D05 ACTIVE / RELEASE FOUNDATION
同一份发布身份,从源码一直活到回滚
最新源码与 EC2 盘点识别出 10 个真实部署单元:10 个能回指 exact source,9 个绑定完整制品,3 个公开运行态身份;SBOM、配置、迁移、SecretRef 与签名 provenance 仍未全局闭合。
LIVE CHANGE CONTROL · AUTH
候选、必需检查与生产真值分开显示
auth 的发布身份实现已经形成可审查候选;生产安全漂移已恢复,但候选没有通过受保护分支,因此没有被冒充为线上 release。
environment · production
- productionSafe
- true
- previewEnabled
- false
- release receipt
- MISSING
REITS Minimum CI / gate (pull_request)QUEUED · no eligible org runner
reits-auth security CI / verify (pull_request)QUEUED · no eligible org runner
feat/d05-release-identity
- artifact startup check
- IMPLEMENTED
- SBOM / config / migration
- IMPLEMENTED
- SecretRef / provenance
- PARTIAL
Required pull-request checks complete on isolated runner.
Protected main contains the exact candidate revision or its merge commit.
Linux artifact and receipt are generated together in an immutable release directory.
Production smoke passes, predecessor rollback is exercised, then the candidate is re-promoted.
LIVE CHANGE CONTROL · DATA SOURCES
先证明候选,再替换原地覆盖式生产
data-sources 的 main 与生产仍精确一致且服务正常,但当前二进制位于可变目录。新候选已经把运行二进制、SBOM、公开配置、40 份 SQLite/PostgreSQL 迁移和 SecretRef 绑定到同一 release ID;保护分支检查未运行,因此没有切换生产。
mutable-in-place-binary
- service
- RUNNING
- artifact
- eb553e7188da
- runtime receipt
- MISSING
REITS Minimum CI / gate (pull_request)QUEUED · no eligible Linux runner
REITS Minimum CI / minimum (pull_request)BLOCKED_BY_GATE · no eligible Linux runner
reits-data-sources@fd9b873244d6-0eab4831edfe
- exact executable
- BOUND
- SBOM / config / 40 migrations
- BOUND
- SecretRef / provenance
- PARTIAL
The protected required gate and dependent minimum job complete on an isolated Linux runner.
Protected main contains the reviewed candidate or its merge commit; rebuild from that exact clean revision.
Provision the dedicated service account, systemd credential and immutable release directory without mutating crawler data.
Pass local health and release identity probes, exercise the named rollback, then atomically move current.
P0 · EXECUTION PLANE
Runner 必须离开生产共享故障域
现有在线 Linux runner 只属于 im-core;组织 runner 为 0,Mac runner 离线。承载 Gitea、IM、业务、数据库和日志的生产 EC2 明确不可用于不受信任 CI。
Linux online
repo-scoped · im-core only
organization runners
17 gates queued
Mac online
native lanes unavailable
Linux org runners
concurrency 1 each
Mac runner
Swift / iOS lane
production co-location
socket + subnet denied
Dedicated CI compute account or VM; no production service is co-located.
Untrusted pull-request jobs cannot access home directories, cloud credentials, Docker sockets or production subnets.
The organization registration secret exists only during offline bootstrap, is never committed/logged and is reset before any daemon starts.
CPU, memory, process, disk and job duration limits are enforced; workspaces are destroyed after every job.
The job UID can reach only loopback; outbound CONNECT requests pass through a root-managed proxy allowlist that denies private destinations and direct sockets.
两台已注册,不等于一台可用于 D05
Gitea 组织、21 个仓库与 AWS 账户已重新盘点。每台 Runner 必须逐项通过 scope、短生命周期、平台标签与隔离证明;“online”只是信号,不是准入结论。
Shared production failure domain for Gitea, business services, IM, databases and logs.
RUNNER ELIGIBLE · FALSEreits-im-core-linux-arm64
Visible only from reits/im-core after scanning all 21 reits repositories; absent from the reits organization inventory.
Runner onlineGitea admin API reports online and idle.
PASSOrganization scopeRepository-scoped to reits/im-core.
FAILEphemeral workspaceGitea reports ephemeral=false.
FAILDedicated compute attestationNo reviewed host or network attestation is bound.
MISSINGReviewed architectureRunner name declares arm64; reviewed D05 Linux template is x86_64.
FAIL!REITS Minimum CI / gate (pull_request)REQUIRED · Waiting to run
!REITS Minimum CI / minimum (pull_request)DEPENDENT · Blocked by required conditions
!reits-auth security CI / verify (pull_request)REQUIRED · Waiting to run
!REITS Minimum CI / gate (pull_request)REQUIRED · Waiting to run
双 AZ 模板已被凭证边界闩锁,禁止创建付费资源
隔离 VPC、零入站、单端点出站与任务后清理已经落到模板;但 host executor 与 daemon 共用 UID,任务可以读取可复用 Runner 凭证,因此 deploy 在访问 AWS 和 Secret 前直接退出。
清空工作目录,不等于隔离 Runner 凭证
Gitea 1.25.4 与最新模板 Runner 2.0.0 已核对;当前 host 模式让 daemon 和不受信任任务使用同一 UID,`.runner` 文件仍在任务信任域内。
/var/lib/reits-runner/work/var/lib/reits-runner/tmp
事件先验真、容量先占位、任务只跑一次、失败必须回到安全态
Controller 服务包、七个运行时端口、持久预留、非对称收据、Token Broker、EC2 Worker、Gitea 精确分配与全局两槽容量控制均已有可执行实现;生产 webhook、持久账本、KMS Key、Gitea 凭证、Launch Template、CI 网络和真实 Worker 仍全部明确不存在。
一条 webhook 只能得到一个 PLAN_ONLY,不可能从客户端打开 apply
当前实现只做可信入口、策略判定、幂等预留和测试收据。所有值都来自机器契约,不用“已设计”冒充“已运行”。
X-Gitea-Signature · constant-time compare
invalid → 401 / no reservationdelivery · run · job · attempt
other transitions → deny18 exact repositories · Mac split
unregistered scope → denydelivery + job attempt · repository + job attempt
runtime store · DYNAMODB_ADAPTER_IMPLEMENTED_NOT_CONFIGURED4 TEST_ONLY receipts · no secrets
apply supported · FALSEX-Gitea-SignatureHMAC over exact raw bytesREQUIRED
X-Gitea-Deliveryunique UUID deliveryREQUIRED
X-Gitea-Eventworkflow_jobREQUIRED
X-Gitea-Event-Typeworkflow_jobREQUIRED
COMPUTEc7i-flex.largelinux-amd64 · ap-southeast-2
NETWORKPRIVATE / 0 INGRESSprivate-ci-only-no-production-route
CREDENTIALROOT TMPFSroot-owned-tmpfs-vs-reits-job
JOBROOTLESS DIND0 host mounts · max 1 job
VOLUMEDELETE ON RETIREencrypted-gp3-delete-on-termination
AUTHORIZATIONFALSE / FALSEcost approval · runtime approval
业务编排已经能完整跑完;容量在 EC2 前占位,所有外部副作用仍被端口边界锁死
DynamoDB、Gitea 与 EC2 请求由纯函数生成;Receipt Signer 校验精确 KMS 身份,Token Broker 只接受 Gitea token header 可清零字节,Capacity Controller 则用代际栅栏阻止第三个并发计划。未配置端口仍 fail closed,TEST_ONLY driver 只证明生命周期和补偿。
reservation-storeDEFAULT DENYreserve + renew + recoverExpired + complete + fail
dual conditional rows + 120s lease + rotating fencing epochreceipt-signerDEFAULT DENYGetPublicKey + Sign + local verify
exact key ARN + pinned SPKI + DIGEST + ECDSA_SHA_256 + chain continuitytoken-brokerDEFAULT DENYPOST /orgs/reits/actions/runners/registration-token
HTTP 200 token header → owned mutable bytes → 30s single-consumer handle → zeroizeworker-providerDEFAULT DENYlaunch + closeCloudBoundary + runJob + terminate
immutable template + private one-instance launch + profile/IMDS closure + one exact job + instance/root-volume retirement proofgitea-control-planeDEFAULT DENYregisterEphemeral + verifyAssignment + deleteRunner
register only after cloud closure + exact org/repo/job/runner + reusable credential removed before code + Gitea 204/404 and local-state terminal proofcapacity-controllerDEFAULT DENYacquire + confirmReplacement + freeze + inspect
global two-slot claim occurs before launch; only signed terminal replacement reopens generation N+1; ambiguity freezes the poolaudit-sinkDEFAULT DENYopen + appendReceipt + sealFailure + inspect + verify
exact plan/job scope + pinned signatures + dual hash chain + CAS head + terminal sealPERSISTENCEDynamoDB reservation and capacity ledgersapproval · cost-and-runtime
NOT_CREATEDSIGNINGasymmetric KMS SIGN_VERIFY keyapproval · security-and-cost
NOT_CREATEDTOKENroot-scoped Gitea broker credentialapproval · security-owner
NOT_CONFIGUREDCOMPUTEEC2 launch template and CI-only networkapproval · cost-and-runtime
NOT_CREATEDJOURNALdurable append-only receipt journalapproval · security-and-cost
NOT_CREATEDONCALLfive-source reconciliation reader, metrics exporter, paging provider and ownerapproval · platform-owner
NOT_CONFIGURED可启动不等于可上线:服务先回答“我活着”,再精确说明“我为什么未就绪”
Node 入口、HTTP 边界与 systemd 加固模板已经闭合。环境变量只能选择 EVIDENCE_ONLY,监听只允许 loopback;生产 webhook 在 JSON 解析与策略处理前返回 503,测试模式只能由代码显式注入。
GET/healthzprocess liveness without readiness claims
200 ALIVEGET/readyzall production prerequisites must be receipted
503 BLOCKEDPOST/webhooks/gitearaw-body HMAC admission; production path currently blocked
