-
Notifications
You must be signed in to change notification settings - Fork 0
feat: add deployer host installer (#22) #69
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Nickfost
wants to merge
90
commits into
main
Choose a base branch
from
feat/issue-22-deployer-host-installer
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
90 commits
Select commit
Hold shift + click to select a range
73f45a1
feat: add deployer host installer
ed8c5e6
fix: address deployer safety review findings
777f8c5
fix: harden deployer retained-state validation
19a0c4e
fix: retain deployed safety evidence
08e1d5d
fix: close deployer runtime recovery gaps
37d2962
test: normalize deployer drain marker mode
773c3ae
fix: serialize runtime policy and recovery state
61b3d0e
fix: fail closed across deployer recovery paths
5ddea4d
fix: preserve validated deployer boundaries
deb781c
fix: pin deployer transaction inputs atomically
817c0bf
fix: close deployer recovery and audit review gaps
9d78330
fix: harden deployer runtime and rollback recovery review gaps
efa5224
fix: close deployer isolation and rollback recovery review gaps
9e52f59
fix: harden deployer transactions, credentials, and audit identity
0242374
fix: track deployed pointer and validate state across recovery paths
c6cffb3
fix: validate deployer identity, isolation, and boundaries end to end
628791d
fix: preserve deployer recovery invariants across lifecycle paths
b471007
fix: close deployer publication, rollback, and uninstall safety gaps
25335bf
test: make drifted-unit uninstall check shellcheck-clean
9c8c5d3
fix: revalidate trust boundaries before every deployer adapter call
24c2b4d
fix: fail closed across deployer recovery, signals, and read-only checks
48c686e
fix: harden deployer publication, recovery manifests, and convergence
aa7f1db
fix: close deployer recovery, snapshot, inhibition, and checkout race…
aab1513
fix: drop redundant checkout ownership probe rejected on CI checkouts
4e0e1f7
fix: harden checkout pinning, promotion, and convergence validation
8c09079
test: expect credential-reference failure before cross-validation ord…
6fd3b5f
test: rotate credential fixture identity in deployed-pair drift regre…
63d5f80
test: match candidate-first credential failure on upgrade path
aa9b129
test: exercise deployed-pair credential drift through the policy refe…
0074803
test: clear recovered rollback state after credential drift regression
d973349
test: substituted live checkout now fails closed at the hash pin
cf07821
test: clear drain fixture before final convergence check
913e798
test: drop invalid trailing convergence check after approval rotation
f61c025
fix: close checkout baseline, pointer, audit, uninstall, and recovery…
8132bd5
fix: stop timers before removing the activation pointer on uninstall
22aeef4
fix: validate systemd boundary and finalize dependencies before recov…
91707e8
test: drifted adapter is caught at candidate validation before recovery
74fa0ff
test: tolerate absent retained pair in drifted-finalize regression
fd68749
test: tolerate absent retained pair in deployed-pair drift regressions
e9e5d7a
test: order deployed-pair drift regressions before finalize recovery
42254a9
test: rebuild retained rollback pair after finalize recovery fixture
2467f17
fix: replace-immune checkout pins, marker type checks, idempotent uni…
4326f6b
fix: propagate tree-read failures, tolerate absent timers, fsync cons…
3f038bd
fix: writability guard before backups, durable commit marker, stale-m…
4d22b56
fix: recovery boundary guards, durable journals, honest availability
26c468e
test: install-root symlink is caught by the existing symlink guard
6a69612
test: availability regression uses a drifted retained policy digest
b037938
