feat: add development device enrollment client #63

Merged
ams-tech merged 1 commit from codex/device-enrollment-client into main 2026-09-22 20:52:46 -04:00
ams-tech commented 2026-09-22 16:41:09 -04:00 (Migrated from github.com)

The enrollment rehearsal currently supplies device keys from its test harness. Add a standalone development client that creates and retains its own P-256 management key, accepts bound bootstrap challenges, installs an issuer-checked certificate, and proves the installed key after a configured boot or process restart.

Private state uses owner-only files, a directory lock and atomic durable updates. Ambiguous proof replies require an authenticated status read before reconciliation or one explicit retry of the saved proof. Access checks always query current fleet authorization. Native packaging and an ARM CI artifact let the existing management system run the client without changing or signing a boot image.

This targets the isolated service in fleet PR #1, with the actual-client integration in fleet PR #2. The station UI remains read-only; automatic station relay, protected-storage deployment and actual device execution remain follow-up work. The client reports production enrollment and hardware qualification as false. Shared contracts, production admission rules and hardware configuration are unchanged.

Validation:

  • Focused Go race tests: private persistence, certificate/challenge/receipt binding, restart requirements, transport failures and uncertain-proof recovery.
  • Repository fast checks passed. Local execution used GOFLAGS=-buildvcs=false because an unrelated /tmp/.git directory confuses Go's worktree metadata detection; test behavior is unchanged.
  • Native standalone package built; the fleet companion rehearsal passed all 20 scenario groups against the exact packaged client, real services and disposable PostgreSQL/PKI, locally and in native x86_64/ARM64 CI.
  • Native Nix unit, static-contract and standalone-client checks passed; changed documentation links and diff whitespace checked. The full local run was interrupted when KVM denial forced the existing 234 GiB staging test into its documented 90+ minute emulation path. The complete required suite remains running on CI, whose x86 runner enables KVM.

Only software, synthetic tests and documentation are published. No device action or private hardware capture is included.

The enrollment rehearsal currently supplies device keys from its test harness. Add a standalone development client that creates and retains its own P-256 management key, accepts bound bootstrap challenges, installs an issuer-checked certificate, and proves the installed key after a configured boot or process restart. Private state uses owner-only files, a directory lock and atomic durable updates. Ambiguous proof replies require an authenticated status read before reconciliation or one explicit retry of the saved proof. Access checks always query current fleet authorization. Native packaging and an ARM CI artifact let the existing management system run the client without changing or signing a boot image. This targets the isolated service in [fleet PR #1](https://github.com/PseudoDesign/kaiba-fleet/pull/1), with the actual-client integration in [fleet PR #2](https://github.com/PseudoDesign/kaiba-fleet/pull/2). The station UI remains read-only; automatic station relay, protected-storage deployment and actual device execution remain follow-up work. The client reports production enrollment and hardware qualification as false. Shared contracts, production admission rules and hardware configuration are unchanged. Validation: - Focused Go race tests: private persistence, certificate/challenge/receipt binding, restart requirements, transport failures and uncertain-proof recovery. - Repository fast checks passed. Local execution used `GOFLAGS=-buildvcs=false` because an unrelated `/tmp/.git` directory confuses Go's worktree metadata detection; test behavior is unchanged. - Native standalone package built; the fleet companion rehearsal passed all 20 scenario groups against the exact packaged client, real services and disposable PostgreSQL/PKI, locally and in [native x86_64/ARM64 CI](https://github.com/PseudoDesign/kaiba-fleet/actions/runs/35782141597). - Native Nix unit, static-contract and standalone-client checks passed; changed documentation links and diff whitespace checked. The full local run was interrupted when KVM denial forced the existing 234 GiB staging test into its documented 90+ minute emulation path. The complete required suite remains running on CI, whose x86 runner enables KVM. Only software, synthetic tests and documentation are published. No device action or private hardware capture is included.
Sign in to join this conversation.
No description provided.