docs: reef attribute refs and resource object workplan

Publish the operational reference convention (reef: and secret:
handles). Add a resource-control view of reef-railiance that excludes
S3. Open RESOURCE-WP-0006 for the five-facet inventory model.
This commit is contained in:
tegwick 2026-08-14 15:44:44 +02:00
parent 4b8fc909e6
commit 5b2435cb58
10 changed files with 395 additions and 1 deletions

View file

@ -149,7 +149,13 @@ resources and utilization; the booked financial fact remains authoritative in
10. **Avoid correlated failure silently.** Shared failure domains may be
intentional, but they and their compensating controls must be explicit.
11. **Credentials stay elsewhere.** Provider keys and billing credentials live
in approved secret-custody lanes, never in this repository.
in approved secret-custody lanes, never in this repository. Inventory
stores `secret:` handles only.
12. **Operating attributes stay on the reef.** Endpoints, buckets, member
lists, and kubeconfig paths are cited as `reef:` references
(`docs/operational-reference-convention.md`). This repository does not
operate the resource. Compute substrate: `reef-railiance`. Object-store
substrate for backup: `reef-storage`, not an add-on to the home reef.
## What it does not own