IMPLEMENTATION KNIFE 05 / 36 · TRANSITION CLOSEOUT
蓝图已收口,真实实现从红门开始
这里不再增加架构刀次。104/104 已闭环;实施账本仍为 4/36,当前 D05。D05‑T01 至 T08 的仓库实现已全部完成(8/8);独立 AWS 角色、成本双签、组织 Runner、原生 Mac 双作用域、dedicated Controller 主机、签名发布、真实回滚与四方终验都尚未在线完成,11 个生产 Gate 全部保持红门。
D05-T01 · CREDENTIAL FIREBREAK
凭据、任务、网络与整机生命周期已经拆开
这是可部署的仓库实现,不是云上验收。一次性 Runner credential 在任务前撤销;任务只进入受限 Docker 容器;AWS authority 在 daemon 启动前隔离;单任务结束后整机退役。
CRED-01REPOSITORY_BOUNDEphemeral runner credential
register --ephemeral; Gitea revokes the exposed runner credential before untrusted code starts
TASK-01REPOSITORY_BOUNDTask container boundary
digest-pinned docker:// labels, privileged=false, valid_volumes=[], docker_host="-" and no host socket mount
CLOUD-01REPOSITORY_BOUNDZero cloud authority at execution
IMDS disabled and instance profile detached before the daemon starts
NET-01REPOSITORY_BOUNDProxy-only task egress
reits-ci0 may reach only 172.30.0.1:3128; task DNS points to empty container loopback; Docker image pulls use loopback Squid; other host and forwarded sockets are rejected
LIFE-01REPOSITORY_BOUNDWhole-machine retirement
daemon exits after one job; credential and task roots are wiped; VM powers off; ASG replaces it
New encrypted Ubuntu VM starts in the isolated CI VPC with a temporary bootstrap profile.
Root retrieves the SSM registration token and creates one ephemeral organization runner credential while the daemon is offline.
The node disables IMDS, detaches its profile, signals CloudFormation, erases temporary AWS values and writes the activation marker.
The unprivileged daemon accepts one job; untrusted steps execute in a bounded Docker container without the host socket or runner credential.
Task traffic is forced through the dedicated bridge to the root-managed CONNECT allowlist; private and direct destinations are denied.
After the one job or any daemon failure, the host deletes containers, workspace, temp data and .runner, then powers off for ASG replacement.
D05-T02 · AWS VALIDATION IDENTITY
验证身份只验证模板,不能顺手变成部署身份
独立角色、临时会话、精确账号与 ARN、固定模板和负向权限探针组成一条可审计链。仓库包已经完整;当前工作区没有 AWS CLI,Cloud Owner 也尚未安装角色,所以所有在线证据继续为零。
cloudformation:ValidateTemplateALLOW
sts:GetCallerIdentityALLOW
cloudformation:Create* / Update* / Delete*DENY
ec2:* · iam:* · ssm:* · secretsmanager:*DENY
Install the role template with an exact trusted IAM principal and out-of-band external ID.
Use an explicit AWS CLI role profile backed by federated or otherwise temporary source credentials.
Call STS GetCallerIdentity and require the exact assumed-role ARN and expected account.
Validate only the pinned runner template body in ap-southeast-2; do not create a change set or stack.
Require a read-only EC2 DescribeInstances probe to fail with AccessDenied, proving the role is not a general cloud identity.
Write a secret-free local receipt binding account, principal, template SHA-256, region and validation response.
D05-T03 · COST AUTHORITY
把报价、批准与自动停机绑定到同一份基础设施
不是一张随手估价卡:官方 SKU、精确模板摘要、两位独立签署人、31 天非续期租约和部署拒绝逻辑共同构成成本准入。当前只是仓库实现完成,Product Owner 与 FinOps 均未签字。
1460 instance-hours × 0.1056160 GB-month × 0.0961460 address-hours × 0.005730-hour planning month两把不同的钥匙,批准同一精确事实
Approve business need, two-runner scope and non-renewing lease.
principal absentApprove current quote, USD ceiling, exclusions and account budget ownership.
principal absentC01IMPLEMENTEDExact source binding
Receipt binds the request digest, runner template SHA-256, region and approved ceiling.
