feat: add guided station campaigns #65
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!65
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/guided-station-campaign"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The read-only station cannot guide an operator through a durable development campaign. This adds a separate touchscreen mode that shows the current step, recorded result, required input and allowed action, with diagnostic history available through report export.
The new
kaiba-provision-campaignservice owns one immutable plan and a private persistent journal. The existing loopback station relays closed actions over station/lane-scoped mTLS. Automatic steps stop at required operator input; duplicate taps and lost replies recover recorded progress. Interrupted execution requires a separately pinned reconciler, and blocked or quarantined outcomes cannot be bypassed from the UI.Execution is limited to digest-pinned Nix-store packet wrappers. The browser supplies no commands, paths or secrets. Wrappers retain their own execution authorization, target checks, one-use intent and evidence handling. Acknowledging an input does not authorize an operation. Raw executor output never enters the screen or journal; only reviewed result codes, bounded failure categories and diagnostic hashes are retained.
This PR is stacked on #64 (
codex/protected-enrollment-state), which is stacked on #63. It delivers the guided controller and UI with a working software demonstration. The reviewed Pi packet/wrappers and isolated real-device fleet eligibility policy remain to be connected. It does not perform hardware operations or change fleet-admission rules. Every exported FA condition remainsnot_evaluated; completing a campaign cannot claim hardware qualification or production enrollment. The observer, disabled foundation and public simulation retain their behavior.Validation passed locally:
nix develop --command scripts/check.sh fast: complete Go suite, station UI checks, Nix formatting, inert deployment smoke test and CI-selection regressions.guided-station-campaigncheck: real packaged controller/station, disposable mTLS, real enrollment client using disposable process-mode state, restart/outage recovery, access denial and secret-free report export. Six fixed executor failure cases cover digest mismatch, stderr, overflow, malformed result, timeout and nonzero exit.The native check initializes and reopens a disposable client identity; it does not issue a certificate, activate fleet membership or establish encrypted cold-boot behavior. Required x86_64 and native ARM CI remain the merge gate. The runbook documents deployment inputs, authority boundaries, recovery and the remaining Pi integration.