1.8 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAILIANCE-WP-0023 | workplan | Hub-core candidate credential lanes | financials | railiance-platform | active | codex | railiance | 2026-08-21 | 2026-08-21 |
|
d2adc2d4-6461-4f7b-affc-7248fea49e60 |
Hub-core candidate credential lanes
Extend exact-scope policy and projections
id: RAILIANCE-WP-0023-T01
status: done
priority: high
state_hub_task_id: "37b69d0e-7eac-40e5-b18a-777fa2b5e2da"
Add only database/creds/hub-core-runtime and
database/creds/hub-core-migration to the existing namespace-limited Core Hub
database store, with separate five-minute ExternalSecret projections.
Activate and verify production lanes
id: RAILIANCE-WP-0023-T02
status: progress
priority: high
state_hub_task_id: "d15f82db-f1ba-467a-bb69-86eb7c314016"
Apply the reviewed policy and projections after rapp-postgres creates the roles. Verify store validity, SecretSynced status, role separation, and lease rotation without reading or logging values.
The exact policy, projections, SecretSynced state, role separation, and production runtime/migration handoff passed on 2026-08-21. Keep this task in progress for the deliberate lease-rotation observation during stabilization.
Hand off the private candidate
id: RAILIANCE-WP-0023-T03
status: done
priority: high
state_hub_task_id: "bb2a73fc-3bee-45a6-83f0-3341639aabdf"
Confirm both Secret metadata objects are ready, then hand the candidate
migration and rollout gate back to RAPPCOREHUB-WP-0002-T03.
Completed 2026-08-21. Both projected Secret metadata objects were Ready, the migration completed, and the candidate advanced through all route groups to production authority without exposing credential values.