reef-railiance/workplans/REEF-RAILIANCE-WP-0004-exposure-grants.md
codex 9ab00f0dff chore: narrow Qonto gates and file exposure-grant workplan
WP-0003 only updates the binding. WP-0004 takes the RMASTER-WP-0023
grants. Production approval does not make Qonto public.
2026-08-15 20:52:04 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated related
REEF-RAILIANCE-WP-0004 workplan File exposure grants; keep new binds private financials reef-railiance ready codex railiance 2026-08-15 2026-08-15
RMASTER-WP-0023
ADR-0008
REEF-RAILIANCE-WP-0003

REEF-RAILIANCE-WP-0004 — exposure grants

Intake from RMASTER-WP-0023-T05. Snapshot: railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md.

Goal

First live admission of the family rule. New binds stay private (or operator only for a named admin path). Existing public surfaces get named grants. Do not take down Forgejo, Coulomb Social, reuse-surface, or Nydus. Do not re-public 6443. Qonto stays private even if WP-0003 later writes production-approved.

T01 — Add reef exposure grants

id: REEF-RAILIANCE-WP-0004-T01
status: todo
priority: high

Add exposure to declarations/reef.yaml with substrate grants for the 80/443 DNS/Ingress surface and Nydus 2224. Residual-risk owners as in the snapshot.

Done when: the declaration validates and names those surfaces.

T02 — Route rapp grants

id: REEF-RAILIANCE-WP-0004-T02
status: todo
priority: medium

File or request grants on the owning declarations for forgejo.coulomb.social, app.coulomb.social, and reuse.coulomb.social. Layer repos may hold residual-risk ownership until the rapps exist.

Done when: each snapshot hostname has a grant home.