IMPLEMENTATION KNIFE 05 / 36 · TRANSITION CLOSEOUT

蓝图已收口,真实实现从红门开始

这里不再增加架构刀次。104/104 已闭环;实施账本仍为 4/36,当前 D05。D05‑T01 至 T08 的仓库实现已全部完成(8/8);独立 AWS 角色、成本双签、组织 Runner、原生 Mac 双作用域、dedicated Controller 主机、签名发布、真实回滚与四方终验都尚未在线完成,11 个生产 Gate 全部保持红门。

ARCHITECTURE BLUEPRINT104 / 104remaining 0 · sequence closed
IMPLEMENTATION PROGRAM4 / 36D05 active · 32 including current
D05 PRODUCTION ACCEPTANCE0 / 1111 signed positive receipts required

D05-T01 · CREDENTIAL FIREBREAK

凭据、任务、网络与整机生命周期已经拆开

这是可部署的仓库实现,不是云上验收。一次性 Runner credential 在任务前撤销;任务只进入受限 Docker 容器;AWS authority 在 daemon 启动前隔离;单任务结束后整机退役。

TASK STATEREPOSITORY IMPLEMENTEDD05-T01Runner credential and task isolation firebreak
LIVE STATEQUALIFICATION REQUIRED0organization runners online · stack NOT_DEPLOYED
G01 / D05NOT ACCEPTED0 / 11repository complete ≠ production accepted
CRED-01REPOSITORY_BOUND

Ephemeral runner credential

register --ephemeral; Gitea revokes the exposed runner credential before untrusted code starts

TASK-01REPOSITORY_BOUND

Task container boundary

digest-pinned docker:// labels, privileged=false, valid_volumes=[], docker_host="-" and no host socket mount

CLOUD-01REPOSITORY_BOUND

Zero cloud authority at execution

IMDS disabled and instance profile detached before the daemon starts

NET-01REPOSITORY_BOUND

Proxy-only task egress

reits-ci0 may reach only 172.30.0.1:3128; task DNS points to empty container loopback; Docker image pulls use loopback Squid; other host and forwarded sockets are rejected

LIFE-01REPOSITORY_BOUND

Whole-machine retirement

daemon exits after one job; credential and task roots are wiped; VM powers off; ASG replaces it

01
BOOTSTRAP

New encrypted Ubuntu VM starts in the isolated CI VPC with a temporary bootstrap profile.

02
REGISTER

Root retrieves the SSM registration token and creates one ephemeral organization runner credential while the daemon is offline.

03
QUARANTINE

The node disables IMDS, detaches its profile, signals CloudFormation, erases temporary AWS values and writes the activation marker.

04
EXECUTE

The unprivileged daemon accepts one job; untrusted steps execute in a bounded Docker container without the host socket or runner credential.

05
EGRESS

Task traffic is forced through the dedicated bridge to the root-managed CONNECT allowlist; private and direct destinations are denied.

06
RETIRE

After the one job or any daemon failure, the host deletes containers, workspace, temp data and .runner, then powers off for ASG replacement.

Repository implementation is complete for D05-T01, but no paid cloud resource was created and no live adversarial receipt exists. This artifact does not satisfy G01 or accept D05.

D05-T02 · AWS VALIDATION IDENTITY

验证身份只验证模板,不能顺手变成部署身份

独立角色、临时会话、精确账号与 ARN、固定模板和负向权限探针组成一条可审计链。仓库包已经完整;当前工作区没有 AWS CLI,Cloud Owner 也尚未安装角色,所以所有在线证据继续为零。

REPOSITORY PACKETIMPLEMENTEDD05‑T02role + policy + verifier + runbook + fixtures
LIVE IDENTITYABSENT0independent assumed-role sessions observed
AWS API RECEIPTNOT OBSERVED0fresh ValidateTemplate receipts
NEXT PLANNED TASKBLOCKEDD05-T03repository packet ready · live approval waits for T02
01 · SOURCEFederated roleCloud Owner supplied exact ARN
02 · ASSUMEreits-cloudformation-validatorexternal ID · ≤ 3600s
03 · IDENTIFYSTS callerexact account + assumed-role ARN
04 · VALIDATECloudFormationpinned template body only
05 · PROVEEC2 deniedread-only negative permission probe
LEAST-AUTHORITY ENVELOPE2 ALLOWED · ALL OTHERS DENIED

cloudformation:ValidateTemplateALLOW

sts:GetCallerIdentityALLOW

cloudformation:Create* / Update* / Delete*DENY

ec2:* · iam:* · ssm:* · secretsmanager:*DENY

Permissions boundary + inline policy · explicit NotAction deny · session ≤ 3600s
01
OWNER_INSTALL · Cloud Account Owner

Install the role template with an exact trusted IAM principal and out-of-band external ID.

OWNER_ACTION_REQUIRED
02
FEDERATE · Independent Validator

Use an explicit AWS CLI role profile backed by federated or otherwise temporary source credentials.

BLOCKED_IDENTITY_ABSENT
03
IDENTIFY · Validation Script

Call STS GetCallerIdentity and require the exact assumed-role ARN and expected account.

BLOCKED_AWS_CLI_ABSENT
04
VALIDATE · AWS CloudFormation

Validate only the pinned runner template body in ap-southeast-2; do not create a change set or stack.

BLOCKED_IDENTITY_ABSENT
05
PROVE_DENY · Validation Script

Require a read-only EC2 DescribeInstances probe to fail with AccessDenied, proving the role is not a general cloud identity.

BLOCKED_IDENTITY_ABSENT
06
SEAL_RECEIPT · Independent Validator

Write a secret-free local receipt binding account, principal, template SHA-256, region and validation response.

BLOCKED_PREDECESSOR
CURRENT BLOCK

D05-T02 repository engineering is complete, but the Cloud Account Owner has not installed the role and no independent assumed-role session or AWS ValidateTemplate receipt exists. D05-T03 remains blocked, G01 remains false, D05 remains 0/11 and implementation remains 4/36.