C02IMPLEMENTED_PENDING_KEYSDual-owner signature
Ed25519 signatures from distinct trusted Product Owner and FinOps principals are mandatory.
C03IMPLEMENTEDBounded compute rate
T3 CPU credits use standard mode and paid one-minute detailed monitoring is disabled.
C04IMPLEMENTEDNo hidden network appliance
The stack contains no NAT Gateway or load balancer; two charged public IPv4 addresses are explicit.
C05IMPLEMENTEDNon-renewing lease
A CloudFormation scheduled action sets ASG min, desired and max capacity to zero at receipt expiry.
C06IMPLEMENTEDFail-closed deploy
The deploy path rejects absent, stale, over-cap, wrong-region, wrong-template or invalid signatures before mutation.
Internet and regional data transfer · Single-job replacement overlap · Taxes, credits, discounts and currency conversion · Any resource or performance setting outside the exact template
D05-T03 repository engineering is complete: the official price snapshot, exact quote, dual-signature receipt verifier, deploy admission and lease expiry are implemented. Product Owner and FinOps have not signed, no cost receipt is valid, D05-T02 live AWS identity remains the current executable prerequisite, D05-T04 remains blocked, G01 remains false, D05 remains 0/11 and implementation remains 4/36.
D05-T04 · 18-REPOSITORY ISOLATION QUALIFICATION
把绿色 CI、Runner 身份和整机销毁拆成三份证据
最新远端 HEAD 已重新抓取,18 个 gate 的原始状态是 9 success / 9 cancelled;但它们都没有绑定到两台合格的一次性组织 Runner,所以合格隔离回执仍是 0/18。这里同时暴露此前遗漏的 17+1 scope:jx-im/im-media-send-kit 不在 reits 组织 Runner 的授权范围内。
reits organization repositories
两条 organization-scoped Linux lanes,单机并发 1、单任务退役、无生产路由。
organization:reits → 2 lanesjx-im/im-media-send-kit
Linux gate 需要 ubuntu-latest,但当前 reits 组织 token 无权覆盖这个外部组织仓库。
transfer · separate lane · revise core scopeaccepted isolation receipts
不能静默排除 shared repo,也不能把旧 Runner 的 success 冒充隔离验收。
all conditions required18 仓执行矩阵
8987dc1ef04c4ce6e17bebee6f3a4ee4813fd237ad40fafbc86257ce04cbb238cb6b2c41d67048b740d9219d606a38c3df68cbb20515d5ca769412829c6b70599b6d175fbded7577d3d6464e76349c1470b8242facP01NOT_RUNRunner credential unreadable
Expected: DENY · operator-trusted receipt required
P02NOT_RUNHost Docker socket absent
Expected: DENY · operator-trusted receipt required
P03NOT_RUNIMDS and task credentials unreachable
Expected: DENY · operator-trusted receipt required
P04NOT_RUNProduction network unreachable
Expected: DENY · operator-trusted receipt required
P05NOT_RUNDirect and unlisted egress denied
Expected: DENY · operator-trusted receipt required
P06NOT_RUNCloud authority absent
Expected: DENY · operator-trusted receipt required
P07NOT_RUNPrevious job residue absent on replacement
Expected: PASS · operator-trusted receipt required
Q01IMPLEMENTEDExact 18-repository revision binding
Every gate receipt must match the owner, repository, revision and gate context in the immutable plan.
Q02IMPLEMENTED_PENDING_LIVE_EVIDENCERunner identity provenance
A green CI status is rejected unless it binds the job to an admitted ephemeral runner and instance.
Q03IMPLEMENTED_PENDING_EXECUTIONSeven hostile probes
Credential, socket, metadata, production route, egress, cloud authority and residue boundaries all need operator-trusted receipts.
Q04IMPLEMENTED_PENDING_REPLACEMENTOne job, one machine
Two old-to-new instance transitions must prove retirement, local destruction and clean replacement.
Q05FAIL_CLOSED_OWNER_DECISION_REQUIRED17 + 1 scope partition
The current reits organization token cannot authorize jx-im/im-media-send-kit; the verifier refuses 18/18 until its scope is resolved.
Q06IMPLEMENTED_PENDING_KEYSIndependent three-role acceptance
Platform SRE, Security and QA must sign the same receipt using distinct Ed25519 keys.
