railiance-platform/docs
codex cc4e659a9e Correct the S3 posture declaration against Tenancy Posture SS13
Self-audit after reading SS6, SS11, SS12 and SS13 in full rather than the
sections cited in review.

openbao A:2 -> A:0. The claim was incoherent (it invoked the absence of
tenant context to justify E:0 and ignored it to claim A2, which SS4.2
defines in terms of tenant context) and unevidenced at the moment of
claiming, which SS13.1 forbids and SS13.1a does not excuse above the floor.
The real authorization evidence, openbao-verify-token-grants.py, is
consumer-boundary and is now cited under the provider statement.

Floor claims carry reason: per SS13.1a; permanent-by-design lines are
marked so SS12 guard does not read them as stalled.

The provider-versus-consumer finding is narrowed: SS6 plus the flex-auth
I1-forever precedent already express a structurally permanent low level,
so that half is withdrawn. What survives is that a provider cannot state
the level it makes reachable for its consumers.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:56:03 +02:00
..
adr RPF-WP-0018 T01-T06: publish S3 posture, placement policy, quotas, ADR surface 2026-08-17 21:55:11 +02:00
evidence Finish architecture-cleanup RAILIANCE-WP-0016 T05 2026-08-15 14:43:44 +02:00
apps-pg.md Finish RAILIANCE-WP-0016 apps-pg resource evidence 2026-08-14 02:05:25 +02:00
argocd-gitops.md Fix openbao-secretstore ArgoCD health: coulombcore scope only 2026-07-08 15:41:04 +02:00
cnpg-option-a-backup.md Include user-engine in offsite CNPG backups 2026-07-30 00:05:58 +02:00
consumption-mode-enforcement.md Finish RAILIANCE-WP-0017 consumption-mode enforcement 2026-08-15 14:56:02 +02:00
credential-broker.md Unblock credential broker warden-sign pilot 2026-07-01 23:10:38 +02:00
credential-change-approval.md Add credential-change delegated applier flow 2026-07-01 20:07:26 +02:00
credential-lane-lifecycle-runbook.md Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision 2026-08-11 22:41:30 +02:00
forgejo-backup.md Add Forgejo daily backup automation (T04/T09 Option A) 2026-07-07 17:19:19 +02:00
forgejo-package-prune.md Cut forgejo package prune over to OpenBao lane 2026-07-26 09:32:08 +02:00
openbao-approved-automation-delegation.md Close delegated prod applier pilot 2026-07-01 23:34:13 +02:00
openbao-emergency-drill-evidence.example.json Add OpenBao emergency drill evidence validator 2026-06-02 00:08:17 +02:00
openbao-restore-drill-evidence.example.json Add OpenBao restore evidence validator 2026-06-01 23:57:00 +02:00
openbao.md Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision 2026-08-11 22:41:30 +02:00
placement-policy.md RPF-WP-0018 T01-T06: publish S3 posture, placement policy, quotas, ADR surface 2026-08-17 21:55:11 +02:00
postgresql-ha.md Finish architecture-cleanup RAILIANCE-WP-0016 T05 2026-08-15 14:43:44 +02:00
put-backup-object-storage.md docs: how to add APPLICATION_ID for the backup bucket policy 2026-08-14 19:52:08 +02:00
rapp-credential-lane-binding.md retarget: CCR-2026-0012 is the general backup object-store lane 2026-08-14 19:19:56 +02:00
rapp-openbao-boundary.md Document rapp-openbao compatibility handoff 2026-07-26 10:39:40 +02:00
rapp-openbao-compatibility-handoff.md Document rapp-openbao compatibility handoff 2026-07-26 10:39:40 +02:00
rapp-platform-service-pattern.md Close RAILIANCE-WP-0015-T06 rapp credential-lane binding 2026-08-14 00:47:28 +02:00
rapp-postgres-boundary.md Broker audit-core dynamic database credentials 2026-08-10 19:36:30 +02:00
reuse-surface-runtime-secrets-rotation-runbook.md Add reuse-surface secrets rotation runbook (RAILIANCE-WP-0011-T04) 2026-07-08 00:01:21 +02:00
s3-consumer-interfaces.md RPF-WP-0018 T01-T06: publish S3 posture, placement policy, quotas, ADR surface 2026-08-17 21:55:11 +02:00
tenancy-posture.md Correct the S3 posture declaration against Tenancy Posture SS13 2026-08-17 22:56:03 +02:00
whynot-design-npm-publish-handoff.md Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision 2026-08-11 22:41:30 +02:00
workload-kv-access-lanes.md Add email-connect transactional SMTP and ingest custody lane. 2026-08-12 13:32:11 +02:00