From 87047faa8e8d1f12cf155d2ac4a85cdc2c947e3d Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 4 Sep 2026 21:40:41 +0200 Subject: [PATCH] docs: rebaseline cluster self-sufficiency workplan Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a06d83-1cbc-71f2-b0dc-e0f48cedae43 --- ...-cluster-self-sufficiency-and-registrar.md | 70 +++++++++++++++---- 1 file changed, 57 insertions(+), 13 deletions(-) diff --git a/workplans/STATE-WP-0081-cluster-self-sufficiency-and-registrar.md b/workplans/STATE-WP-0081-cluster-self-sufficiency-and-registrar.md index b982b21..cde2d83 100644 --- a/workplans/STATE-WP-0081-cluster-self-sufficiency-and-registrar.md +++ b/workplans/STATE-WP-0081-cluster-self-sufficiency-and-registrar.md @@ -4,17 +4,20 @@ type: workplan title: "Cluster self-sufficiency: remove workstation coupling and fix the registrar" domain: infotech repo: state-hub -status: proposed +status: active owner: codex topic_slug: infotech created: "2026-08-21" -updated: "2026-08-21" +updated: "2026-09-04" parent_project: prj-state-hub-retirement parent_workplan: SHR-WP-0001 related: - STATE-WP-0079 - RMGR-WP-0005 - RMGR-WP-0008 + - STATE-WP-0083 + - STATE-WP-0084 + - STATE-WP-0086 - ADR-007 - ADR-010 state_hub_workstream_id: "bb2798fd-0680-5027-8479-3af3a5b048de" @@ -33,6 +36,21 @@ beside it. End state: **workstation coding agents push to forgejo; cluster infrastructure reads from forgejo. Neither reads the other's disk.** +## Re-baseline — 2026-09-04 + +The original plan assumed the cluster sweep would regain write access to an +operator checkout and then migrate that checkout onto a PVC. That implementation +shape was superseded by the Forge-derived projection work in `STATE-WP-0083`, +`STATE-WP-0084`, and `STATE-WP-0086`: the central service now clones exact Forge +commits ephemerally and reconciles them without writing identifiers into a +shared checkout. + +The live State Hub pod no longer mounts `/home/tegwick` or `/root/.ssh`. It uses +the `state-hub` service account and an OpenBao-projected Forge read credential. +The registrar guard has also been retired. Remaining work is limited to runtime +hardening, completing the repository-model audit, deciding the dashboard +disposition, and publishing the operating boundary. + ## Admissibility under the retirement freeze `policies/retirement-freeze.md` allows changes that fix operational risk or @@ -68,7 +86,7 @@ sync requests and why the newest `custodian-sync` commits are from July. ```task id: STATE-WP-0081-T01 -status: todo +status: cancel priority: high state_hub_task_id: "7dca680b-d34d-5bfe-838e-b463a4487a9c" ``` @@ -85,11 +103,16 @@ a working baseline makes every later change verifiable. Verification is end-to-end, not a green pod: run the sweep and confirm `EBIND-WP-0002` gets a `state_hub_workstream_id` written back into its file. +**Superseded 2026-09-04.** The shared write path was deliberately abandoned. +Forge-derived reconciliation now assigns deterministic identifiers without a +cluster writer touching the operator checkout; `EBIND-WP-0002` is registered and +finished. See `STATE-WP-0083`, `STATE-WP-0084`, and `STATE-WP-0086`. + ## Give the pod its own clones ```task id: STATE-WP-0081-T02 -status: todo +status: cancel priority: high state_hub_task_id: "3fd4d23c-6b67-5b92-b312-25a7295773fd" ``` @@ -107,11 +130,15 @@ Sizing input: the current tree is ~78 repos; `markitect_project` alone is 24 MB. Keep the sweep's repo list driven by the hub's repo registry, not by whatever happens to be on a disk. +**Superseded 2026-09-04.** The service uses short-lived Forge clones rather than +a long-lived PVC clone tree. The required boundary is achieved: the live pod has +no hostPath into an operator home directory. + ## Replace the operator SSH key with a service identity ```task id: STATE-WP-0081-T03 -status: todo +status: done priority: high state_hub_task_id: "8e5a5eb8-f29c-5cab-a19d-3447b6e0c26a" ``` @@ -127,6 +154,10 @@ fleet should not be the same key a human uses interactively. Credential custody routes through OpenBao, not this repo — see `.claude/rules/credential-routing.md`. Do not put key material in the chart. +**Completed 2026-09-04.** The live workload uses its Kubernetes service account +and an OpenBao-projected Forge read token. Neither the operator SSH directory nor +a personal private key is mounted into the pod. + ## Run as a non-root user ```task @@ -136,8 +167,10 @@ priority: medium state_hub_task_id: "57ab0ced-ef3f-5260-b7d6-e2a78ff4e023" ``` -Set `runAsUser`/`runAsGroup` and a `fsGroup` matching the PVC. Depends on T02: -once the pod owns its storage there is no reason for it to be root. +Set an explicit non-root `runAsUser`/`runAsGroup`, disallow privilege escalation, +drop unnecessary capabilities, and use a read-only root filesystem if the +application permits it. The PVC dependency no longer applies because T02 was +superseded by ephemeral Forge clones. Closes the recurrence: today's ownership fix will be undone by the next sweep while the pod still runs as root. @@ -146,7 +179,7 @@ while the pod still runs as root. ```task id: STATE-WP-0081-T05 -status: todo +status: progress priority: high state_hub_task_id: "530fbd27-e463-51d2-b09c-ba9827d057de" ``` @@ -164,6 +197,12 @@ that will move. `remote_url` correction is unambiguous and can proceed immediately. +**Progress 2026-09-04.** Repository representation now carries per-host +`host_paths`, a compatibility `local_path`, and Forge remotes. Cluster +reconciliation consumes Forge commits rather than workstation paths. Complete a +fleet-wide audit before closing this task, including confirmation that no +cluster consumer still interprets `local_path` as an authoritative checkout. + ## Serve the dashboard from the cluster ```task @@ -209,7 +248,7 @@ like a queue. ```task id: STATE-WP-0081-T08 -status: todo +status: done priority: high state_hub_task_id: "782c502a-5ce2-5ec3-8f07-b550c9705013" ``` @@ -228,12 +267,17 @@ rule entirely. Coordinate rather than duplicate — the derivation belongs to Reply to the queued agents when it is done; several have been waiting since 2026-08-20. +**Completed 2026-09-04.** `EBIND-WP-0002`, `RMGR-WP-0008`, and `RMGR-WP-0009` +are finished; exact-commit reconciliation is operational; and the interim +single-writer registrar guard was retired by the Forge-derived projection path. + ## Acceptance -- [ ] Sweep writes successfully from the pod; `EBIND-WP-0002` registered -- [ ] Pod uses its own clone volume; no hostPath into any home directory -- [ ] Pod authenticates with a dedicated key, runs as non-root +- [x] Shared-checkout writeback superseded; `EBIND-WP-0002` registered +- [x] Pod uses ephemeral Forge clones; no hostPath into any home directory +- [x] Pod authenticates with a dedicated service identity +- [ ] Pod runs as non-root with an explicit restrictive security context - [ ] No `/home/worsch` path in any cluster-consumed record; `remote_url` values current - [ ] Dashboard reachable without the workstation, or formally handed to `hub-core` - [ ] Boundary rule written and discoverable by agents -- [ ] Registrar queue drained; interim single-writer rule retired or explicitly deferred +- [x] Registrar queue drained; interim single-writer rule retired