D05-T05 · NATIVE MAC RUNNER QUALIFICATION
在线 Mac 只是候选,两个原生任务才构成可签署的 Lane
最新 Gitea 1.25.4 只读审计发现一台在线 Mac Runner,但它属于 jx-im/im-client-ios-swift 单仓且可复用;matrix-quant-im-ios 的历史原生任务虽成功,却没有 scope、ephemeral、cleanup 和签名回执;im-media-send-kit 仍为 cancelled。工作台因此把 1 台物理 Mac、2 个串行 Runner generation、2 个 exact job 和 3 方签名拆开呈现。
Dedicated Apple-silicon Mac
单并发、无个人会话、无生产路由、无云凭据;只允许 root 注册 authority 和 `_reits_ci` 原生任务身份。
arm64 · FileVault · Xcode.app · capacity 1reits/matrix-quant-im-ios
organization:reits
reits-macos-native-v1:hostjx-im/im-media-send-kit
repository:jx-im/im-media-send-kit
macos-latest:hostaccepted native jobs
两段 scope 串行执行,Runner ID 不复用;每段都必须完成 credential revoke、workspace cleanup 和 retirement。
MOBILE_PLATFORM · SECURITY · QA工具链存在,不代表设备已获准
现有 Mac Runner 拒绝原因
#27 · repository:jx-im/im-client-ios-swiftOnline is not enough: this runner belongs to an unrelated repository, is reusable and has no signed host or cleanup receipt.
#1 · repository:jx-im/im-client-ios-swiftThe offline registration is reusable and mixes macOS and Ubuntu labels.
绿色结果、任务身份和资格回执分列
e4813fd23765- run / job
- 66958 / 87631
- runner
- 41 · codex-mx-ios-foundation-v2-20260724
- label
- mq-ios-foundation-ci-20260724
RAW_NATIVE_SUCCESS_SCOPE_EPHEMERAL_CLEANUP_AND_SIGNATURES_UNPROVEN
NO RECEIPTd5f0e3e5d658- run / job
- 66045 / 86511
- runner
- NONE · not assigned
- label
- macos-latest
NO_NATIVE_EXECUTION
NO RECEIPTM01NOT_RUNRegistration token unreadable by job user
Expected · DENYM02NOT_RUNRunner credential cannot poll a second job
Expected · DENYM03NOT_RUNPersonal keychain and iCloud identities absent
Expected · DENYM04NOT_RUNDocker socket, cloud authority and production routes absent
Expected · DENYM05NOT_RUNSigned native toolchain matches the job host
Expected · PASSM06NOT_RUNWorkspace and simulator state destroyed before scope switch
Expected · PASSN01IMPLEMENTED_PENDING_OWNER_AUTHORITYTwo explicit scopes
The reits organization and jx-im repository use separate registration authorities and runner generations.
N02IMPLEMENTED_PENDING_HOST_BINDINGDedicated physical Mac
The accepted host has no personal session, production route, cloud authority or unrelated runner service.
N03IMPLEMENTED_PENDING_LIVE_RECEIPTOne credential, one job
act_runner 0.2.12+ ephemeral registration revokes the exposed runner credential before untrusted steps.
N04IMPLEMENTED_PENDING_LIVE_BINDINGPlatform-safe scheduling
The reits organization lane uses a dedicated label; the generic macos label is allowed only inside the exact jx-im repository scope.
N05IMPLEMENTED_PENDING_SIGNED_PROFILENative toolchain identity
Architecture, macOS build, Xcode build, Swift version and developer directory are bound to the receipt.
N06IMPLEMENTED_PENDING_HOST_PROBESCredential and network firebreak
Root registration material, login keychain, iCloud identity, Docker socket, cloud credentials and production routes are denied.
N07IMPLEMENTED_PENDING_TWO_CLEANUPSSerial cleanup boundary
Runner state, workspace, DerivedData and simulator data are destroyed before another scope is registered.
N08IMPLEMENTED_PENDING_KEYSIndependent admission
Mobile Platform, Security and QA sign one plan-bound receipt with distinct Ed25519 keys.
