Add the §0 playbook and kubernetes-then-knative gate to the guide.
Implement rmgr rapp skeleton/wrap/place, draft postgres consumers,
and copy the fleet image workflow when missing.
user-engine already runs from net-kingdom/sso-mfa/k8s/user-engine.
The rapp absorbs those manifests (manifest-managed), keeps or
cutovers the dedicated CNPG cluster, and becomes the only apply home.
rail-knative is verified as a runtime but not production-approved.
Keep rapp-user-engine a single-repo pilot; a future grouped
rapp-netkingdom-identity is only legal if members share rollback fate.
Path A (rapp-*) is the target; Path B (create-overlay) is transitional;
Path C (railiance-apps S5) is how user-facing apps still ship. Fabric
is discovery only.
Record how rapp-* repos wrap first-party apps for Railiance, using
user-engine as the pilot. Opens RMGR-WP-0006 (T01 done) and includes
fix-consistency ID writeback for WP-0004/0005/0006.
ADR-008 was concurrently allocated by two authors on 2026-08-17: the
multi-tenancy framework (earlier provenance, draft-1 lineage) and the hub
authority model. The multi-tenancy ADR keeps 008; the hub authority model
becomes ADR-010.
Also corrects the 'read replica' phrasing in T01, superseded by ADR-010.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
T07 rebuild local instances as caches; T08 separate file-derived from
hub-native data and rescope STATE-WP-0068; T09 disposition the 28 orphans
(blocks T07); T10 assign one authoritative hub per record before the hub
split lands.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
RPF/RAPPS/RFORGE/RTELE assigned; four live plans migrated keeping running
numbers; six repos' conventions repointed. Executed centrally as an
authorized exception to ADR-007 decision 4, with the reason recorded.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Three prefixes across seven repos, each a concurrently-allocated number
line. Recommends the-custodian keeps CUST-WP-, RAIL-BS- needs a call, and
RAILIANCE- is retired outright since it names a family rather than a repo —
the same defect as PRJ-WP-. Execution of each rename belongs to a worker in
that repo per ADR-007 decision 4.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Implements ADR-007 decision 2: interim single-writer, target UUIDv5 derived
from the globally unique PREFIX-WP-NNNN so writeback is idempotent across
instances. T04 migrates the 758 files carrying hub identifiers. T06 covers
lifecycle protection including the C-15 task-status override.
RMGR-WP-0004 gains T08 enforcing ADR-007 identifier uniqueness, which gates
RMGR-WP-0005-T03 — deriving from a non-unique identifier would manufacture
UUID collisions.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Repo Manager takes ownership of the standards repositories must comply with
— flavor, required files, naming, classification, conformance checking —
and of governed scaffolding, per prj-state-hub-retirement decision
747011c6.
Hubs are registers; they do not scaffold or rewrite repo files. Extends
ADR-001 from data to behaviour. Receives the implementation retargeted out
of STATE-WP-0080.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Add dual-run flags/meter, harden task-status (idempotency, UUID, head,
push), State Hub adapter for PATCH /tasks and C-15/reconcile proxy, pilot
evidence, and finish RMGR-WP-0002.
Document how State Hub registers, resolves, reconciles, and mutates
repos; blueprint Stage B dual-run toward retirement; open workplan for
SH adapter writeback/reconcile without non-retirement refactors.
Implement observe/reconcile/update-task-status CLI path: workplan parse,
JSON projection index, git-backed task status writeback with correlation
events, and E2E pytest plus evidence artifacts. Finish foundation workplan.
Strengthen Intent and Scope for State Hub registration and HelixForge
boundaries; mark foundation workplan active. Classification synced via
register-from-classification (do not re-run statehub register bootstrap —
it collides with RMGR-WP-0001).