--- id: REEF-RAILIANCE-WP-0004 type: workplan title: "File exposure grants; keep new binds private" domain: financials repo: reef-railiance status: ready owner: codex topic_slug: railiance created: "2026-08-15" updated: "2026-08-15" related: - RMASTER-WP-0023 - ADR-0008 - REEF-RAILIANCE-WP-0003 --- # REEF-RAILIANCE-WP-0004 — exposure grants Intake from `RMASTER-WP-0023-T05`. Snapshot: `railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`. ## Goal First live admission of the family rule. New binds stay `private` (or `operator` only for a named admin path). Existing public surfaces get named grants. Do not take down Forgejo, Coulomb Social, reuse-surface, or Nydus. Do not re-public `6443`. Qonto stays private even if WP-0003 later writes `production-approved`. ## T01 — Add reef exposure grants ```task id: REEF-RAILIANCE-WP-0004-T01 status: todo priority: high ``` Add `exposure` to `declarations/reef.yaml` with substrate grants for the 80/443 DNS/Ingress surface and Nydus `2224`. Residual-risk owners as in the snapshot. **Done when:** the declaration validates and names those surfaces. ## T02 — Route rapp grants ```task id: REEF-RAILIANCE-WP-0004-T02 status: todo priority: medium ``` File or request grants on the owning declarations for `forgejo.coulomb.social`, `app.coulomb.social`, and `reuse.coulomb.social`. Layer repos may hold residual-risk ownership until the rapps exist. **Done when:** each snapshot hostname has a grant home.