Install pilot.kaiba.pseudo.design identity services on Ace #14
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/nix-pseudo-design!14
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/spiffe-persistent-pilot"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Install Ace's persistent identity foundation for pilot.kaiba.pseudo.design: a standalone loopback-only SPIRE authority, local agent, durable bootstrap guards and exact-systemd-unit health probe. The Fleet #29 module is reviewed and merged. Preserve the kernel, storage/unlock configuration, Hydra, regular PostgreSQL, SSH and retained pilot identity.
The recorded native generation-10 installation passed guarded activation, explicit initialization, persistent switch, fresh SSH, workload issuance/isolation and server/agent restart without reusing the consumed grant. A subsequent warm reboot passed automatic startup with unchanged identity and enrollment. The source in this PR reproduces that exact system closure: /nix/store/ylpbjk8jzr195l7yn7f713sgjfimicbs-nixos-system-ace-26.05.20260807.ee48b14. Mako's configuration is unchanged.
Review corrected the activation helper to check each required service and automount individually; systemctl with several unit names otherwise succeeds when only one is active. Bash syntax, ShellCheck and three isolated any-active/all-active behavior scenarios pass. The correction does not change the evaluated system closure and was not executed against live services.
This repository has no PR CI checks for this head; the validation above and pinned Fleet module/VM results are the evidence, not a missing-CI pass. Later cold-start, workstation-disconnection, LAN migration and bounded spare-NVMe observations belong to the child #15 and its linked reports. Those later changes are already on the running generation-14 Ace installation; merging this historical foundation does not deploy generation 10 again.
Merge before #15. Renewal continuity, remaining native LAN acceptance, the twenty-four-hour unattended run and final deployment from merged pins remain open. Public DNS, autonomous offline operation, secure boot and hardware rollback protection remain separate milestones; full_qualification remains false.