503 PROD / 202 FIXTURE01DEDICATED_HOSTBLOCKED
02SERVICE_IDENTITYBLOCKED
03WEBHOOK_SECRETBLOCKED
04RESERVATION_STOREBLOCKED
05RECEIPT_SIGNERBLOCKED
06TOKEN_BROKERBLOCKED
07WORKER_PROVIDERBLOCKED
08GITEA_CONTROLBLOCKED
09CAPACITY_CONTROLLERBLOCKED
10AUDIT_SINKBLOCKED
11OWNER_APPROVALBLOCKED
dedicated non-login identityshared production host condition denycredential file referenceno new privilegesstrict filesystem protectionempty capabilitiesloopback-only IP policy0077 process umask
Readiness 不再是一排可以手填的布尔值,而是一张能回指身份、配置与证据的收据
装配器先钉住 dedicated host、非登录服务身份与五个只读 Reader,再逐条验证 11 个 Gate attestation。缺一条就是 503;重复、过期、错 scope、错签名或 secret-like 字段直接拒绝,不能靠环境变量把 Controller 变成 READY。
controllerrfctl1:…c64
servicereits-runner-factory · 991:991
bind / mode127.0.0.1:8110 · EVIDENCE_ONLY
attestation keykeyref://…/production-p256-v1
Reservationreservation-ledger
Capacitycapacity-ledger
Workerec2-worker-read-model
Runnergitea-runner-read-model
Journalappend-only-journal
manifestDigestsha256:…manifest
identityDigestsha256:…identity
receiptDigestsha256:…receipt
expiresT+300s max
01DEDICATED_HOSTTEST_VERIFIED
02SERVICE_IDENTITYTEST_VERIFIED
03WEBHOOK_SECRETTEST_VERIFIED
04RESERVATION_STORETEST_VERIFIED
05RECEIPT_SIGNERTEST_VERIFIED
06TOKEN_BROKERTEST_VERIFIED
07WORKER_PROVIDERTEST_VERIFIED
08GITEA_CONTROLTEST_VERIFIED
09CAPACITY_CONTROLLERTEST_VERIFIED
10AUDIT_SINKTEST_VERIFIED
11OWNER_APPROVALMISSING
planexact service identity, five ordered readers and reference-only configurationimmutable assembly plan and manifest digest
assemblefresh dedicated-host identity plus zero to eleven verified gate attestationsblocked or ready receipt without constructing an adapter
verifyrecompute plan, identity, receipt and packet digests and reverify attestationslocal integrity verdict with no external call
toControllerRuntimeonly a verified packet may project ordered readiness gatesreceipt-backed service readiness snapshot
01MANIFEST_PLANNEDservice, reader and attestation boundaries have one digest
02IDENTITY_BOUNDfresh dedicated-host and non-login service identity matches the manifest
03GATES_PARTIALone or more required attestations remain missing and readiness stays blocked
04READY_VERIFIEDall eleven fresh attestations verify under the pinned key reference
05DENIED_INTEGRITYidentity, scope, time, signature, shape or digest verification failed
01readiness cannot be enabled by environment booleans or caller-provided gate flagsPASS
02one manifest binds one production controller identity and one immutable assembly identifierPASS
03the service identity is a dedicated non-login user with an exact UID and GIDPASS
04the manifest only permits loopback port 8110 in EVIDENCE_ONLY modePASS
05the runtime host must attest dedicated control-plane use and no production workload sharingPASS
06runtime identity freshness is bounded by the manifest attestation agePASS
07exactly five ordered source-reader descriptors exist without wildcard fallbackPASS
08every reader is strongly consistent and has read-only least-privilege operationsPASS
09reader configuration uses ConfigRef values and never embeds credentials or secret materialPASS
10the attestation verifier key is an exact KeyRef and cannot be supplied inlinePASS
11exactly eleven named readiness gates exist and unknown gate names are deniedPASS
12gate readiness comes from the presence of a verified attestation rather than a boolean fieldPASS
13every attestation binds controller, manifest, runtime identity and evidence digestPASS
14every attestation is fresh, unexpired and verified by the injected pinned verifierPASS
15duplicate gate attestations are denied instead of last-write-wins replacementPASS
16partial evidence produces BLOCKED_CONFIGURATION with an exact missing-gate listPASS
17READY_VERIFIED requires eleven of eleven verified attestationsPASS
18plan, identity, readiness receipt and packet digests are independently recomputedPASS
19a runtime projection can only be derived from a fully verified assembly packetPASS
20assembly owns no install, listener, source call, adapter construction, external write or mutationPASS
RF_ASSEMBLY_MANIFEST|SERVICE|READERSdeny unsafe service or reader assembly before identity evaluationRF_ASSEMBLY_IDENTITY|IDENTITY_TIMEdeny shared, stale or scope-drifted controller runtime identityRF_ASSEMBLY_ATTESTATION|ATTESTATION_SET|ATTESTATION_TIMEdeny malformed, duplicate, unknown, stale or expired Gate evidenceRF_ASSEMBLY_SIGNATUREdeny when the injected pinned verifier rejects or failsRF_ASSEMBLY_RECEIPT|RUNTIME|PACKET|DIGESTdeny any readiness projection or digest inconsistencyRF_ASSEMBLY_SECRETdeny secret-like fields before plan, receipt or packet materialization01install one reviewed root-owned production assembly manifestREQUIRED
02attest a dedicated control-plane host with no shared production workloadREQUIRED
03install the exact non-login reits-runner-factory service identityREQUIRED
04resolve all five reader ConfigRefs under a read-only IAM and local-agent boundaryREQUIRED
05configure the pinned asymmetric readiness-attestation verifierREQUIRED
06issue and verify all eleven scope-bound readiness attestationsREQUIRED
07persist and expose the readiness receipt digest through loopback health onlyREQUIRED
08obtain security, runtime and cost owner approvals before any Controller activationREQUIRED
Controller 不能相信“调用者给我的 JSON”,它只相信同一个文件描述符上的所有权、字节与引用证明
Loader 只打开一个精确路径,拒绝 symlink、hard link、权限放宽、读中换 inode、非 canonical JSON 和任意类型回退;11 个 ConfigRef 与 1 个 VERIFY_ONLY KeyRef 必须逐项匹配,缺失只会得到 BLOCKED_CONFIGURATION。
/etc/reits-runner-factory/controller-runtime.json- owner / group
- root:reits-runner-factory
- mode / links
- 0640 · nlink 1
- bytes
- 1–65,536
- descriptor
- dev + ino + mtimeNs stable
- content
- UTF-8 · canonical JSON + LF
- proof
- contentDigest + fileProofDigest
DYNAMODB_TABLE_ARNap-southeast-2 and exact reviewed table name
×3NOT CONFIGUREDIAM_ROLE_ARNexact read-only role suffix without wildcard
×4NOT CONFIGUREDAWS_REGIONap-southeast-2
×1NOT CONFIGUREDHTTPS_ORIGINhttps://gitea.reits.tech
×1NOT CONFIGUREDSECRET_REFopaque SecretRef only; never a credential value
×1NOT CONFIGUREDROOT_AGENT_SOCKETexact /run read-only agent socket
×1NOT CONFIGUREDECDSA_P256_SHA256VERIFY_ONLY metadata and pinned SPKI digest
×1NOT CONFIGUREDfileProofVERIFIED · TEST_ONLY
ConfigRef11/11 · TYPED
KeyRefMISSING · VERIFY_ONLY
adapter construction0 · DENIED
UNLOADEDno production manifest or reference has been read
FILE_VERIFIEDpath, ownership, mode, link count and same-descriptor metadata passed
MANIFEST_VALIDATEDcanonical JSON passed the runtime assembly manifest planner
REFERENCES_PARTIALone or more typed references are absent and activation remains blocked
CONFIGURATION_RESOLVEDeleven ConfigRefs and one KeyRef are fresh, typed and digest-bound
DENIED_INTEGRITYfile, encoding, manifest, reference, time or digest contract failed
RF_RUNTIME_CONFIG_PATH|FILE_READ|FILE_METADATA|FILE_SIZE|TOCTOUdeny an untrusted path, link, owner, mode, size or changing descriptor
RF_RUNTIME_CONFIG_ENCODING|JSON|CANONICAL|MANIFESTdeny malformed bytes or a manifest outside the assembly contract
RF_RUNTIME_CONFIG_REF_SET|RESOLVER|RESOLUTION|RESOLUTION_TIMEdeny missing inventory, unsafe type/source/value or stale ConfigRef metadata
RF_RUNTIME_CONFIG_KEY_REF|KEY_RESOLVER|KEY|KEY_TIMEdeny an unpinned, signing-capable, private or stale trust descriptor
RF_RUNTIME_CONFIG_BUNDLE|FILE_PROOF|MISSING|STATUS|DIGESTdeny any bundle truth or digest inconsistency
01only /etc/reits-runner-factory/controller-runtime.json may be openedPASS
02the production driver opens with O_NOFOLLOW and O_CLOEXECPASS
03the manifest must be a regular file rather than a symlink, directory or devicePASS
