WIP: Add appliance credentials, autonomous agent and bounded update executor #109

Draft
ams-tech wants to merge 1 commit from codex/autonomous-appliance-updates into main
ams-tech commented 2026-10-03 20:05:25 -04:00 (Migrated from github.com)

Production units need outbound remote updates without development SSH or a general command channel. This adds an appliance credential client, fixed-origin TLS transport, bounded artifact cache, autonomous polling loop, typed Unix IPC and a durable update executor with independent release/authority verification.

The executor writes and independently reads back only complete configured inactive-slot ranges, checks state compatibility and idle quiesce, journals before mutation, and requires trial plus normal-boot confirmation. Same-key credential renewal/recovery and lost acknowledgements survive restart. Uncertain writes and incomplete journals remain preserved reconciliation outcomes. Busy devices defer with bounded diagnostics; ordinary activation defaults to 02:00–04:00 UTC.

Uses the pinned shared runtime from https://github.com/pd-codex/kaiba-contracts/pull/16 and the companion Fleet core. Existing development/pilot clients, retained signed candidates and hardware evidence are unchanged. Hydra stays disabled.

Validation: full provisioning Go suite passes (managed-worktree VCS stamping disabled), new package race tests and reproducible x86 Nix appliance checks pass. Tests cover wrong identities/signatures, expiry, replay, interrupted writes/cache downloads, offline confirmation, failed trial, lost commit responses, current peer UID, root-server authentication and bounded diagnostics. Native x86/ARM checks are included in the flake.

This is a draft software implementation milestone. The media driver explicitly accepts regular files only. No production credential, signed appliance image, native block/boot adapter, installed service or physical acceptance is claimed. The complete remaining profile/issuer/image/VM/native gates are documented in docs/autonomous-appliance-updates-implementation.md; the approved full plan remains incomplete pending those bindings and qualification.

Production units need outbound remote updates without development SSH or a general command channel. This adds an appliance credential client, fixed-origin TLS transport, bounded artifact cache, autonomous polling loop, typed Unix IPC and a durable update executor with independent release/authority verification. The executor writes and independently reads back only complete configured inactive-slot ranges, checks state compatibility and idle quiesce, journals before mutation, and requires trial plus normal-boot confirmation. Same-key credential renewal/recovery and lost acknowledgements survive restart. Uncertain writes and incomplete journals remain preserved reconciliation outcomes. Busy devices defer with bounded diagnostics; ordinary activation defaults to 02:00–04:00 UTC. Uses the pinned shared runtime from https://github.com/pd-codex/kaiba-contracts/pull/16 and the companion Fleet core. Existing development/pilot clients, retained signed candidates and hardware evidence are unchanged. Hydra stays disabled. Validation: full provisioning Go suite passes (managed-worktree VCS stamping disabled), new package race tests and reproducible x86 Nix appliance checks pass. Tests cover wrong identities/signatures, expiry, replay, interrupted writes/cache downloads, offline confirmation, failed trial, lost commit responses, current peer UID, root-server authentication and bounded diagnostics. Native x86/ARM checks are included in the flake. This is a draft software implementation milestone. The media driver explicitly accepts regular files only. No production credential, signed appliance image, native block/boot adapter, installed service or physical acceptance is claimed. The complete remaining profile/issuer/image/VM/native gates are documented in docs/autonomous-appliance-updates-implementation.md; the approved full plan remains incomplete pending those bindings and qualification.
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin codex/autonomous-appliance-updates:codex/autonomous-appliance-updates
git switch codex/autonomous-appliance-updates
Sign in to join this conversation.
No description provided.