diff --git a/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md b/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md index a933f19..aa803a6 100644 --- a/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md +++ b/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md @@ -8,7 +8,7 @@ status: blocked owner: codex topic_slug: railiance created: "2026-07-26" -updated: "2026-07-29" +updated: "2026-08-08" state_hub_workstream_id: "c3f9fbfd-3db1-4387-8b65-7d53ba57138d" --- @@ -119,3 +119,15 @@ workplan is therefore `blocked` until either a second independent failure domain is implemented and drilled or the founder explicitly accepts single-node production availability risk for Qonto. The current binding remains accurately `verified`, not `production-approved`. + +2026-08-08 alignment: live inspection still reports one Ready node, which also +owns the control-plane and etcd roles. `railiance-cluster/RAIL-BS-WP-0007` now +owns the required three-server embedded-etcd topology, source-backed +node-to-reef failure-domain map, and machine-readable one-server-loss S2 +drill. `state-hub/CUST-WP-0038` is a downstream stateful consumer and does not +substitute for the Qonto gate. After the S2 drill passes, T04 closes only when +the Qonto live verification is rerun with fresh evidence while Railiance01 is +absent, proving the service path, restricted egress, identity/secret delivery, +dependency behavior, and restoration on the surviving cluster. The alternate +closure remains explicit founder acceptance of the single-node production +availability risk.