D05-T03 · COST AUTHORITY

把报价、批准与自动停机绑定到同一份基础设施

不是一张随手估价卡:官方 SKU、精确模板摘要、两位独立签署人、31 天非续期租约和部署拒绝逻辑共同构成成本准入。当前只是仓库实现完成,Product Owner 与 FinOps 均未签字。

REPOSITORY PACKETIMPLEMENTEDD05‑T03quote + dual signature + lease expiry + deploy gate
FIXED 730H BASEOFFICIAL SKUUSD 176.84Sydney · on-demand · tax and variable transfer excluded
PROPOSED MONTHLY CEILINGNOT APPROVEDUSD 250USD 73.164 variable allowance
TRUSTED SIGNATURESABSENT0 / 2Product Owner + FinOps · distinct principals required
COMPUTEUSD 154.1762 × t3.large Linux1460 instance-hours × 0.1056
ROOT_STORAGEUSD 15.3602 × 80 GB gp3160 GB-month × 0.096
PUBLIC_IPV4USD 7.3002 × in-use public IPv41460 address-hours × 0.005
FIXED BASEUSD 176.836before variable allowance730-hour planning month
DUAL AUTHORITY

两把不同的钥匙,批准同一精确事实

0 / 2 SIGNED
01
PRODUCT_OWNERPENDING

Approve business need, two-runner scope and non-renewing lease.

principal absent
02
FINOPSPENDING

Approve current quote, USD ceiling, exclusions and account budget ownership.

principal absent
Ed25519distinct key IDs≤ 31 daysnon-renewing
C01IMPLEMENTED

Exact source binding

Receipt binds the request digest, runner template SHA-256, region and approved ceiling.

C02IMPLEMENTED_PENDING_KEYS

Dual-owner signature

Ed25519 signatures from distinct trusted Product Owner and FinOps principals are mandatory.

C03IMPLEMENTED

Bounded compute rate

T3 CPU credits use standard mode and paid one-minute detailed monitoring is disabled.

C04IMPLEMENTED

No hidden network appliance

The stack contains no NAT Gateway or load balancer; two charged public IPv4 addresses are explicit.

C05IMPLEMENTED

Non-renewing lease

A CloudFormation scheduled action sets ASG min, desired and max capacity to zero at receipt expiry.

C06IMPLEMENTED

Fail-closed deploy

The deploy path rejects absent, stale, over-cap, wrong-region, wrong-template or invalid signatures before mutation.

VARIABLE / NOT FIXED

Internet and regional data transfer · Single-job replacement overlap · Taxes, credits, discounts and currency conversion · Any resource or performance setting outside the exact template

CURRENT BLOCK

D05-T03 repository engineering is complete: the official price snapshot, exact quote, dual-signature receipt verifier, deploy admission and lease expiry are implemented. Product Owner and FinOps have not signed, no cost receipt is valid, D05-T02 live AWS identity remains the current executable prerequisite, D05-T04 remains blocked, G01 remains false, D05 remains 0/11 and implementation remains 4/36.

D05-T04 · 18-REPOSITORY ISOLATION QUALIFICATION

把绿色 CI、Runner 身份和整机销毁拆成三份证据

最新远端 HEAD 已重新抓取,18 个 gate 的原始状态是 9 success / 9 cancelled;但它们都没有绑定到两台合格的一次性组织 Runner,所以合格隔离回执仍是 0/18。这里同时暴露此前遗漏的 17+1 scope:jx-im/im-media-send-kit 不在 reits 组织 Runner 的授权范围内。

REPOSITORY PACKETIMPLEMENTEDD05‑T04plan + collector + verifier + matrix + hostile probes
RAW GATE STATUSNOT QUALIFICATION9 / 189 cancelled · exact current revisions
QUALIFIED RECEIPTSABSENT0 / 18runner + job + revision + replacement identity required
ORGANIZATION RUNNERSOFFLINE0 + 0reits organization + jx-im organization
PARTITION ATARGET READY
17

reits organization repositories

两条 organization-scoped Linux lanes,单机并发 1、单任务退役、无生产路由。

organization:reits → 2 lanes
PARTITION BOWNER DECISION
1

jx-im/im-media-send-kit

Linux gate 需要 ubuntu-latest,但当前 reits 组织 token 无权覆盖这个外部组织仓库。

transfer · separate lane · revise core scope
QUALIFICATIONBLOCKED
0 / 18

accepted isolation receipts

不能静默排除 shared repo,也不能把旧 Runner 的 success 冒充隔离验收。

all conditions required
EXACT REVISION LEDGER

18 仓执行矩阵

0 QUALIFIED
01
reits/data-sources8987dc1ef0
ubuntu-latestfailureNO RECEIPT
02
reits/im-core4c4ce6e17b
ubuntu-latestsuccessNO RECEIPT
03
jx-im/im-media-send-kitd5f0e3e5d6
macos-latestfailureNO RECEIPT
04
reits/im-uiebee6f3a4e
ubuntu-latestsuccessNO RECEIPT
05
reits/matrix-quant-im-iose4813fd237
macos-latestsuccessNO RECEIPT
06
reits/matrix-x-chat-iosad40fafbc8
ubuntu-latestfailureNO RECEIPT
07
reits/matrixantai-backtest6257ce04cb
ubuntu-latestsuccessNO RECEIPT
08
reits/matrixantai-simb238cb6b2c
ubuntu-latestsuccessNO RECEIPT
09
reits/miniapp-open-platform41d67048b7
ubuntu-latestsuccessNO RECEIPT
10
reits/opensdk40d9219d60
ubuntu-latestfailureNO RECEIPT
11
reits/public-booking-platform6a38c3df68
ubuntu-latestfailureNO RECEIPT
12
reits/quant-platformcbb20515d5
ubuntu-latestsuccessNO RECEIPT
13
reits/reits-authca76941282
ubuntu-latestfailureNO RECEIPT
14
reits/reits-bbs9c6b70599b
ubuntu-latestfailureNO RECEIPT
15
reits/reits-info-portal6d175fbded
ubuntu-latestfailureNO RECEIPT
16
reits/reits-knowledge7577d3d646
ubuntu-latestsuccessNO RECEIPT
17
reits/reits-media4e76349c14
ubuntu-latestfailureNO RECEIPT
18
reits/trading-data-source70b8242fac
ubuntu-latestsuccessNO RECEIPT
G01 CANDIDATE EQUATION
18 / 18exact gates
+
7 / 7hostile probes
+
2 / 2replacements
+
3 / 3signatures
Current accepted values: 0 + 0 + 0 + 0
P01NOT_RUN

Runner credential unreadable

Expected: DENY · operator-trusted receipt required

P02NOT_RUN

Host Docker socket absent

Expected: DENY · operator-trusted receipt required

P03NOT_RUN

IMDS and task credentials unreachable

Expected: DENY · operator-trusted receipt required

P04NOT_RUN

Production network unreachable

Expected: DENY · operator-trusted receipt required

P05NOT_RUN

Direct and unlisted egress denied

Expected: DENY · operator-trusted receipt required

P06NOT_RUN

Cloud authority absent

Expected: DENY · operator-trusted receipt required

P07NOT_RUN

Previous job residue absent on replacement

Expected: PASS · operator-trusted receipt required

Q01IMPLEMENTED

Exact 18-repository revision binding

Every gate receipt must match the owner, repository, revision and gate context in the immutable plan.

