state-hub/workplans/STATE-WP-0088-preflight-signing-runtime-acceptance.md
tegwick 29428bb304
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Close live preflight signing and rotation acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 18:11:41 +02:00

71 lines
3 KiB
Markdown

---
id: STATE-WP-0088
type: workplan
title: "Accept the platform preflight signing lane in the State Hub API"
domain: infotech
repo: state-hub
status: finished
owner: codex
topic_slug: infotech
created: "2026-09-05"
updated: "2026-09-05"
related:
- RPF-WP-0035
- STATE-WP-0085
- FLEX-WP-0020
quality_dod: DoD-Ok
quality_dod_note: "Live API-only signing and fenced CAS rotation accepted; predecessor signature denial and recovered primary health evidenced. No residual implementation work."
quality_dor: DoR-Ok
quality_dor_note: "Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence."
state_hub_workstream_id: "22f2d7dc-5766-5b09-9f18-12abd4b5512b"
---
## Wire and validate API-only delivery
```task
id: STATE-WP-0088-T01
status: done
priority: high
state_hub_task_id: "1d6a3deb-588c-5b3f-a334-8ab5ff9a8ee6"
```
Chart opt-in `renamePreflight.enabled` adds a required explicit Secret ref only
to the API container. Default disabled; no plaintext chart values or shared env
Secret ownership. Helm rendering proves MCP/migration exclusion. Existing
repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO.
## Accept live signing and fenced rotation
```task
id: STATE-WP-0088-T02
status: done
priority: high
state_hub_task_id: "55b32d0d-d30a-50c2-bae0-d6e3a357e6d1"
```
Fresh live flex-auth -> access-engine preflight returns exactly the
`preflight_signing_unavailable` blocker. Target is primary/railiance01,
namespace/release/deployment state-hub, current API SA state-hub and one replica.
After platform custody verification, enable the chart, prove API-only delivery,
all-replica key equality, health and non-mutating signed preflight. Then stop all
API replicas (including terminating pods), rotate with CAS through platform,
wait ESO, restart and prove predecessor invalidation and forward recovery.
Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md.
No repository rename is in scope. Live completion is pending attended OpenBao
OIDC/MFA; ambient session returned 403.
Completed 2026-09-05 under the user's instruction to lead activation from
railiance-platform. CCR-2026-0015 is active. Production chart commit `49e3182`
was fetched from Forge into ephemeral deployment storage; server dry-run changed
only the API Deployment. Helm revision 59 retained image `main-cdff3b7`.
One API replica matched the ESO key and signed preflight passed with zero
blockers. Every API pod then stopped; platform rotated CAS 1 to KV version 2;
ESO refreshed and one API replica recovered. New preflight passed, predecessor
failed specifically by signature, and primary health passed. MCP and shared env
Secret excluded from signing delivery. No repository rename executed.
Evidence is owned by platform:
`railiance-platform/docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`.
Protected predecessor fixture removed after verification. No residual scope;
the consuming FLEX-WP-0020 cutover remains separately governed.