04the file owner is root and the group is the dedicated reits-runner-factory identityPASS
05the file mode is exactly 0640 and the hard-link count is exactly onePASS
06the manifest is non-empty and bounded to 65536 bytesPASS
07before and after metadata from the same open descriptor must match exactlyPASS
08the verified byte length must equal the file size metadataPASS
09the file is strict UTF-8 without NUL bytesPASS
10the file is canonical JSON with exactly one trailing newlinePASS
11the parsed manifest must pass the existing runtime assembly plannerPASS
12the file proof binds path, inode, device, mtime, size and content digestPASS
13the manifest contains exactly eleven ordered ConfigRefsPASS
14every ConfigRef has one expected semantic type and no generic fallbackPASS
15DynamoDB and IAM ARNs are exact-suffix and wildcard-freePASS
16the Gitea origin is HTTPS and pinned to gitea.reits.techPASS
17the credential configuration resolves only to a SecretRef, never a credential valuePASS
18the root-agent socket is pinned beneath /run/reits-runner-factoryPASS
19the readiness KeyRef resolves to VERIFY_ONLY P-256 metadata without private materialPASS
20all resolution metadata is no older than five minutes and never from the futurePASS
21missing references produce BLOCKED_CONFIGURATION rather than a partial runtime adapterPASS
22file, reference-set, resolution, assembly-plan and bundle digests are independently recomputedPASS
23bundle verification never constructs a reader, signer, credential or listenerPASS
24production installation, reads, adapters, writes, mutations and paid resources remain zeroPASS
01install the reviewed canonical manifest as root:reits-runner-factory mode 0640REQUIRED
02provision the eleven exact ConfigRef records in a root-owned read-only storeREQUIRED
03provision the verify-only KeyRef descriptor and pinned public SPKI digestREQUIRED
04bind ConfigRef resolution to read-only IAM roles and the root-agent socket ACLREQUIRED
05attach the verified configuration bundle to Controller boot before readiness evaluationREQUIRED
06issue the eleven readiness attestations only after live configuration checksREQUIRED
07install and supervise the Controller on its dedicated host while keeping loopback-only bindREQUIRED
08obtain security, runtime and cost owner approvals before activationREQUIRED
把 12 个已验证引用,收敛成六个最小权限组件;任何半成品都必须逆序清理
Composer 只接收处于有效窗口内的 resolved bundle,固定构造五个只读 Reader 与一个 VERIFY_ONLY attestation verifier。Bundle 只能消费一次、Capability 不可伪造、投影只能一次;生产 entrypoint 仍保持 unconfigured。
ReservationReaderreservation-ledger
2 REFSREAD ONLY READERNOT CONSTRUCTEDCapacityReadercapacity-ledger
2 REFSREAD ONLY READERNOT CONSTRUCTEDWorkerReaderec2-worker-read-model
2 REFSREAD ONLY READERNOT CONSTRUCTEDRunnerReadergitea-runner-read-model
3 REFSREAD ONLY READERNOT CONSTRUCTEDJournalReaderappend-only-journal
2 REFSREAD ONLY READERNOT CONSTRUCTEDReadinessAttestationVerifierroot-owned-trust-store
1 REFATTESTATION VERIFIERNOT CONSTRUCTEDbundleVERIFIED · CONSUMED
failurefactory 06 / verifier
constructed05 TEST_ONLY readers
cleanup05 → 01 · REVERSE
- 01ReservationReader.dispose()5th
- 02CapacityReader.dispose()4th
- 03WorkerReader.dispose()3rd
- 04RunnerReader.dispose()2nd
- 05JournalReader.dispose()1st
snapshot-coordinatorfive authority-pinned read functions
one complete five-source TEST_ONLY capturePROVEN TEST_ONLYruntime-assemblyone verify-only P-256 attestation function
one signed-gate TEST_ONLY assembly packetPROVEN TEST_ONLYcontroller-readinessreceipt-backed runtime projection
one 1/11 blocked service readiness projectionPROVEN TEST_ONLY01UNPLANNEDno configuration bundle has been verified or consumed
02CONFIGURATION_VERIFIEDthe resolved bundle and validity window passed again
03COMPOSINGsix factories are executing in deterministic order
04COMPOSEDone opaque capability owns all six TEST_ONLY components
05PROJECTEDguarded readers and verifier were exposed exactly once
06DISPOSEDall components closed in reverse and future calls are denied
07DENIEDconfiguration, factory, component, handle, receipt or cleanup failed closed
RF_BOOTSTRAP_CONFIGURATION_VERIFY|CONFIGURATION_BLOCKED|CONFIGURATION_TIME|CONFIGURATION_BINDINGdeny unverified, partial, expired, future or rebound configurationRF_BOOTSTRAP_FACTORY|FACTORY_SET|COMPONENTdeny missing factories, constructor failures and components with excess authorityRF_BOOTSTRAP_REPLAY|HANDLEdeny bundle reuse, projected capability reuse and forged handlesRF_BOOTSTRAP_PLAN|RECEIPT|DIGESTdeny component inventory, plan, composition or receipt driftRF_BOOTSTRAP_CLEANUP|DISPOSEDdeny ambiguous cleanup and every call after terminal disposalRF_RECON_SOURCE_*|RF_ASSEMBLY_SIGNATUREdownstream readers and verifier remain fail closed after projection01only a positively verified CONFIGURATION_RESOLVED bundle may be plannedPASS
02all twelve references must be present before composition beginsPASS
03the bundle must be current at the bootstrap clock and not merely internally well formedPASS
04the configuration bundle digest binds every component planPASS
05the manifest and assembly-plan digests remain unchanged across bootstrapPASS
06exactly five read-only Reader components and one attestation verifier are requiredPASS
07factory names and ordering are closed rather than caller extensiblePASS
08Reservation Reader receives exactly its table and read-role referencesPASS
09Capacity Reader receives exactly its table and read-role referencesPASS
10Worker Reader receives exactly its region and read-role referencesPASS
11Runner Reader receives only origin, opaque SecretRef and root-agent socket referencesPASS
12Journal Reader receives exactly its table and read-role referencesPASS
13the attestation verifier receives verify-only public trust metadata without private materialPASS
14configuration values are represented publicly only by a configuration digestPASS
15all constructed components must identify as TEST_ONLYPASS
16Reader components expose only read and dispose callablesPASS
17the verifier component exposes only verify and dispose callablesPASS
18no component may expose a listen, server, start, write or mutation surfacePASS
19one bundle digest may create only one bootstrap capabilityPASS
20a bootstrap capability cannot be forged from its public fieldsPASS
21a capability may project dependencies exactly oncePASS
22projected calls are guarded by the live capability statePASS
23partial factory failure disposes every completed component in reverse orderPASS
24terminal disposal attempts every component in reverse orderPASS
25post-disposal Reader and verifier calls are deniedPASS
26plan, component, composition and receipt digests are independently recomputedPASS
27composition performs zero external reads, writes, mutations and listener startsPASS
28the production service entrypoint remains unconfigured and production truth remains zeroPASS
01install the reviewed root-owned runtime manifest and resolve all twelve referencesREQUIRED
02implement five production read-only factories with exact IAM and network boundariesREQUIRED
03implement the production P-256 public-key verifier without signing authorityREQUIRED
04prove constructor and disposal behavior for every real SDK and root-agent clientREQUIRED
05bind the projected readers to the production snapshot coordinatorREQUIRED
06bind the projected verifier to runtime assembly before readiness evaluationREQUIRED
07issue a dedicated host and service identity receipt for the Controller processREQUIRED
08install and supervise the loopback-only Controller only after all eleven Gates attestREQUIRED
09obtain security, runtime and cost owner approvals before activationREQUIRED
11 张 Gate 收据先闭环,再投影内存 Handler;网络监听权永远不随 Handler 一起下发
