feat: integrate protected enrollment storage for malak CLI #67
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!67
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/malak-cli-enrollment"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Protected enrollment storage was merged in #64 onto a feature branch after its parent had already reached main. Main therefore still lacks the protected-mount guard and bounded storage helper. Integrate that reviewed commit directly, and use malak's CLI procedures for the first Ace admission.
The runtime, packaging and test changes match
0d13ccbexactly: boot-based enrollment requires the expected LUKS2/ext4 mount with protective flags and no swap, and the development helper supports the bounded create/close/restart/reopen/close experiment. Its hardware and production qualification flags remain false.Update the Ace plan and linked scope/admission/handoff documents to defer touchscreen/GUI provisioning and the development-Pi station. Preserve durable CLI intent, reconciliation, diagnostic reporting and all FA-01–FA-08 acceptance conditions. The guided controller and browser work from #65 is excluded; existing station/UI code is unchanged.
Validation:
GOFLAGS=-buildvcs=false nix develop --command scripts/check.sh fastpassed. The first local run could not obtain Git metadata in twogo listdependency checks; disabling only VCS stamping resolved that environment issue.enrollment-storageandenrollment-storage-vmchecks passed, including credential continuity across restart and rejection of unprotected storage.nix flake check -Lis running; native ARM and required repository CI will run on this PR.0d13ccb; no guided-campaign/controller or touchscreen changes are present.git diff --checkpassed. No physical device, deployment or production signing operation was performed.