uptime 36m > lease TTL 30m, 21 samples, zero not-ready, zero query failures, zero kubelet readiness 503s, no restarts. The verdict now names the uptime it checked, so the claim can be audited rather than taken. T05 done upstream in canned-prompts 0.2.0 / migration 0003. DR-3 had already resolved the identity question as app-local accounts with OIDC demand-gated; research found that rather than my judgement supplying it. Left open deliberately: the NetworkPolicy ingress rule still admits any namespace. Publisher identity now gates writes so it is no longer the only control, and it should narrow once the legitimate callers are known — recorded rather than tightened on a guess. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
64 lines
2.1 KiB
YAML
64 lines
2.1 KiB
YAML
kind: managed-workload-package
|
|
repo_family: rapp
|
|
rapp_id: rapp-canned-prompts
|
|
repo: rapp-canned-prompts
|
|
ownership_repo: canned-prompts
|
|
contract_version: 1.0.0
|
|
readiness_state: verified
|
|
workload_identity:
|
|
name: canned-prompts
|
|
package_type: manifest-managed-platform-service
|
|
data_classification: internal
|
|
criticality: medium
|
|
primary_rail: rail-kubernetes
|
|
supported_rails:
|
|
- rail-kubernetes
|
|
bound_reefs:
|
|
- reef-railiance
|
|
runtime_dependencies:
|
|
- kubernetes-api
|
|
- openbao-database-secrets-engine
|
|
composition:
|
|
purpose: >-
|
|
Package and operate the canned-prompts hosted registry and index on
|
|
Railiance. Format semantics, package validation, API compatibility, the
|
|
schema and its migrations, and image publication remain owned by
|
|
canned-prompts. PostgreSQL topology, database isolation, backups and
|
|
credential issuance remain owned by rapp-postgres and the platform
|
|
credential broker.
|
|
member_repos:
|
|
- repo: rapp-canned-prompts
|
|
role: managed runtime package
|
|
deployables:
|
|
- canned-prompts
|
|
upstream_components:
|
|
- name: canned-prompts
|
|
source: forgejo.coulomb.social/coulomb/canned-prompts
|
|
# Published 2026-09-07 from canned-prompts service/Dockerfile, tag 0.2.0.
|
|
# Pinned by digest rather than tag: a tag can be moved, and
|
|
# live-image-digest-match would then pass against something that is no
|
|
# longer what this repo reviewed.
|
|
version: sha256:d5de508ea66d3ad9e354f05ccb6f764bd3b01d290631558f0e866059e8a705a6
|
|
rollout_contract:
|
|
default_mode: kubectl-server-side-apply
|
|
smoke_contract:
|
|
required:
|
|
- state-health-ok
|
|
- migration-at-head
|
|
- external-secrets-ready
|
|
- private-service-only
|
|
- networkpolicies-present
|
|
- live-image-digest-match
|
|
rollback_contract:
|
|
order:
|
|
- previous-immutable-image-digest
|
|
- apply-reviewed-git-revision
|
|
source_documents:
|
|
- repo: canned-prompts
|
|
path: CannedPromptFormat.md
|
|
- repo: canned-prompts
|
|
path: service/README.md
|
|
- repo: canned-prompts
|
|
path: workplans/CANP-WP-0006-hosted-registry-service.md
|
|
- repo: repo-manager
|
|
path: docs/RailianceAppDeploymentGuide.md
|