D05-T06 · INDEPENDENT CONTROLLER DEPLOYMENT
8110 只能出现在独立控制面,不能借 Portal 主机偷跑
最新 EC2 只读盘点确认 Portal 正运行于 8100,但该主机存在生产标记,Controller unit、manifest、readiness、进程和 8110 全部缺席。仓库现在把 6 个 exact artifact、6 个生产组件资格、11 项 readiness、8 项 runtime probe 与 Security / Runtime / SRE 三方签名整理为一份可执行资格包;G01–G04 未闭合前仍拒绝安装。
shared production application EC2
8100Portal 正常运行,但生产主机标记会同时触发 unit 与 preflight 的 co-location 拒绝。
/etc/reits-production-host · PRESENTdedicated linux-amd64 control plane
8110无公网 IP、无入站规则、无生产路由、无 instance profile、无 IMDS、无 Runner 共置。
127.0.0.1:8110 · reverse proxy 0One fresh exact receipt
2h同一 release、host、manifest、unit、六组件、11 receipts、8 probes 和 rollback。
SECURITY · RUNTIME · SRE共享生产机保持关闭状态
代码候选与生产资格分列
每个 Owner 都必须交付可验证回执
C01NOT_RUNDedicated host identity
signed evidence · absentC02NOT_RUNNetwork and cloud authority absence
signed evidence · absentC03NOT_RUNService identity and systemd sandbox
signed evidence · absentC04NOT_RUNManifest, credential reference and six components
signed evidence · absentC05NOT_RUNHealth plus 11 of 11 readiness
signed evidence · absentC06NOT_RUNNegative webhook rejection
signed evidence · absentC07NOT_RUNNo public or reverse-proxy route
signed evidence · absentC08NOT_RUNRestart, stop closure and rollback
signed evidence · absentHOST-FIREBREAKREPOSITORY_BOUNDProduction host marker blocks co-location
The unit and preflight both reject /etc/reits-production-host; the Portal EC2 is an explicit denial fixture.
LOOPBACK-ONLYREPOSITORY_BOUND8110 cannot become a public application route
Exact bind 127.0.0.1, IPAddressDeny=any, IPAddressAllow=localhost and zero reverse proxy routes are required.
ROOT-MANIFESTREPOSITORY_BOUNDRuntime configuration is not caller supplied
One root-owned 0640 manifest and exact ConfigRef/KeyRef digests must feed the six-component bootstrap.
CREDENTIAL-REFERENCEREPOSITORY_BOUNDWebhook credential values never enter evidence
systemd LoadCredential and /run/credentials references are permitted; secret-shaped JSON fields are denied.
READINESS-NO-BOOLEANREPOSITORY_BOUNDReadiness requires eleven signed receipts
A caller ready=true value, repository fixture or HTTP 200 without the verified receipt chain cannot promote readiness.
NEGATIVE-WEBHOOKREPOSITORY_BOUNDBad requests must fail closed
Unsigned, malformed and non-loopback webhook probes are mandatory and cannot create a plan, worker or external write.
STOP-AND-ROLLBACKREPOSITORY_BOUNDListener closure and predecessor recovery are evidence
Stop must close 8110, rollback must restore the named predecessor and neither transition may expose a public route.
THREE-PARTY-SIGNATUREREPOSITORY_BOUNDRuntime cannot self-approve
Distinct Security, Runtime and SRE Ed25519 principals sign the same two-hour receipt.
D05-T07 · EXACT RELEASE + INTENTIONAL ROLLBACK
发布身份不是版本号;回滚不是把旧目录写进表格
这一刀把 G09/G10 的证据主体校正为独立主机上的 reits-runner-factory-controller。Portal 的 EC2 release 和 Sites version 只负责承载架构说明,不能替 Controller 获得发布或回滚资格。只有 T06 正向回执、六字段同源身份、四类证明、八步有序回滚和四方独立签名同时成立,才产生 G09/G10 候选。
旧 release evidence 保留为 point-in-time 历史快照,不再作为当前 T07 资格。G09/G10 的唯一合格主体是 dedicated control-plane host 上的 Controller 服务。
签名 provenance、SBOM、配置、迁移集合与运行态必须指向同一不可变 materialization。
/releases/<current-source>只能切换到已知、已签名、已生产合格且与 current 不同的精确前序版本。
/releases/<predecessor-source>恢复后必须回到最初 current release,并持续观察至少 60 秒;前序版本不得残留激活。
final === before · exact bytes运行中的文档目标与缺席的 Controller 分列
任何一个字段漂移都拒绝整份回执
not observedMISSINGnot observedMISSINGnot observedMISSINGnot observedMISSINGnot observedMISSINGnot observedMISSING八个单调递增事件组成一条不可拆分的恢复证据链
SUPPLY_CHAINUNSIGNEDsigned provenance and six-field release identity
distinct principal + key requiredRELEASE_ENGINEERINGUNSIGNEDordered atomic switch and recovery transaction
distinct principal + key requiredSREUNSIGNEDhost, unit, listener and materialization observation
distinct principal + key requiredINDEPENDENT_QAUNSIGNEDtiming, readiness, loss and final-state adjudication
distinct principal + key requiredSUBJECT-FENCEREPOSITORY_BOUNDPortal release cannot impersonate Controller
Service, host class, release prefix and endpoint are exact; developer-portal@ and Sites versions are always ineligible.
