From 9ffeac2e92dc7207bb258b612c47adf121d3f1eb Mon Sep 17 00:00:00 2001 From: codex Date: Sun, 26 Jul 2026 13:34:56 +0200 Subject: [PATCH] Add Knative and Qonto admission evidence --- WORK-RECORDS.md | 7 ++ bindings/rails.yaml | 13 ++- bindings/rapps.yaml | 11 +- declarations/reef.yaml | 4 +- evidence/admission/rail-knative-baseline.json | 39 +++++++ .../admission/rail-kubernetes-baseline.json | 39 +++++++ schemas/admission-evidence-v1.schema.json | 59 ++++++++++ ...-knative-and-qonto-production-admission.md | 103 ++++++++++++++++++ 8 files changed, 270 insertions(+), 5 deletions(-) create mode 100644 evidence/admission/rail-knative-baseline.json create mode 100644 evidence/admission/rail-kubernetes-baseline.json create mode 100644 schemas/admission-evidence-v1.schema.json create mode 100644 workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index e8bb933..71bf7e6 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -9,7 +9,14 @@ | Kind | ID | Status | Lane | Source | | --- | --- | --- | --- | --- | | workplan | REEF-RAILIANCE-WP-0001 | finished | — | workplans/REEF-RAILIANCE-WP-0001-bootstrap-and-wave1-import.md | +| workplan | REEF-RAILIANCE-WP-0002 | active | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | | task | REEF-RAILIANCE-WP-0001-T01 | done | — | workplans/REEF-RAILIANCE-WP-0001-bootstrap-and-wave1-import.md | | task | REEF-RAILIANCE-WP-0001-T02 | done | — | workplans/REEF-RAILIANCE-WP-0001-bootstrap-and-wave1-import.md | | task | REEF-RAILIANCE-WP-0001-T03 | done | — | workplans/REEF-RAILIANCE-WP-0001-bootstrap-and-wave1-import.md | | task | REEF-RAILIANCE-WP-0001-T04 | done | — | workplans/REEF-RAILIANCE-WP-0001-bootstrap-and-wave1-import.md | +| task | REEF-RAILIANCE-WP-0002-T01 | done | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | +| task | REEF-RAILIANCE-WP-0002-T02 | progress | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | +| task | REEF-RAILIANCE-WP-0002-T03 | todo | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | +| task | REEF-RAILIANCE-WP-0002-T04 | todo | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | +| task | REEF-RAILIANCE-WP-0002-T05 | wait | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | +| task | REEF-RAILIANCE-WP-0002-T06 | todo | — | workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md | diff --git a/bindings/rails.yaml b/bindings/rails.yaml index f140d06..f158337 100644 --- a/bindings/rails.yaml +++ b/bindings/rails.yaml @@ -2,5 +2,16 @@ reef_id: reef-railiance hosted_rails: - rail_id: rail-kubernetes role: primary - status: active + readiness_state: declared + contract_version: 1.0.0 + evidence: + - evidence/admission/rail-kubernetes-baseline.json notes: First-wave default execution rail for the grouped Railiance home reef. + - rail_id: rail-knative + role: derived + readiness_state: declared + contract_version: 1.0.0 + base_rail: rail-kubernetes + evidence: + - evidence/admission/rail-knative-baseline.json + notes: Declared second-wave rail; not installed or production-approved. diff --git a/bindings/rapps.yaml b/bindings/rapps.yaml index d8df8c4..0c84a6c 100644 --- a/bindings/rapps.yaml +++ b/bindings/rapps.yaml @@ -1,5 +1,10 @@ reef_id: reef-railiance -bound_rapps: [] +bound_rapps: + - rapp_id: rapp-qonto + rail_id: rail-knative + readiness_state: declared + evidence: + - ../rapp-qonto/docs/security-and-reliability-gates.md notes: - - No grouped home-reef workload bindings are declared yet. - - Add `rapp` bindings here only when the substrate decision is explicit and source-backed. + - The Qonto binding is topology-only until admission evidence supports promotion. + - Add or promote bindings only when the substrate decision is explicit and source-backed. diff --git a/declarations/reef.yaml b/declarations/reef.yaml index 7f92ead..2df7741 100644 --- a/declarations/reef.yaml +++ b/declarations/reef.yaml @@ -8,7 +8,9 @@ criticality: high primary_rail: