railiance-platform/assurance/service-records.json
codex 445f1361dc
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Advance blocked assurance and operator callback work
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 14:16:49 +02:00

198 lines
11 KiB
JSON

{
"schema": "railiance-platform.service-records.v1",
"reviewed": "2026-09-06",
"review_owner": "railiance-platform",
"review_scope": "S3 disclosure of unsupported guarantees; not external package approval",
"services": [
{
"service": "apps-pg",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-platform",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"vergabe",
"coulomb_social"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"retention": "30 days",
"existing_evidence": "docs/evidence/scaleway-primary-restore-2026-09-06.json",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "platform-pg",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-postgres",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"audit-core",
"tenant-engine",
"core-hub",
"isolation-probe"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"retention": "30 days",
"existing_evidence": "rapp-postgres/docs/evidence/backup-restore-2026-08-13.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "platform-pg-2",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-postgres",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"sbom-nexus"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-postgres"
},
"retention": "30 days",
"existing_evidence": "rapp-postgres/docs/evidence/RAPP-POSTGRES-WP-0005-T04-boundary-restore-2026-08-22.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "openbao",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "rapp-openbao",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"approved credential lanes"
],
"failure_domain": "single-node railiance01",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + rapp-openbao"
},
"retention": "KV history/audit/snapshot retention not accepted",
"existing_evidence": "reviews/WARDEN-WP-0027-T02-DRILL-20260822-01-openbao-snapshot-receipt.json",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
},
{
"service": "forgejo-backup",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-forge",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"forgejo"
],
"failure_domain": "source host, Scaleway full archive and native database backup, independent encrypted Nextcloud essentials copy",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-forge"
},
"retention": "Scaleway native database: 30 days. Nextcloud essentials: proposed 7 daily + 2 weekly within 10 GiB; scheduled tier/retention cutover remains pending in RPF-WP-0038-T04.",
"existing_evidence": "docs/forgejo-backup.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "Scaleway native Forgejo database recovery and full application archive recovery passed on 2026-09-06; independent Nextcloud essentials recovery passed with packages disabled. See RPF-WP-0038 evidence. No accepted numeric availability/RPO/RTO guarantees or recurring tiered archive cadence are established."
},
{
"service": "cnpg-option-a",
"accountable_owner": "railiance-platform",
"package_or_consumer_owner": "railiance-platform",
"operator_role": "attended platform operator; application proof by consumer owner",
"consumers": [
"production-of-record CNPG logical dumps"
],
"failure_domain": "source host plus separately encrypted Nextcloud copy",
"availability": {
"status": "unsupported",
"target": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rpo": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"rto": {
"status": "unsupported",
"target_seconds": null,
"decision_owner": "railiance-platform + railiance-platform"
},
"retention": "offsite retention not accepted",
"existing_evidence": "docs/cnpg-option-a-backup.md",
"recovery_custody": "OpenBao: 2-of-3 operator quorum plus independent encrypted snapshot custody; database/offsite: governed backup lane and separately available restore key. Availability not verified in this task.",
"maintenance_abort": "docs/railiance01-coordinated-reboot.md; stop before mutation when freshness, quorum, consumer readiness or named abort operator is absent",
"freshness_policy": "assurance/service-contract.json; diagnostic thresholds only, no installed cadence approval",
"requirement_assessment": "No accepted numeric consumer availability/RPO/RTO requirement found in the reviewed contracts. Service classes inform placement, not guarantees. Refuse any request for guaranteed HA/node-loss recovery until matched to supported substrate and package proof."
}
]
}