这一层把 resolved configuration、六组件 capability、runtime assembly 与 service core 接成真实可执行链。只有 11/11 签名证据全部通过,才会产生一次性内存请求处理器;生产 webhook 仍返回 503,代码没有 listen、startServer 或安装路径。
CONFIGURATIONCONFIGURATION_RESOLVEDbundleDigest · sha256:…
COMPOSITIONCOMPOSED_TEST_ONLYcompositionId · rfboot1:…
ASSEMBLYREADY_VERIFIEDpacketDigest · sha256:…
SERVICE CORESERVICE_HANDLER_READY_TEST_ONLYruntimeBootstrapId · rfsrv1:…
- receipt source
- VERIFIED_ASSEMBLY_RECEIPT_ONLY
- handler created
- TRUE · TEST_ONLY
- production webhook
- FALSE · 503
- listener authorized
- FALSE · NO API
- external reads / writes
- 0 / 0
- secret values
- 0
MODEEVIDENCE_ONLY
BIND INTENT127.0.0.1:8110
ACTUAL LISTENERABSENT
GET /healthz200 · ALIVE_READYliveness + receipt-backed ready
FIXTURE PASSGET /readyz200 · READY · 11/11manifest + identity + receipt digests
FIXTURE PASSPOST /webhooks/gitea503 · RF_CONTROLLER_NOT_READYready Handler 也没有 production action 权
EXPECTED DENYlisten(8110)NOT A FUNCTIONnetwork authority is a separate future receipt
STRUCTURAL DENYRF_READY_DEDICATED_HOSTselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_SERVICE_IDENTITYselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_WEBHOOK_SECRETselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_RESERVATION_STOREselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_RECEIPT_SIGNERselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_TOKEN_BROKERselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_WORKER_PROVIDERselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_GITEA_CONTROLselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_CAPACITY_CONTROLLERselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_AUDIT_SINKselected fixtureSIGNED + VERIFIED
production runtimeMISSING
RF_READY_OWNER_APPROVALselected fixtureSIGNED + VERIFIED
production runtimeMISSING
UNPREPAREDno configuration bundle or component capability has been consumedCOMPOSINGthe six-component TEST_ONLY closure is being builtASSEMBLINGidentity and all Gate attestations are being verifiedREADY_HANDLERa receipt-backed service core exists only in memoryPROJECTEDone guarded request function has been projectedDISPOSINGfuture request calls are denied before reverse cleanup startsDISPOSEDall six components are closed and the handler is revokedDENIEDconfiguration, composition, assembly, service, receipt or cleanup failed closedRF_SERVICE_BOOTSTRAP_DEPENDENCIES|CONFIG|INPUTdeny incomplete, extended or authority-bearing orchestration inputsRF_BOOTSTRAP_*deny unverified configuration, factory drift, replay and component cleanup ambiguityRF_ASSEMBLY_*deny runtime identity, attestation, signature, time and packet driftRF_SERVICE_BOOTSTRAP_READINESS|TIMEdeny partial or expired readiness before a handler existsRF_SERVICE_BOOTSTRAP_SERVICEdeny service factories that throw, stay unready or expose excess authorityRF_SERVICE_BOOTSTRAP_HANDLE|DISPOSED|CLEANUPdeny forged, replayed, revoked or ambiguously disposed capabilitiesRF_SERVICE_BOOTSTRAP_RECEIPT|DIGESTdeny runtime bootstrap truth, identity and provenance drift01the orchestrator accepts only the exact TEST_ONLY bootstrap composer surfacePASS
02service configuration remains EVIDENCE_ONLY on loopback port 8110PASS
03apply, public routing and external writes remain disabledPASS
04policy, worker template and service configuration are cloned and deeply frozenPASS
05a resolved configuration bundle is consumed only through the reviewed composerPASS
06exactly five read-only Readers and one verify-only attestation component remain underneath the capabilityPASS
07runtime assembly uses only the verifier projected by the live composition capabilityPASS
08runtime identity remains bound to the manifest controller, host and service identityPASS
09all eleven readiness Gate attestations are required before service constructionPASS
10duplicate, stale, future, wrong-scope and bad-signature attestations deny bootstrapPASS
11a BLOCKED_CONFIGURATION assembly packet never creates a service handlerPASS
12the runtime projection is reconstructed only from the verified readiness receiptPASS
13service readiness must report 11 of 11 with a verified receiptPASS
14the service factory may expose only handle, readiness, response headers and modePASS
15the projected capability exposes one guarded request function and no socket functionPASS
16no listen, server or start operation is accepted from the service factoryPASS
17production webhook handling remains 503 even inside a ready TEST_ONLY handlerPASS
18health and readiness requests remain loopback-context onlyPASS
19one runtime capability may project a handler exactly oncePASS
20forged and replayed handles are rejectedPASS
21expired readiness evidence cannot be prepared or projectedPASS
22disposal revokes the request guard before component cleanup beginsPASS
23post-disposal handler calls are rejectedPASS
24prepare failure disposes every successfully composed componentPASS
25cleanup ambiguity fails closed and never emits a capabilityPASS
26bootstrap, assembly and readiness receipt digests remain linked in one receiptPASS
27runtime bootstrap identity is deterministic for composition, assembly packet and observed timePASS
28receipt verification rejects shape, truth, identity and digest driftPASS
29external reads, writes, mutations and listener starts remain zero during orchestrationPASS
30the production Controller entrypoint remains unconfigured and port 8110 remains absentPASS
01install and verify the root-owned runtime manifest and all twelve typed referencesREQUIRED
02replace all six TEST_ONLY factories with reviewed production read-only implementationsREQUIRED
03issue a dedicated host and non-login service identity receiptREQUIRED
04produce fresh signed evidence for all eleven readiness GatesREQUIRED
05prove the production service handler against real read adapters without granting write authorityREQUIRED
06add an independent owner-approved listener authorization receipt with expiry and rollback bindingREQUIRED
07install the hardened systemd unit only on the dedicated control-plane hostREQUIRED
08expose loopback through an authenticated reverse proxy only after security and runtime reviewREQUIRED
09run live readiness, webhook denial, incident, rollback and cost-control acceptance before activationREQUIRED
生产证据必须先成为一份可验证、不可部署的档案,才有资格进入监听授权评审
发布单元、专用主机、非登录服务身份、五个只读 Reader、一个验签器和十一张 Gate 收据在这里形成同一条短时效信任链。通过只代表“证据结构合格”,不会创建 Handler、安装 systemd、访问外部系统或打开 8110。
- host class
- DEDICATED_CONTROL_PLANE
- shared workloads
- FALSE
- production marker
- REQUIRED
- active Runner service
- 0
- bind
- 127.0.0.1:8110
- validity
- ≤ 300 seconds
- user / group
- reits-runner-factory
- root account
- DENIED
- shell
- /usr/sbin/nologin
- capabilities
- []
- credentials
- REFS ONLY
- NoNewPrivileges
- TRUE
ReservationReaderreservation ledger
READ_ONLYimplementation + config digestNOT QUALIFIEDCapacityReadercapacity ledger
READ_ONLYimplementation + config digestNOT QUALIFIEDWorkerReaderEC2 read model
READ_ONLYimplementation + config digestNOT QUALIFIEDRunnerReaderGitea + root agent
READ_ONLYimplementation + config digestNOT QUALIFIEDJournalReaderappend-only journal
READ_ONLYimplementation + config digestNOT QUALIFIEDReadinessAttestationVerifierroot-owned trust store
VERIFY_ONLYimplementation + config digestNOT QUALIFIEDRF_READY_DEDICATED_HOSTidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_SERVICE_IDENTITYidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_WEBHOOK_SECRETidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_RESERVATION_STOREidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_RECEIPT_SIGNERidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_TOKEN_BROKERidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_WORKER_PROVIDERidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_GITEA_CONTROLidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_CAPACITY_CONTROLLERidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_AUDIT_SINKidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGRF_READY_OWNER_APPROVALidentity bindingcontroller + manifest + host
