
|
|
bound release-identity/rollback proof. Automation and pruning remain disabled.
|
|
Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.
|