Q02IMPLEMENTED_PENDING_LIVE_EVIDENCE

Runner identity provenance

A green CI status is rejected unless it binds the job to an admitted ephemeral runner and instance.

Q03IMPLEMENTED_PENDING_EXECUTION

Seven hostile probes

Credential, socket, metadata, production route, egress, cloud authority and residue boundaries all need operator-trusted receipts.

Q04IMPLEMENTED_PENDING_REPLACEMENT

One job, one machine

Two old-to-new instance transitions must prove retirement, local destruction and clean replacement.

Q05FAIL_CLOSED_OWNER_DECISION_REQUIRED

17 + 1 scope partition

The current reits organization token cannot authorize jx-im/im-media-send-kit; the verifier refuses 18/18 until its scope is resolved.

Q06IMPLEMENTED_PENDING_KEYS

Independent three-role acceptance

Platform SRE, Security and QA must sign the same receipt using distinct Ed25519 keys.

CURRENT BLOCK

D05-T04 repository engineering is complete, including the exact 18-repository matrix, seven hostile probes, one-job replacement contract, signed receipt verifier and the newly exposed 17+1 scope gap. Live execution is not admitted: T02 is absent, T03 is unsigned, both organizations have zero online organization runners, the shared jx-im repository has no approved lane, qualified receipts remain 0/18, G01 remains false, D05 remains 0/11 and implementation remains 4/36.

D05-T05 · NATIVE MAC RUNNER QUALIFICATION

在线 Mac 只是候选,两个原生任务才构成可签署的 Lane

最新 Gitea 1.25.4 只读审计发现一台在线 Mac Runner,但它属于 jx-im/im-client-ios-swift 单仓且可复用;matrix-quant-im-ios 的历史原生任务虽成功,却没有 scope、ephemeral、cleanup 和签名回执;im-media-send-kit 仍为 cancelled。工作台因此把 1 台物理 Mac、2 个串行 Runner generation、2 个 exact job 和 3 方签名拆开呈现。

REPOSITORY PACKETIMPLEMENTEDD05‑T05plan · collector · verifier · host profiles · six probes
MAC INVENTORYCANDIDATE ONLY1 / 2online / registered · organization scope 0
RAW NATIVE JOBSNOT QUALIFICATION1 + 1historical success + cancelled
QUALIFIED JOB RECEIPTSABSENT0 / 2exact job + generation + cleanup + signatures
G02 / D05DENIED0 / 1D05 remains 0 / 11
PHYSICAL TRUST DOMAINUNBOUND
1

Dedicated Apple-silicon Mac

单并发、无个人会话、无生产路由、无云凭据;只允许 root 注册 authority 和 `_reits_ci` 原生任务身份。

arm64 · FileVault · Xcode.app · capacity 1
GENERATION 1HISTORICAL_SUCCESS_QUALIFICATION_RECEIPT_MISSING

reits/matrix-quant-im-ios

organization:reits

reits-macos-native-v1:host
validate-and-test · e4813fd237
GENERATION 2CANCELLED_NO_ELIGIBLE_REPOSITORY_RUNNER

jx-im/im-media-send-kit

repository:jx-im/im-media-send-kit

macos-latest:host
minimum · d5f0e3e5d6
SIGNED ADMISSION0 / 3
0 / 2

accepted native jobs

两段 scope 串行执行,Runner ID 不复用;每段都必须完成 credential revoke、workspace cleanup 和 retirement。

MOBILE_PLATFORM · SECURITY · QA
UNBOUND HOST CANDIDATE

工具链存在,不代表设备已获准

TOOLCHAIN_PRESENT_HOST_IDENTITY_AND_ISOLATION_UNBOUND
ARCHarm64MACOS26.3.125D2128XCODE26.317C529SWIFT6.2.4ACT_RUNNERABSENTbinary not bound
该快照来自开发工作站只读检查,没有绑定 Runner ID,也没有改变设备、LaunchDaemon 或 Gitea。
LIVE GITEA INVENTORY

现有 Mac Runner 拒绝原因

0 ELIGIBLE
online
pp-mac-ios-runner-codex#27 · repository:jx-im/im-client-ios-swift
REUSABLEDENIED_WRONG_REPOSITORY_SCOPE_AND_REUSABLE

Online is not enough: this runner belongs to an unrelated repository, is reusable and has no signed host or cleanup receipt.

offline
pp-mac-ios-runner#1 · repository:jx-im/im-client-ios-swift
REUSABLEDENIED_OFFLINE_REUSABLE_AND_LABEL_COLLISION

The offline registration is reusable and mixes macOS and Ubuntu labels.

EXACT NATIVE WORKLOAD LEDGER

绿色结果、任务身份和资格回执分列

0 / 2 QUALIFIED
01
reits/matrix-quant-im-iossuccesse4813fd23765
run / job
66958 / 87631
runner
41 · codex-mx-ios-foundation-v2-20260724
label
mq-ios-foundation-ci-20260724

RAW_NATIVE_SUCCESS_SCOPE_EPHEMERAL_CLEANUP_AND_SIGNATURES_UNPROVEN

NO RECEIPT
02
jx-im/im-media-send-kitcancelledd5f0e3e5d658
run / job
66045 / 86511
runner
NONE · not assigned
label
macos-latest

NO_NATIVE_EXECUTION

NO RECEIPT
01
PREFLIGHT · Device OwnerSeal host and toolchain profile
REPOSITORY_BOUND_LIVE_RECEIPT_REQUIRED
02
REGISTER_REITS · REITs Organization OwnerCreate one ephemeral organization registration with a dedicated native label
OWNER_ACTION_REQUIRED
03
RUN_IOS · Mobile PlatformExecute the exact iOS policy job and retain the job identity
BLOCKED_PREDECESSOR
04
DESTROY_REITS · Device OwnerDestroy runner credential, workspace, DerivedData and simulator state
BLOCKED_PREDECESSOR
05
REGISTER_JXIM · jx-im Repository OwnerCreate one separate ephemeral repository registration
OWNER_ACTION_REQUIRED
06
RUN_SWIFT · Mobile PlatformExecute the exact Swift package job
BLOCKED_PREDECESSOR
07
DESTROY_JXIM · Device OwnerDestroy the second runner generation and all job state
BLOCKED_PREDECESSOR
08
SIGN · Mobile Platform + Security + QASign the same fresh two-job qualification receipt
0_OF_3_SIGNATURES
G02 CANDIDATE EQUATION
2 / 2exact jobs
+
2 / 2ephemeral registrations
+
2 / 2cleanups
+
6 / 6hostile probes
+
3 / 3signatures
Current accepted values: 0 + 0 + 0 + 0 + 0
M01NOT_RUN

