rapp-canned-prompts/workplans/RCP-WP-0001-statehub-bootstrap.md
tegwick 5a0f4cb5c8 Package canned-prompts for Railiance
Registers the repo with State Hub (agents / practice, prefix RCP-WP) and fills
in the rapp shape.

declarations/rapp.yaml declares a manifest-managed platform service owned by
canned-prompts, bound to rail-kubernetes and reef-railiance, with rollout,
smoke and rollback contracts.

The image pin says `pending-publication` rather than carrying a placeholder
digest. The image builds and was verified locally (canned-prompts
CANP-WP-0006-T06) but has never been pushed, so no registry digest exists. A
placeholder shaped like a real digest would be worse than a sentinel: it could
be mistaken for something deployable.

manifests/ follows the rapp-sbom-nexus shape: namespace labelled for the
postgres client, external secrets from OpenBao, a migration Job, and the
runtime Deployment with a ClusterIP-only Service, dedicated ServiceAccount and
default-deny plus runtime NetworkPolicies.

Three choices worth stating. Credentials arrive as mounted files, never env
vars — an env var holding a password is visible in kubectl describe, in crash
dumps, and to anything that can read /proc. Migrations run as a Job rather than
at start-up, so a schema rollback stays separate from a code rollback and
replicas do not race. Liveness points at /healthz, which checks only that the
process is up: pointing it at a database-dependent path would restart every
replica during a database blip.

Egress is PostgreSQL and DNS only. A package arrives by publish; the registry
never reaches out, so it is given no path to.

tools/smoke.sh checks what only the cluster can answer and calls
canned-prompts' service/tools/smoke.py for health and migration head, rather
than holding a second opinion about whether the service is healthy.

RCP-WP-0002 carries the two operator actions that block a first rollout —
publishing the image and provisioning database roles — and records
per-publisher identity as a decision belonging upstream, which this repo must
not paper over with cluster configuration implying finer control than exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 388925@bnt-lap001
Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 21:44:17 +02:00

1.8 KiB

id type title domain repo status owner topic_slug created updated
RCP-WP-0001 workplan Bootstrap State Hub integration agents rapp-canned-prompts finished codex practice 2026-09-06 2026-09-06

Bootstrap State Hub integration

Package and operate the canned-prompts hosted registry and index on Railiance, without moving product ownership out of canned-prompts.

Review Generated Integration Files

id: RCP-WP-0001-T01
status: done
priority: high

Review INTENT.md, SCOPE.md, AGENTS.md, and .custodian-brief.md. Replace generated placeholders with repo-specific facts where needed.

Done: INTENT.md written to the rapp shape — what this repo decides, and what it explicitly does not. .repo-classification.yaml added (tooling / agents, validated against the canon allowed-values). The unresolved {CREDENTIAL_ROUTING} token the generator leaves behind was removed; it is a template defect already reported to state-hub.

Verify Local Developer Workflow

id: RCP-WP-0001-T02
status: done
priority: high

Identify the repo's install, test, lint, build, and run commands. Add or refine those commands in the agent instructions so future coding sessions can verify changes confidently.

Done. This repo builds nothing: it packages an image built in canned-prompts. Verification is tools/smoke.sh against a live deployment, plus YAML parse checks over manifests/. Recorded in SCOPE.md.

Seed First Real Workplan

id: RCP-WP-0001-T03
status: done
priority: medium

Done: workplans/RCP-WP-0002-first-deployment.md.

Create the first implementation workplan for the repository's most important next change. After workplan file updates, run the sync locally from this repo checkout:

statehub fix-consistency