reef-railiance/workplans/REEF-RAILIANCE-WP-0004-exposure-grants.md
2026-08-21 01:35:28 +02:00

3.3 KiB

id type title domain repo status owner topic_slug created updated quality_dod quality_dod_at quality_dod_by quality_dod_note related state_hub_workstream_id
REEF-RAILIANCE-WP-0004 workplan File exposure grants; keep new binds private financials reef-railiance finished codex railiance 2026-08-15 2026-08-21 DoD-Ok 2026-08-21 codex Both tasks are done; declaration validation, tests, owner routing, and State Hub reconciliation passed.
RMASTER-WP-0023
ADR-0008
REEF-RAILIANCE-WP-0003
dff82d6f-11d5-466e-93ce-c9503ec43838

REEF-RAILIANCE-WP-0004 — exposure grants

Intake from RMASTER-WP-0023-T05. Snapshot: railiance-master/docs/evidence/reef-railiance-exposure-snapshot-2026-08-15.md.

Goal

First live admission of the family rule. New binds stay private (or operator only for a named admin path). Existing public surfaces get named grants. Do not take down Forgejo, Coulomb Social, reuse-surface, or Nydus. Do not re-public 6443. Qonto stays private even if WP-0003 later writes production-approved.

T01 — Add reef exposure grants

id: REEF-RAILIANCE-WP-0004-T01
status: done
priority: high
state_hub_task_id: "52d14311-b1be-4d11-aa75-86042b8ba72b"

Add exposure to declarations/reef.yaml with substrate grants for the 80/443 DNS/Ingress surface and Nydus 2224. Residual-risk owners as in the snapshot.

Done when: the declaration validates and names those surfaces.

Completed 2026-08-18. declarations/reef.yaml now records the already-live 80/443 ingress surface and the Nydus 2224 exception with dated grants and residual-risk ownership. The stale hand-maintained bound_rapps projection was removed; the family validator derives it from rApp declarations.

T02 — Route rapp grants

id: REEF-RAILIANCE-WP-0004-T02
status: done
priority: medium
state_hub_task_id: "02dadeaf-8d51-4199-9f54-5d704555b20d"

File or request grants on the owning declarations for forgejo.coulomb.social, app.coulomb.social, and reuse.coulomb.social. Layer repos may hold residual-risk ownership until the rapps exist.

Done when: each snapshot hostname has a grant home.

Completed 2026-08-21. The three pre-existing snapshot hostnames now have exact, dated grants in declarations/reef.yaml, which is their living substrate and public-DNS grant home while their family rApps do not yet exist. Residual-risk ownership remains with railiance-infra for forgejo.coulomb.social and with railiance-apps for app.coulomb.social and reuse.coulomb.social, matching the source snapshot. When those workloads gain rapp-* declarations, each public rApp must also carry its own binding grant before the reef-level grants can be treated as sufficient for that family declaration.

The handoff is routed to railiance-infra in State Hub message 2438f29d-f9e0-4e58-bbbe-cd8445a7ae14 and to railiance-apps in message 85f0a3c7-306c-4a58-ab3b-9c847d3b11b1.

The separately approved policy.coulomb.social grant already has its family home in rapp-policy-nexus, and its production binding is recorded in bindings/rapps.yaml.

Outcome

Finished 2026-08-21. Every public surface in the 2026-08-15 snapshot now has a living, source-backed grant: ports 80, 443, and 2224 plus the exact Forgejo, Coulomb Social, and reuse hostnames. New bindings remain private by default, and no grant was added for port 6443 or Qonto.