2.2 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| REEF-RAILIANCE-WP-0004 | workplan | File exposure grants; keep new binds private | financials | reef-railiance | active | codex | railiance | 2026-08-15 | 2026-08-18 |
|
dff82d6f-11d5-466e-93ce-c9503ec43838 |
REEF-RAILIANCE-WP-0004 — exposure grants
Intake from RMASTER-WP-0023-T05. Snapshot:
railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md.
Goal
First live admission of the family rule. New binds stay private (or
operator only for a named admin path). Existing public surfaces get
named grants. Do not take down Forgejo, Coulomb Social, reuse-surface,
or Nydus. Do not re-public 6443. Qonto stays private even if WP-0003
later writes production-approved.
T01 — Add reef exposure grants
id: REEF-RAILIANCE-WP-0004-T01
status: done
priority: high
state_hub_task_id: "52d14311-b1be-4d11-aa75-86042b8ba72b"
Add exposure to declarations/reef.yaml with substrate grants for the
80/443 DNS/Ingress surface and Nydus 2224. Residual-risk owners as in
the snapshot.
Done when: the declaration validates and names those surfaces.
Completed 2026-08-18. declarations/reef.yaml now records the already-live
80/443 ingress surface and the Nydus 2224 exception with dated grants and
residual-risk ownership. The stale hand-maintained bound_rapps projection was
removed; the family validator derives it from rApp declarations.
T02 — Route rapp grants
id: REEF-RAILIANCE-WP-0004-T02
status: progress
priority: medium
state_hub_task_id: "02dadeaf-8d51-4199-9f54-5d704555b20d"
File or request grants on the owning declarations for
forgejo.coulomb.social, app.coulomb.social, and
reuse.coulomb.social. Layer repos may hold residual-risk ownership
until the rapps exist.
Done when: each snapshot hostname has a grant home.
2026-08-18: the newly approved policy.coulomb.social grant has a family home
in rapp-policy-nexus, and its production binding is recorded in
bindings/rapps.yaml. The three pre-existing snapshot hostnames still need
their eventual rApp/layer declaration homes, so this task remains in progress.