--- id: STATE-WP-0088 type: workplan title: "Accept the platform preflight signing lane in the State Hub API" domain: infotech repo: state-hub status: active owner: codex topic_slug: infotech created: "2026-09-05" updated: "2026-09-05" related: - RPF-WP-0035 - STATE-WP-0085 - FLEX-WP-0020 quality_dor: DoR-Ok quality_dor_note: "Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence." --- ## Wire and validate API-only delivery ```task id: STATE-WP-0088-T01 status: done priority: high ``` Chart opt-in `renamePreflight.enabled` adds a required explicit Secret ref only to the API container. Default disabled; no plaintext chart values or shared env Secret ownership. Helm rendering proves MCP/migration exclusion. Existing repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO. ## Accept live signing and fenced rotation ```task id: STATE-WP-0088-T02 status: progress priority: high ``` Fresh live flex-auth -> access-engine preflight returns exactly the `preflight_signing_unavailable` blocker. Target is primary/railiance01, namespace/release/deployment state-hub, current API SA state-hub and one replica. After platform custody verification, enable the chart, prove API-only delivery, all-replica key equality, health and non-mutating signed preflight. Then stop all API replicas (including terminating pods), rotate with CAS through platform, wait ESO, restart and prove predecessor invalidation and forward recovery. Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md. No repository rename is in scope. Live completion is pending attended OpenBao OIDC/MFA; ambient session returned 403.