Registration token unreadable by job user

Expected · DENY
M02NOT_RUN

Runner credential cannot poll a second job

Expected · DENY
M03NOT_RUN

Personal keychain and iCloud identities absent

Expected · DENY
M04NOT_RUN

Docker socket, cloud authority and production routes absent

Expected · DENY
M05NOT_RUN

Signed native toolchain matches the job host

Expected · PASS
M06NOT_RUN

Workspace and simulator state destroyed before scope switch

Expected · PASS
N01IMPLEMENTED_PENDING_OWNER_AUTHORITY

Two explicit scopes

The reits organization and jx-im repository use separate registration authorities and runner generations.

N02IMPLEMENTED_PENDING_HOST_BINDING

Dedicated physical Mac

The accepted host has no personal session, production route, cloud authority or unrelated runner service.

N03IMPLEMENTED_PENDING_LIVE_RECEIPT

One credential, one job

act_runner 0.2.12+ ephemeral registration revokes the exposed runner credential before untrusted steps.

N04IMPLEMENTED_PENDING_LIVE_BINDING

Platform-safe scheduling

The reits organization lane uses a dedicated label; the generic macos label is allowed only inside the exact jx-im repository scope.

N05IMPLEMENTED_PENDING_SIGNED_PROFILE

Native toolchain identity

Architecture, macOS build, Xcode build, Swift version and developer directory are bound to the receipt.

N06IMPLEMENTED_PENDING_HOST_PROBES

Credential and network firebreak

Root registration material, login keychain, iCloud identity, Docker socket, cloud credentials and production routes are denied.

N07IMPLEMENTED_PENDING_TWO_CLEANUPS

Serial cleanup boundary

Runner state, workspace, DerivedData and simulator data are destroyed before another scope is registered.

N08IMPLEMENTED_PENDING_KEYS

Independent admission

Mobile Platform, Security and QA sign one plan-bound receipt with distinct Ed25519 keys.

CURRENT BLOCK

D05-T05 repository engineering is complete: exact native workloads, two-scope serial registration, dedicated-host profile, six probes, two cleanup receipts and three-party signed admission are executable. Live acceptance remains blocked because the only online Mac runner is reusable and scoped to an unrelated repository, the historical iOS success has no trusted scope or cleanup receipt, the Swift package job is cancelled, accepted receipts remain 0/2, G02 remains false, D05 remains 0/11 and implementation remains 4/36.

D05-T06 · INDEPENDENT CONTROLLER DEPLOYMENT

8110 只能出现在独立控制面,不能借 Portal 主机偷跑

最新 EC2 只读盘点确认 Portal 正运行于 8100,但该主机存在生产标记,Controller unit、manifest、readiness、进程和 8110 全部缺席。仓库现在把 6 个 exact artifact、6 个生产组件资格、11 项 readiness、8 项 runtime probe 与 Security / Runtime / SRE 三方签名整理为一份可执行资格包;G01–G04 未闭合前仍拒绝安装。

REPOSITORY PACKETIMPLEMENTEDD05‑T06plan · preflight · collector · verifier · receipt contract
DEPENDENCY GATESDENIED0 / 4G01–G04 required before installation
PRODUCTION COMPONENTSUNBOUND0 / 6repository candidate ≠ production receipt
READINESS RECEIPTSABSENT0 / 11caller boolean cannot promote readiness
LOOPBACK LISTENERABSENT0 / 1127.0.0.1:8110 · no public route
CURRENT HOSTFORBIDDEN

shared production application EC2

8100

Portal 正常运行,但生产主机标记会同时触发 unit 与 preflight 的 co-location 拒绝。

/etc/reits-production-host · PRESENT
TARGET TRUST DOMAINNOT PROVISIONED

dedicated linux-amd64 control plane

8110

无公网 IP、无入站规则、无生产路由、无 instance profile、无 IMDS、无 Runner 共置。

127.0.0.1:8110 · reverse proxy 0
QUALIFICATION0 / 3

One fresh exact receipt

2h

同一 release、host、manifest、unit、六组件、11 receipts、8 probes 和 rollback。

SECURITY · RUNTIME · SRE
LIVE EC2 READ-ONLY AUDIT

共享生产机保持关闭状态

DENIED_SHARED_PRODUCTION_HOST_AND_REQUIRED_RUNTIME_ABSENT
PRODUCTION MARKERPRESENTDEDICATED MARKERABSENTUNIT / PROCESS0 / 0MANIFEST / RECEIPTS0 / 0PUBLIC ROUTES08110 LISTENERS0
developer-portal@0d22b6098f92-7015f86fa477 · observed 2026-07-24T09:46:42Z
SIX-COMPONENT PRODUCTION BINDING

代码候选与生产资格分列

0 / 6 BOUND
01
RESERVATION_READERREAD_ONLY
REPOSITORYPRODUCTION · NO
02
CAPACITY_READERREAD_ONLY
REPOSITORYPRODUCTION · NO
03
WORKER_READERREAD_ONLY
REPOSITORYPRODUCTION · NO
04
RUNNER_READERREAD_ONLY
REPOSITORYPRODUCTION · NO
05
JOURNAL_READERREAD_ONLY
REPOSITORYPRODUCTION · NO
06
READINESS_VERIFIERVERIFY_ONLY
REPOSITORYPRODUCTION · NO
ELEVEN-SOURCE READINESS

