rapp-canned-prompts/SCOPE.md

56 lines
2.1 KiB
Markdown
Raw Normal View History

Package canned-prompts for Railiance Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills in the rapp shape. declarations/rapp.yaml declares a manifest-managed platform service owned by canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout, smoke and rollback contracts. The image pin says `pending-publication` rather than carrying a placeholder digest. The image builds and was verified locally (canned-prompts CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A placeholder shaped like a real digest would be worse than a sentinel: it could be mistaken for something deployable. manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the postgres client, external secrets from OpenBao, a migration Job, and the runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and default-deny plus runtime NetworkPolicies. Three choices worth stating. Credentials arrive as mounted files, never env vars — an env var holding a password is visible in kubectl describe, in crash dumps, and to anything that can read /proc. Migrations run as a Job rather than at start-up, so a schema rollback stays separate from a code rollback and replicas do not race. Liveness points at /healthz, which checks only that the process is up: pointing it at a database-dependent path would restart every replica during a database blip. Egress is PostgreSQL and DNS only. A package arrives by publish; the registry never reaches out, so it is given no path to. tools/smoke.sh checks what only the cluster can answer and calls canned-prompts' service/tools/smoke.py for health and migration head, rather than holding a second opinion about whether the service is healthy. RCP-WP-0002 carries the two operator actions that block a first rollout — publishing the image and provisioning database roles — and records per-publisher identity as a decision belonging upstream, which this repo must not paper over with cluster configuration implying finer control than exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 21:44:17 +02:00
# SCOPE
## One-liner
Package and operate the `canned-prompts` hosted registry and index on
Railiance, without moving product ownership into an operations repository.
## In Scope
- `declarations/rapp.yaml` — the managed-workload declaration: composition,
image pin, rollout, smoke and rollback contracts.
- `manifests/` — namespace, external secrets, migration Job, and the runtime
Deployment, Service, ServiceAccount and NetworkPolicies.
- `tools/smoke.sh` — deployment-level verification, delegating the
service-level half to `canned-prompts`.
- Rollout, rollback and the network posture.
## Out of Scope
- What a valid prompt package is, what any endpoint means, the schema and its
migrations, and image publication — all `canned-prompts`.
- PostgreSQL topology, isolation, backups, credential issuance — `rapp-postgres`
and the platform credential broker.
- Who may publish. The service's identity is a single shared token proving
"the operator"; per-publisher identity is an open question upstream, and this
repo must not imply finer control than exists.
## Current State
Publish the image, pin it by digest, and request the database RCP-WP-0002-T01 done. Published forgejo.coulomb.social/coulomb/canned-prompts:0.1.0 and pinned sha256:e0ded3c7fe25... in declarations/rapp.yaml and both manifests. Pinned by digest rather than tag: a tag can be moved, and live-image-digest-match would then pass against something that is no longer what this repo reviewed. Verified after the push by fetching the manifest back by digest rather than trusting the push output. readiness_state draft -> declared. Not deployed, so not `deployed`. T02 requested rather than performed. rapp-postgres now carries consumers/canned-prompts.yaml against its documented PostgresConsumer shape, and its agent has the request. `make provision-consumers`, which mints the OpenBao credentials, was deliberately not run: credential issuance belongs to that repo's operator, and running it from the consuming side would take a decision that is not this repo's, however available the script is. T03 and T04 move to wait behind it. Also corrected a check of my own: I briefly read the cluster list as lacking platform-pg-2 and suspected the manifests targeted a host that does not exist. That was my own truncated output. platform-pg-2 is present and healthy, and the postgres-client label matches what sbom-nexus actually carries in the cluster rather than only what its repo says. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-07 08:43:35 +02:00
**Declared.** The image is published and pinned by digest
(`sha256:e0ded3c7fe2548c910445deaa31ec42e84f129a92aa324841e231a53fee1f123`), the manifests parse, and
`readiness_state` is `declared`. Nothing is deployed yet.
Package canned-prompts for Railiance Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills in the rapp shape. declarations/rapp.yaml declares a manifest-managed platform service owned by canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout, smoke and rollback contracts. The image pin says `pending-publication` rather than carrying a placeholder digest. The image builds and was verified locally (canned-prompts CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A placeholder shaped like a real digest would be worse than a sentinel: it could be mistaken for something deployable. manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the postgres client, external secrets from OpenBao, a migration Job, and the runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and default-deny plus runtime NetworkPolicies. Three choices worth stating. Credentials arrive as mounted files, never env vars — an env var holding a password is visible in kubectl describe, in crash dumps, and to anything that can read /proc. Migrations run as a Job rather than at start-up, so a schema rollback stays separate from a code rollback and replicas do not race. Liveness points at /healthz, which checks only that the process is up: pointing it at a database-dependent path would restart every replica during a database blip. Egress is PostgreSQL and DNS only. A package arrives by publish; the registry never reaches out, so it is given no path to. tools/smoke.sh checks what only the cluster can answer and calls canned-prompts' service/tools/smoke.py for health and migration head, rather than holding a second opinion about whether the service is healthy. RCP-WP-0002 carries the two operator actions that block a first rollout — publishing the image and provisioning database roles — and records per-publisher identity as a decision belonging upstream, which this repo must not paper over with cluster configuration implying finer control than exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 21:44:17 +02:00
Publish the image, pin it by digest, and request the database RCP-WP-0002-T01 done. Published forgejo.coulomb.social/coulomb/canned-prompts:0.1.0 and pinned sha256:e0ded3c7fe25... in declarations/rapp.yaml and both manifests. Pinned by digest rather than tag: a tag can be moved, and live-image-digest-match would then pass against something that is no longer what this repo reviewed. Verified after the push by fetching the manifest back by digest rather than trusting the push output. readiness_state draft -> declared. Not deployed, so not `deployed`. T02 requested rather than performed. rapp-postgres now carries consumers/canned-prompts.yaml against its documented PostgresConsumer shape, and its agent has the request. `make provision-consumers`, which mints the OpenBao credentials, was deliberately not run: credential issuance belongs to that repo's operator, and running it from the consuming side would take a decision that is not this repo's, however available the script is. T03 and T04 move to wait behind it. Also corrected a check of my own: I briefly read the cluster list as lacking platform-pg-2 and suspected the manifests targeted a host that does not exist. That was my own truncated output. platform-pg-2 is present and healthy, and the postgres-client label matches what sbom-nexus actually carries in the cluster rather than only what its repo says. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-07 08:43:35 +02:00
One thing blocks a first rollout: the database and its roles do not exist.
