S3 Platform Services — PostgreSQL HA, Valkey, object storage
Find a file
codex f3cf832a35
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Declare the security layer, and repair the placement admission check
Layer declaration (gate-house). INTENT.md now carries the declaration in its own
voice with layer.yaml as the machine-readable form, adapted from ops-warden's
reference. railiance-platform is Staff: operating OpenBao is not a claim to the
Tooling layer, because §4 is explicit that no operator-of-third-party-Tooling
shape exists and that someone running it stays a declared gap. Six direct
Tooling contacts are mapped by capability rather than by file — one §5.2
conduit, one §5.1 diagnostic, four §5.3 gaps with intended owners and review
dates — and the uncatalogued contacts are listed so the check is total. We are
PEP-shaped and the unreachable-engine stance map is NOT published; that is
recorded as an open obligation to build against v0.8, not left silent.

Placement admission. canned-prompts was added as a PostgresConsumer on
platform-pg-2 in rapp-postgres 1b68b4c without a placement owner here, which is
exactly the cross-repo drift the assurance check exists to catch; the check had
been failing on it. Registered with its real boundary evidence, corrected the
stale test expectation that pinned the overflow cell at one consumer, and
updated the SCOPE occupancy line to 2/4.

Also records owner input received today: key-cape's issuer view on CCR-2026-0020's
presenting actor, and their confirmation that codex-railiance-platform correctly
stays tenant:coulomb, so the flagged T02 discrepancy is closed as not-a-defect.

The whynot-design npm field is NOT changed. Two dated live receipts here name
NPM_AUTH_TOKEN as the field, including an attended founder fetch; that is
recorded against the counterparty claim rather than either side being flipped
before the session settles it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-09 23:27:14 +02:00
.claude/rules docs: add scoped registrar recovery guidance 2026-08-21 21:38:35 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-04 12:49:59 +02:00
argocd Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
assurance Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
credential-change-requests Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
credential-grants Close RAILIANCE-WP-0015-T06 rapp credential-lane binding 2026-08-14 00:47:28 +02:00
data/consumption-mode Finish RAILIANCE-WP-0017 consumption-mode enforcement 2026-08-15 14:56:02 +02:00
docs Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
helm Define scoped Forgejo native backup on the Scaleway primary 2026-09-06 00:48:25 +02:00
history Verify telemetry essentials recovery from versioned Scaleway archive 2026-09-06 23:46:20 +02:00
interfaces Add direct WP-0024 load driver handoff 2026-08-22 16:17:03 +02:00
lib Contain backup upload credentials and prepare provider recovery gates 2026-09-05 19:21:06 +02:00
manifests Bind audit E2 retry projection to new engagement 2026-08-22 20:56:58 +02:00
openbao Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00
registry Draft capability entry (reuse-surface REUSE-WP-0017-T04, cohort 3) 2026-07-06 19:50:54 +02:00
reviews Record WP0027 platform snapshot receipt 2026-08-23 00:32:20 +02:00
schemas Add versioned ephemeral custody lifecycle 2026-08-22 21:56:42 +02:00
scripts Prepare the read-only attended session for four open custody questions 2026-09-09 20:07:51 +02:00
tests Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
tools Reject unfinished or truncated Forgejo backup archives before encryption 2026-09-05 22:10:22 +02:00
workplans Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-09 14:41:39 +02:00
.gitignore Ignore derived local Repo Manager cache 2026-09-05 10:19:08 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
.sops.yaml Finish architecture-cleanup RAILIANCE-WP-0016 T05 2026-08-15 14:43:44 +02:00
AGENTS.md Document credential lane designs and adopt fast projection sync 2026-09-05 10:41:56 +02:00
ArchitectureBlueprint.md Reopen the ArgoCD question on corrected evidence 2026-08-12 00:05:14 +02:00
CLAUDE.md Add credential routing instructions for all agent runtimes 2026-06-18 22:48:39 +02:00
INTENT.md Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
layer.yaml Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:54:20 +02:00
Makefile Define scoped Forgejo native backup on the Scaleway primary 2026-09-06 00:48:25 +02:00
SCOPE.md Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
tenancy.yaml Fix apps-pg tenancy evidence declaration 2026-08-23 13:21:42 +02:00
WORK-RECORDS.md Refresh the generated work record index 2026-09-09 14:42:10 +02:00