每个 Owner 都必须交付可验证回执

0 / 11 READY
01
DEDICATED_HOSTPLATFORM_SRE
MISSING
02
SERVICE_IDENTITYSECURITY
MISSING
03
WEBHOOK_SECRETSECURITY
MISSING
04
RESERVATION_STOREDATA_PLATFORM
MISSING
05
RECEIPT_SIGNERSECURITY
MISSING
06
TOKEN_BROKERDEVELOPER_PLATFORM
MISSING
07
WORKER_PROVIDERPLATFORM_SRE
MISSING
08
GITEA_CONTROLDEVELOPER_PLATFORM
MISSING
09
CAPACITY_CONTROLLERPLATFORM_SRE
MISSING
10
AUDIT_SINKQA_ARCHITECTURE
MISSING
11
OWNER_APPROVALPRODUCT_OWNER
MISSING
01
DEPENDENCIES · Gate OwnersVerify fresh positive G01-G04 receipts
0_OF_4
02
HOST · Platform SREAttest a stopped dedicated host
HOST_ABSENT
03
INSTALL · Security + RuntimeInstall exact release, identity, manifest and credential reference
BLOCKED_PREDECESSOR
04
BIND · RuntimeBind six production-qualified components
0_OF_6
05
READY · Gate OwnersVerify all readiness receipts
0_OF_11
06
LISTEN · Release OwnerStart exactly one loopback listener
0_LISTENERS
07
PROBE · Security + QARun negative webhook, route, restart and stop probes
0_OF_8
08
SIGN · Security + Runtime + SRESign one fresh exact qualification receipt
0_OF_3
T06 QUALIFICATION EQUATION
4 / 4dependency gates
+
6 / 6exact artifacts
+
6 / 6production components
+
11 / 11readiness
+
8 / 8runtime probes
+
3 / 3signatures
Current accepted values: 0 + 0 + 0 + 0 + 0 + 0
C01NOT_RUN

Dedicated host identity

signed evidence · absent
C02NOT_RUN

Network and cloud authority absence

signed evidence · absent
C03NOT_RUN

Service identity and systemd sandbox

signed evidence · absent
C04NOT_RUN

Manifest, credential reference and six components

signed evidence · absent
C05NOT_RUN

Health plus 11 of 11 readiness

signed evidence · absent
C06NOT_RUN

Negative webhook rejection

signed evidence · absent
C07NOT_RUN

No public or reverse-proxy route

signed evidence · absent
C08NOT_RUN

Restart, stop closure and rollback

signed evidence · absent
HOST-FIREBREAKREPOSITORY_BOUND

Production host marker blocks co-location

The unit and preflight both reject /etc/reits-production-host; the Portal EC2 is an explicit denial fixture.

LOOPBACK-ONLYREPOSITORY_BOUND

8110 cannot become a public application route

Exact bind 127.0.0.1, IPAddressDeny=any, IPAddressAllow=localhost and zero reverse proxy routes are required.

ROOT-MANIFESTREPOSITORY_BOUND

Runtime configuration is not caller supplied

One root-owned 0640 manifest and exact ConfigRef/KeyRef digests must feed the six-component bootstrap.

CREDENTIAL-REFERENCEREPOSITORY_BOUND

Webhook credential values never enter evidence

systemd LoadCredential and /run/credentials references are permitted; secret-shaped JSON fields are denied.

READINESS-NO-BOOLEANREPOSITORY_BOUND

Readiness requires eleven signed receipts

A caller ready=true value, repository fixture or HTTP 200 without the verified receipt chain cannot promote readiness.

NEGATIVE-WEBHOOKREPOSITORY_BOUND

Bad requests must fail closed

Unsigned, malformed and non-loopback webhook probes are mandatory and cannot create a plan, worker or external write.

STOP-AND-ROLLBACKREPOSITORY_BOUND

Listener closure and predecessor recovery are evidence

Stop must close 8110, rollback must restore the named predecessor and neither transition may expose a public route.

THREE-PARTY-SIGNATUREREPOSITORY_BOUND

Runtime cannot self-approve

Distinct Security, Runtime and SRE Ed25519 principals sign the same two-hour receipt.

CURRENT BLOCK

D05-T06 is repository-complete only. The current EC2 is a shared production application host and is forbidden by both the unit and preflight. Installation requires fresh G01-G04 receipts, a separately authorized dedicated host, six production component qualifications, eleven signed readiness receipts, eight probes and three independent signatures. No service, listener, route, credential, paid resource or D05 acceptance was created.

D05-T07 · EXACT RELEASE + INTENTIONAL ROLLBACK

发布身份不是版本号;回滚不是把旧目录写进表格

这一刀把 G09/G10 的证据主体校正为独立主机上的 reits-runner-factory-controller。Portal 的 EC2 release 和 Sites version 只负责承载架构说明,不能替 Controller 获得发布或回滚资格。只有 T06 正向回执、六字段同源身份、四类证明、八步有序回滚和四方独立签名同时成立,才产生 G09/G10 候选。

REPOSITORY PACKETIMPLEMENTEDD05‑T07plan · preflight · collector · verifier · keyring
ELIGIBLE CONTROLLER RELEASEABSENT0 / 1dedicated host + exact signed current release
IDENTITY / ATTESTATIONSUNBOUND0 / 6 · 0 / 4source → artifact → runtime
ROLLBACK CHAINNOT EXECUTED0 / 8current → predecessor → exact current
INDEPENDENT SIGNATURESABSENT0 / 4distinct role · principal · Ed25519 key
TRUST-BOUNDARY CORRECTIONDeveloper Portal / Sites ≠ Runner Controller

旧 release evidence 保留为 point-in-time 历史快照,不再作为当前 T07 资格。G09/G10 的唯一合格主体是 dedicated control-plane host 上的 Controller 服务。

PORTAL · EXCLUDEDSITES · EXCLUDEDCONTROLLER · ONLY ELIGIBLE SUBJECT
01 · EXACT CURRENTABSENT
runner-controller@source-artifact

签名 provenance、SBOM、配置、迁移集合与运行态必须指向同一不可变 materialization。

/releases/<current-source>
02 · NAMED PREDECESSORABSENT
distinct production-qualified release

只能切换到已知、已签名、已生产合格且与 current 不同的精确前序版本。

/releases/<predecessor-source>
03 · RECOVERED CURRENTNOT_EXECUTED
same exact original identity

恢复后必须回到最初 current release,并持续观察至少 60 秒;前序版本不得残留激活。

final === before · exact bytes
READ-ONLY PRODUCTION OBSERVATION

运行中的文档目标与缺席的 Controller 分列

2026-07-24T10:10:20Z
PORTAL EC2developer-portal@b054fafa3f83-2a8ba8c119abDOCUMENTATION · INELIGIBLESITESv258 · succeededDOCUMENTATION · INELIGIBLECONTROLLER UNIT / 8110not-found · 0QUALIFICATION · ABSENTT06 / RELEASE / ROLLBACK RECEIPTS0 / 0 / 0LIVE EVIDENCE · ABSENT
SIX-FIELD SUBJECT IDENTITY

