--- id: RMGR-WP-0006 type: workplan title: "Railiance managed-app wrapper setup" domain: infotech repo: repo-manager status: finished owner: grok topic_slug: infotech created: "2026-08-18" updated: "2026-08-18" parent_project: prj-state-hub-retirement related: - RMGR-WP-0004 state_hub_workstream_id: "0d6d2ebf-4b74-4908-995c-17b8987ede05" --- # Railiance managed-app wrapper setup ## Goal Give Repo Manager a governed path to set up `rapp-` repositories so ordinary applications (starting with `user-engine`) can run on Railiance as managed workloads: declared, packaged, bound to a rail and reef, and operable without copying charts into `railiance-apps`. This specializes `RMGR-WP-0004` scaffolding for the `rapp-*` family. It does not move family schemas out of `railiance-master`, and it does not operate the cluster. Practice and remaining work are structured in [`docs/RailianceAppDeploymentGuide.md`](../docs/RailianceAppDeploymentGuide.md). ## Record the wrapper best-practice guide ```task id: RMGR-WP-0006-T01 status: done priority: high state_hub_task_id: "cb1e2e4e-9aef-4669-89f6-86ea8512b7d2" ``` Survey live rails (`rail-kubernetes`, `rail-knative`), reefs (`reef-railiance`, `reef-storage`), existing rapps, and the `user-engine` / `rapp-user-engine` pair. Write `docs/RailianceAppDeploymentGuide.md` as the best-practice shape and the work breakdown for later scaffolder phases. **Result (2026-08-18):** guide written. Pilot target is `rapp-user-engine` (empty stub). Copy targets are `rapp-policy-nexus` and `rapp-openbao`, not drifted `rapp-qonto`. ## Bootstrap the user-engine wrapper to `declared` ```task id: RMGR-WP-0006-T02 status: done priority: high state_hub_task_id: "f0e53954-403a-4e2c-b39f-0bab00eed3cc" ``` Fill `rapp-user-engine` with the bootstrap baseline and a schema-valid `declarations/rapp.yaml` at `readiness_state: declared` (or `draft` if image/consumer pins are still missing). Follow the worked example in the guide. Validate with `railiance-master/tools/validate-family-declarations.py --root ..`. Do not place the rapp (`bound_reefs` stays empty) and do not set public exposure. **Result (2026-08-18):** `rapp-user-engine` has the bootstrap set and a schema-valid `declarations/rapp.yaml` at `declared`. Isolated family validation: `4 declaration(s) ok`. ## Generate the Kubernetes package skeleton ```task id: RMGR-WP-0006-T03 status: done priority: high state_hub_task_id: "3ba6828e-7514-4f4d-a1d3-54134e039f55" ``` Absorb `net-kingdom/sso-mfa/k8s/user-engine/` into `rapp-user-engine/manifests/` (or a Helm chart only if a rewrite is justified separately). Add Makefile `server-dry-run` / `deploy` / `verify-live` / `rollback DIGEST=…` and a runtime-contract doc. Leave a pointer in NetKingdom so there is one apply path. `make server-dry-run` must pass. No production apply in this task. Package type is `manifest-managed-platform-service` unless the rewrite to Helm is an explicit later decision. **Result (2026-08-18):** manifests absorbed, Makefile `render|server-dry-run|deploy|verify-live|rollback` added, NetKingdom README points here. `make server-dry-run` passes. Restore-drill is a separate target so completed Jobs are not reapplied. ## Draft platform handoffs ```task id: RMGR-WP-0006-T04 status: done priority: medium state_hub_task_id: "0c2846d9-5db2-4b97-becd-0367b5737188" ``` Draft the `rapp-postgres` consumer and secret-reference list for user-engine. Apply them only in the owning repos (`rapp-postgres`, `railiance-platform`) after those owners accept the draft. This repo records the request; it does not become the credential home. **Result (2026-08-18):** `docs/platform-handoffs.md` keeps the dedicated `user-engine-pg` Cluster and lists OpenBao/delivery/flex-auth references. No postgres consumer file is added. ## Implement `rmgr rapp` scaffolding ```task id: RMGR-WP-0006-T05 status: done priority: high state_hub_task_id: "6cf89776-ff31-4dd1-aa9a-39474fc387aa" ``` Turn P1–P4 from the guide into Repo Manager commands (`rapp init`, `rapp skeleton`, `rapp validate`) that are idempotent, secret-free, and refuse to invent rails, reefs, or package types. Pilot by regenerating the user-engine wrapper (or the next engine stub) without hand-editing the baseline files. Depends on the shape proven in T02–T03 and on `RMGR-WP-0004` scaffolding ownership. **Result (2026-08-18):** `rmgr rapp init|validate|pin-image` added. `init` refuses a `rapp-` workload name and refuses to overwrite an existing declaration. `validate` runs the family validator against an isolated sibling root so undeclared engine stubs do not fail the check. ## Residuals - `rapp-secrets-engine` and `rapp-tenant-engine` remain undeclared stubs; wrap them only after the user-engine path validates. - `rapp-vergabe-teilnahme` extraction stays a `railiance-apps` residual (ADR-0003). This workplan does not close that item. - Schema enum `helm-managed-application` would be a `railiance-master` change if the platform-service name proves misleading.