These workplans exist only in the retired local hub. Their random pre-ADR-007 identifiers are refused by C-06 as stale references, so they cannot be registered. Deriving from the canonical record id takes no identity from anything: central does not hold them and the old ids die with the cache. Records central already holds were deliberately left untouched. Refs CUST-WP-0068-T06 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAILIANCE-WP-0023 | workplan | Hub-core candidate credential lanes | financials | railiance-platform | finished | codex | railiance | 2026-08-21 | 2026-08-22 |
|
ec52fbe6-571b-570e-884b-c7a32ff7bcc8 |
Hub-core candidate credential lanes
Extend exact-scope policy and projections
id: RAILIANCE-WP-0023-T01
status: done
priority: high
state_hub_task_id: "d3d45d08-3e95-5669-b321-c1e8474d2eb0"
Add only database/creds/hub-core-runtime and
database/creds/hub-core-migration to the existing namespace-limited Core Hub
database store, with separate five-minute ExternalSecret projections.
Activate and verify production lanes
id: RAILIANCE-WP-0023-T02
status: done
priority: high
state_hub_task_id: "c6e180b5-b3e6-500f-8d28-449092780946"
Apply the reviewed policy and projections after rapp-postgres creates the roles. Verify store validity, SecretSynced status, role separation, and lease rotation without reading or logging values.
Completed 2026-08-22. The exact policy, projections, SecretSynced state, role
separation, and production runtime/migration handoff passed on 2026-08-21. A
subsequent scheduled five-minute reconciliation advanced both target Secret
resource versions. After projected-volume propagation, the candidate watcher
replaced only its application child while the pod UID remained stable,
readiness stayed true, and the container restart count stayed zero. No
credential value was read or logged. Evidence:
docs/evidence/core-hub-private-shadow-2026-08-21.md.
Hand off the private candidate
id: RAILIANCE-WP-0023-T03
status: done
priority: high
state_hub_task_id: "58b852a9-98fe-55aa-b3de-316f4d6c4c59"
Confirm both Secret metadata objects are ready, then hand the candidate
migration and rollout gate back to RAPPCOREHUB-WP-0002-T03.
Completed 2026-08-21. Both projected Secret metadata objects were Ready, the migration completed, and the candidate advanced through all route groups to production authority without exposing credential values.