任何一个字段漂移都拒绝整份回执

0 / 6 BOUND
01
SOURCEexact 40-character Controller source revision
not observedMISSING
02
ARTIFACTimmutable Controller artifact sha256
not observedMISSING
03
SBOMCycloneDX SBOM digest bound to the artifact
not observedMISSING
04
CONFIGroot-owned production configuration digest
not observedMISSING
05
MIGRATIONexplicit migration-set digest including an empty set
not observedMISSING
06
RUNTIMElive runner-controller@source-artifact identity
not observedMISSING
01
SUPPLY_CHAINSIGNED BUILD PROVENANCE
MISSING
02
SREIMMUTABLE ROOT OWNED MATERIALIZATION
MISSING
03
RUNTIMELIVE CONTROLLER RUNTIME IDENTITY
MISSING
04
INDEPENDENT_QAORDERED ROLLBACK RECOVERY CHAIN
MISSING
ORDERED ROLLBACK RUNBOOK

八个单调递增事件组成一条不可拆分的恢复证据链

0 / 8 EXECUTED
01
RB-01 · Release Engineering + SREMaintenance authorization and automatic recovery guard
NOT_AUTHORIZED
02
RB-02 · Independent QAFreeze exact current identity and runtime state
NOT_EXECUTED
03
RB-03 · Release EngineeringAtomic predecessor switch
NOT_EXECUTED
04
RB-04 · SRE + QAPredecessor identity and readiness verification
NOT_EXECUTED
05
RB-05 · Release EngineeringAtomic recovery to exact original current
NOT_EXECUTED
06
RB-06 · SRE + QARecovered current verification
NOT_EXECUTED
07
RB-07 · Independent QABounded timing, zero loss and zero route proof
NOT_EXECUTED
08
RB-08 · All four rolesFour-party signed qualification receipt
0_OF_4
T07 QUALIFICATION EQUATION
1 / 1live T06 receipt
+
6 / 6identity fields
+
4 / 4attestations
+
8 / 8rollback steps
+
4 / 4signatures
Current accepted values: 0 + 0 + 0 + 0 + 0 · T07 receipt accepts D05: NO
SUPPLY_CHAINUNSIGNED

signed provenance and six-field release identity

distinct principal + key required
RELEASE_ENGINEERINGUNSIGNED

ordered atomic switch and recovery transaction

distinct principal + key required
SREUNSIGNED

host, unit, listener and materialization observation

distinct principal + key required
INDEPENDENT_QAUNSIGNED

timing, readiness, loss and final-state adjudication

distinct principal + key required
SUBJECT-FENCEREPOSITORY_BOUND

Portal release cannot impersonate Controller

Service, host class, release prefix and endpoint are exact; developer-portal@ and Sites versions are always ineligible.

T06-PREDECESSORREPOSITORY_BOUND

Live T06 qualification is mandatory

The receipt must bind the same dedicated host, 11/11 readiness and one loopback listener.

SIX-FIELD-IDENTITYREPOSITORY_BOUND

Source through runtime remain one subject

Source, artifact, SBOM, configuration, migration and runtime release ID are independently signed.

IMMUTABLE-ROOTSREPOSITORY_BOUND

Both releases are immutable materializations

Current and predecessor roots are root-owned, exact-digest verified and not writable by the service identity.

ORDERED-ROLLBACKREPOSITORY_BOUND

Eight events form one monotonic chain

Missing, duplicate, reordered or cross-host events deny the receipt.

AUTO-RECOVERYREPOSITORY_BOUND

The drill cannot strand the predecessor

A recovery guard is armed before the switch; the final release must equal the exact original current.

LOOPBACK-INVARIANTREPOSITORY_BOUND

8110 remains private throughout

Before, predecessor and after observations each require one 127.0.0.1 listener and zero public routes.

FOUR-PARTY-SEALREPOSITORY_BOUND

Publisher cannot approve its own drill

Supply Chain, Release Engineering, SRE and Independent QA use distinct principals and Ed25519 keys.

CURRENT BLOCK

D05-T07 repository contracts are complete, but no eligible Controller release, live T06 receipt, signed provenance, immutable Controller materialization, rollback event or independent signature exists. The running Developer Portal and owner-only Sites version document the architecture only; neither can satisfy Controller G09 or G10. D05 remains 0/11 and 4/36.

D05-T08 · FOUR-OWNER FINAL ACCEPTANCE

最后一刀不是再画一个绿勾,而是封存可被四方签署的完整判决对象

T08 把 G01–G11、T07 rollback、exact release、预算、运行终态与四个独立责任席位收进同一份 30 分钟终验收据。验证器只能输出候选晋级授权,不能修改实施账本;真正的 4/36 D05 → 5/36 D06 仍须由外部账本 authority 执行一次 CAS。

REPOSITORY SEQUENCECOMPLETE8 / 8T01–T08 packets · no next repository task
LIVE GATESDENIED0 / 11same release · fresh · independently signed
CLOSURE DOSSIERABSENT0 / 1canonical SHA-256 sealed decision object
FINAL APPROVALSUNSIGNED0 / 4FinOps · Runtime · Security · Product
PROGRAM LEDGERCAS BLOCKED4 → 5 / 36D05 remains active · D06 is only a candidate
CURRENT AUTHORITY MAP历史 release / owner 快照不再决定本次终验

G09/G10 只读取当前 T07 Controller release + rollback qualification;G11 只读取本 T08 四方终验。运行中的 Portal release 与 Sites version 是文档目标,不是 Controller 的资格主体。

01 · GATESBLOCKED
0/11

G01-G11 are satisfied for one exact release

02 · DOSSIERBLOCKED
0/1

seal the exact fresh closure dossier

03 · INDEPENDENT_REVIEWSBLOCKED
0/3

FinOps, Runtime and Security sign independently

04 · PRODUCT_DECISIONBLOCKED
0/1

Product signs after all independent reviewers

05 · CASBLOCKED
0/1

external ledger authority compares 4/36 D05 then advances to 5/36 D06

ELEVEN-GATE CLOSURE ROSTER

每一道门都必须绑定同一 exact release

0 / 11 LIVE
D05-G01
Linux organization Runner capacityPlatform SRE · D05-T04
CAPACITYDENIED
D05-G02
Native Mac Runner capacityMobile Platform · D05-T05
CAPACITYDENIED
D05-G03
Credential and network isolationSecurity · D05-T06
READINESSDENIED
D05-G04
Controller production assemblyArchitecture · D05-T06
READINESSDENIED
D05-G05
Eleven readiness checksController Owner · D05-T06
ACTIVATIONDENIED
D05-G06
Single loopback listener on 8110Runtime Owner · D05-T06
ACTIVATIONDENIED
D05-G07
Hardened dedicated-host installationPlatform SRE · D05-T06
INSTALLATIONDENIED
D05-G08
Live negative and recovery probesIndependent QA · D05-T06
INSTALLATIONDENIED
D05-G09
Exact signed Controller release identitySupply Chain · D05-T07
RELEASEDENIED
D05-G10
Intentional rollback and exact recoveryRelease Engineering · D05-T07
RELEASEDENIED
D05-G11
Four-owner final acceptanceProduct Owner · D05-T08
FINALDENIED
EXACT CLOSURE DOSSIER