fix: hook-free checkout validation, backup guards, durable state tran…
5945492
test: rebuild retained rollback pair before digest/credential drift f…
48c6c68
test: align rollback fixtures with publish-over-unusable-incumbent se…
4a5e2f3
fix: durable rollback publication, boundary-ordered recovery, exact c…
e736b1f
test: round-ten regressions for durability, boundaries, and checkout …
f4b3df2
fix: durable journal retirement, boundary sync before finalize, hones…
33d54ab
test: marker-committed rollback reports change; regression coverage
5e1b765
fix: durable restore retirement, failed-deploy audit, capability bind…
e574a7d
test: capability cross-installation rejection, reload-failure uninsta…
41601a3
fix: recovery without deployed dependencies, durable uninstall, key p…
f0ca8c4
test: uninstall without configuration directory removes the deploymen…
e5e722a
fix: fail-closed durability for journals, drain markers, consumption,…
c5097c4
fix: rollback core durable before commit marker, audit inode restore,…
edede66
test: audit-inode restore, drifted-timer uninstall stop, deployed-bou…
fc43923
fix: production gate, drift-unit role rejection, snapshot and availab…
acd287f
test: round-fifteen regressions; state-snapshot helper for recovery f…
d4f00d6
fix: reject ordinary-CI timers, timer-aware uninstall no-op, document…
146dd29
test: ordinary-CI drift timer rejection fixture
48a538d
fix: fail-closed mixed-role helper in runtime, policy snapshot remove…
1dc18a0
fix: timer enablement scope, Docker pull-in for scheduled services, r…
376eeae
test: repair replaces a damaged active release from the validated che…
399cd41
fix: marker after boundary durability, active-marker sync, timer prob…
42be82d
fix: inhibited adapter call, durable marker clearing, honest uninstal…
5275e21
fix: last-known-good validation before deploy, production rollback ga…
3938a7d
test: marker-deleting adapter cannot replay; regressions pass
b968ff2
fix: full retained-pair validation before deploy, audit prefix integr…
0ebff52
test: rollback baseline gate, consumption-marker replay guard, audit-…
53cf72b
fix: directory-level marker restore, full release validation, availab…
381ac8b
test: directory-level consumption restore, regressions for round twen…
f9ea431
fix: pointer restore ordering, full release predicate, audit prefix r…
ae6302c
fix: retire incumbent snapshot only after the durable success audit
f0b62de
fix: post-publication pointer truth, success-path marker preservation…
d119c29
fix: incumbent-based retirement, controller-side deployer guard, boun…
886a95d
test: controller installer rejects a deployer host
16d5851
fix: controller rollback guard, incumbent content restore, audit orde…
5c8302c
fix: shared role-admission lock, maintenance Docker sanitization, per…
d46ed5d
fix: incumbent metadata restore, audit metadata repair, retained-pair…
abb8dd7
fix: restore recovery metadata after adapter drift
ee99bfc
test: separate recovery metadata fixture paths
b58e8d2
fix: preserve deployer rollback across adapter updates
515b071
fix: retain completed deployment rollback marker
668213b
fix: accept canonical Debian os-release symlink
2ad48c7
test: exercise os-release symlink during install
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,19 @@ | ||
| [Unit] | ||
| Description=Run application-owned scoped deployer cleanup | ||
| After=docker.service | ||
| Wants=docker.service | ||
|
|
||
| [Service] | ||
| Type=oneshot | ||
| User=root | ||
| ExecStart=/opt/ci-fleet-deployer/current/scripts/deployer-runtime.sh cleanup | ||
| Environment=CI_FLEET_DEPLOYER_CONFIG=/var/lib/ci-fleet-deployer/active-policy.conf | ||
| TimeoutStartSec=15min | ||
| UMask=0077 | ||
| NoNewPrivileges=yes | ||
| PrivateTmp=yes | ||
| ProtectHome=yes | ||
