Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
3.5 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | quality_dod | quality_dod_note | quality_dor | quality_dor_note | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| STATE-WP-0088 | workplan | Accept the platform preflight signing lane in the State Hub API | infotech | state-hub | finished | codex | infotech | 2026-09-05 | 2026-09-05 |
|
DoD-Ok | Live API-only signing and fenced CAS rotation accepted; predecessor signature denial and recovered primary health evidenced. No residual implementation work. | DoR-Ok | Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence. | 22f2d7dc-5766-5b09-9f18-12abd4b5512b |
Wire and validate API-only delivery
id: STATE-WP-0088-T01
status: done
priority: high
state_hub_task_id: "1d6a3deb-588c-5b3f-a334-8ab5ff9a8ee6"
Chart opt-in renamePreflight.enabled adds a required explicit Secret ref only
to the API container. Default disabled; no plaintext chart values or shared env
Secret ownership. Helm rendering proves MCP/migration exclusion. Existing
repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO.
Accept live signing and fenced rotation
id: STATE-WP-0088-T02
status: done
priority: high
state_hub_task_id: "55b32d0d-d30a-50c2-bae0-d6e3a357e6d1"
Before activation, the live flex-auth -> access-engine preflight returned
exactly the preflight_signing_unavailable blocker. Target is primary/railiance01,
namespace/release/deployment state-hub, current API SA state-hub and one replica.
After platform custody verification, enable the chart, prove API-only delivery,
all-replica key equality, health and non-mutating signed preflight. Then stop all
API replicas (including terminating pods), rotate with CAS through platform,
wait ESO, restart and prove predecessor invalidation and forward recovery.
Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md.
No repository rename is in scope. Initial activation required attended OpenBao
OIDC/MFA because the ambient session returned 403; completion is recorded below.
Completed 2026-09-05 under the user's instruction to lead activation from
railiance-platform. CCR-2026-0015 is active. Production chart commit 49e3182
was fetched from Forge into ephemeral deployment storage; server dry-run changed
only the API Deployment. Helm revision 59 retained image main-cdff3b7.
One API replica matched the ESO key and signed preflight passed with zero
blockers. Every API pod then stopped; platform rotated CAS 1 to KV version 2;
ESO refreshed and one API replica recovered. New preflight passed, predecessor
failed specifically by signature, and primary health passed. MCP and shared env
Secret excluded from signing delivery. No repository rename executed.
Evidence is owned by platform:
railiance-platform/docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json.
Protected predecessor fixture removed after verification. No residual scope;
the consuming FLEX-WP-0020 cutover remains separately governed.
Independent review reverified the new API replica against the materialized key
and the predecessor captured before rotation. The verifier now rejects expiry
as sufficient rotation evidence and also requires primary/railiance01 health.
Receipt: docs/evidence/STATE-WP-0088-independent-signing-verification-20260905.json.
The private predecessor token was removed after this verification.