feat: export authenticated provisioning records for fleet intake #60

Merged
ams-tech merged 4 commits from codex/provisioning-record-export into main 2026-09-21 21:51:03 -04:00
ams-tech commented 2026-09-21 17:15:21 -04:00 (Migrated from github.com)

Provisioning currently has no authenticated producer for the shared ProvisioningRecord. This adds a read-only exporter with stable persisted revisions and optional, transaction-scoped control/audit evidence reads. Development outcomes remain candidate evidence with both readiness flags false.

The exporter reads independent authorities, brackets audit collection with control reads, preserves exact retained evidence, validates referenced receipts and pins reviewed profile/posture/release inputs. Fleet service identities cannot acquire claims, submit control commands or append audit events. Existing station/lane routes remain unchanged when the optional handoff configuration is absent. The exporter is packaged separately from hardware executors.

Validation: the full provisioning Go suite passed; focused revision, authorization, strict encoding and real-workflow mapping tests passed; repository Nix formatting passed. A native x86 Nix integration check in kaiba-fleet exercised the packaged services, mTLS reads, development rejection, source outages, restart/retry and unchanged source stores. Native provisioning CI runs on this PR. Cross-repository checks run in private fleet CI, with a pinned producer, an exact-commit dispatch input and scheduled producer-main compatibility checks; the public producer workflow cannot read the private fleet repository.

The initial source mapping and synthetic fixture reuse the retained kaiba-controller export patch, with provenance in docs/fleet-export.md. This PR adds the live interfaces and a separate durable revision allocator. No hardware operation, production admission or independent full audit-chain qualification is claimed.

Related implementation: https://github.com/PseudoDesign/kaiba-fleet/pull/1. Shared integration obligations: https://github.com/pd-codex/kaiba-contracts/pull/7. Merge the producer before fleet; all PRs remain unmerged pending review.

Provisioning currently has no authenticated producer for the shared ProvisioningRecord. This adds a read-only exporter with stable persisted revisions and optional, transaction-scoped control/audit evidence reads. Development outcomes remain candidate evidence with both readiness flags false. The exporter reads independent authorities, brackets audit collection with control reads, preserves exact retained evidence, validates referenced receipts and pins reviewed profile/posture/release inputs. Fleet service identities cannot acquire claims, submit control commands or append audit events. Existing station/lane routes remain unchanged when the optional handoff configuration is absent. The exporter is packaged separately from hardware executors. Validation: the full provisioning Go suite passed; focused revision, authorization, strict encoding and real-workflow mapping tests passed; repository Nix formatting passed. A native x86 Nix integration check in kaiba-fleet exercised the packaged services, mTLS reads, development rejection, source outages, restart/retry and unchanged source stores. Native provisioning CI runs on this PR. Cross-repository checks run in private fleet CI, with a pinned producer, an exact-commit dispatch input and scheduled producer-main compatibility checks; the public producer workflow cannot read the private fleet repository. The initial source mapping and synthetic fixture reuse the retained kaiba-controller export patch, with provenance in docs/fleet-export.md. This PR adds the live interfaces and a separate durable revision allocator. No hardware operation, production admission or independent full audit-chain qualification is claimed. Related implementation: https://github.com/PseudoDesign/kaiba-fleet/pull/1. Shared integration obligations: https://github.com/pd-codex/kaiba-contracts/pull/7. Merge the producer before fleet; all PRs remain unmerged pending review.
Sign in to join this conversation.
No description provided.