`rapp-postgres` has the request as `consumers/canned-prompts.yaml`; minting the
OpenBao credentials is its operator's step, not this repo's.
Package canned-prompts for Railiance Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills in the rapp shape. declarations/rapp.yaml declares a manifest-managed platform service owned by canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout, smoke and rollback contracts. The image pin says `pending-publication` rather than carrying a placeholder digest. The image builds and was verified locally (canned-prompts CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A placeholder shaped like a real digest would be worse than a sentinel: it could be mistaken for something deployable. manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the postgres client, external secrets from OpenBao, a migration Job, and the runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and default-deny plus runtime NetworkPolicies. Three choices worth stating. Credentials arrive as mounted files, never env vars — an env var holding a password is visible in kubectl describe, in crash dumps, and to anything that can read /proc. Migrations run as a Job rather than at start-up, so a schema rollback stays separate from a code rollback and replicas do not race. Liveness points at /healthz, which checks only that the process is up: pointing it at a database-dependent path would restart every replica during a database blip. Egress is PostgreSQL and DNS only. A package arrives by publish; the registry never reaches out, so it is given no path to. tools/smoke.sh checks what only the cluster can answer and calls canned-prompts' service/tools/smoke.py for health and migration head, rather than holding a second opinion about whether the service is healthy. RCP-WP-0002 carries the two operator actions that block a first rollout — publishing the image and provisioning database roles — and records per-publisher identity as a decision belonging upstream, which this repo must not paper over with cluster configuration implying finer control than exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 21:44:17 +02:00
Publish the image, pin it by digest, and request the database RCP-WP-0002-T01 done. Published forgejo.coulomb.social/coulomb/canned-prompts:0.1.0 and pinned sha256:e0ded3c7fe25... in declarations/rapp.yaml and both manifests. Pinned by digest rather than tag: a tag can be moved, and live-image-digest-match would then pass against something that is no longer what this repo reviewed. Verified after the push by fetching the manifest back by digest rather than trusting the push output. readiness_state draft -> declared. Not deployed, so not `deployed`. T02 requested rather than performed. rapp-postgres now carries consumers/canned-prompts.yaml against its documented PostgresConsumer shape, and its agent has the request. `make provision-consumers`, which mints the OpenBao credentials, was deliberately not run: credential issuance belongs to that repo's operator, and running it from the consuming side would take a decision that is not this repo's, however available the script is. T03 and T04 move to wait behind it. Also corrected a check of my own: I briefly read the cluster list as lacking platform-pg-2 and suspected the manifests targeted a host that does not exist. That was my own truncated output. platform-pg-2 is present and healthy, and the postgres-client label matches what sbom-nexus actually carries in the cluster rather than only what its repo says. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-07 08:43:35 +02:00
`workplans/RCP-WP-0002-first-deployment.md` carries the remaining sequence.
Package canned-prompts for Railiance Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills in the rapp shape. declarations/rapp.yaml declares a manifest-managed platform service owned by canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout, smoke and rollback contracts. The image pin says `pending-publication` rather than carrying a placeholder digest. The image builds and was verified locally (canned-prompts CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A placeholder shaped like a real digest would be worse than a sentinel: it could be mistaken for something deployable. manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the postgres client, external secrets from OpenBao, a migration Job, and the runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and default-deny plus runtime NetworkPolicies. Three choices worth stating. Credentials arrive as mounted files, never env vars — an env var holding a password is visible in kubectl describe, in crash dumps, and to anything that can read /proc. Migrations run as a Job rather than at start-up, so a schema rollback stays separate from a code rollback and replicas do not race. Liveness points at /healthz, which checks only that the process is up: pointing it at a database-dependent path would restart every replica during a database blip. Egress is PostgreSQL and DNS only. A package arrives by publish; the registry never reaches out, so it is given no path to. tools/smoke.sh checks what only the cluster can answer and calls canned-prompts' service/tools/smoke.py for health and migration head, rather than holding a second opinion about whether the service is healthy. RCP-WP-0002 carries the two operator actions that block a first rollout — publishing the image and provisioning database roles — and records per-publisher identity as a decision belonging upstream, which this repo must not paper over with cluster configuration implying finer control than exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 21:44:17 +02:00
## Verification
This repo builds nothing.
```bash
for f in manifests/*.yaml; do python3 -c "import yaml,sys; list(yaml.safe_load_all(open('$f')))"; done
bash -n tools/smoke.sh
NS=canned-prompts ./tools/smoke.sh # against a live deployment
```
## Getting Oriented
- Intent and boundaries: `INTENT.md`
- The declaration: `declarations/rapp.yaml`
- What the service is: `canned-prompts/service/README.md`
- Deployment guide: `repo-manager/docs/RailianceAppDeploymentGuide.md`