state-hub/workplans/STATE-WP-0088-preflight-signing-runtime-acceptance.md
tegwick e96ef197cf feat: add API-only preflight signing delivery and rotation acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
2026-09-05 16:39:02 +02:00

1.7 KiB

id type title domain repo status owner topic_slug created updated related quality_dor quality_dor_note
STATE-WP-0088 workplan Accept the platform preflight signing lane in the State Hub API infotech state-hub active codex infotech 2026-09-05 2026-09-05
RPF-WP-0035
STATE-WP-0085
FLEX-WP-0020
DoR-Ok Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence.

Wire and validate API-only delivery

id: STATE-WP-0088-T01
status: done
priority: high

Chart opt-in renamePreflight.enabled adds a required explicit Secret ref only to the API container. Default disabled; no plaintext chart values or shared env Secret ownership. Helm rendering proves MCP/migration exclusion. Existing repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO.

Accept live signing and fenced rotation

id: STATE-WP-0088-T02
status: progress
priority: high

Fresh live flex-auth -> access-engine preflight returns exactly the preflight_signing_unavailable blocker. Target is primary/railiance01, namespace/release/deployment state-hub, current API SA state-hub and one replica. After platform custody verification, enable the chart, prove API-only delivery, all-replica key equality, health and non-mutating signed preflight. Then stop all API replicas (including terminating pods), rotate with CAS through platform, wait ESO, restart and prove predecessor invalidation and forward recovery. Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md. No repository rename is in scope. Live completion is pending attended OpenBao OIDC/MFA; ambient session returned 403.