--- id: REEF-RAILIANCE-WP-0004 type: workplan title: "File exposure grants; keep new binds private" domain: financials repo: reef-railiance status: finished owner: codex topic_slug: railiance created: "2026-08-15" updated: "2026-08-21" quality_dod: DoD-Ok quality_dod_at: "2026-08-21" quality_dod_by: codex quality_dod_note: "Both tasks are done; declaration validation, tests, owner routing, and State Hub reconciliation passed." related: - RMASTER-WP-0023 - ADR-0008 - REEF-RAILIANCE-WP-0003 state_hub_workstream_id: "dff82d6f-11d5-466e-93ce-c9503ec43838" --- # REEF-RAILIANCE-WP-0004 — exposure grants Intake from `RMASTER-WP-0023-T05`. Snapshot: `railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`. ## Goal First live admission of the family rule. New binds stay `private` (or `operator` only for a named admin path). Existing public surfaces get named grants. Do not take down Forgejo, Coulomb Social, reuse-surface, or Nydus. Do not re-public `6443`. Qonto stays private even if WP-0003 later writes `production-approved`. ## T01 — Add reef exposure grants ```task id: REEF-RAILIANCE-WP-0004-T01 status: done priority: high state_hub_task_id: "52d14311-b1be-4d11-aa75-86042b8ba72b" ``` Add `exposure` to `declarations/reef.yaml` with substrate grants for the 80/443 DNS/Ingress surface and Nydus `2224`. Residual-risk owners as in the snapshot. **Done when:** the declaration validates and names those surfaces. Completed 2026-08-18. `declarations/reef.yaml` now records the already-live 80/443 ingress surface and the Nydus 2224 exception with dated grants and residual-risk ownership. The stale hand-maintained `bound_rapps` projection was removed; the family validator derives it from rApp declarations. ## T02 — Route rapp grants ```task id: REEF-RAILIANCE-WP-0004-T02 status: done priority: medium state_hub_task_id: "02dadeaf-8d51-4199-9f54-5d704555b20d" ``` File or request grants on the owning declarations for `forgejo.coulomb.social`, `app.coulomb.social`, and `reuse.coulomb.social`. Layer repos may hold residual-risk ownership until the rapps exist. **Done when:** each snapshot hostname has a grant home. Completed 2026-08-21. The three pre-existing snapshot hostnames now have exact, dated grants in `declarations/reef.yaml`, which is their living substrate and public-DNS grant home while their family rApps do not yet exist. Residual-risk ownership remains with `railiance-infra` for `forgejo.coulomb.social` and with `railiance-apps` for `app.coulomb.social` and `reuse.coulomb.social`, matching the source snapshot. When those workloads gain `rapp-*` declarations, each public rApp must also carry its own binding grant before the reef-level grants can be treated as sufficient for that family declaration. The handoff is routed to `railiance-infra` in State Hub message `2438f29d-f9e0-4e58-bbbe-cd8445a7ae14` and to `railiance-apps` in message `85f0a3c7-306c-4a58-ab3b-9c847d3b11b1`. The separately approved `policy.coulomb.social` grant already has its family home in `rapp-policy-nexus`, and its production binding is recorded in `bindings/rapps.yaml`. ## Outcome Finished 2026-08-21. Every public surface in the 2026-08-15 snapshot now has a living, source-backed grant: ports 80, 443, and 2224 plus the exact Forgejo, Coulomb Social, and reuse hostnames. New bindings remain private by default, and no grant was added for port 6443 or Qonto.