Admit Policy Nexus public binding

This commit is contained in:
codex 2026-08-18 12:53:39 +02:00
parent b09b66330f
commit f3735a56ae
4 changed files with 41 additions and 9 deletions

View file

@ -9,8 +9,6 @@ primary_rail: rail-kubernetes
hosted_rails:
- rail-kubernetes
- rail-knative
bound_rapps:
- rapp-qonto
current_members:
- Railiance01
source_documents:
@ -24,3 +22,18 @@ compatibility_notes:
- Railiance01 is the first current member of the grouped home reef.
- Additional Railiance home servers should join this reef when they share the same substrate boundary.
- Split the grouped reef later if member lifecycle, access, or workload-placement policy diverges.
exposure:
posture: public
grants:
- port: 80
reason: Public HTTP ingress, ACME challenges, and HTTPS redirects for approved application hostnames
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra
- port: 443
reason: Public TLS ingress for approved application hostnames
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra
- port: 2224
reason: HostEurope Nydus provider agent required by the platform
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra