railiance-platform/docs
codex f3cf832a35
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Declare the security layer, and repair the placement admission check
Layer declaration (gate-house). INTENT.md now carries the declaration in its own
voice with layer.yaml as the machine-readable form, adapted from ops-warden's
reference. railiance-platform is Staff: operating OpenBao is not a claim to the
Tooling layer, because §4 is explicit that no operator-of-third-party-Tooling
shape exists and that someone running it stays a declared gap. Six direct
Tooling contacts are mapped by capability rather than by file — one §5.2
conduit, one §5.1 diagnostic, four §5.3 gaps with intended owners and review
dates — and the uncatalogued contacts are listed so the check is total. We are
PEP-shaped and the unreachable-engine stance map is NOT published; that is
recorded as an open obligation to build against v0.8, not left silent.

Placement admission. canned-prompts was added as a PostgresConsumer on
platform-pg-2 in rapp-postgres 1b68b4c without a placement owner here, which is
exactly the cross-repo drift the assurance check exists to catch; the check had
been failing on it. Registered with its real boundary evidence, corrected the
stale test expectation that pinned the overflow cell at one consumer, and
updated the SCOPE occupancy line to 2/4.

Also records owner input received today: key-cape's issuer view on CCR-2026-0020's
presenting actor, and their confirmation that codex-railiance-platform correctly
stays tenant:coulomb, so the flagged T02 discrepancy is closed as not-a-defect.