T06-PREDECESSORREPOSITORY_BOUNDLive T06 qualification is mandatory
The receipt must bind the same dedicated host, 11/11 readiness and one loopback listener.
SIX-FIELD-IDENTITYREPOSITORY_BOUNDSource through runtime remain one subject
Source, artifact, SBOM, configuration, migration and runtime release ID are independently signed.
IMMUTABLE-ROOTSREPOSITORY_BOUNDBoth releases are immutable materializations
Current and predecessor roots are root-owned, exact-digest verified and not writable by the service identity.
ORDERED-ROLLBACKREPOSITORY_BOUNDEight events form one monotonic chain
Missing, duplicate, reordered or cross-host events deny the receipt.
AUTO-RECOVERYREPOSITORY_BOUNDThe drill cannot strand the predecessor
A recovery guard is armed before the switch; the final release must equal the exact original current.
LOOPBACK-INVARIANTREPOSITORY_BOUND8110 remains private throughout
Before, predecessor and after observations each require one 127.0.0.1 listener and zero public routes.
FOUR-PARTY-SEALREPOSITORY_BOUNDPublisher cannot approve its own drill
Supply Chain, Release Engineering, SRE and Independent QA use distinct principals and Ed25519 keys.
D05-T08 · FOUR-OWNER FINAL ACCEPTANCE
最后一刀不是再画一个绿勾,而是封存可被四方签署的完整判决对象
T08 把 G01–G11、T07 rollback、exact release、预算、运行终态与四个独立责任席位收进同一份 30 分钟终验收据。验证器只能输出候选晋级授权,不能修改实施账本;真正的 4/36 D05 → 5/36 D06 仍须由外部账本 authority 执行一次 CAS。
G09/G10 只读取当前 T07 Controller release + rollback qualification;G11 只读取本 T08 四方终验。运行中的 Portal release 与 Sites version 是文档目标,不是 Controller 的资格主体。
G01-G11 are satisfied for one exact release
seal the exact fresh closure dossier
FinOps, Runtime and Security sign independently
Product signs after all independent reviewers
external ledger authority compares 4/36 D05 then advances to 5/36 D06
每一道门都必须绑定同一 exact release
D05-G01D05-G02D05-G03D05-G04D05-G05D05-G06D05-G07D05-G08D05-G09D05-G10D05-G11签署人看到的是同一份字节对象
sha256: canonical(payload)- 01
exact source, artifact, SBOM, configuration, migration and runtime release identity
- 02
eleven ordered fresh independently signed gate receipts
- 03
live T07 rollback qualification bound to the same host and release
- 04
bounded budget and one private 8110 listener with zero public routes
- 05
four distinct final principals and public keys
FINOPSbudget ceiling, hold and expiry
RUNTIME_OWNER11/11 readiness, listener, rollback and final runtime
SECURITY_OWNERsubject, signatures, freshness, isolation and zero public route
PRODUCT_OWNERfinal business acceptance after all independent reviews
EXACT-SUBJECTREPOSITORY_BOUNDOne Controller release only
Every receipt binds the same service, host, source, artifact, configuration and runtime identity.
ELEVEN-OF-ELEVENREPOSITORY_BOUNDNo partial gate closure
Missing, duplicate, reordered, cross-release or unsigned G01-G11 evidence denies final acceptance.