validity≤ 300s
MISSINGUNVERIFIEDcandidate facts have no authorityVERIFYING_IDENTITIESrelease, host and service bindings are checkedVERIFYING_ADAPTERSsix production implementation qualifications are checkedVERIFYING_GATESeleven attestations and readiness reconstruction are checkedADMITTED_EVIDENCE_ONLYa non-deployable evidence capability exists in memoryPROJECTEDone frozen dossier has been projectedDISPOSEDthe capability and retained dossier are revokedDENIEDany identity, authority, time, signature or digest drift fails closed- 01Adapter qualification arriveslistenerAuthority=true
- 02Secret/authority scanner runsSTRUCTURAL DENY
- 03Signature chain is not promotedNO CAPABILITY
- 04Production counters remain0 / 0 / 0
01release identity binds one signed production source, artifact, configuration and distinct rollback targetPASS
02runtime identity is no older than five minutesPASS
03the host is dedicated to the control plane and reports no shared production workloadsPASS
04the immutable production marker must be presentPASS
05no Runner service may be active on the Controller hostPASS
06the only admissible Controller bind is 127.0.0.1:8110PASS
07the service user and group are reits-runner-factoryPASS
08the service account is non-root and non-loginPASS
09the service home and unit name are exactPASS
10inline secret values remain zero and only credential references are allowedPASS
11the service has no Linux capabilities and NoNewPrivileges is truePASS
12exactly five read-only Readers and one verify-only component are admittedPASS
13adapter order, authority, operation, permission and ConfigRef sets are exactPASS
14every adapter implementation and configuration evidence is digest-boundPASS
15no adapter grants external write or listener authorityPASS
16adapter qualifications bind the exact release and hostPASS
17exactly eleven ordered readiness attestations are requiredPASS
18every Gate binds the exact controller, manifest and runtime identityPASS
19the readiness issuer is pinned to the reviewed production P-256 KeyRefPASS
20every signed receipt is current and valid for at most five minutesPASS
21nineteen signatures must verify positivelyPASS
22the READY_VERIFIED receipt reconstructs the same eleven Gate evidence digestsPASS
23the readiness receipt identity digest is derived from the exact runtime identityPASS
24the admission expiry is the earliest upstream expiryPASS
25one admission capability can project only oncePASS
26forged, replayed and disposed capabilities are deniedPASS
27the projected dossier contains no function or mutable authorityPASS
28the admission receipt always sets deploymentAuthorized=falsePASS
29the admission receipt always sets listenerAuthorized=false and handlerCreated=falsePASS
30external reads, writes, mutations and listener starts remain zeroPASS
31secret-like fields are structurally rejectedPASS
32production webhook acceptance remains zeroPASS
33the existing unconfigured production entrypoint is unchangedPASS
34port 8110 remains absent until a separate owner-approved listener receipt existsPASS
01publish a signed Controller release unit with an exercised rollback targetREQUIRED
02provision and attest a dedicated non-production control-plane hostREQUIRED
03install the reviewed non-login service identity and hardened unit without starting itREQUIRED
04implement and independently review the five production read adaptersREQUIRED
05install the verify-only readiness public key through a root-owned KeyRefREQUIRED
06collect nineteen fresh signatures and all eleven Gate evidence objectsREQUIRED
07run the admission verifier on the target host with external calls still disabledREQUIRED
08obtain a separate expiring owner-approved listener authorizationREQUIRED
09perform live negative-webhook, rollback, incident, security and cost acceptance before activationREQUIRED
把“上线”拆成可审阅的八步运行手册;每一步都看得见,但没有一步能执行
Listener 候选之后新增独立的激活规划层。它只接受精确候选、已打开的 15 分钟变更窗口、目标机停机态证明、60 秒即时回滚守卫,以及两个不同人员对同一 scope 的确认。输出是一次性冻结 runbook,不安装 Unit、不启动 Service、不打开 8110。
VERIFY_CANDIDATEcandidate digest + authority + expiry
NO_EXECUTORBLOCKEDVERIFY_WINDOWwindow + scope + two-person check
NO_EXECUTORBLOCKEDSNAPSHOT_ROLLBACKportal 8100 + rollback release
NO_EXECUTORBLOCKEDINSTALL_UNITfuture unit install boundary
NO_EXECUTORBLOCKEDSTART_LOOPBACKfuture loopback start boundary
NO_EXECUTORBLOCKEDPROBE_HEALTH/healthz + /readyz
NO_EXECUTORBLOCKEDAUTO_ROLLBACKwatchdog ≤ 60 seconds
NO_EXECUTORBLOCKEDSEAL_RECEIPTobserved truth receipt
NO_EXECUTORBLOCKED- portal :8100
- HEALTHY
- port :8110
- ABSENT
- systemd unit
- NOT INSTALLED
- controller service
- INACTIVE
- reverse proxy
- ABSENT
- public route
- ABSENT
- rollback release
- PRESENT · EXACT
- disk headroom
- ≥ 1 GiB
START_ERRORsystemd start returns non-zeroROLL BACKREADINESS_TIMEOUTtwo probes do not become readyROLL BACKIDENTITY_DRIFTrelease / config / unit identity changesROLL BACKUNEXPECTED_BINDanything binds beyond loopback :8110ROLL BACKPROXY_DRIFTproxy or public routing appearsROLL BACKCHANGE_OWNERowns change scope and maintenance window
CONFIRM_DRY_RUN_ONLYPRODUCTION MISSINGINCIDENT_COMMANDERowns rollback call and incident command
CONFIRM_DRY_RUN_ONLYPRODUCTION MISSINGUNTRUSTEDthe packet has no activation-planning standingCANDIDATE_BOUNDthe authoritative listener candidate is current and unmodifiedWINDOW_OPENthe signed change window is open and no longer than 15 minutesSTOPPED_STATE_PROVEN8110, unit, service, proxy and route are absent while portal 8100 is healthyROLLBACK_GUARDEDthe complete fail trigger set has a 60-second recovery deadlineTWO_PERSON_CONFIRMEDtwo different subjects confirm the same dry-run scopeRUNBOOK_CANDIDATEone opaque fixture-only zero-executor capability existsPROJECTED_OR_DISPOSEDthe capability cannot be consumed againDENIEDany drift fails closed without install, start, listener or mutation- 01Listener candidate and change window verifyAUTHORITY PASS
- 02
port8110Absent=falseenters signed preflightSTATE CONFLICT - 03Confirmations are not promotedNO HANDLE
- 04Install, start, listener and mutations remain0 / 0 / 0 / 0
01the upstream listener candidate is exact, digest-bound, unexpired and positively verified by its authorityPASS
02fixture-only listener authority can produce only a fixture-only dry-run runbookPASS
03the listener candidate carries activationAuthorized=false and listenerStartAuthorized=falsePASS
04release identity is unchanged from the listener candidatePASS
05rollback release is unchanged from the listener candidate and remains distinctPASS
06controller identity is unchanged from the listener candidatePASS
07host identity is unchanged from the listener candidatePASS
08manifest digest is unchanged from the listener candidatePASS
09configuration digest is unchanged from the listener candidatePASS
10systemd unit digest is unchanged from the listener candidatePASS
11the only request action is PLAN_ACTIVATION_ONLYPASS
12service user is exactly reits-runner-factoryPASS
13service unit is exactly reits-runner-factory-controller.servicePASS
14bind host is exactly 127.0.0.1 and port is exactly 8110PASS
15public route and reverse proxy requests are always falsePASS
16the plan request window is no longer than 60 secondsPASS
17the maintenance window is signed, currently open and no longer than 15 minutesPASS
18the maintenance change identifier is format constrainedPASS
19preflight proves port 8110 is absentPASS
20preflight proves the Controller unit is not installedPASS
21preflight proves the Controller service is not activePASS
