docs(P00): incorporate grill binding conditions C-44..C-49
Grill verdict: CONDITIONAL PROCEED at 0.82 confidence. 6 binding conditions incorporated: - C-44: P03 fail-closed on SSH-push failure (local fallback only when 0 nodes) - C-45: P04 log-only mode default (enforce after bootstrap ACL verified) - C-46: P12 depends on P05+P06 (seal+auth) in addition to P03+P04 - C-47: uat-signoff.sh 4 critical-path assertions (remote deploy, ACL deny, seal, OIDC) - C-48: docs/uat.md Proxmox prerequisite + alternative 3xUbuntu path - C-49: narrative softened to 'last round before UAT validation' ---ci--- project: orca phase: 0 milestone: v0.13 status: grill ---/ci---
This commit is contained in:
+7
-1
@@ -629,7 +629,7 @@ CI agent verifies and cuts v1.0.0).
|
||||
`acl.Check` on every request path; `acl.json` 0600; audit actor =
|
||||
OIDC sub/SVID; WebAuthn registration requires auth.
|
||||
|
||||
### Binding conditions (for GRILL ratification)
|
||||
### Binding conditions (for GRILL ratification — C-39..C-49)
|
||||
|
||||
- **C-39**: P03 (scheduler wiring) is the riskiest phase — changes the
|
||||
core `job run` path. Must not break existing `job run` (local
|
||||
@@ -645,6 +645,12 @@ CI agent verifies and cuts v1.0.0).
|
||||
P01..P11 slip, P12 still ships (honest signal via failing
|
||||
assertions). The signoff script is idempotent and read-only.
|
||||
- **C-43**: `verify-reqs` bold-format regex must be fixed in P11 so
|
||||
- **C-44**: P03 MUST fail-closed when scheduler selects a node but SSH-push fails. Local fallback only when `len(registeredNodes)==0`. Test case mandatory.
|
||||
- **C-45**: P04 MUST implement log-only/dry-run mode as default for first invocation after ACL wiring. Enforce mode after bootstrap ACL verified.
|
||||
- **C-46**: P12 dependency table MUST include P05 (seal) and P06 (auth init-idp) in addition to P03 and P04.
|
||||
- **C-47**: P12 `uat-signoff.sh` MUST include explicit assertions for: (a) job deployed to remote node, (b) ACL deny-by-default, (c) seal/unseal round-trip, (d) OIDC health check.
|
||||
- **C-48**: P12 `docs/uat.md` MUST document hardware prerequisites (Proxmox VE 8/9 host required). Alternative UAT path (3x Ubuntu, Proxmox claims skipped) MUST be documented.
|
||||
- **C-49**: Plan narrative MUST soften "last hardening round" to "last hardening round before UAT validation." UAT will likely surface 3-7 issues requiring patch release.
|
||||
the consistency gate works for v0.12 AND v0.13.
|
||||
|
||||
### Risk register (for grill + research, for ongoing monitoring)
|
||||
|
||||
Reference in New Issue
Block a user