Deliver production installation for standalone, server and agent roles #7

Open
opened 2026-10-01 12:11:16 -04:00 by ams-tech · 0 comments
ams-tech commented 2026-10-01 12:11:16 -04:00 (Migrated from github.com)

The LAN pilot uses explicitly prepared NixOS profiles and owner-run operations. It does not yet provide a supported product installation experience for a new device.

Build a reviewed installation and management flow for self-contained, server and agent roles. Use the LAN integration's identity/admission contracts and record exact installed revisions. Preserve the distinction between local operation and admission to an owner authority.

Acceptance:

  • Let the owner select the role, trust domain and existing/new authority explicitly; role changes must preserve or deliberately retire prior identity state.
  • Provide enrollment, owner approval, status, bounded renewal term/reapproval and revocation workflows with narrowly scoped service identities.
  • Package prerequisite checks, persistent service installation, encrypted-state requirements, backup and supported recovery procedures; ambiguous operations reconcile the original journal and operation ID.
  • Keep private keys on their custody devices and keep raw credentials/backup contents out of UI, logs and public reports.
  • Show term and credential expiry, blocked reasons and actionable recovery steps without claiming hardware or offline qualification.
  • Test installation, supported upgrades/restarts and role transitions on the documented production target profiles, including failure and retained-state behavior.

The current LAN work remains gated on real renewal, native acceptance, a full 24-hour unattended observation and deployment from reviewed merged revisions. This issue does not waive those gates or extend its deadline. Public DNS rollout is separate.

References: LAN closeout plan, SPIFFE/SPIRE next steps.

The LAN pilot uses explicitly prepared NixOS profiles and owner-run operations. It does not yet provide a supported product installation experience for a new device. Build a reviewed installation and management flow for self-contained, server and agent roles. Use the LAN integration's identity/admission contracts and record exact installed revisions. Preserve the distinction between local operation and admission to an owner authority. Acceptance: - Let the owner select the role, trust domain and existing/new authority explicitly; role changes must preserve or deliberately retire prior identity state. - Provide enrollment, owner approval, status, bounded renewal term/reapproval and revocation workflows with narrowly scoped service identities. - Package prerequisite checks, persistent service installation, encrypted-state requirements, backup and supported recovery procedures; ambiguous operations reconcile the original journal and operation ID. - Keep private keys on their custody devices and keep raw credentials/backup contents out of UI, logs and public reports. - Show term and credential expiry, blocked reasons and actionable recovery steps without claiming hardware or offline qualification. - Test installation, supported upgrades/restarts and role transitions on the documented production target profiles, including failure and retained-state behavior. The current LAN work remains gated on real renewal, native acceptance, a full 24-hour unattended observation and deployment from reviewed merged revisions. This issue does not waive those gates or extend its deadline. Public DNS rollout is separate. References: [LAN closeout plan](https://github.com/PseudoDesign/kaiba-infra/blob/codex/spiffe-spire-next-steps/docs/lan-closeout.md), [SPIFFE/SPIRE next steps](https://github.com/PseudoDesign/kaiba-infra/pull/6).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
kaiba/kaiba-infra#7
No description provided.