22preflight proves no proxy or public route is configuredPASS
23preflight proves the existing portal on 8100 is healthyPASS
24preflight proves the exact rollback release is presentPASS
25preflight requires at least one GiB of disk headroomPASS
26rollback deadline is no longer than 60 secondsPASS
27rollback probes are exactly /healthz and /readyzPASS
28rollback requires two healthy probesPASS
29start error, readiness timeout, identity drift, unexpected bind and proxy drift all trigger rollbackPASS
30the rollback guard itself exposes no executorPASS
31change owner and incident commander are both required in canonical orderPASS
32change owner and incident commander must be different subjectsPASS
33both subjects sign CONFIRM_DRY_RUN_ONLY for the same scope and noncePASS
34five evidence signatures must verify positivelyPASS
35the nonce is format-checked and single-usePASS
36secret-like and executable fields are structurally rejectedPASS
37the runbook handle is opaque, one-shot and WeakMap-backedPASS
38the projected runbook contains eight declarative NO_EXECUTOR stepsPASS
39the projected runbook exposes no function and zero executable stepsPASS
40activation, unit install, service start and listener start remain falsePASS
41external reads, writes, mutations, paid resources, proxy and public routes remain zeroPASS
42the production entrypoint remains unconfigured and port 8110 remains absentPASS
01replace the fixture listener candidate with an authority-verified target-host candidateREQUIRED
02open an approved production maintenance window with an immutable change identifierREQUIRED
03capture signed target-host preflight while 8110, unit, service, proxy and route are absentREQUIRED
04prove portal 8100 health and the exact rollback release before any install actionREQUIRED
05collect different change owner and incident commander subjects for the exact scopeREQUIRED
06implement a separately reviewed least-privilege executor without shell interpolationREQUIRED
07implement an independently testable rollback executor and 60-second watchdogREQUIRED
08exercise install, start, health, readiness and every rollback trigger on a non-production hostREQUIRED
09obtain a new authority receipt before activation; this dry-run runbook can never be promotedREQUIRED
把安装、启动、探针和补偿拼成可验证事务;真实主机仍然没有执行入口
上一步的零权限 runbook 不能成为生产授权。本工作台只在内存驱动中复现严格顺序:锁定、快照、安装、loopback 启动、双探针、释放;任何漂移进入反向补偿,补偿本身异常则封存为 CONTAINED。
ACQUIRE_LOCKexclusive fixture fence
STEP RECEIPTSNAPSHOT_ROLLBACKcapture rollback baseline
STEP RECEIPTINSTALL_UNITdigest-bound fixture unit
STEP RECEIPTSTART_LOOPBACK127.0.0.1:8110 only
STEP RECEIPTPROBE_HEALTHpositive /healthz receipt
STEP RECEIPTPROBE_READYpositive /readyz receipt
STEP RECEIPTRELEASE_LOCKrelease fixture fence
STEP RECEIPTSTOP_LOOPBACKstop fixture listener first
IF REACHEDREMOVE_UNITremove fixture unit second
IF REACHEDRESTORE_SNAPSHOTrestore snapshot third
IF REACHEDRELEASE_LOCKrelease fence last
ALWAYSacquireLockACQUIRE_LOCKFIXTURE ONLYsnapshotRollbackSNAPSHOT_ROLLBACKFIXTURE ONLYinstallUnitINSTALL_UNITFIXTURE ONLYstartLoopbackSTART_LOOPBACKFIXTURE ONLYprobeHealthPROBE_HEALTH_OR_READYFIXTURE ONLYstopLoopbackSTOP_LOOPBACKFIXTURE ONLYremoveUnitREMOVE_UNITFIXTURE ONLYrestoreSnapshotRESTORE_SNAPSHOTFIXTURE ONLYreleaseLockRELEASE_LOCKFIXTURE ONLYCOMMITTEDunit + listener exist only inside the memory driver
5ROLLED_BACKsnapshot + unit + listener all prove absent
9CONTAINEDcompound failure code retained for manual review
4- 01lock → snapshot → install → startRECEIPTS PASS
- 02/healthz driver call failsROLLBACK
- 03STOP_LOOPBACK compensation failsAMBIGUOUS
- 04remove + restore + release continueCONTAINED
UNTRUSTEDthe packet has no transaction standingPLAN_BOUNDthe authoritative fixture-only plan is exact and currentPREPAREDone opaque 30-second fixture capability existsLOCKEDthe in-memory host fence was acquiredSNAPSHOTTEDthe in-memory rollback state was capturedUNIT_INSTALLED_FIXTUREthe digest-bound unit exists only inside the memory driverLOOPBACK_STARTED_FIXTUREthe memory driver reports only 127.0.0.1:8110HEALTHY_FIXTUREboth fixture health paths positively verifiedCOMMITTED_FIXTUREthe success receipt is test-only and grants no production authorityROLLED_BACK_FIXTUREreverse-order compensation proved a clean memory stateCONTAINED_FIXTUREambiguous compensation is sealed for manual review without production effectDENIEDinput, provenance, sequence or receipt drift failed closed01replace the fixture-only activation plan with a newly reviewed production authority receiptREQUIRED
02implement a target-host driver as a separate least-privilege package with no shell interpolationREQUIRED
03bind every target-host effect receipt to an asymmetric production signer and monotonic journalREQUIRED
04run the transaction and every compensation branch on a disposable non-production hostREQUIRED
05prove the 60-second rollback watchdog independently from the forward executorREQUIRED
06prove systemd sandbox, filesystem ownership and configuration references on the target hostREQUIRED
07capture live negative evidence that no public route or reverse proxy existsREQUIRED
08obtain a new two-person change authorization for the exact target-host transactionREQUIRED
09wire the production executor only through a separately reviewed composition rootREQUIRED
10repeat EC2 inventory and port audit immediately before any production activationREQUIRED
先审驱动边界与反证,再允许候选包进入独立测试主机
工作台消费上游事务回执、独立包描述符、9 份端口证据和 8 份拒绝证据,只签发测试资格回执。它不 import 候选包、不调用驱动、不读取凭据,也不能安装 Unit、启动服务或创建 8110 listener。
- package
- @reits/runner-factory-target-host-driver
- platform
- linux/amd64
- service user
- reits-runner-factory
- systemd unit
- reits-runner-factory-controller.service
- bind
- 127.0.0.1:8110
- health
- /healthz → /readyz
acquireLockACQUIRE_LOCK
SIGNED EVIDENCEsnapshotRollbackSNAPSHOT_ROLLBACK
SIGNED EVIDENCEinstallUnitINSTALL_UNIT
SIGNED EVIDENCEstartLoopbackSTART_LOOPBACK
SIGNED EVIDENCEprobeHealthPROBE_HEALTH_OR_READY
SIGNED EVIDENCEstopLoopbackSTOP_LOOPBACK
SIGNED EVIDENCEremoveUnitREMOVE_UNIT
SIGNED EVIDENCErestoreSnapshotRESTORE_SNAPSHOT
SIGNED EVIDENCEreleaseLockRELEASE_LOCK
SIGNED EVIDENCE/run/lock/reits-runner-factory-controller.lockcreate-exclusive + remove
/opt/reits-runner-factory/releases/{releaseId}read immutable candidate only
/var/lib/reits-runner-factory/rollback/{changeId}.jsoncreate-exact + restore-exact
/etc/systemd/system/reits-runner-factory-controller.serviceinstall exact digest + remove exact
daemon-reloadafter exact unit install or removal only
EXACT UNITis-activeexact controller unit only
EXACT UNITshowallowlisted unit properties only
EXACT UNITstartexact unit after lock and snapshot
EXACT UNITstopexact unit during compensation
EXACT UNITGENERIC_COMMAND_PORTno generic execution surfaceDENY PROVEDSHELL_INTERPOLATIONarguments never become shell textDENY PROVEDPATH_TRAVERSALpaths stay inside exact templatesDENY PROVEDDYNAMIC_UNIT_NAMEcaller cannot select a unitDENY PROVEDPUBLIC_BINDbind must remain 127.0.0.1DENY PROVEDREVERSE_PROXYno proxy or route authorityDENY PROVEDCREDENTIAL_READdriver cannot fetch secretsDENY PROVEDUNSIGNED_STEP_RECEIPTevery effect returns signed proofDENY PROVED- 01
UPSTREAM RECEIPTexact activation-transaction digest
VERIFIED - 02
PACKAGE DESCRIPTORseparate artifact · linux/amd64 · test-only
BOUND - 03
9 PORT RECEIPTScandidate + descriptor + contract identity
SIGNED - 04
GENERIC_COMMAND_PORTforbidden field injected by fixture RFDQ-40
DENIED - 05
QUALIFICATION HANDLEnever minted after negative evidence drift
ABSENT