rail-kubernetes hosted_rails: - rail-kubernetes -bound_rapps: [] + - rail-knative +bound_rapps: + - rapp-qonto current_members: - Railiance01 source_documents: diff --git a/evidence/admission/rail-knative-baseline.json b/evidence/admission/rail-knative-baseline.json new file mode 100644 index 0000000..856d6ca --- /dev/null +++ b/evidence/admission/rail-knative-baseline.json @@ -0,0 +1,39 @@ +{ + "contract_version": "1.0.0", + "reef_id": "reef-railiance", + "subject": "rail-knative", + "readiness_state": "declared", + "checked_at": "2026-07-26T00:00:00Z", + "checks": { + "compatibility": { + "status": "pass", + "evidence": [ + "../rail-knative/declarations/rail.yaml", + "../rail-kubernetes/declarations/rail.yaml" + ], + "notes": "Declaration compatibility passes; runtime versions are not yet observed." + }, + "capacity": { + "status": "unknown", + "evidence": [], + "notes": "CPU, memory, pod, and control-plane headroom must be measured." + }, + "ingress": {"status": "unknown", "evidence": []}, + "network": {"status": "unknown", "evidence": []}, + "identity_and_secrets": {"status": "unknown", "evidence": []}, + "observability": {"status": "unknown", "evidence": []}, + "recovery": {"status": "unknown", "evidence": []}, + "failure_domain": { + "status": "unknown", + "evidence": [], + "notes": "Knative would share the current single-member Kubernetes reef." + } + }, + "residual_risks": [ + { + "risk": "Single server and shared control plane for a critical bank-connected workload", + "status": "open", + "owner": "railiance-infra" + } + ] +} diff --git a/evidence/admission/rail-kubernetes-baseline.json b/evidence/admission/rail-kubernetes-baseline.json new file mode 100644 index 0000000..d5c3bad --- /dev/null +++ b/evidence/admission/rail-kubernetes-baseline.json @@ -0,0 +1,39 @@ +{ + "contract_version": "1.0.0", + "reef_id": "reef-railiance", + "subject": "rail-kubernetes", + "readiness_state": "declared", + "checked_at": "2026-07-26T00:00:00Z", + "checks": { + "compatibility": { + "status": "pass", + "evidence": [ + "declarations/reef.yaml", + "bindings/rails.yaml", + "../rail-kubernetes/declarations/rail.yaml" + ] + }, + "capacity": { + "status": "unknown", + "evidence": [], + "notes": "Automated capacity and headroom probe not yet recorded." + }, + "ingress": {"status": "unknown", "evidence": []}, + "network": {"status": "unknown", "evidence": []}, + "identity_and_secrets": {"status": "unknown", "evidence": []}, + "observability": {"status": "unknown", "evidence": []}, + "recovery": {"status": "unknown", "evidence": []}, + "failure_domain": { + "status": "unknown", + "evidence": [], + "notes": "Current grouped reef has one declared member." + } + }, + "residual_risks": [ + { + "risk": "Single declared server and shared Kubernetes control plane", + "status": "open", + "owner": "railiance-infra" + } + ] +} diff --git a/schemas/admission-evidence-v1.schema.json b/schemas/admission-evidence-v1.schema.json new file mode 100644 index 0000000..65eeb30 --- /dev/null +++ b/schemas/admission-evidence-v1.schema.json @@ -0,0 +1,59 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://railiance.dev/schemas/reef-admission-evidence-v1.schema.json", + "type": "object", + "additionalProperties": false, + "required": [ + "contract_version", + "reef_id", + "subject", + "readiness_state", + "checked_at", + "checks", + "residual_risks" + ], + "properties": { + "contract_version": {"const": "1.0.0"}, + "reef_id": {"const": "reef-railiance"}, + "subject": {"type": "string", "pattern": "^(rail|rapp)-[a-z0-9-]+$"}, + "readiness_state": { + "enum": ["declared", "installed", "verified", "production-approved", "deprecated"] + }, + "checked_at": {"type": "string", "format": "date-time"}, + "checks": { + "type": "object", + "additionalProperties": { + "type": "object", + "required": ["status", "evidence"], + "properties": { + "status": {"enum": ["pass", "fail", "unknown", "not-applicable"]}, + "evidence": {"type": "array", "items": {"type": "string"}}, + "notes": {"type": "string"} + } + }, + "required": [ + "compatibility", + "capacity", + "ingress", + "network", + "identity_and_secrets", + "observability", + "recovery", + "failure_domain" + ] + }, + "residual_risks": { + "type": "array", + "items": { + "type": "object", + "required": ["risk", "status", "owner"], + "properties": { + "risk": {"type": "string"}, + "status": {"enum": ["open", "mitigated", "accepted"]}, + "owner": {"type": "string"}, + "decision": {"type": "string"} + } + } + } + } +} diff --git a/workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md b/workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md new file mode 100644 index 0000000..874b8ce --- /dev/null +++ b/workplans/REEF-RAILIANCE-WP-0002-knative-and-qonto-production-admission.md @@ -0,0 +1,103 @@ +--- +id: REEF-RAILIANCE-WP-0002 +type: workplan +title: "Admit rail-knative and rapp-qonto with production evidence" +domain: financials +repo: reef-railiance +status: active +owner: codex +topic_slug: railiance +created: "2026-07-26" +updated: "2026-07-26" +state_hub_workstream_id: "5b31c13e-ddc9-495f-8325-88fa770982c5" +--- + +# REEF-RAILIANCE-WP-0002 - Knative and Qonto production admission + +## Goal + +Host a derived `rail-knative` slice while keeping `rail-kubernetes` primary, +and bind `rapp-qonto` only through explicit readiness evidence. + +## T01 - Publish the admission schema and baseline + +```task +id: REEF-RAILIANCE-WP-0002-T01 +status: done +priority: high +state_hub_task_id: "a20cc59f-bb93-4d1b-bf46-0d67c2270b98" +``` + +Add declared, installed, verified, production-approved, and deprecated states +plus source-linked evidence requirements. + +2026-07-26: Added the admission schema and a baseline record for the existing +Kubernetes rail. The baseline intentionally records unresolved capacity, +recovery, and failure-domain evidence rather than inferring it from topology. + +## T02 - Collect the Knative substrate baseline + +```task +id: REEF-RAILIANCE-WP-0002-T02 +status: progress +priority: high +state_hub_task_id: "833f6246-23bc-43ac-802d-7595b18f77a2" +``` + +Collect Kubernetes version, capacity/headroom, ingress, DNS/TLS, network, +identity/secret delivery, observability, backup/restore, and maintenance +evidence before installation. + +## T03 - Install and verify the derived rail + +```task +id: REEF-RAILIANCE-WP-0002-T03 +status: todo +priority: high +state_hub_task_id: "ff070df6-8ffa-40e6-bbaa-2dcff20f64f2" +``` + +Install only after the baseline matches the derived rail prerequisites. Record +versioned smoke and rollback evidence. + +## T04 - Bind and verify rapp-qonto + +```task +id: REEF-RAILIANCE-WP-0002-T04 +status: progress +priority: high +state_hub_task_id: "485e757b-6519-4f2e-a678-d66ef14206f5" +``` + +Add the binding at `declared`, then promote it only from machine-readable +identity, egress, cold-start, audit, revocation, rollback, and dependency +failure evidence. + +2026-07-26: Added topology-only declared bindings for `rail-knative` and +`rapp-qonto`. Baseline evidence keeps unmeasured runtime checks `unknown`; no +installed, verified, or production-approved state is claimed. + +## T05 - Decide production residual risk + +```task +id: REEF-RAILIANCE-WP-0002-T05 +status: wait +priority: high +state_hub_task_id: "f1ac627d-1ec8-445b-acd9-a65eeb068d3c" +``` + +Reserve human interaction for explicit acceptance or mitigation of the +single-server/shared-control-plane failure domain. Automated evidence must be +complete first. + +## T06 - Automate evidence freshness and drift + +```task +id: REEF-RAILIANCE-WP-0002-T06 +status: todo +priority: medium +state_hub_task_id: "82685f27-575e-4956-8c46-433a2ab2b9ea" +``` + +Make probes idempotent and suitable for scheduled reconciliation. Expired or +failed evidence must prevent false production-ready state.