| ProtectSystem=strict | ||
| ReadOnlyPaths=/etc/ci-fleet-deployer /opt/ci-fleet-deployer | ||
| ReadWritePaths=/var/lib/ci-fleet-deployer /var/log/ci-fleet-deployer /var/lock/ci-fleet-deployer /run/docker.sock | ||
| RestrictSUIDSGID=yes | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| [Unit] | ||
| Description=Run scoped ci-fleet deployer cleanup daily | ||
|
|
||
| [Timer] | ||
| OnCalendar=daily | ||
| RandomizedDelaySec=15min | ||
| Persistent=true | ||
| Unit=ci-fleet-deployer-cleanup.service | ||
|
|
||
| [Install] | ||
| WantedBy=timers.target |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,17 @@ | ||
| [Unit] | ||
| Description=Drain the ci-fleet deployer before maintenance | ||
|
|
||
| [Service] | ||
| Type=oneshot | ||
| User=root | ||
| ExecStart=/opt/ci-fleet-deployer/current/scripts/deployer-runtime.sh drain | ||
| Environment=CI_FLEET_DEPLOYER_CONFIG=/var/lib/ci-fleet-deployer/active-policy.conf | ||
| TimeoutStartSec=2min | ||
| UMask=0077 | ||
| NoNewPrivileges=yes | ||
| PrivateTmp=yes | ||
| ProtectHome=yes | ||
| ProtectSystem=strict | ||
| ReadOnlyPaths=/etc/ci-fleet-deployer /opt/ci-fleet-deployer | ||
| ReadWritePaths=/var/lib/ci-fleet-deployer /var/log/ci-fleet-deployer /var/lock/ci-fleet-deployer | ||
| RestrictSUIDSGID=yes |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,19 @@ | ||
| [Unit] | ||
| Description=Check ci-fleet deployer health | ||
| After=docker.service | ||
| Wants=docker.service | ||
|
|
||
| [Service] | ||
| Type=oneshot | ||
| User=root | ||
| ExecStart=/opt/ci-fleet-deployer/current/scripts/deployer-runtime.sh health | ||
| Environment=CI_FLEET_DEPLOYER_CONFIG=/var/lib/ci-fleet-deployer/active-policy.conf | ||
| TimeoutStartSec=2min | ||
| UMask=0077 | ||
| NoNewPrivileges=yes | ||
| PrivateTmp=yes | ||
| ProtectHome=yes | ||
| ProtectSystem=strict | ||
| ReadOnlyPaths=/etc/ci-fleet-deployer /opt/ci-fleet-deployer | ||
| ReadWritePaths=/var/lib/ci-fleet-deployer /var/log/ci-fleet-deployer /var/lock/ci-fleet-deployer /run/docker.sock | ||
| RestrictSUIDSGID=yes |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| [Unit] | ||
| Description=Check ci-fleet deployer health every five minutes | ||
|
|
||
| [Timer] | ||
| OnActiveSec=2min | ||
| OnUnitActiveSec=5min | ||
| RandomizedDelaySec=30s | ||
| Persistent=true | ||
| Unit=ci-fleet-deployer-health.service | ||
|
|
||
| [Install] | ||
| WantedBy=timers.target |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,25 @@ | ||
| [Unit] | ||
| Description=Run one approved ci-fleet deployment | ||
| After=docker.service network-online.target | ||
| Wants=docker.service network-online.target | ||
|
|
||
|
Nickfost marked this conversation as resolved.
|
||
| [Service] | ||
| Type=oneshot | ||
| User=root | ||
| Group=root | ||
| ExecStart=/opt/ci-fleet-deployer/current/scripts/deployer-runtime.sh deploy | ||
|
Nickfost marked this conversation as resolved.
|
||
| Environment=CI_FLEET_DEPLOYER_CONFIG=/var/lib/ci-fleet-deployer/active-policy.conf | ||
| Environment=CI_FLEET_DEPLOYER_REQUEST=/var/lib/ci-fleet-deployer/request.conf | ||
| TimeoutStartSec=45min | ||
| # A hung adapter must not hold the lock or inhibitor beyond the documented | ||
| # 45-minute deployment bound; stop quickly after TERM and let KILL follow. | ||
| TimeoutStopSec=30s | ||
| UMask=0077 | ||
| NoNewPrivileges=yes | ||
| PrivateTmp=yes | ||
| ProtectHome=yes | ||
| ProtectSystem=strict | ||
| ReadOnlyPaths=/etc/ci-fleet-deployer /opt/ci-fleet-deployer | ||
| ReadWritePaths=/var/lib/ci-fleet-deployer /var/log/ci-fleet-deployer /var/lock/ci-fleet-deployer /run/docker.sock | ||
| RestrictSUIDSGID=yes | ||
| LockPersonality=yes | ||
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.