3.3 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | quality_dod | quality_dod_at | quality_dod_by | quality_dod_note | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| REEF-RAILIANCE-WP-0004 | workplan | File exposure grants; keep new binds private | financials | reef-railiance | finished | codex | railiance | 2026-08-15 | 2026-08-21 | DoD-Ok | 2026-08-21 | codex | Both tasks are done; declaration validation, tests, owner routing, and State Hub reconciliation passed. |
|
dff82d6f-11d5-466e-93ce-c9503ec43838 |
REEF-RAILIANCE-WP-0004 — exposure grants
Intake from RMASTER-WP-0023-T05. Snapshot:
railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md.
Goal
First live admission of the family rule. New binds stay private (or
operator only for a named admin path). Existing public surfaces get
named grants. Do not take down Forgejo, Coulomb Social, reuse-surface,
or Nydus. Do not re-public 6443. Qonto stays private even if WP-0003
later writes production-approved.
T01 — Add reef exposure grants
id: REEF-RAILIANCE-WP-0004-T01
status: done
priority: high
state_hub_task_id: "52d14311-b1be-4d11-aa75-86042b8ba72b"
Add exposure to declarations/reef.yaml with substrate grants for the
80/443 DNS/Ingress surface and Nydus 2224. Residual-risk owners as in
the snapshot.
Done when: the declaration validates and names those surfaces.
Completed 2026-08-18. declarations/reef.yaml now records the already-live
80/443 ingress surface and the Nydus 2224 exception with dated grants and
residual-risk ownership. The stale hand-maintained bound_rapps projection was
removed; the family validator derives it from rApp declarations.
T02 — Route rapp grants
id: REEF-RAILIANCE-WP-0004-T02
status: done
priority: medium
state_hub_task_id: "02dadeaf-8d51-4199-9f54-5d704555b20d"
File or request grants on the owning declarations for
forgejo.coulomb.social, app.coulomb.social, and
reuse.coulomb.social. Layer repos may hold residual-risk ownership
until the rapps exist.
Done when: each snapshot hostname has a grant home.
Completed 2026-08-21. The three pre-existing snapshot hostnames now have exact,
dated grants in declarations/reef.yaml, which is their living substrate and
public-DNS grant home while their family rApps do not yet exist. Residual-risk
ownership remains with railiance-infra for forgejo.coulomb.social and with
railiance-apps for app.coulomb.social and reuse.coulomb.social, matching
the source snapshot. When those workloads gain rapp-* declarations, each
public rApp must also carry its own binding grant before the reef-level grants
can be treated as sufficient for that family declaration.
The handoff is routed to railiance-infra in State Hub message
2438f29d-f9e0-4e58-bbbe-cd8445a7ae14 and to railiance-apps in message
85f0a3c7-306c-4a58-ab3b-9c847d3b11b1.
The separately approved policy.coulomb.social grant already has its family
home in rapp-policy-nexus, and its production binding is recorded in
bindings/rapps.yaml.
Outcome
Finished 2026-08-21. Every public surface in the 2026-08-15 snapshot now has a living, source-backed grant: ports 80, 443, and 2224 plus the exact Forgejo, Coulomb Social, and reuse hostnames. New bindings remain private by default, and no grant was added for port 6443 or Qonto.