签署人看到的是同一份字节对象

ABSENT
EXPECTED IDENTITYd05-final@source-artifactsha256: canonical(payload)
  1. 01

    exact source, artifact, SBOM, configuration, migration and runtime release identity

  2. 02

    eleven ordered fresh independently signed gate receipts

  3. 03

    live T07 rollback qualification bound to the same host and release

  4. 04

    bounded budget and one private 8110 listener with zero public routes

  5. 05

    four distinct final principals and public keys

FRESHNESS ≤ 30 min final · ≤ 120 min gatesRUNTIME 11/11 ready · 8110 × 1 · public × 0RECOVERY exact current · data loss × 0
FINAL ACCEPTANCE EQUATION · ALL TERMS ARE CONJUNCTIVE
11 / 11fresh gates
+
1 / 1exact dossier
+
1 / 1live T07
+
4 / 4final approvals
+
1 / 1ledger CAS
= D05 ACCEPTED
CURRENT · 0 + 0 + 0 + 0 + 0 = DENIED · repository 8/8 does not change the production result
01MISSING
FINOPS

budget ceiling, hold and expiry

independent review · distinct principal + Ed25519 key
02MISSING
RUNTIME_OWNER

11/11 readiness, listener, rollback and final runtime

independent review · distinct principal + Ed25519 key
03MISSING
SECURITY_OWNER

subject, signatures, freshness, isolation and zero public route

independent review · distinct principal + Ed25519 key
04MISSING
PRODUCT_OWNER

final business acceptance after all independent reviews

must sign last · distinct principal + Ed25519 key
EXACT-SUBJECTREPOSITORY_BOUND

One Controller release only

Every receipt binds the same service, host, source, artifact, configuration and runtime identity.

ELEVEN-OF-ELEVENREPOSITORY_BOUND

No partial gate closure

Missing, duplicate, reordered, cross-release or unsigned G01-G11 evidence denies final acceptance.

FRESHNESSREPOSITORY_BOUND

Point-in-time truth

Final receipt lasts at most 30 minutes and no gate evidence may exceed 120 minutes.

DOSSIER-SEALREPOSITORY_BOUND

Exact byte closure

A canonical SHA-256 dossier binds release identity, receipts and runtime outcome.

SEPARATION-OF-DUTIESREPOSITORY_BOUND

Four independent principals

FinOps, Runtime, Security and Product use distinct principals and Ed25519 public keys.

PRODUCT-LASTREPOSITORY_BOUND

Product cannot pre-approve

Product acceptance must be signed strictly after all three independent reviews.

ZERO-EFFECT-VERIFIERREPOSITORY_BOUND

Verification does not mutate

The verifier authorizes a candidate transition but executes zero ledger, runtime or cloud writes.

LEDGER-CASREPOSITORY_BOUND

No stale program advance

A separate authority must compare current 4/36 D05 before advancing exactly once to 5/36 D06.

REPOSITORY 8/8 · LIVE EXECUTION RETURNS TO D05-T02

D05-T08 completes the eighth and final repository task, not the production acceptance. The eligible subject is only an exact production-qualified Controller release on its dedicated host. With G01-G11 at 0/11, no closure dossier, no live T07 receipt, no four-owner signatures and no ledger compare-and-swap, D05 remains unaccepted at 4/36. Repository work has no successor task; live execution returns to D05-T02 and D06 remains blocked.

LIVE RUNTIME TRUTH

Portal 在线,不等于 Controller 已部署

2026-07-24 只读快照;所有数字来自最新 EC2 和已有生产证据,未创建资源、未安装 unit、未启动 8110。发布 SHA 绑定当前 Portal exact release,但不冒充 Controller release。

AUDIT BASELINE8ae9d1b4observed EC2 release
PORTAL SERVICEACTIVE127.0.0.1:8100 · 1 listener
CONTROLLER PORT08110 listeners
CONTROLLER UNITS0systemd units
INSTALL ROOTS0dedicated roots
LOCAL AWS CLIABSENTno cloud apply authority

D05 · ELEVEN-GATE MATRIX

11 个门全部显示真实阻塞,不用绿色占位

11 个 Gate denied;第一个失败是 D05-G01。每个卡片都绑定责任人、目标、观测和机器证据。

D05-G01DENIED
G01–G02 · Runner capacity

ORGANIZATION LINUX RUNNER CAPACITY

OWNER
PLATFORM_SRE
TARGET
2 organization-scoped Linux runners; concurrency one; single-use ephemeral boundary
OBSERVED
1 台 Linux 候选、1 台在线;组织级 0、ephemeral 0、合格 0
DENIED_NO_ORGANIZATION_EPHEMERAL_CAPACITY证据 →
D05-G02DENIED
G01–G02 · Runner capacity

INDEPENDENT MAC RUNNER LANE

OWNER
MOBILE_PLATFORM
TARGET
1 online organization-scoped Mac runner with platform-safe labels and signed native job receipt
OBSERVED
8 台 Mac 候选、6 台在线;全部仓库级可复用,部分标签混用;合格 0
D05-G03DENIED
G03–G04 · Configuration + factories

ROOT OWNED RUNTIME CONFIGURATION

OWNER
SECURITY
TARGET
root-owned canonical manifest, eleven typed ConfigRefs, one verify-only KeyRef and a least-visible SecretRef boundary
OBSERVED
manifest, service identity and resolved production references are absent on the production host
D05-G04DENIED
G03–G04 · Configuration + factories

REVIEWED PRODUCTION FACTORIES

OWNER
GLOBAL_ARCHITECTURE
TARGET
six reviewed production factories, five authority-pinned read sources and one verify-only attestation verifier
OBSERVED
closed source implementations and fixture proofs exist, but every factory remains TEST_ONLY with zero production bindings
D05-G05DENIED
G05–G06 · Readiness + listener

ELEVEN LIVE READINESS RECEIPTS

OWNER
CONTROLLER_OWNER
TARGET
eleven fresh signature-verified readiness receipts bound to one Controller release, manifest, configuration and runtime identity
OBSERVED
zero readiness directory, zero receipt files, zero configured Gates and no Controller runtime identity on the production host
D05-G06DENIED
G05–G06 · Readiness + listener

