{"schemaVersion":"developer.reits.tech/runner-controller-activation-evidence/v1","status":"G05_G06_DENIED_NO_LIVE_READINESS_OR_LISTENER_AUTHORIZATION","observedAt":"2026-07-21T09:05:20Z","observationMode":"READ_ONLY_HOST_ROUTE_AND_RECEIPT_AUDIT_NO_SERVICE_START","program":{"acceptedKnives":4,"totalKnives":36,"currentKnife":"D05","closeoutCut":4,"remainingIncludingCurrent":32,"remainingAfterAcceptance":31,"d05Accepted":false},"gateSummary":{"targetedGates":2,"satisfiedGates":0,"positiveAcceptanceReceipts":0,"missingArtifactGroups":14,"missingReadinessReceipts":11,"decision":"DENY_AND_ESCALATE_TO_CONTROLLER_AND_RELEASE_OWNERS"},"gates":[{"id":"D05-G05","name":"ELEVEN_LIVE_READINESS_RECEIPTS","owner":"CONTROLLER_OWNER","target":"eleven fresh signature-verified readiness receipts bound to one Controller release, manifest, configuration and runtime identity","observed":"zero readiness directory, zero receipt files, zero configured Gates and no Controller runtime identity on the production host","positiveReceiptsObserved":0,"decision":"DENIED_NO_LIVE_READINESS_RECEIPTS"},{"id":"D05-G06","name":"INDEPENDENT_LISTENER_AUTHORIZATION","owner":"RELEASE_OWNER","target":"one independent expiring authorization bound to exact host, release, config, unit, endpoint, rollback, negative webhook proof and four approvals","observed":"authorization file, systemd unit, loopback listener and reverse proxy route are all absent","positiveReceiptsObserved":0,"decision":"DENIED_NO_LISTENER_AUTHORIZATION"}],"routeSeparation":[{"id":"portal-evidence-api","label":"Developer Portal evidence API","endpoint":"127.0.0.1:8100/api/runner-factory/controller","httpStatus":"200","classification":"DOCUMENTATION_EVIDENCE_ROUTE","countsAsControllerListener":false},{"id":"controller-loopback-health","label":"Controller loopback health","endpoint":"127.0.0.1:8110/health","httpStatus":"000","classification":"CONNECTION_REFUSED_LISTENER_ABSENT","countsAsControllerListener":false},{"id":"controller-reverse-proxy","label":"Controller reverse proxy","endpoint":"nginx route to 8110","httpStatus":"NOT_CONFIGURED","classification":"NO_PUBLIC_OR_PROXY_ROUTE","countsAsControllerListener":false},{"id":"controller-service-unit","label":"Controller service unit","endpoint":"reits-runner-factory-controller.service","httpStatus":"NOT_FOUND","classification":"UNIT_AND_PROCESS_ABSENT","countsAsControllerListener":false}],"host":{"environment":"production EC2 / ap-southeast-2","portalReleaseAtAudit":"developer-portal@55161cd61846-27c84a64788b","portalSourceAtAudit":"55161cd61846eee6396a2fb0a18b14dd87b54015","checks":[{"id":"ACT-01","label":"runtime manifest","target":"/etc/reits-runner-factory/controller-runtime.json","observed":"ABSENT","status":"DENIED"},{"id":"ACT-02","label":"readiness receipt store","target":"/var/lib/reits-runner-factory/readiness","observed":"ABSENT","status":"DENIED"},{"id":"ACT-03","label":"listener authorization","target":"/var/lib/reits-runner-factory/listener-authorization.json","observed":"ABSENT","status":"DENIED"},{"id":"ACT-04","label":"runtime directory","target":"/run/reits-runner-factory","observed":"ABSENT","status":"DENIED"},{"id":"ACT-05","label":"systemd unit","target":"reits-runner-factory-controller.service","observed":"not-found / inactive","status":"DENIED"},{"id":"ACT-06","label":"Controller process","target":"dedicated service identity","observed":"0","status":"SAFE_ABSENT"},{"id":"ACT-07","label":"8110 listener / nginx route","target":"loopback only / no public route","observed":"0 / 0","status":"SAFE_CLOSED"}]},"readiness":{"required":11,"observed":0,"ready":false,"receiptStoreInstalled":false,"runtimeIdentityConfigured":false,"gates":[{"id":"RF_READY_DEDICATED_HOST","owner":"PLATFORM_SRE","evidence":"dedicated control-plane host attestation","status":"MISSING"},{"id":"RF_READY_SERVICE_IDENTITY","owner":"SECURITY","evidence":"non-login UID/GID and hardened unit digest","status":"MISSING"},{"id":"RF_READY_WEBHOOK_SECRET","owner":"SECURITY","evidence":"root-only SecretRef resolution and rotation receipt","status":"MISSING"},{"id":"RF_READY_RESERVATION_STORE","owner":"DATA_PLATFORM","evidence":"read/write boundary and recovery drill receipt","status":"MISSING"},{"id":"RF_READY_RECEIPT_SIGNER","owner":"SECURITY","evidence":"exact KMS key, verifier pin and rotation receipt","status":"MISSING"},{"id":"RF_READY_TOKEN_BROKER","owner":"DEVELOPER_PLATFORM","evidence":"one-time Gitea token boundary receipt","status":"MISSING"},{"id":"RF_READY_WORKER_PROVIDER","owner":"PLATFORM_SRE","evidence":"single-use worker lifecycle receipt","status":"MISSING"},{"id":"RF_READY_GITEA_CONTROL","owner":"DEVELOPER_PLATFORM","evidence":"assignment and double-retirement receipt","status":"MISSING"},{"id":"RF_READY_CAPACITY_CONTROLLER","owner":"PLATFORM_SRE","evidence":"two-slot