WIP: Document Kaiba LAN integration, staged deployment and qualification #6

Draft
ams-tech wants to merge 56 commits from codex/spiffe-spire-next-steps into main
ams-tech commented 2026-09-29 00:28:14 -04:00 (Migrated from github.com)

Document SPIFFE/SPIRE standalone, server and agent roles and the LAN rollout at pilot.kaiba.pseudo.design: Ace runs the authority and DNS primary, Mako retains its admitted identity and DNS replica, and Malak remains an operator with its former authority fenced.

The runbook records the completed disposable-NVMe physical campaign, original encrypted-storage acceptance, warm reboots, clean PoE cold start and Malak disconnection observation, with evidence hashes and explicit hardware limitations. It also tracks the remaining owner-approved thirty-day renewal term and final LAN acceptance.

Merged compatible host components now pass temporary NixOS test activation on Ace and Mako. The bounded staging helper pins both closures, requires a verified stopped-writer encrypted backup, preserves activation intents, compares retained authority history, and uses an independent restoration watchdog. Both hosts pass retained membership/key-state checks, fresh workload observations and all twelve DNS queries. Hydra and regular PostgreSQL remain unaffected. Boot profiles are unchanged; persistent installation is still pending.

Validation: fourteen staging tests, two native disposable watchdog rehearsals, exact configuration diffs, dry activation, native runtime acceptance on both hosts, and documentation whitespace checks. The host repository has no PR CI checks; their absence is not counted as a pass. Private credentials, keys, database rows and backups are excluded from this PR.

The current checkpoint also records merged SPIRE-transition rehearsal PR 40, locally validated SPIRE-backup draft PR 41 and authority-preparation draft PR 42. Preparation preserves the original deadline and refuses reuse once any delegation history exists. Exact-head local validation includes 155 migration tests, 75 guard tests, ten PostgreSQL groups, Nix evaluation, fourteen VM groups and 28 native ARM64 boundary tests. GitHub billing/spending capacity prevented all twelve current PR 41/42 jobs from executing, so these checks are unavailable, not passing. Restore CI and merge parent PR 41 before child PR 42. The latest read-only LAN baseline retains both memberships and passes all twelve DNS queries per host.

The original deadline remains 2026-10-03T02:06:35Z. No renewal delegation or unattended observation is active. Remaining gates include coordinated trust/host continuation, native measured validity and SPIRE signing bounds, retained-key canaries, fault acceptance, twenty-four hours of unattended renewal, and persistent deployment from reviewed merged revisions. full_qualification: false remains in force. Public DNS, product installation/UI, autonomous offline operation, secure boot and hardware rollback protection are separate milestones.

Document SPIFFE/SPIRE standalone, server and agent roles and the LAN rollout at `pilot.kaiba.pseudo.design`: Ace runs the authority and DNS primary, Mako retains its admitted identity and DNS replica, and Malak remains an operator with its former authority fenced. The runbook records the completed disposable-NVMe physical campaign, original encrypted-storage acceptance, warm reboots, clean PoE cold start and Malak disconnection observation, with evidence hashes and explicit hardware limitations. It also tracks the remaining owner-approved thirty-day renewal term and final LAN acceptance. Merged compatible host components now pass temporary NixOS test activation on Ace and Mako. The bounded staging helper pins both closures, requires a verified stopped-writer encrypted backup, preserves activation intents, compares retained authority history, and uses an independent restoration watchdog. Both hosts pass retained membership/key-state checks, fresh workload observations and all twelve DNS queries. Hydra and regular PostgreSQL remain unaffected. Boot profiles are unchanged; persistent installation is still pending. Validation: fourteen staging tests, two native disposable watchdog rehearsals, exact configuration diffs, dry activation, native runtime acceptance on both hosts, and documentation whitespace checks. The host repository has no PR CI checks; their absence is not counted as a pass. Private credentials, keys, database rows and backups are excluded from this PR. The current checkpoint also records merged SPIRE-transition rehearsal PR 40, locally validated SPIRE-backup draft PR 41 and authority-preparation draft PR 42. Preparation preserves the original deadline and refuses reuse once any delegation history exists. Exact-head local validation includes 155 migration tests, 75 guard tests, ten PostgreSQL groups, Nix evaluation, fourteen VM groups and 28 native ARM64 boundary tests. GitHub billing/spending capacity prevented all twelve current PR 41/42 jobs from executing, so these checks are unavailable, not passing. Restore CI and merge parent PR 41 before child PR 42. The latest read-only LAN baseline retains both memberships and passes all twelve DNS queries per host. The original deadline remains `2026-10-03T02:06:35Z`. No renewal delegation or unattended observation is active. Remaining gates include coordinated trust/host continuation, native measured validity and SPIRE signing bounds, retained-key canaries, fault acceptance, twenty-four hours of unattended renewal, and persistent deployment from reviewed merged revisions. `full_qualification: false` remains in force. Public DNS, product installation/UI, autonomous offline operation, secure boot and hardware rollback protection are separate milestones.
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin codex/spiffe-spire-next-steps:codex/spiffe-spire-next-steps
git switch codex/spiffe-spire-next-steps
Sign in to join this conversation.
No description provided.