UNTRUSTEDthe candidate has no qualification standingTRANSACTION_BOUNDthe exact fixture transaction contract was positively verifiedDESCRIPTOR_BOUNDthe separate package exposes only the exact typed surfaceEVIDENCE_BOUNDnine port and eight denial receipts are exact and signedPREPAREDone opaque 60-second dossier capability existsQUALIFIED_TEST_ONLYthe dossier passed without package loading or executionDISPOSEDan unused capability was revokedDENIEDshape, provenance, scope or receipt drift failed closed01implement the driver in a separate repository from this dossier evaluatorREQUIRED
02review every filesystem and systemd syscall in the candidate packageREQUIRED
03attach an asymmetric production step signer without exporting private materialREQUIRED
04attach a durable monotonic journal with ambiguity containmentREQUIRED
05run all nine ports and eight denials on a disposable non-production hostREQUIRED
06prove every compensation branch inside the independent sixty-second watchdogREQUIRED
07prove the installed systemd sandbox and exact filesystem ownershipREQUIRED
08capture live negative route, proxy, credential and public-bind evidenceREQUIRED
09obtain a fresh production authority receipt and separate composition reviewREQUIRED
把候选驱动送上测试主机之前,先冻结隔离拓扑、12 阶段证据链与独立看门狗
这一工作台只准入“如何测试”的不可变计划:它验证上游资格回执、非生产主机轮廓、证据空槽与失败收敛规则,不创建 EC2、不加载候选包、不调用驱动,也不启动 watchdog。真正的主机测试仍需要独立授权。
- provider
- AWS_EC2_DISPOSABLE_TEST_HOST
- platform
- linux/amd64
- environment
- NON_PRODUCTION_CONFORMANCE
- artifact
- PRESTAGED_IMMUTABLE_IMAGE
- identity
- reits-runner-factory
- loopback
- 127.0.0.1:8110
W1PROCESS_EXIT_NON_ZEROPLANNED
W2HEALTH_DEADLINE_EXCEEDEDPLANNED
W3READY_DEADLINE_EXCEEDEDPLANNED
W4PUBLIC_BIND_DETECTEDPLANNED
W5REVERSE_PROXY_DETECTEDPLANNED
W6UNIT_DIGEST_DRIFTPLANNED
W7ROLLBACK_EVIDENCE_MISSINGPLANNED
W8MONOTONIC_JOURNAL_GAPPLANNED
claimHostHOST_CLAIM
PLANNED_NOT_EXECUTEDverifyIsolationISOLATION_ATTESTATION
PLANNED_NOT_EXECUTEDverifyBaselineBASELINE_ATTESTATION
PLANNED_NOT_EXECUTEDstageArtifactARTIFACT_ATTESTATION
PLANNED_NOT_EXECUTEDexerciseForwardFORWARD_TRACE
PLANNED_NOT_EXECUTEDexerciseDenialsNEGATIVE_GUARD_TRACE
PLANNED_NOT_EXECUTEDtriggerWatchdogWATCHDOG_TRACE
PLANNED_NOT_EXECUTEDexerciseCompensationCOMPENSATION_TRACE
PLANNED_NOT_EXECUTEDverifyHostCleanHOST_CLEAN_ATTESTATION
PLANNED_NOT_EXECUTEDverifyNetworkCleanNETWORK_CLEAN_ATTESTATION
PLANNED_NOT_EXECUTEDretireHostRETIREMENT_ATTESTATION
PLANNED_NOT_EXECUTEDsealDossierDOSSIER_SEAL
PLANNED_NOT_EXECUTEDHOST_CLAIMclaimHost · asymmetric signer required
REQUIRED_NOT_OBSERVEDISOLATION_ATTESTATIONverifyIsolation · asymmetric signer required
REQUIRED_NOT_OBSERVEDBASELINE_ATTESTATIONverifyBaseline · asymmetric signer required
REQUIRED_NOT_OBSERVEDARTIFACT_ATTESTATIONstageArtifact · asymmetric signer required
REQUIRED_NOT_OBSERVEDFORWARD_TRACEexerciseForward · asymmetric signer required
REQUIRED_NOT_OBSERVEDNEGATIVE_GUARD_TRACEexerciseDenials · asymmetric signer required
REQUIRED_NOT_OBSERVEDWATCHDOG_TRACEtriggerWatchdog · asymmetric signer required
REQUIRED_NOT_OBSERVEDCOMPENSATION_TRACEexerciseCompensation · asymmetric signer required
REQUIRED_NOT_OBSERVEDHOST_CLEAN_ATTESTATIONverifyHostClean · asymmetric signer required
REQUIRED_NOT_OBSERVEDNETWORK_CLEAN_ATTESTATIONverifyNetworkClean · asymmetric signer required
REQUIRED_NOT_OBSERVEDRETIREMENT_ATTESTATIONretireHost · asymmetric signer required
REQUIRED_NOT_OBSERVEDDOSSIER_SEALsealDossier · asymmetric signer required
REQUIRED_NOT_OBSERVED- 01
UPSTREAM RECEIPTexact test-only driver qualification
VERIFIED - 02
HOST PROFILEbindHost mutated to 0.0.0.0
DRIFT - 03
ISOLATION GUARDexact 127.0.0.1:8110 required
DENIED - 04
ADMISSION HANDLEnever minted
ABSENT - 05
HOST / DRIVER / WATCHDOGno downstream action possible
0 / 0 / 0
CONTROLLER_PROCESS_ABSENTREQUIRED_NOT_OBSERVEDPORT_8110_ABSENTREQUIRED_NOT_OBSERVEDPUBLIC_BIND_ABSENTREQUIRED_NOT_OBSERVEDREVERSE_PROXY_ABSENTREQUIRED_NOT_OBSERVEDUNIT_REMOVED_OR_EXACTLY_RESTOREDREQUIRED_NOT_OBSERVEDROLLBACK_SNAPSHOT_EXACTLY_RESTOREDREQUIRED_NOT_OBSERVEDEXCLUSIVE_LOCK_RELEASEDREQUIRED_NOT_OBSERVEDHOST_AND_ROOT_VOLUME_RETIREDREQUIRED_NOT_OBSERVEDUNTRUSTEDno upstream qualification standing existsQUALIFICATION_BOUNDthe exact target-host driver qualification was positively verifiedHOST_PROFILE_BOUNDthe non-production disposable-host boundary is exactPLAN_BOUNDtwelve phases and the independent watchdog are frozen without commandsEVIDENCE_MANIFEST_BOUNDall twelve future evidence slots are explicit and unobservedPREPAREDone opaque sixty-second admission capability existsADMITTED_TEST_ONLYthe plan may proceed only to a separately authorized disposable-host runDISPOSEDan unused capability was revokedDENIEDshape, isolation, provenance, execution material or receipt drift failed closed01obtain explicit cost and runtime approval for a disposable non-production hostREQUIRED
02create a dedicated non-production account and VPC with no production connectivityREQUIRED
03build and sign the prestaged immutable conformance imageREQUIRED
04implement the separate target-host driver package and complete syscall reviewREQUIRED
05configure an asymmetric evidence signer without exporting private materialREQUIRED
06configure a durable monotonic journal and independent watchdog identityREQUIRED
07execute all twelve phases and eight watchdog triggers on the disposable hostREQUIRED
08capture signed terminal evidence for process, port, proxy, unit, snapshot and lock cleanupREQUIRED
09prove instance and root-volume retirement from an independent authorityREQUIRED
10review the sealed conformance dossier before any production activation discussionREQUIRED
谁可以宣布一次主机测试可信:不是 Controller 自报,而是完整签名证据链共同裁决
工作台把已准入计划、fixture 执行回执、12 份阶段回执与 8 份独立终态证明拼成一份只读卷宗。任一身份、顺序、前驱摘要、签名或 watchdog authority 漂移都会拒绝封存;输出只代表 fixture conformance,不授予生产晋级权。
- execution id
- rfdhcx1:…fixture
- mode
- IN_MEMORY_HOST_EVIDENCE_FIXTURE_ONLY
- host claim
- sha256:…bound
- image
- sha256:…immutable
- journal head
- phase[12].receiptDigest
- timebox
- ≤ 15 minutes
EXECUTION SIGNERfixture-p256-conformance-execution
1 VERIFIEDPHASE SIGNERfixture-p256-conformance-evidence
12 VERIFIEDTERMINAL AUTHORITYINDEPENDENT_FIXTURE_WATCHDOG
8 VERIFIEDclaimHostHOST_CLAIM
GENESIS · sha256:…01VERIFIED_FIXTURE_ONLYverifyIsolationISOLATION_ATTESTATION
← 01 · sha256:…02VERIFIED_FIXTURE_ONLYverifyBaselineBASELINE_ATTESTATION
← 02 · sha256:…03VERIFIED_FIXTURE_ONLYstageArtifactARTIFACT_ATTESTATION
← 03 · sha256:…04VERIFIED_FIXTURE_ONLYexerciseForwardFORWARD_TRACE
← 04 · sha256:…05VERIFIED_FIXTURE_ONLYexerciseDenialsNEGATIVE_GUARD_TRACE
← 05 · sha256:…06VERIFIED_FIXTURE_ONLYtriggerWatchdogWATCHDOG_TRACE
← 06 · sha256:…07VERIFIED_FIXTURE_ONLYexerciseCompensationCOMPENSATION_TRACE
← 07 · sha256:…08VERIFIED_FIXTURE_ONLYverifyHostCleanHOST_CLEAN_ATTESTATION
← 08 · sha256:…09VERIFIED_FIXTURE_ONLYverifyNetworkCleanNETWORK_CLEAN_ATTESTATION
← 09 · sha256:…10VERIFIED_FIXTURE_ONLYretireHostRETIREMENT_ATTESTATION
← 10 · sha256:…11VERIFIED_FIXTURE_ONLYsealDossierDOSSIER_SEAL
← 11 · sha256:…12VERIFIED_FIXTURE_ONLYCONTROLLER_PROCESS_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYPORT_8110_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYPUBLIC_BIND_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYREVERSE_PROXY_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYUNIT_REMOVED_OR_EXACTLY_RESTOREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYROLLBACK_SNAPSHOT_EXACTLY_RESTOREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYEXCLUSIVE_LOCK_RELEASEDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLYHOST_AND_ROOT_VOLUME_RETIREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY- 01
PLAN + EXECUTIONexact upstream digests
VERIFIED - 02
PHASE CHAIN12 ordered receipts · journal closes
VERIFIED - 03
TERMINAL AUTHORITYmutated to CONTROLLER_SELF_REPORT
DRIFT - 04
INDEPENDENCE GUARDController self-report cannot replace the independent terminal watchdog authority.
