Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills in the rapp shape. declarations/rapp.yaml declares a manifest-managed platform service owned by canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout, smoke and rollback contracts. The image pin says `pending-publication` rather than carrying a placeholder digest. The image builds and was verified locally (canned-prompts CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A placeholder shaped like a real digest would be worse than a sentinel: it could be mistaken for something deployable. manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the postgres client, external secrets from OpenBao, a migration Job, and the runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and default-deny plus runtime NetworkPolicies. Three choices worth stating. Credentials arrive as mounted files, never env vars — an env var holding a password is visible in kubectl describe, in crash dumps, and to anything that can read /proc. Migrations run as a Job rather than at start-up, so a schema rollback stays separate from a code rollback and replicas do not race. Liveness points at /healthz, which checks only that the process is up: pointing it at a database-dependent path would restart every replica during a database blip. Egress is PostgreSQL and DNS only. A package arrives by publish; the registry never reaches out, so it is given no path to. tools/smoke.sh checks what only the cluster can answer and calls canned-prompts' service/tools/smoke.py for health and migration head, rather than holding a second opinion about whether the service is healthy. RCP-WP-0002 carries the two operator actions that block a first rollout — publishing the image and provisioning database roles — and records per-publisher identity as a decision belonging upstream, which this repo must not paper over with cluster configuration implying finer control than exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
1.8 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated |
|---|---|---|---|---|---|---|---|---|---|
| RCP-WP-0001 | workplan | Bootstrap State Hub integration | agents | rapp-canned-prompts | finished | codex | practice | 2026-09-06 | 2026-09-06 |
Bootstrap State Hub integration
Package and operate the canned-prompts hosted registry and index on Railiance, without moving product ownership out of canned-prompts.
Review Generated Integration Files
id: RCP-WP-0001-T01
status: done
priority: high
Review INTENT.md, SCOPE.md, AGENTS.md, and .custodian-brief.md.
Replace generated placeholders with repo-specific facts where needed.
Done: INTENT.md written to the rapp shape — what this repo decides, and what
it explicitly does not. .repo-classification.yaml added (tooling / agents,
validated against the canon allowed-values). The unresolved
{CREDENTIAL_ROUTING} token the generator leaves behind was removed; it is a
template defect already reported to state-hub.
Verify Local Developer Workflow
id: RCP-WP-0001-T02
status: done
priority: high
Identify the repo's install, test, lint, build, and run commands. Add or refine those commands in the agent instructions so future coding sessions can verify changes confidently.
Done. This repo builds nothing: it packages an image built in canned-prompts.
Verification is tools/smoke.sh against a live deployment, plus YAML parse
checks over manifests/. Recorded in SCOPE.md.
Seed First Real Workplan
id: RCP-WP-0001-T03
status: done
priority: medium
Done: workplans/RCP-WP-0002-first-deployment.md.
Create the first implementation workplan for the repository's most important next change. After workplan file updates, run the sync locally from this repo checkout:
statehub fix-consistency