INDEPENDENT LISTENER AUTHORIZATION

OWNER
RELEASE_OWNER
TARGET
one independent expiring authorization bound to exact host, release, config, unit, endpoint, rollback, negative webhook proof and four approvals
OBSERVED
authorization file, systemd unit, loopback listener and reverse proxy route are all absent
D05-G07DENIED
G07–G08 · Installation + live probes

HARDENED CONTROLLER INSTALLATION

OWNER
PLATFORM_SRE
TARGET
non-login identity, root-owned unit, exact digest, filesystem ownership, credential references, hardening profile, loopback-only network policy and signed installation receipt
OBSERVED
service user, group, unit, installation root, runtime directories, manifest, process and listener are absent
D05-G08DENIED
G07–G08 · Installation + live probes

LIVE HEALTH READINESS NEGATIVE WEBHOOK

OWNER
QA
TARGET
live health and readiness receipts plus unsigned, invalid-signature, stale, replay, wrong-scope and unready webhook denial receipts
OBSERVED
health, readiness and six webhook probe attempts all returned HTTP 000 because the Controller listener is absent; connection refusal is not application-level denial proof
D05-G09DENIED
G09–G10 · Identity + rollback

Exact signed Controller release identity

OWNER
Supply Chain
TARGET
exact production-qualified runner-controller release on the dedicated control-plane host
OBSERVED
0 positive receipts · source D05-T07
D05-G10DENIED
G09–G10 · Identity + rollback

Intentional rollback and exact recovery

OWNER
Release Engineering
TARGET
exact production-qualified runner-controller release on the dedicated control-plane host
OBSERVED
0 positive receipts · source D05-T07
D05-G11DENIED
G11 · Four-owner final acceptance

Four-owner final acceptance

OWNER
Product Owner
TARGET
exact production-qualified runner-controller release on the dedicated control-plane host
OBSERVED
0 positive receipts · source D05-T08

AUTHORITY FIREWALL

代码权限、外部身份与付费生产权限分开

“继续开发”允许完成安全的仓库实现,但不会自动授予云成本、设备控制、生产变更或多方签署权限。

SAFE_LOCAL1

可直接执行

Portal、契约、测试、静态基础设施与 fail-closed 安全修复

OWNER_INPUT2

需要外部身份/设备

AWS 验证身份

Mac Runner 主机与设备 Owner

PAID_PRODUCTION3

需要成本/生产批准

两 AZ Runner 资源

独立 Controller 主机与 8110

Intentional rollback drill

ORDERED EXECUTION

从第一个可执行修复走到 D05 四方验收

顺序表达安全和证据依赖。跳过前置、只看到 HTTP 200 或只创建资源,都不能推进实施计数。

01
D05-T01 · Platform Engineering + Security

修复 Runner 凭据与任务隔离边界

组织 Runner 必须 single-use;任务不可读取可复用 daemon credential;不得进入生产 VPC。

02
D05-T02 · Cloud Account Owner

恢复独立 AWS 验证身份

仓库已交付一小时临时角色、最小权限边界、精确身份检查、ValidateTemplate 和 deny probe;Cloud Owner 尚未创建角色,AWS 仍未在线接受。

03
D05-T03 · Product Owner + FinOps

批准两台隔离 Linux Runner 成本

官方 Sydney SKU 报价、精确模板摘要、Product Owner + FinOps Ed25519 双签名、USD 250 上限和非续期 ASG 归零租约已实现;真实签名仍为 0/2。

04
D05-T04 · Platform SRE

部署并完成 18 仓隔离演练

精确 18 仓 revision、17+1 scope 分区、7 项恶意探针、两次整机替换与三方签名验证器已完成;在线执行仍等待 T02、T03 和 shared repo owner 决策。

05
D05-T05 · Mobile Platform + Security + QA

恢复独立 Mac 原生 Runner

两个精确原生 workload、两段串行 ephemeral scope、专用主机与工具链证明、六项恶意探针、两份 cleanup 回执和三方 Ed25519 验证已实现;在线 Mac Runner 仍是错误单仓 scope 且可复用,合格回执为 0/2。

06
D05-T06 · Security + Runtime + SRE

部署独立 Controller 与 8110

dedicated-host preflight、六个 exact artifact、六个 production component receipt、11 项 readiness、8 项 probe 与三方 Ed25519 资格包已实现;G01–G04、独立主机和 8110 在线回执仍为零。

07
D05-T07 · Supply Chain + QA + Release

签署 release identity 并执行 intentional rollback

source/artifact/SBOM/config/migration/runtime 六项同源签署;真实回滚和恢复观察窗。

08
D05-T08 · Cost + Runtime + Security + Product

完成 G11 四方验收

11/11 Gate、freshness、独立签名、exact release binding 与 Product Owner 决策缺一不可。

DEPENDENCY FAN-OUT

D05 未验收会直接拦住 7 刀

这是全局架构层面的真实关键路径:发布底座没闭环,身份、媒体、可观测、恢复、行情和最终发布都不能安全前推。

D06W1

浏览器认证 SDK / BFF

Identity Platform

PLANNED
D07W1

MFA、恢复与签名密钥 Phase B

Identity Security

PLANNED
D12W2

Media 生产部署与隔离直传

Media Platform

PLANNED
D14W2

关联可观测、状态与事件指挥

Site Reliability Engineering

PLANNED
D15W2

完整备份与隔离恢复

Recovery Engineering

PLANNED
D29W5

Trading 持久任务、SecretRef 与生产部署

Market Data

PLANNED
D35W6

Exact Release、生产 Smoke 与回滚证明

Release Engineering + Operations

PLANNED
TRANSITION ARTIFACT COMPLETE

D05‑T01 至 T08 仓库序列 8/8 收口,真实终验仍从 Cloud Owner 的 T02 开始

T08 已把 G01–G11、exact Controller release、真实 rollback、预算终态、四个独立 Ed25519 席位、Product 最后签署和账本 CAS 收进 fail-closed 机器契约。当前 Portal EC2 和 Sites 只承载架构文档,明确排除在 Controller G09–G11 之外;Controller unit、8110、T07 回执、closure dossier、终验签名与账本写入仍全部为零。仓库开发没有下一任务;线上执行回到最早未完成的 D05‑T02。只有 11/11 门禁、1/1 dossier、1/1 T07、4/4 签署和 1/1 CAS 全部成立,实施账本才可从 4/36 变为 5/36,并解锁 D06。