Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
1.7 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | quality_dor | quality_dor_note | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| STATE-WP-0088 | workplan | Accept the platform preflight signing lane in the State Hub API | infotech | state-hub | active | codex | infotech | 2026-09-05 | 2026-09-05 |
|
DoR-Ok | Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence. |
Wire and validate API-only delivery
id: STATE-WP-0088-T01
status: done
priority: high
Chart opt-in renamePreflight.enabled adds a required explicit Secret ref only
to the API container. Default disabled; no plaintext chart values or shared env
Secret ownership. Helm rendering proves MCP/migration exclusion. Existing
repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO.
Accept live signing and fenced rotation
id: STATE-WP-0088-T02
status: progress
priority: high
Fresh live flex-auth -> access-engine preflight returns exactly the
preflight_signing_unavailable blocker. Target is primary/railiance01,
namespace/release/deployment state-hub, current API SA state-hub and one replica.
After platform custody verification, enable the chart, prove API-only delivery,
all-replica key equality, health and non-mutating signed preflight. Then stop all
API replicas (including terminating pods), rotate with CAS through platform,
wait ESO, restart and prove predecessor invalidation and forward recovery.
Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md.
No repository rename is in scope. Live completion is pending attended OpenBao
OIDC/MFA; ambient session returned 403.