reef-railiance/workplans/REEF-RAILIANCE-WP-0004-exposure-grants.md
codex 9ab00f0dff chore: narrow Qonto gates and file exposure-grant workplan
WP-0003 only updates the binding. WP-0004 takes the RMASTER-WP-0023
grants. Production approval does not make Qonto public.
2026-08-15 20:52:04 +02:00

58 lines
1.5 KiB
Markdown

---
id: REEF-RAILIANCE-WP-0004
type: workplan
title: "File exposure grants; keep new binds private"
domain: financials
repo: reef-railiance
status: ready
owner: codex
topic_slug: railiance
created: "2026-08-15"
updated: "2026-08-15"
related:
- RMASTER-WP-0023
- ADR-0008
- REEF-RAILIANCE-WP-0003
---
# REEF-RAILIANCE-WP-0004 — exposure grants
Intake from `RMASTER-WP-0023-T05`. Snapshot:
`railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md`.
## Goal
First live admission of the family rule. New binds stay `private` (or
`operator` only for a named admin path). Existing public surfaces get
named grants. Do not take down Forgejo, Coulomb Social, reuse-surface,
or Nydus. Do not re-public `6443`. Qonto stays private even if WP-0003
later writes `production-approved`.
## T01 — Add reef exposure grants
```task
id: REEF-RAILIANCE-WP-0004-T01
status: todo
priority: high
```
Add `exposure` to `declarations/reef.yaml` with substrate grants for the
80/443 DNS/Ingress surface and Nydus `2224`. Residual-risk owners as in
the snapshot.
**Done when:** the declaration validates and names those surfaces.
## T02 — Route rapp grants
```task
id: REEF-RAILIANCE-WP-0004-T02
status: todo
priority: medium
```
File or request grants on the owning declarations for
`forgejo.coulomb.social`, `app.coulomb.social`, and
`reuse.coulomb.social`. Layer repos may hold residual-risk ownership
until the rapps exist.
**Done when:** each snapshot hostname has a grant home.