WIP: Add appliance credentials, autonomous agent and bounded update executor #109
Draft
ams-tech wants to merge 1 commit from
codex/autonomous-appliance-updates into main
pull from: codex/autonomous-appliance-updates
merge into: kaiba:main
kaiba:main
kaiba:codex/forgejo-primary-hosting
kaiba:codex/pages-deployment-gate
kaiba:codex/ci-backlog-recovery
kaiba:codex/production-provisioning-plan
kaiba:codex/task1-storage-public-review
kaiba:codex/retain-firmware-build-notices
kaiba:codex/raspberry-pi-firmware-notices
kaiba:codex/task1-recovered-staging-bindings
kaiba:codex/task1-reviewed-witnesses
kaiba:codex/task1-native-staging-manifest
kaiba:codex/effective-trust-observation
kaiba:codex/pilot-trust-continuation
kaiba:codex/offline-qualification-evidence
kaiba:codex/spiffe-roadmap
kaiba:codex/hydra-pr-manual
kaiba:codex/hydra-github-ci
kaiba:codex/hydra-on-ace
kaiba:codex/pilot-listener-readiness
kaiba:codex/pilot-host-system-path
kaiba:codex/pilot-serving-handoff
kaiba:codex/pilot-access-checks
kaiba:codex/pilot-host-deployment
kaiba:codex/pilot-authority-transition
kaiba:codex/pilot-ssh-dispatch
kaiba:codex/pilot-device-host-hook
kaiba:codex/mako-enrollment-hooks
kaiba:codex/pilot-enrollment-runner
kaiba:codex/pilot-enrollment-reports
kaiba:codex/select-arm64-heavy-checks
kaiba:codex/recovered-credential-renewal
kaiba:codex/pilot-recovery-installation
kaiba:codex/pilot-recovery-proof
kaiba:codex/pilot-renewal-history
kaiba:codex/pilot-renewal-client
kaiba:codex/pilot-device-diagnostics
kaiba:codex/pilot-credential-lifecycle
kaiba:codex/pilot-enrollment
kaiba:codex/ci-runtime-source-isolation
kaiba:codex/signer-test-timeout
kaiba:codex/ace-mako-pilot
kaiba:codex/malak-cli-enrollment
kaiba:codex/protected-enrollment-state
kaiba:codex/ace-adoption-plan
kaiba:codex/device-enrollment-client
kaiba:codex/guided-station-campaign
kaiba:codex/copied-storage-failure-metadata
kaiba:codex/copied-storage-comparison
kaiba:codex/provisioning-record-export
kaiba:codex/enrollment-handoff
kaiba:codex/feasibility-status
kaiba:codex/remaining-lock-observation
kaiba:codex/lock-clear-readback
kaiba:codex/development-signing-compat
kaiba:codex/signing-response-lengths
kaiba:codex/device-secret-response-diagnostics
kaiba:codex/firmware-rejection-observer
kaiba:codex/device-secret-lock-checks
kaiba:codex/hmac-lock-observation
kaiba:codex/offline-storage-observation
kaiba:codex/offline-storage-development
kaiba:codex/remote-luks-development
kaiba:codex/hmac-evidence-assessment
kaiba:codex/device-secret-hmac-diagnostics
kaiba:codex/device-secret-development
kaiba:codex/device-secret-failure-diagnostics
kaiba:codex/device-secret-usb-identity
kaiba:codex/per-device-boot-root-plan
kaiba:codex/firmware-crypto-locks
kaiba:codex/signing-failure-diagnostics
kaiba:codex/device-secret-native-export
kaiba:codex/device-secret-execution-packet
kaiba:codex/device-secret-target-harness
kaiba:codex/hmac-feasibility-runner
kaiba:codex/native-verity-evidence
kaiba:codex/read-only-slot-metadata
kaiba:codex/native-offline-positive-evidence
kaiba:codex/native-offline-handoff-main
kaiba:codex/native-offline-candidate
kaiba:codex/device-secret-feasibility
kaiba:codex/native-offline-handoff
kaiba:codex/station-read-only-status
kaiba:codex/implementation-staging
kaiba:codex/documentation-cleanup
kaiba:codex/fleet-admission-policy
kaiba:scope-rework
kaiba:codex/native-staging-export
kaiba:codex/public-root-payload-key-scan
kaiba:codex/rpi5-verifier-public-inputs-20260915
kaiba:codex/rpi5-campaign-preparation
kaiba:codex/rpi5-verifier-signing-handoff
kaiba:codex/rpi5-prephysical-validation
kaiba:codex/rpi5-recovery-preparation
kaiba:codex/rpi5-campaign-sandbox
kaiba:codex/gpt-test-feedback
kaiba:codex/gpt-metadata-captures
kaiba:codex/first-physical-baseline
kaiba:codex/release-candidate-ci
kaiba:codex/scope-build-inputs
kaiba:codex/development-checks
kaiba:codex/scope-pi-jemalloc-overlay
kaiba:codex/rpi5-stable-campaign-provisioner-final
kaiba:codex/rpi5-stable-verifier-campaign
kaiba:codex/fix-arm64-tcg-boot-timeout
kaiba:codex/rpi5-initramfs-verifier
kaiba:codex/goals-rework
No reviewers
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!109
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/autonomous-appliance-updates"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Production units need outbound remote updates without development SSH or a general command channel. This adds an appliance credential client, fixed-origin TLS transport, bounded artifact cache, autonomous polling loop, typed Unix IPC and a durable update executor with independent release/authority verification.
The executor writes and independently reads back only complete configured inactive-slot ranges, checks state compatibility and idle quiesce, journals before mutation, and requires trial plus normal-boot confirmation. Same-key credential renewal/recovery and lost acknowledgements survive restart. Uncertain writes and incomplete journals remain preserved reconciliation outcomes. Busy devices defer with bounded diagnostics; ordinary activation defaults to 02:00–04:00 UTC.
Uses the pinned shared runtime from https://github.com/pd-codex/kaiba-contracts/pull/16 and the companion Fleet core. Existing development/pilot clients, retained signed candidates and hardware evidence are unchanged. Hydra stays disabled.
Validation: full provisioning Go suite passes (managed-worktree VCS stamping disabled), new package race tests and reproducible x86 Nix appliance checks pass. Tests cover wrong identities/signatures, expiry, replay, interrupted writes/cache downloads, offline confirmation, failed trial, lost commit responses, current peer UID, root-server authentication and bounded diagnostics. Native x86/ARM checks are included in the flake.
This is a draft software implementation milestone. The media driver explicitly accepts regular files only. No production credential, signed appliance image, native block/boot adapter, installed service or physical acceptance is claimed. The complete remaining profile/issuer/image/VM/native gates are documented in docs/autonomous-appliance-updates-implementation.md; the approved full plan remains incomplete pending those bindings and qualification.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.