railiance-infra/workplans/RAIL-HO-WP-0013-host-time-baseline.md
codex 9886567b40
Some checks failed
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / source-contract (push) Has been cancelled
Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
2026-09-27 18:47:55 +02:00

140 lines
6.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: RAIL-HO-WP-0013
type: workplan
title: "Declare and verify the Railiance host UTC baseline"
domain: financials
repo: railiance-infra
status: blocked
flavor: planning
owner: codex
topic_slug: railiance
created: "2026-09-14"
updated: "2026-09-27"
related_workplans:
- RCLK-WP-0005
- RCLK-WP-0002
- RAIL-HO-WP-0011
state_hub_workstream_id: "788a005b-f6d4-5db9-8866-21251951fa0b"
---
Owner work record for RCLK-WP-0005-T01/T02. Canonical S1 ownership is already
settled by railiance-master ADR-0004 and docs/reef-first-wave-source-map.md.
Do not create a competing time baseline in railiance-hosts or bootstrap.
Read-only railiance01 observation on 2026-09-14: Ubuntu 24.04.4 LTS/KVM,
systemd-timesyncd active/enabled, UTC, synchronized flag yes, distro fallback
ntp.ubuntu.com, no local drop-in, no UDP/123 listener in the observed namespace.
The inspected sample reported offset -634us, root distance 3.432ms and normal
leap state. This is operational metadata, not an independent UTC error proof.
Receipt and repeatable collector: railiance-clock/docs/evidence/2026-09-14-railiance01-clock-inventory.json
and tools/observe_host_clock.py. No configuration or clock change was made.
## Adopt the existing daemon and review a versioned UTC policy
```task
id: RAIL-HO-WP-0013-T01
status: wait
priority: high
state_hub_task_id: "9e5db140-0642-58de-8a9c-1c5a3cfd7b6e"
```
Retain systemd-timesyncd as the baseline candidate; do not install chrony/ntpd
as a second daemon. Join RCLK-WP-0002's upstream independence, leap convention,
health/error/holdover and consumer-bound review. Specify inventory opt-in, exact
server/fallback list, boot/poll policy, health export and rollback. The current
single-provider distro fallback is evidence, not a reviewed independent source set.
Define what source health can honestly claim before exposing it to the clock app.
## Implement one declarative host role and verification entry point
```task
id: RAIL-HO-WP-0013-T02
status: wait
priority: high
state_hub_task_id: "75f17ffa-b781-549d-82ce-d19d431c2618"
```
Depends on T01 policy review. Add opt-in Ansible role under ansible/roles/ and a
narrow playbook that manages only the reviewed time-service drop-in and service
state. Integrate bootstrap.yaml through the same role, not copied tasks. Guard
against other active time daemons and unsupported host platforms. Add health
verification to the owner baseline/Goss handoff with explicit unusable states.
No CAP_SYS_TIME or clock write operation for the application time service; that
capability belongs only to the admitted host daemon. No public UDP/123 ingress.
## Prove IaC convergence, drift and recovery before live rollout
```task
id: RAIL-HO-WP-0013-T03
status: wait
priority: high
state_hub_task_id: "c9d142b0-9c8d-5abf-82d9-099a772da5ec"
```
Depends on T02. Lint/render and disposable VM convergence; second apply must be
no-op. Detect intentional disposable drift, verify reboot persistence and source
outage/recovery, and prove source-based rollback. Measure health reporting limits.
Record exact source revision/target/config checksum and no unrelated changes.
A mocked systemctl result or container-only check is not host synchronization proof.
## Apply the reviewed source and return steady-state handoff
```task
id: RAIL-HO-WP-0013-T04
status: wait
priority: high
state_hub_task_id: "9adae3a6-8ee6-538b-9bb3-1ee32ed185e1"
```
Depends on T03 and normal reviewed live-host authorization. Produce the exact
railiance01 diff and clock-step/credential-consumer impact plan, then use owner
IaC to apply/read back. Reverify usable host health and no extra listener/daemon;
record rollback and monitoring ownership. Hand evidence to RCLK-WP-0005 and
railiance-bootstrap for ordering/rehearsal. Keep all residuals live before closure.
No corporate workstation time settings or app-clock trust adoption in this plan.
2026-09-15: operator requested implementation and consumer use. Added opt-in
railiance_clock owner role and host-time playbook; bootstrap invokes the same
role. Authority activation requires artifact hash, admission reference and
explicit signing-key delivery. Defaults change no clocks and deploy no service.
Native convergence, custody and measured UTC policy acceptance remain open.
## Live deployment — 2026-09-15
CCR-2026-0028 authorizes the systemd authority and attended host-file custody.
The role now prepares identity independently of key delivery, supports a verified
preinstalled key, and pins the production wheel in Railiance01 inventory.
The authority and health timer are active/enabled on loopback 8787. Readiness
and signed workstation acceptance passed; receipt is in railiance-clock and
railiance-platform docs/evidence/2026-09-15-railiance-clock-production.json.
Health collection needs read-only adjtimex; ProtectClock is disabled only on
that exporter, while both services retain empty capability sets. Disposable
outage/reboot/rollback rehearsals remain tracked in T03.
## Closeout review — 2026-09-27
All four residual tasks are `wait`; deployed source alone does not meet their
acceptance criteria. T01 is blocked on RCLK-WP-0002 source/leap/error-model
acceptance; that owner's T01–T03 are still in progress and T04 is todo. T02 has
an implemented opt-in role and passes native Ansible syntax checking, but still
requires T01's reviewed policy and baseline/Goss health integration. T03 requires
an admitted disposable Ubuntu VM for convergence/no-op, drift, reboot,
source-outage/recovery and rollback evidence. No such test target is declared in
this repository. T04's prior live deployment evidence stands, but its required
T03 recovery evidence and steady-state handoff remain outstanding.
Refreshed read-only inventory:
`docs/evidence/2026-09-27-railiance01-clock-inventory.json`, collected with the
existing railiance-clock collector. Installed systemd and systemd-timesyncd:
`255.4-1ubuntu8.17`. Effective system/fallback source: `ntp.ubuntu.com`;
per-link and runtime source lists empty. Poll bounds 32–64 seconds, root-distance
threshold 500ms, observed leap 0. UTC, timesyncd active, synchronization reported,
no UDP/123 listener and no observed competing daemon. These are diagnostics,
not independent accuracy or source-independence proof. Configuration hashes are
in the receipt; no host configuration was changed.
The September 14 duplicate-workplan inbox warning is historical: the current
checkout has one WP-0013 file and already contains consolidation commit
`c402245`. Preserve its existing task UUIDs. Workplan is `blocked` on the
remaining review and native recovery prerequisites.