1.6 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAILIANCE-WP-0023 | workplan | Hub-core candidate credential lanes | financials | railiance-platform | active | codex | railiance | 2026-08-21 | 2026-08-21 |
|
Hub-core candidate credential lanes
Extend exact-scope policy and projections
id: RAILIANCE-WP-0023-T01
status: done
priority: high
Add only database/creds/hub-core-runtime and
database/creds/hub-core-migration to the existing namespace-limited Core Hub
database store, with separate five-minute ExternalSecret projections.
Activate and verify production lanes
id: RAILIANCE-WP-0023-T02
status: progress
priority: high
Apply the reviewed policy and projections after rapp-postgres creates the roles. Verify store validity, SecretSynced status, role separation, and lease rotation without reading or logging values.
The exact policy, projections, SecretSynced state, role separation, and production runtime/migration handoff passed on 2026-08-21. Keep this task in progress for the deliberate lease-rotation observation during stabilization.
Hand off the private candidate
id: RAILIANCE-WP-0023-T03
status: done
priority: high
Confirm both Secret metadata objects are ready, then hand the candidate
migration and rollout gate back to RAPPCOREHUB-WP-0002-T03.
Completed 2026-08-21. Both projected Secret metadata objects were Ready, the migration completed, and the candidate advanced through all route groups to production authority without exposing credential values.