WIP: Document Kaiba LAN integration, staged deployment and qualification #6
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-infra!6
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/spiffe-spire-next-steps"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Document SPIFFE/SPIRE standalone, server and agent roles and the LAN rollout at
pilot.kaiba.pseudo.design: Ace runs the authority and DNS primary, Mako retains its admitted identity and DNS replica, and Malak remains an operator with its former authority fenced.The runbook records the completed disposable-NVMe physical campaign, original encrypted-storage acceptance, warm reboots, clean PoE cold start and Malak disconnection observation, with evidence hashes and explicit hardware limitations. It also tracks the remaining owner-approved thirty-day renewal term and final LAN acceptance.
Merged compatible host components now pass temporary NixOS test activation on Ace and Mako. The bounded staging helper pins both closures, requires a verified stopped-writer encrypted backup, preserves activation intents, compares retained authority history, and uses an independent restoration watchdog. Both hosts pass retained membership/key-state checks, fresh workload observations and all twelve DNS queries. Hydra and regular PostgreSQL remain unaffected. Boot profiles are unchanged; persistent installation is still pending.
Validation: fourteen staging tests, two native disposable watchdog rehearsals, exact configuration diffs, dry activation, native runtime acceptance on both hosts, and documentation whitespace checks. The host repository has no PR CI checks; their absence is not counted as a pass. Private credentials, keys, database rows and backups are excluded from this PR.
The current checkpoint also records merged SPIRE-transition rehearsal PR 40, locally validated SPIRE-backup draft PR 41 and authority-preparation draft PR 42. Preparation preserves the original deadline and refuses reuse once any delegation history exists. Exact-head local validation includes 155 migration tests, 75 guard tests, ten PostgreSQL groups, Nix evaluation, fourteen VM groups and 28 native ARM64 boundary tests. GitHub billing/spending capacity prevented all twelve current PR 41/42 jobs from executing, so these checks are unavailable, not passing. Restore CI and merge parent PR 41 before child PR 42. The latest read-only LAN baseline retains both memberships and passes all twelve DNS queries per host.
The original deadline remains
2026-10-03T02:06:35Z. No renewal delegation or unattended observation is active. Remaining gates include coordinated trust/host continuation, native measured validity and SPIRE signing bounds, retained-key canaries, fault acceptance, twenty-four hours of unattended renewal, and persistent deployment from reviewed merged revisions.full_qualification: falseremains in force. Public DNS, product installation/UI, autonomous offline operation, secure boot and hardware rollback protection are separate milestones.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.