railiance-platform/tenancy.yaml
codex dc4245361d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Finish RPF-WP-0018; RPF-WP-0019 repository-complete
RPF-WP-0018 closed: all seven tasks done. The provider-declaration finding
was adopted upstream and its canonical form is the provider: block in
tenancy.yaml; adaptive-pricing declined the standing co-signature and
supplied typed tier minima instead, recorded in ADR-0002. Three corrections
against our own output are recorded in the documents rather than edited
away.

RPF-WP-0019 T03 done (ceiling of three, memory binding, apps-pg-2 named as
overflow, enforced by make apps-pg-verify-capacity). T01/T02 are
repository-complete: backup target, retention, per-consumer connection
limits, role timeouts and Burstable resources are declared in source and
published in s3-consumer-interfaces 1.1.0 before rollout. They stay in
progress because no live application, backup success or restore proof
exists, and declared configuration is not a section 13 artifact. T04 waits
on that window.

apps-pg R reason corrected to say the target is declared-not-applied rather
than absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 13:35:04 +02:00

126 lines
4.8 KiB
YAML

# Canonical vector set for services owned or held in custody here.
# Human reasoning remains in docs/tenancy-posture.md.
schema_version: "0.1"
framework: netkingdom-tenancy-posture
services:
- service: apps-pg
role: relational-storage-provider
tenancy:
current: { I: 0, A: 0, E: 0, P: "n/a", R: 0, V: 0 }
target: { I: 0, A: 0, E: 0, P: "n/a", R: 2, V: 1 }
reviewed: "2026-08-17"
review_due: "2027-02-17"
service_class: interactive
permanent: [I, A, E, P]
reason:
I: "The storage provider receives credentials, not tenant claims."
A: "No tenant context is bound at the database provider."
E: "Tenant enforcement belongs to each consuming application."
P: "apps-pg provides P1; a substrate is not itself at a P level."
R: "A backup target and 30-day retention are declared in source and
not yet applied; no successful backup or restore exists. R stays 0
until evidenced, per §13.1 — declared configuration is not an
artifact."
V: "No recovery exercise or failover evidence exists."
gap:
R: "RPF-WP-0019 establishes a backup target and declared horizon."
V: "Exercise recovery after the backup target is established."
provider:
capability: data.relational
profile: s5-application-databases
axes:
E:
available: 2
maximum: 3
conditions:
- "E2 is entirely consumer-side."
- "E3 requires adoption of the rapp-postgres GUC contract."
- "E4 is unreachable on a shared cluster without per-tenant credentials."
P:
available: 1
maximum: 2
conditions:
- "P2 requires a new dedicated cluster for the consumer."
R:
available: 0
maximum: 2
conditions:
- "A governed backup target must exist before R2 is available."
V:
available: 0
maximum: 1
conditions:
- "Single-node recovery must be documented and exercised."
- service: forgejo-db
role: relational-storage-provider
tenancy:
current: { I: 0, A: 0, E: 0, P: "n/a", R: 0, V: 0 }
target: { I: 0, A: 0, E: 0, P: "n/a", R: 2, V: 1 }
reviewed: "2026-08-17"
review_due: "2027-02-17"
service_class: interactive
permanent: [I, A, E, P]
reason:
I: "The database receives a Forgejo credential, not tenant claims."
A: "No NetKingdom tenant context is bound at this provider."
E: "Tenant enforcement, if any, belongs to Forgejo."
P: "forgejo-db provides P2 to Forgejo; it is not itself at P2."
R: "A backup procedure exists, but no declared retention or erasure horizon does."
V: "No exercised recovery objective or failover evidence exists."
gap:
R: "Declare the backup window and publish the effective erasure horizon."
V: "Exercise recovery and record the interruption."
provider:
capability: data.relational
profile: dedicated-forgejo-database
axes:
P:
available: 2
maximum: 2
R:
available: 0
maximum: 2
conditions:
- "Declare and evidence retention on the existing backup path."
V:
available: 0
maximum: 1
conditions:
- "Single-node recovery must be exercised."
- service: openbao
role: credential-provider
tenancy:
current: { I: 0, A: 0, E: 0, P: 0, R: 0, V: 0 }
target: { I: 0, A: 0, E: 0, P: 0, R: 1, V: 1 }
reviewed: "2026-08-17"
review_due: "2027-02-17"
service_class: latency-critical
permanent: [I, A, E, P]
reason:
I: "OpenBao authenticates workloads and does not resolve NetKingdom tenants."
A: "No tenant context is carried or bound."
E: "OpenBao holds workload secrets, not tenant-keyed records."
P: "One instance is shared by every credential consumer."
R: "No retention position covers audit output or KV version history."
V: "Node recovery requires operator unseal; no recovery objective is evidenced."
gap:
R: "Declare the platform default for audit output and KV history."
V: "Exercise the complete restart and unseal path against a recovery objective."
provider:
capability: credential.vending
axes:
E:
available: 0
maximum: 4
conditions:
- "Per-tenant paths, roles and credentials are required for tenant-level E4."
- "Current evidence proves consumer-boundary scoping, not tenant-boundary scoping."
evidence:
- "scripts/openbao-verify-token-grants.py"
V:
available: 0
maximum: 1
conditions:
- "Single-node restart and unseal recovery must be exercised."