ledger and whole-pool freeze receipt","status":"MISSING"},{"id":"RF_READY_AUDIT_SINK","owner":"QA_ARCHITECTURE","evidence":"append-only signed journal continuity receipt","status":"MISSING"},{"id":"RF_READY_OWNER_APPROVAL","owner":"PRODUCT_OWNER","evidence":"cost, runtime and security scope approval","status":"MISSING"}],"admissionRequirements":[{"id":"release","count":1,"proof":"signed exact source, artifact, configuration and rollback identity","status":"MISSING"},{"id":"host","count":1,"proof":"dedicated control-plane host, production marker, zero Runner service and loopback bind","status":"MISSING"},{"id":"service","count":1,"proof":"non-login UID/GID, no capabilities, credential references only and hardened unit digest","status":"MISSING"},{"id":"adapters","count":6,"proof":"five READ_ONLY Readers plus one VERIFY_ONLY attestation verifier","status":"MISSING"},{"id":"gates","count":11,"proof":"ordered issuer-pinned attestations bound to the exact manifest and runtime identity","status":"MISSING"},{"id":"readiness","count":1,"proof":"READY_VERIFIED receipt that reconstructs all eleven Gate facts","status":"MISSING"}]},"listenerAuthorization":{"endpoint":"127.0.0.1:8110","maximumValiditySeconds":120,"authorizationReceiptsObserved":0,"listenerStarts":0,"publicRoutes":0,"reverseProxyRoutes":0,"requirements":[{"id":"admission","count":1,"proof":"authority-verified unexpired production-evidence admission receipt","status":"MISSING"},{"id":"request","count":1,"proof":"exact release, host, config, unit and loopback endpoint request","status":"MISSING"},{"id":"rollback","count":1,"proof":"signed distinct-target rollback rehearsal within 300 seconds","status":"MISSING"},{"id":"negative-webhook","count":1,"proof":"signed rejection proof for unsigned, invalid and stale deliveries","status":"MISSING"},{"id":"operational-drills","count":2,"proof":"ordered rollback and incident drill receipts","status":"MISSING"},{"id":"owner-approvals","count":4,"proof":"security, runtime, cost and operations approvals","status":"MISSING"},{"id":"nonce","count":1,"proof":"single-use scope-bound authorization nonce","status":"MISSING"},{"id":"expiry","count":1,"proof":"earliest upstream expiry with a 120-second maximum","status":"MISSING"}],"stateModel":["UNTRUSTED","ADMISSION_BOUND","TARGET_BOUND","RECOVERY_PROVEN","OWNERS_APPROVED","CANDIDATE","PROJECTED_OR_DISPOSED","DENIED"]},"verificationPacks":[{"id":"production-evidence-admission","status":"PASS_PRODUCTION_EVIDENCE_ADMISSION_NOT_CONFIGURED","fixtures":56,"accepted":6,"denied":50,"fixtureSignatures":339},{"id":"listener-authorization","status":"PASS_FIXTURE_ONLY","fixtures":53,"accepted":6,"denied":47,"fixtureSignatures":132}],"operatorPlan":{"nextAction":"Controller Owner must collect eleven live readiness receipts on the approved dedicated host; Release Owner may then issue a separate 120-second candidate-only authorization after rollback, negative-webhook, incident and four-owner evidence binds the same exact scope.","forbiddenActions":["Do not count the Developer Portal evidence API on port 8100 as a Controller listener or readiness receipt.","Do not create a listener authorization from fixture signatures, a portal release identity or raw readiness booleans.","Do not start the service before all eleven fresh readiness receipts reconstruct one READY_VERIFIED packet.","Do not configure nginx, a public route or reverse proxy for Controller port 8110.","Do not reuse a nonce, exceed 120 seconds or omit rollback and negative-webhook evidence."]},"safetyTruth":{"readOnlyAuditPerformed":true,"credentialsRecorded":false,"configurationWrites":0,"serviceInstallations":0,"readinessReceiptsIssued":0,"listenerAuthorizationsIssued":0,"listenerStarts":0,"reverseProxyChanges":0,"externalReadsExecuted":0,"externalWritesExecuted":0,"paidResourcesCreated":false,"g05Satisfied":false,"g06Satisfied":false,"d05Accepted":false},"verification":{"status":"PASS_READ_ONLY_READINESS_AND_LISTENER_OBSERVATION","targetedGates":2,"satisfiedGates":0,"hostChecks":7,"requiredReadinessReceipts":11,"observedReadinessReceipts":0,"admissionArtifactGroups":6,"listenerArtifactGroups":8,"fixtureCases":109,"fixtureSignatures":471,"positiveAcceptanceReceipts":0,"listenerStarts":0,"reverseProxyRoutes":0,"externalWritesExecuted":0},"discovery":{"workbench":"/release-foundation#runner-controller-activation-evidence","schema":"/schemas/runner-controller-activation-evidence.v1.schema.json","readinessAssembly":"/api/runner-factory/controller/runtime-assembly","productionAdmission":"/api/runner-factory/controller/production-evidence-admission","listenerAuthorization":"/api/runner-factory/controller/listener-authorization","d05Closure":"/api/runner-factory/controller/d05-acceptance-closure"}}