Record production provisioning and remote update plan #105

Merged
ams-tech merged 2 commits from codex/production-provisioning-plan into main 2026-10-03 16:43:31 -04:00
ams-tech commented 2026-10-03 14:29:42 -04:00 (Migrated from github.com)

The first production Pi needs a repeatable provisioning and qualification procedure that preserves it as a production candidate and requires no routine sudo commands or manual fixture changes. Record the agreed procedure using the existing fleet profile and the already-owned development Pi for comparison, without repeating its ownership operation or consuming another new board.

The plan also records the selected remote-network update path and A/B NVMe slots. A companion design defines production management credentials, staged qualification access, signed transition offers, the bounded updater, credential continuity and the required boot-selection/interruption-recovery qualification. It identifies reusable components and new production fleet/issuer work explicitly.

This is documentation only: no credentials are issued, devices changed, service deployed or readiness gate closed. Physical execution and production issuance retain their existing scoped authorization.

Validation: checked local Markdown links, agreed-scope/status assertions and git diff --check. No runtime changes or runtime tests.

The first production Pi needs a repeatable provisioning and qualification procedure that preserves it as a production candidate and requires no routine sudo commands or manual fixture changes. Record the agreed procedure using the existing fleet profile and the already-owned development Pi for comparison, without repeating its ownership operation or consuming another new board. The plan also records the selected remote-network update path and A/B NVMe slots. A companion design defines production management credentials, staged qualification access, signed transition offers, the bounded updater, credential continuity and the required boot-selection/interruption-recovery qualification. It identifies reusable components and new production fleet/issuer work explicitly. This is documentation only: no credentials are issued, devices changed, service deployed or readiness gate closed. Physical execution and production issuance retain their existing scoped authorization. Validation: checked local Markdown links, agreed-scope/status assertions and git diff --check. No runtime changes or runtime tests.
Sign in to join this conversation.
No description provided.