FRESHNESSREPOSITORY_BOUNDPoint-in-time truth
Final receipt lasts at most 30 minutes and no gate evidence may exceed 120 minutes.
DOSSIER-SEALREPOSITORY_BOUNDExact byte closure
A canonical SHA-256 dossier binds release identity, receipts and runtime outcome.
SEPARATION-OF-DUTIESREPOSITORY_BOUNDFour independent principals
FinOps, Runtime, Security and Product use distinct principals and Ed25519 public keys.
PRODUCT-LASTREPOSITORY_BOUNDProduct cannot pre-approve
Product acceptance must be signed strictly after all three independent reviews.
ZERO-EFFECT-VERIFIERREPOSITORY_BOUNDVerification does not mutate
The verifier authorizes a candidate transition but executes zero ledger, runtime or cloud writes.
LEDGER-CASREPOSITORY_BOUNDNo stale program advance
A separate authority must compare current 4/36 D05 before advancing exactly once to 5/36 D06.
LIVE RUNTIME TRUTH
Portal 在线,不等于 Controller 已部署
2026-07-24 只读快照;所有数字来自最新 EC2 和已有生产证据,未创建资源、未安装 unit、未启动 8110。发布 SHA 绑定当前 Portal exact release,但不冒充 Controller release。
D05 · ELEVEN-GATE MATRIX
11 个门全部显示真实阻塞,不用绿色占位
11 个 Gate denied;第一个失败是 D05-G01。每个卡片都绑定责任人、目标、观测和机器证据。
ORGANIZATION LINUX RUNNER CAPACITY
- OWNER
- PLATFORM_SRE
- TARGET
- 2 organization-scoped Linux runners; concurrency one; single-use ephemeral boundary
- OBSERVED
- 1 台 Linux 候选、1 台在线;组织级 0、ephemeral 0、合格 0
INDEPENDENT MAC RUNNER LANE
- OWNER
- MOBILE_PLATFORM
- TARGET
- 1 online organization-scoped Mac runner with platform-safe labels and signed native job receipt
- OBSERVED
- 8 台 Mac 候选、6 台在线;全部仓库级可复用,部分标签混用;合格 0
ROOT OWNED RUNTIME CONFIGURATION
- OWNER
- SECURITY
- TARGET
- root-owned canonical manifest, eleven typed ConfigRefs, one verify-only KeyRef and a least-visible SecretRef boundary
- OBSERVED
- manifest, service identity and resolved production references are absent on the production host
REVIEWED PRODUCTION FACTORIES
- OWNER
- GLOBAL_ARCHITECTURE
- TARGET
- six reviewed production factories, five authority-pinned read sources and one verify-only attestation verifier
- OBSERVED
- closed source implementations and fixture proofs exist, but every factory remains TEST_ONLY with zero production bindings
ELEVEN LIVE READINESS RECEIPTS
- OWNER
- CONTROLLER_OWNER
- TARGET
- eleven fresh signature-verified readiness receipts bound to one Controller release, manifest, configuration and runtime identity
- OBSERVED
- zero readiness directory, zero receipt files, zero configured Gates and no Controller runtime identity on the production host
INDEPENDENT LISTENER AUTHORIZATION
- OWNER
- RELEASE_OWNER
- TARGET
- one independent expiring authorization bound to exact host, release, config, unit, endpoint, rollback, negative webhook proof and four approvals
- OBSERVED
- authorization file, systemd unit, loopback listener and reverse proxy route are all absent
HARDENED CONTROLLER INSTALLATION
- OWNER
- PLATFORM_SRE
- TARGET
- non-login identity, root-owned unit, exact digest, filesystem ownership, credential references, hardening profile, loopback-only network policy and signed installation receipt
- OBSERVED
