Qualify the production hardware, storage and offline identity profile #97

Open
opened 2026-10-01 12:11:32 -04:00 by ams-tech · 0 comments
ams-tech commented 2026-10-01 12:11:32 -04:00 (Migrated from github.com)

The completed Ace spare-NVMe campaign demonstrated selected interrupted-write outcomes, retained synthetic state, backup restore and refusal to start without trusted time. It does not qualify the original pilot storage path, secure boot, protected key custody, trusted offline time or hardware rollback prevention.

Qualify an explicitly selected production hardware/storage profile in a separate campaign. Keep the retained LAN installation and its only working authority copy outside destructive testing.

Acceptance:

  • Document the exact board, storage, firmware, encrypted-state path, key-custody mechanism and intended supported offline behavior.
  • Define and implement the boot authentication, hardware monotonic-state/rollback and trusted-time mechanisms before claiming their properties.
  • Rehearse failure and restoration paths with independent encrypted backups and independently retained acknowledgements; detect stale backup state without silently recreating identities or databases.
  • Exercise selected interrupted writes, acknowledged commits, power loss, obsolete-state restoration and offline/clock-loss cases on the intended storage/encryption path with recovery access available.
  • Retain failed/inconclusive attempts, immutable image/runtime pins, measured observations and explicit evidence limits. Publish only sanitized results and evidence hashes.
  • Update the qualification matrix only for demonstrated properties; keep full_qualification:false until every applicable gate is satisfied.

No additional drive swaps or destructive power tests are part of the current LAN closeout. The previous campaign required two swaps and returned Ace to its original encrypted pilot disk. Its software isolation was not a physical air gap, and external stale-backup detection was not hardware anti-rollback enforcement.

References: physical campaign receipt, qualification limits and gates, LAN closeout plan.

The completed Ace spare-NVMe campaign demonstrated selected interrupted-write outcomes, retained synthetic state, backup restore and refusal to start without trusted time. It does not qualify the original pilot storage path, secure boot, protected key custody, trusted offline time or hardware rollback prevention. Qualify an explicitly selected production hardware/storage profile in a separate campaign. Keep the retained LAN installation and its only working authority copy outside destructive testing. Acceptance: - Document the exact board, storage, firmware, encrypted-state path, key-custody mechanism and intended supported offline behavior. - Define and implement the boot authentication, hardware monotonic-state/rollback and trusted-time mechanisms before claiming their properties. - Rehearse failure and restoration paths with independent encrypted backups and independently retained acknowledgements; detect stale backup state without silently recreating identities or databases. - Exercise selected interrupted writes, acknowledged commits, power loss, obsolete-state restoration and offline/clock-loss cases on the intended storage/encryption path with recovery access available. - Retain failed/inconclusive attempts, immutable image/runtime pins, measured observations and explicit evidence limits. Publish only sanitized results and evidence hashes. - Update the qualification matrix only for demonstrated properties; keep full_qualification:false until every applicable gate is satisfied. No additional drive swaps or destructive power tests are part of the current LAN closeout. The previous campaign required two swaps and returned Ace to its original encrypted pilot disk. Its software isolation was not a physical air gap, and external stale-backup detection was not hardware anti-rollback enforcement. References: [physical campaign receipt](https://github.com/PseudoDesign/kaiba-provisioning/blob/codex/offline-qualification-evidence/docs/observations/2026-09-30-nvme-physical-qualification.json), [qualification limits and gates](https://github.com/PseudoDesign/kaiba-infra/blob/codex/spiffe-spire-next-steps/docs/offline-qualification.md), [LAN closeout plan](https://github.com/PseudoDesign/kaiba-infra/blob/codex/spiffe-spire-next-steps/docs/lan-closeout.md).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
kaiba/kaiba-provisioning#97
No description provided.