feat: add pilot client diagnostics and reference submission #73
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-provisioning!73
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/pilot-device-diagnostics"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The pilot client previously reported transport failures and HTTP denials as the same reconciliation error and lacked a command for the existing diagnostic-reference endpoint. This adds bounded request classifications and structured CLI errors, plus
submit-diagnosticwith an explicit idempotency key, bounded input and receipt verification against the existing enrollment and canonical request.Failures still match
ErrReconcilethrougherrors.Isand never trigger automatic retries. Diagnostic submission leaves credential state unchanged and never fetches the referenced URI. No fleet API or persisted credential-state schema changes.Validation:
nix develop --command scripts/check.sh fastandnix build --no-link .#checks.x86_64-linux.unitpassed. Synthetic mTLS tests cover HTTP errors, timeouts/cancellation, trust failures, redirects, invalid responses, lost-reply explicit retry, substituted receipts, input rejection and unchanged credential state. CLI tests verify bounded error output without underlying error text.Software only: deployment, live diagnostic submission and real negative-result evidence remain pending. No device operations, policy extensions, private evidence or credentials are included. Leave unmerged for review and required CI.