RPF-WP-0018 closed: all seven tasks done. The provider-declaration finding was adopted upstream and its canonical form is the provider: block in tenancy.yaml; adaptive-pricing declined the standing co-signature and supplied typed tier minima instead, recorded in ADR-0002. Three corrections against our own output are recorded in the documents rather than edited away. RPF-WP-0019 T03 done (ceiling of three, memory binding, apps-pg-2 named as overflow, enforced by make apps-pg-verify-capacity). T01/T02 are repository-complete: backup target, retention, per-consumer connection limits, role timeouts and Burstable resources are declared in source and published in s3-consumer-interfaces 1.1.0 before rollout. They stay in progress because no live application, backup success or restore proof exists, and declared configuration is not a section 13 artifact. T04 waits on that window. apps-pg R reason corrected to say the target is declared-not-applied rather than absent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
28 lines
699 B
Text
28 lines
699 B
Text
# Decrypted helm values — never commit plaintext secrets
|
|
helm/*.yaml
|
|
!helm/*.sops.yaml
|
|
!helm/*.yaml.template
|
|
!helm/openbao-values.yaml
|
|
!helm/openbao-middleware.yaml
|
|
!helm/openbao-ui-overlay-k8s.yaml
|
|
# Kubernetes manifests (no secrets) are safe to commit
|
|
!helm/*-cluster.yaml
|
|
!helm/*-networkpolicies.yaml
|
|
!helm/*-databases.yaml
|
|
!helm/*-backup.yaml
|
|
|
|
# ArgoCD repository credentials — encrypt locally, never commit
|
|
argocd/repositories/*.repository.sops.yaml
|
|
!argocd/repositories/*.repository.sops.yaml.template
|
|
|
|
# Kubeconfig
|
|
*.kubeconfig
|
|
|
|
# Credential broker local lease/token material
|
|
.local/credential-leases/
|
|
*.openbao-token
|
|
|
|
# Python bytecode caches
|
|
__pycache__/
|
|
*.pyc
|
|
tools/vendor/bin/kubectl
|