Add guarded Ace/Mako pilot profiles and fix early mount ordering #15

Merged
ams-tech merged 25 commits from codex/spiffe-lan-qualification into main 2026-10-01 23:32:17 -04:00
ams-tech commented 2026-09-29 03:33:37 -04:00 (Migrated from github.com)

Provide explicit persistent LAN profiles for Ace’s imported authority and DNS primary, and Mako’s admitted agent and DNS replica. Startup verifies protected imported state and retained membership; activation cannot create a replacement identity. The profiles preserve existing applications and storage, fix imported-state boot ordering, and keep debugfs root-only.

Optional admission continuation preserves Mako’s original receipt and requires a fresh restricted read of its exact owner-approved term and membership. It defaults to disabled. Deployable dependencies now select reviewed merged Fleet d7027c24b523a1030b855ec8fe1b6582ad2ce1aa, provisioning 30c35edd336bd61dda87993c92de742c01fa37c2, and DNS e1f18fbc355b70b2d87245288d4ebb837434cbdd; historical test and hardware pins stay unchanged. Parent PR 14 is merged.

Validation: local Nix two-host composition, admitted-member guard (22 cases), tmpfiles, retained-device persistence VM, and legacy encrypted-storage checks pass. This repository has no PR CI checks; their absence is not a pass. Fleet’s six selected parent checks include native ARM64/x86_64 and VM coverage. Dated native boot, cold-start and power-off observations apply to the previous deployed profiles, not the newly selected dependencies. A fresh read-only baseline at 2026-10-02T03:16Z confirms retained identities, 17 Ace services, 7 Mako services and all 12 DNS queries from each host.

Both active candidate profiles built natively on Ace from head 72cf3f8. Read-only comparison with installed profiles confirms unchanged kernel/initrd/firmware/filesystems, unit sets and enabled services. Eight Ace pilot units and Mako’s admission guard/tmpfiles unit differ; regular applications are unchanged. The candidate Ace storage/import guard passes against retained native state; Mako’s candidate admission guard passes against its retained receipt/key cache with continuation disabled. These are compatibility checks, not activation of a new term.

Ace generation 14 and Mako generation 15 remain installed. Coordinated trust/host-policy transition, bounded SPIRE signing, native acceptance of the new term, retained-key canaries and 24-hour unattended renewal still gate LAN closure. The original 2026-10-03T02:06:35Z deadline is unchanged. Malak remains fenced, full_qualification remains false, and private credentials/database contents are excluded. Production installation and hardware qualification remain separate milestones.

Provide explicit persistent LAN profiles for Ace’s imported authority and DNS primary, and Mako’s admitted agent and DNS replica. Startup verifies protected imported state and retained membership; activation cannot create a replacement identity. The profiles preserve existing applications and storage, fix imported-state boot ordering, and keep debugfs root-only. Optional admission continuation preserves Mako’s original receipt and requires a fresh restricted read of its exact owner-approved term and membership. It defaults to disabled. Deployable dependencies now select reviewed merged Fleet d7027c24b523a1030b855ec8fe1b6582ad2ce1aa, provisioning 30c35edd336bd61dda87993c92de742c01fa37c2, and DNS e1f18fbc355b70b2d87245288d4ebb837434cbdd; historical test and hardware pins stay unchanged. Parent PR 14 is merged. Validation: local Nix two-host composition, admitted-member guard (22 cases), tmpfiles, retained-device persistence VM, and legacy encrypted-storage checks pass. This repository has no PR CI checks; their absence is not a pass. Fleet’s six selected parent checks include native ARM64/x86_64 and VM coverage. Dated native boot, cold-start and power-off observations apply to the previous deployed profiles, not the newly selected dependencies. A fresh read-only baseline at 2026-10-02T03:16Z confirms retained identities, 17 Ace services, 7 Mako services and all 12 DNS queries from each host. Both active candidate profiles built natively on Ace from head 72cf3f8. Read-only comparison with installed profiles confirms unchanged kernel/initrd/firmware/filesystems, unit sets and enabled services. Eight Ace pilot units and Mako’s admission guard/tmpfiles unit differ; regular applications are unchanged. The candidate Ace storage/import guard passes against retained native state; Mako’s candidate admission guard passes against its retained receipt/key cache with continuation disabled. These are compatibility checks, not activation of a new term. Ace generation 14 and Mako generation 15 remain installed. Coordinated trust/host-policy transition, bounded SPIRE signing, native acceptance of the new term, retained-key canaries and 24-hour unattended renewal still gate LAN closure. The original 2026-10-03T02:06:35Z deadline is unchanged. Malak remains fenced, full_qualification remains false, and private credentials/database contents are excluded. Production installation and hardware qualification remain separate milestones.
Sign in to join this conversation.
No description provided.