railiance-platform/workplans
codex f3ba7ca882
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Admit KeyCape approval-engine client custody paths and delivery
Answers KEY-WP-0013-T02. Both proposed KV paths are confirmed unchanged; the
field name is corrected to CLIENT_SECRET for the platform uppercase convention
and the CCR validator. Kubernetes delivery references are confirmed against the
live sso namespace. Attended authority is the governed openbao-platform-admin-login
lane, and the rollout is one attended window ordered after the Authelia issuer
precondition.

Adds CCR-2026-0017/0018, two exact-path read policies, two namespace-limited
ClusterSecretStores with Kubernetes auth, two ExternalSecrets, and RPF-WP-0035-T05.
Nothing is applied and no value exists: both CCRs remain proposed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-08 14:53:32 +02:00
..
archived Review blocked platform obligations and archive completed ESO recovery 2026-09-05 21:16:53 +02:00
.gitkeep chore(init): scaffold railiance-platform (S3 Platform Services) 2026-03-10 00:36:06 +01:00
README.md Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
RPF-WP-0015-audit-core-custody-and-recovery-coordination.md Review blocked platform obligations and archive completed ESO recovery 2026-09-05 21:16:53 +02:00
RPF-WP-0025-openbao-operator-only-access.md Advance blocked assurance and operator callback work 2026-09-06 14:16:49 +02:00
RPF-WP-0027-keycape-live-secret-exposure-recovery.md Consolidate platform workplans and assess intent gaps 2026-09-05 11:14:42 +02:00
RPF-WP-0029-backup-credential-default-removal.md Record successful full offsite Forgejo recovery and remaining custody gate 2026-09-06 01:36:39 +02:00
RPF-WP-0035-credential-lane-implementation.md Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
RPF-WP-0036-platform-service-assurance.md Track Q2 receiver implementation and live acceptance dependency 2026-09-06 19:18:14 +02:00
RPF-WP-0038-forgejo-scaleway-primary-coverage.md Record archive recovery lifecycle and validate receipt provenance 2026-09-06 14:53:15 +02:00

Current platform work

Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are under archived/; their IDs and UUIDs are preserved. The number of blocked plans is not a count of missing implementations or independent incidents.

Workplan Purpose and next gate S3 boundary
RPF-WP-0027 Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom.
RPF-WP-0029 Backup cutover and full offsite application recovery complete; old share invalidation receipt remains S3 retains custody acceptance; S1 and forge own their backup execution.
RPF-WP-0025 Private OpenBao access; fresh attended callback/login then guarded retraction Coordinate package, issuer, tunnel and DNS owners; keep the window separate.
RPF-WP-0015 Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts.
RPF-WP-0035 Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window.
RPF-WP-0036 Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff Run the assurance commands; live acceptance and external ownership remain gated.
RPF-WP-0038 Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention.

RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining acceptance gates. Treat credential exposure closure as the highest-priority attended work; task order does not combine or waive approvals.

Assessment and disposition of every plan and generated current record index.

Do not recreate completed workplans because an old Hub alias or generated brief still shows them active. Use source IDs, and follow AGENTS.md for verified sync.

Latest closure review

2026-09-05 blocker review: At that review: 12 unfinished tasks across six genuine blocked plans. The September 6 follow-up adds WP-0038 with one remaining full-archive task. All terminal plans have only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived. Three retired Hub aliases still appear open; they are a derived-view defect, not three more workplans. Use this file before the dated generated brief.