reef-railiance/declarations/reef.yaml
2026-08-18 12:53:39 +02:00

39 lines
1.3 KiB
YAML

kind: substrate-reef
reef_id: reef-railiance
repo: reef-railiance
ownership_repo: railiance-infra
substrate_kind: server-group
lifecycle_state: active
criticality: high
primary_rail: rail-kubernetes
hosted_rails:
- rail-kubernetes
- rail-knative
current_members:
- Railiance01
source_documents:
- repo: railiance-master
path: docs/reef-first-wave-rollout.md
- repo: railiance-master
path: docs/reef-substrate-model.md
- repo: railiance-infra
path: docs/reef-first-wave-source-map.md
compatibility_notes:
- Railiance01 is the first current member of the grouped home reef.
- Additional Railiance home servers should join this reef when they share the same substrate boundary.
- Split the grouped reef later if member lifecycle, access, or workload-placement policy diverges.
exposure:
posture: public
grants:
- port: 80
reason: Public HTTP ingress, ACME challenges, and HTTPS redirects for approved application hostnames
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra
- port: 443
reason: Public TLS ingress for approved application hostnames
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra
- port: 2224
reason: HostEurope Nydus provider agent required by the platform
approved_on: "2026-08-15"
residual_risk_owner: railiance-infra