kind: managed-workload-package repo_family: rapp rapp_id: rapp-canned-prompts repo: rapp-canned-prompts ownership_repo: canned-prompts contract_version: 1.0.0 readiness_state: verified workload_identity: name: canned-prompts package_type: manifest-managed-platform-service data_classification: internal criticality: medium primary_rail: rail-kubernetes supported_rails: - rail-kubernetes bound_reefs: - reef-railiance runtime_dependencies: - kubernetes-api - openbao-database-secrets-engine composition: purpose: >- Package and operate the canned-prompts hosted registry and index on Railiance. Format semantics, package validation, API compatibility, the schema and its migrations, and image publication remain owned by canned-prompts. PostgreSQL topology, database isolation, backups and credential issuance remain owned by rapp-postgres and the platform credential broker. member_repos: - repo: rapp-canned-prompts role: managed runtime package deployables: - canned-prompts upstream_components: - name: canned-prompts source: forgejo.coulomb.social/coulomb/canned-prompts # Published 2026-09-07 from canned-prompts service/Dockerfile, tag 0.1.5. # Pinned by digest rather than tag: a tag can be moved, and # live-image-digest-match would then pass against something that is no # longer what this repo reviewed. version: sha256:14c7b92f20d63f2e70ea17b0b45d3c483521fbbaf14ee5bc277fa541e10452e2 rollout_contract: default_mode: kubectl-server-side-apply smoke_contract: required: - state-health-ok - migration-at-head - external-secrets-ready - private-service-only - networkpolicies-present - live-image-digest-match rollback_contract: order: - previous-immutable-image-digest - apply-reviewed-git-revision source_documents: - repo: canned-prompts path: CannedPromptFormat.md - repo: canned-prompts path: service/README.md - repo: canned-prompts path: workplans/CANP-WP-0006-hosted-registry-service.md - repo: repo-manager path: docs/RailianceAppDeploymentGuide.md