The whynot-design npm field is NOT changed. Two dated live receipts here name
NPM_AUTH_TOKEN as the field, including an attended founder fetch; that is
recorded against the counterparty claim rather than either side being flipped
before the session settles it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-09 23:27:14 +02:00
..
adr Implement S3 service assurance and admission checks 2026-09-05 11:43:55 +02:00
credential-lane-designs Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00
evidence feat: verify live KeyCape custody and preserve versions on resume 2026-09-09 02:18:12 +02:00
apps-pg.md Finish RPF-WP-0019 apps-pg controls and recovery 2026-08-20 22:58:45 +02:00
argocd-gitops.md Document recovered ESO lanes and recognize explicit invalid-token responses 2026-09-05 18:51:40 +02:00
audit-core-database-lease-approval.example.json Harden WP-0024 recovery execution gates 2026-08-22 14:00:18 +02:00
audit-core-database-lease-recovery.md Correct WP-0024 lease selection contract 2026-08-22 14:46:12 +02:00
audit-core-whitehat-e2-credential-projection.md Add attended Whitehat E2 credential projection 2026-08-22 12:59:38 +02:00
backup-credential-recovery.md Record verified Forgejo Scaleway backup and recovery 2026-09-06 01:03:02 +02:00
backup-provider-coverage.md Verify full and essentials recovery and implement bounded retention tooling 2026-09-06 11:10:50 +02:00
backup-storage-tiers.md Verify full and essentials recovery and implement bounded retention tooling 2026-09-06 11:10:50 +02:00
cnpg-option-a-backup.md Include user-engine in offsite CNPG backups 2026-07-30 00:05:58 +02:00
coding-agent-openbao-identity.md Finish coding-agent high-risk boundary coverage 2026-08-22 10:03:54 +02:00
consumption-mode-enforcement.md Finish RAILIANCE-WP-0017 consumption-mode enforcement 2026-08-15 14:56:02 +02:00
credential-broker.md Adopt canonical flex-auth credential checks 2026-08-23 14:03:40 +02:00
credential-change-approval.md Close CCR drift and high-risk policy gaps 2026-08-21 01:29:28 +02:00
credential-lane-lifecycle-runbook.md Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision 2026-08-11 22:41:30 +02:00
custody-projection-contract.example.json Add versioned ephemeral custody lifecycle 2026-08-22 21:56:42 +02:00
ephemeral-custody-lifecycle.md Add versioned ephemeral custody lifecycle 2026-08-22 21:56:42 +02:00
eso-auth-recovery.md Document recovered ESO lanes and recognize explicit invalid-token responses 2026-09-05 18:51:40 +02:00
forgejo-backup.md Verify Scaleway primary recovery and distinguish secondary backup coverage 2026-09-06 00:34:43 +02:00
forgejo-package-prune.md Add failure-safe cluster image capture hook 2026-09-05 10:04:38 +02:00
keycape-exposure-rotation-approval.example.json Record final KeyCape recovery receipt 2026-08-23 14:51:50 +02:00
keycape-live-secret-exposure-recovery.md Record final KeyCape recovery receipt 2026-08-23 14:51:50 +02:00
net-kingdom-credential-custody-contract.md Draft NetKingdom credential custody contract 2026-08-23 21:48:29 +02:00
openbao-approved-automation-delegation.md Close delegated prod applier pilot 2026-07-01 23:34:13 +02:00
openbao-emergency-drill-evidence.example.json Add OpenBao emergency drill evidence validator 2026-06-02 00:08:17 +02:00
openbao-open-questions-session.md Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
openbao-public-listener-transition.md feat(RAILIANCE-WP-0027): add contained callback role update 2026-08-23 14:37:01 +02:00
openbao-reboot-snapshot-receipt.example.json Harden WP-0024 recovery execution gates 2026-08-22 14:00:18 +02:00
openbao-restore-drill-evidence.example.json Add OpenBao restore evidence validator 2026-06-01 23:57:00 +02:00
openbao.md feat(RAILIANCE-WP-0027): prepare operator-only OpenBao access 2026-08-23 12:50:23 +02:00
placement-policy.md Implement S3 service assurance and admission checks 2026-09-05 11:43:55 +02:00
platform-ownership-handoffs.md Review blocked platform obligations and archive completed ESO recovery 2026-09-05 21:16:53 +02:00
postgresql-ha.md Finish architecture-cleanup RAILIANCE-WP-0016 T05 2026-08-15 14:43:44 +02:00
put-backup-object-storage.md docs: how to add APPLICATION_ID for the backup bucket policy 2026-08-14 19:52:08 +02:00
railiance01-coordinated-reboot.md Harden WP-0024 recovery execution gates 2026-08-22 14:00:18 +02:00
rapp-credential-lane-binding.md retarget: CCR-2026-0012 is the general backup object-store lane 2026-08-14 19:19:56 +02:00
rapp-openbao-boundary.md Document rapp-openbao compatibility handoff 2026-07-26 10:39:40 +02:00
rapp-openbao-compatibility-handoff.md Document rapp-openbao compatibility handoff 2026-07-26 10:39:40 +02:00
rapp-platform-service-pattern.md Close RAILIANCE-WP-0015-T06 rapp credential-lane binding 2026-08-14 00:47:28 +02:00
rapp-postgres-boundary.md Broker audit-core dynamic database credentials 2026-08-10 19:36:30 +02:00
reuse-surface-runtime-secrets-rotation-runbook.md Add reuse-surface secrets rotation runbook (RAILIANCE-WP-0011-T04) 2026-07-08 00:01:21 +02:00
s3-consumer-interfaces.md Implement S3 service assurance and admission checks 2026-09-05 11:43:55 +02:00
service-assurance.md Validate OpenBao snapshot evidence and record assurance closure gates 2026-09-06 15:24:58 +02:00
tenancy-posture.md Finish RPF-WP-0019 apps-pg controls and recovery 2026-08-20 22:58:45 +02:00
WH-ENG-20260822-AUDIT-E2-03-custody-contract.json Approve audit E2 third custody contract 2026-08-22 23:30:07 +02:00
whynot-design-npm-publish-handoff.md Update Gitea prose to Forgejo; place forge; record ArgoCD as an open decision 2026-08-11 22:41:30 +02:00
workload-kv-access-lanes.md Declare the security layer, and repair the placement admission check 2026-09-09 23:27:14 +02:00
wp0024-owner-review-interface.md Add direct WP-0024 load driver handoff 2026-08-22 16:17:03 +02:00