71 lines
2.2 KiB
Markdown
71 lines
2.2 KiB
Markdown
---
|
|
id: REEF-RAILIANCE-WP-0004
|
|
type: workplan
|
|
title: "File exposure grants; keep new binds private"
|
|
domain: financials
|
|
repo: reef-railiance
|
|
status: active
|
|
owner: codex
|
|
topic_slug: railiance
|
|
created: "2026-08-15"
|
|
updated: "2026-08-18"
|
|
related:
|
|
- RMASTER-WP-0023
|
|
- ADR-0008
|
|
- REEF-RAILIANCE-WP-0003
|
|
state_hub_workstream_id: "dff82d6f-11d5-466e-93ce-c9503ec43838"
|
|
---
|
|
|
|
# REEF-RAILIANCE-WP-0004 — exposure grants
|
|
|
|
Intake from `RMASTER-WP-0023-T05`. Snapshot:
|
|
`railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`.
|
|
|
|
## Goal
|
|
|
|
First live admission of the family rule. New binds stay `private` (or
|
|
`operator` only for a named admin path). Existing public surfaces get
|
|
named grants. Do not take down Forgejo, Coulomb Social, reuse-surface,
|
|
or Nydus. Do not re-public `6443`. Qonto stays private even if WP-0003
|
|
later writes `production-approved`.
|
|
|
|
## T01 — Add reef exposure grants
|
|
|
|
```task
|
|
id: REEF-RAILIANCE-WP-0004-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "52d14311-b1be-4d11-aa75-86042b8ba72b"
|
|
```
|
|
|
|
Add `exposure` to `declarations/reef.yaml` with substrate grants for the
|
|
80/443 DNS/Ingress surface and Nydus `2224`. Residual-risk owners as in
|
|
the snapshot.
|
|
|
|
**Done when:** the declaration validates and names those surfaces.
|
|
|
|
Completed 2026-08-18. `declarations/reef.yaml` now records the already-live
|
|
80/443 ingress surface and the Nydus 2224 exception with dated grants and
|
|
residual-risk ownership. The stale hand-maintained `bound_rapps` projection was
|
|
removed; the family validator derives it from rApp declarations.
|
|
|
|
## T02 — Route rapp grants
|
|
|
|
```task
|
|
id: REEF-RAILIANCE-WP-0004-T02
|
|
status: progress
|
|
priority: medium
|
|
state_hub_task_id: "02dadeaf-8d51-4199-9f54-5d704555b20d"
|
|
```
|
|
|
|
File or request grants on the owning declarations for
|
|
`forgejo.coulomb.social`, `app.coulomb.social`, and
|
|
`reuse.coulomb.social`. Layer repos may hold residual-risk ownership
|
|
until the rapps exist.
|
|
|
|
**Done when:** each snapshot hostname has a grant home.
|
|
|
|
2026-08-18: the newly approved `policy.coulomb.social` grant has a family home
|
|
in `rapp-policy-nexus`, and its production binding is recorded in
|
|
`bindings/rapps.yaml`. The three pre-existing snapshot hostnames still need
|
|
their eventual rApp/layer declaration homes, so this task remains in progress.
|