railiance-platform/workplans/README.md
codex 234b1b559f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Implement S3 service assurance and admission checks
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 11:43:55 +02:00

2.4 KiB

Current platform work

Reviewed 2026-09-05. Six open workplans: six blocked on explicit owner/live gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are under archived/; their IDs and UUIDs are preserved. The number of blocked plans is not a count of missing implementations or independent incidents.

Workplan Purpose and next gate S3 boundary
RPF-WP-0027 Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom.
RPF-WP-0029 Backup credential exposure; attended provider invalidation and replacement recovery receipts S3 retains custody acceptance; S1 and forge own their backup execution.
RPF-WP-0025 Private OpenBao access; fresh attended callback/login then guarded retraction Coordinate package, issuer, tunnel and DNS owners; keep the window separate.
RPF-WP-0015 Two prepared recovery exercises; fresh synthetic-load/outage approvals and custody readiness S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts.
RPF-WP-0035 One implementation queue for secrets-engine JWT, Fluid operator KV and preflight signing Three independent task gates; no new approval inherited from the completed designs.
RPF-WP-0036 Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff Run the assurance commands; live acceptance and external ownership remain gated.

RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining acceptance gates. Treat credential exposure closure as the highest-priority attended work; task order does not combine or waive approvals.

Assessment and disposition of every plan and generated current record index.

Do not recreate completed workplans because an old Hub alias or generated brief still shows them active. Use source IDs, and follow AGENTS.md for verified sync.