- service user, group, unit, installation root, runtime directories, manifest, process and listener are absent
LIVE HEALTH READINESS NEGATIVE WEBHOOK
- OWNER
- QA
- TARGET
- live health and readiness receipts plus unsigned, invalid-signature, stale, replay, wrong-scope and unready webhook denial receipts
- OBSERVED
- health, readiness and six webhook probe attempts all returned HTTP 000 because the Controller listener is absent; connection refusal is not application-level denial proof
Exact signed Controller release identity
- OWNER
- Supply Chain
- TARGET
- exact production-qualified runner-controller release on the dedicated control-plane host
- OBSERVED
- 0 positive receipts · source D05-T07
Intentional rollback and exact recovery
- OWNER
- Release Engineering
- TARGET
- exact production-qualified runner-controller release on the dedicated control-plane host
- OBSERVED
- 0 positive receipts · source D05-T07
Four-owner final acceptance
- OWNER
- Product Owner
- TARGET
- exact production-qualified runner-controller release on the dedicated control-plane host
- OBSERVED
- 0 positive receipts · source D05-T08
AUTHORITY FIREWALL
代码权限、外部身份与付费生产权限分开
“继续开发”允许完成安全的仓库实现,但不会自动授予云成本、设备控制、生产变更或多方签署权限。
ORDERED EXECUTION
从第一个可执行修复走到 D05 四方验收
顺序表达安全和证据依赖。跳过前置、只看到 HTTP 200 或只创建资源,都不能推进实施计数。
修复 Runner 凭据与任务隔离边界
组织 Runner 必须 single-use;任务不可读取可复用 daemon credential;不得进入生产 VPC。
恢复独立 AWS 验证身份
仓库已交付一小时临时角色、最小权限边界、精确身份检查、ValidateTemplate 和 deny probe;Cloud Owner 尚未创建角色,AWS 仍未在线接受。
批准两台隔离 Linux Runner 成本
官方 Sydney SKU 报价、精确模板摘要、Product Owner + FinOps Ed25519 双签名、USD 250 上限和非续期 ASG 归零租约已实现;真实签名仍为 0/2。
部署并完成 18 仓隔离演练
精确 18 仓 revision、17+1 scope 分区、7 项恶意探针、两次整机替换与三方签名验证器已完成;在线执行仍等待 T02、T03 和 shared repo owner 决策。
恢复独立 Mac 原生 Runner
两个精确原生 workload、两段串行 ephemeral scope、专用主机与工具链证明、六项恶意探针、两份 cleanup 回执和三方 Ed25519 验证已实现;在线 Mac Runner 仍是错误单仓 scope 且可复用,合格回执为 0/2。
部署独立 Controller 与 8110
dedicated-host preflight、六个 exact artifact、六个 production component receipt、11 项 readiness、8 项 probe 与三方 Ed25519 资格包已实现;G01–G04、独立主机和 8110 在线回执仍为零。
签署 release identity 并执行 intentional rollback
source/artifact/SBOM/config/migration/runtime 六项同源签署;真实回滚和恢复观察窗。
完成 G11 四方验收
11/11 Gate、freshness、独立签名、exact release binding 与 Product Owner 决策缺一不可。
DEPENDENCY FAN-OUT
D05 未验收会直接拦住 7 刀
这是全局架构层面的真实关键路径:发布底座没闭环,身份、媒体、可观测、恢复、行情和最终发布都不能安全前推。
D06W1浏览器认证 SDK / BFF
Identity Platform
PLANNEDD07W1MFA、恢复与签名密钥 Phase B
Identity Security
PLANNEDD12W2Media 生产部署与隔离直传
Media Platform
PLANNEDD14W2关联可观测、状态与事件指挥
Site Reliability Engineering
PLANNEDD15W2完整备份与隔离恢复
Recovery Engineering
PLANNEDD29W5Trading 持久任务、SecretRef 与生产部署
Market Data
PLANNEDD35W6Exact Release、生产 Smoke 与回滚证明
Release Engineering + Operations
PLANNEDD05‑T01 至 T08 仓库序列 8/8 收口,真实终验仍从 Cloud Owner 的 T02 开始
T08 已把 G01–G11、exact Controller release、真实 rollback、预算终态、四个独立 Ed25519 席位、Product 最后签署和账本 CAS 收进 fail-closed 机器契约。当前 Portal EC2 和 Sites 只承载架构文档,明确排除在 Controller G09–G11 之外;Controller unit、8110、T07 回执、closure dossier、终验签名与账本写入仍全部为零。仓库开发没有下一任务;线上执行回到最早未完成的 D05‑T02。只有 11/11 门禁、1/1 dossier、1/1 T07、4/4 签署和 1/1 CAS 全部成立,实施账本才可从 4/36 变为 5/36,并解锁 D06。