DENIED - 05
DOSSIER HANDLEnever minted after proof drift
ABSENT
UNTRUSTEDpacket not trustedPLAN_ADMISSION_BOUNDexact plan admission verifiedEXECUTION_RECEIPT_BOUNDfixture execution identity boundPHASE_CHAIN_BOUND12 receipts form one chainTERMINAL_PROOF_BOUND8 independent terminal proofs boundPREPAREDopaque handle mintedSEALED_TEST_ONLYfixture-only seal issuedVERIFIEDseal digest re-verifiedDISPOSEDunused handle retiredDENIEDfail-closed terminal state01obtain explicit cost and runtime approval for a disposable non-production hostREQUIRED
02create a dedicated non-production account and VPC with no production connectivityREQUIRED
03build and sign the prestaged immutable conformance imageREQUIRED
04implement the separate target-host driver package and complete syscall reviewREQUIRED
05configure asymmetric evidence signers without exporting private materialREQUIRED
06configure a durable monotonic journal and independent watchdog identityREQUIRED
07execute all twelve phases and eight watchdog assertions on the disposable hostREQUIRED
08capture signed terminal evidence for process, port, proxy, unit, snapshot and lock cleanupREQUIRED
09prove instance and root-volume retirement from an independent authorityREQUIRED
10review the sealed production dossier under a separately approved promotion policyREQUIRED
把“可以测试”拆成三份独立批准:谁付钱、允许跑多久、谁负责证明彻底销毁
这不是创建 EC2 的按钮。工作台只把已封存的 fixture 卷宗、合成成本上限、隔离运行时边界和独立退役预留绑定为一份不可变执行信封。任一批准过期、预算越界、镜像漂移或销毁责任缺失,信封都不会生成。
INDEPENDENT_COST_OWNERsynthetic estimate is inside a 500 milli-USD test ceilingfixture-p256-cost-owner
INDEPENDENT_RUNTIME_OWNER900-second isolated non-production run and 120-second cleanup boundaryfixture-p256-runtime-owner
INDEPENDENT_RETIREMENT_WATCHDOGinstance and root-volume retirement proof is mandatoryfixture-p256-retirement-watchdog
- pricing basis
- SYNTHETIC_FIXTURE_NOT_LIVE_QUOTE
- live price reads
- 0
- run window
- 900s
- cleanup window
- 120s
- production connectivity
- FALSE
- public network
- FALSE
sealed dossier receiptsha256:… exact subject binding
UPSTREAM VERIFIEDimmutable imagesha256:… exact subject binding
BOUND_NOT_LOADEDtarget-host driver artifactsha256:… exact subject binding
BOUND_NOT_LOADEDController service bundlesha256:… exact subject binding
BOUND_NOT_LOADEDtwelve-phase conformance plan bundlesha256:… exact subject binding
BOUND_NOT_LOADEDindependent watchdog bundlesha256:… exact subject binding
BOUND_NOT_LOADEDdeny-by-default network policysha256:… exact subject binding
BOUND_NOT_LOADEDinstance-and-volume cleanup policysha256:… exact subject binding
BOUND_NOT_LOADED- 00s
REQUEST WINDOW OPENSnonce-bound authorization request
≤ 60s - 01
FOUR TRUST RECEIPTS VERIFIEDdossier + three independent owners
FIXTURE - 02
PACKAGE DIGEST FROZENcost and runtime limits become immutable
BOUND - 03
NO-LAUNCH ENVELOPE MINTEDeligible only for a separately approved fixture executor
TEST_ONLY - ⊣
HOST LAUNCH BARRIERno executor, IAM, quote or paid-resource authority
STOP
- 01
SEALED DOSSIERexact receipt and pinned contract digest
VERIFIED - 02
COST APPROVALmaximum 500 milli-USD
BOUND - 03
ESTIMATED COSTmutated to 501 milli-USD
OVER CAP - 04
BUDGET GUARDA synthetic estimate above the independently approved maximum cannot mint an execution envelope.
DENIED - 05
ENVELOPE / HOST / BILLINGno downstream capability or side effect
0 / 0 / 0
UNTRUSTEDpacket not trustedDOSSIER_BOUNDsealed dossier provenance verifiedCOST_APPROVED_TEST_ONLYsynthetic cost ceiling acceptedRUNTIME_APPROVED_TEST_ONLYisolated runtime envelope acceptedRETIREMENT_RESERVED_TEST_ONLYindependent cleanup owner reservedPACKAGE_MANIFEST_BOUNDall package and policy digests frozenPREPAREDopaque capability mintedAUTHORIZED_TEST_ONLY_NO_LAUNCHtest-only no-launch receipt issuedVERIFIEDreceipt digest re-verifiedDISPOSEDunused capability revokedDENIEDfail-closed terminal state01obtain explicit user authorization for paid disposable non-production computeREQUIRED
02replace synthetic cost evidence with a reviewed immutable pricing quote sourceREQUIRED
03create a dedicated non-production account and VPC with no production connectivityREQUIRED
04build and sign the prestaged immutable conformance image and all package artifactsREQUIRED
05configure independent cost, runtime and retirement signing authoritiesREQUIRED
06implement and syscall-review a separate host executor with no shell surfaceREQUIRED
07configure a durable monotonic execution journal and independent watchdog runtimeREQUIRED
08execute the package on one disposable host under the exact cost and time envelopeREQUIRED
09capture independent process, port, proxy, unit, snapshot, lock, instance and volume retirement proofREQUIRED
10review the resulting real-host dossier before any production activation discussionREQUIRED
执行器不是一个 Shell:每一步只能走命名端口,主机占位只允许一次,结束必须交出独立退役证明
工作台把上一层 no-launch 信封投影到内存 fixture 驱动。五个执行端口与三个独立 watchdog 端口分属不同 authority;任何 BASH、进程、主机接触、包加载或退役歧义都会中止前进,绝不会被解释为付费主机授权。
sha256(authorizationId + executionPackageId + dossierId)hostClaimKey- maximum claims
- 1
- durable claim store
- NOT CONFIGURED
- AWS ClientToken
- NOT DERIVED
- fixture scope
- TRUE
- REQUEST30s authorization windowBOUND
- WATCHDOGreserved before session openFIXTURE
- RETIREMENTinstance + root volumeMANDATORY
CLAIM_HOSTclaimHost()derive one fixture-only host claim
BIND_EXECUTION_PACKAGEbindPackage()bind without loading package bytes
START_DEADLINE_WATCHDOGstartDeadlineWatchdog()reserve fixture deadline observation
ATTEST_ISOLATIONattestIsolation()prove modeled network and credential closure
OPEN_FIXTURE_SESSIONopenSession()open an in-memory typed session only
SEAL_FIXTURE_SESSIONsealSession()seal fixture evidence without a spawned process
RETIRE_FIXTURE_HOSTretireHost()retire modeled instance and root volume
VERIFY_RETIREMENTverifyRetirement()positively verify terminal retirement
- 01
AUTHORIZED ENVELOPEexact no-launch receipt
VERIFIED - 02
CLAIM STEPtyped fixture evidence expected
OPEN - 03
SHELL SURFACEmutated from NONE to BASH
DRIFT - 04
STEP VERIFIERA typed fixture step that exposes BASH is rejected before it can become trusted executor evidence.
DENY - 05
HOST / PROCESS / PACKAGEno trusted forward progress
0 / 0 / 0
UNTRUSTEDpacket not trustedENVELOPE_VERIFIEDupstream provenance acceptedREQUEST_BOUNDexact no-spend request frozenHOST_CLAIMED_FIXTURE_ONLYdeterministic fixture claimPACKAGE_BOUND_NOT_LOADEDidentity bound; bytes absentWATCHDOG_RESERVED_FIXTURE_ONLYindependent deadline reservedISOLATION_ATTESTED_FIXTURE_ONLYmodeled closure attestedSESSION_OPEN_IN_MEMORYtyped session onlySESSION_SEALED_IN_MEMORYevidence sealed; no processHOST_RETIREMENT_REQUESTED_FIXTURE_ONLYmandatory cleanup invokedRETIREMENT_VERIFIED_FIXTURE_ONLYinstance + root volume provenROLLED_BACK_OR_CONTAINEDsafe failure terminal01A user must explicitly authorize a reviewed real cost ceiling and quote source for a paid disposable host.REQUIRED
02A durable idempotent host-claim store with generation fencing must be deployed and recovery-drilled.REQUIRED
03A reviewed no-shell production worker driver must implement the exact closed typed-port interface.REQUIRED
04An independently owned deadline and retirement driver must be deployed with separate credentials.REQUIRED
05A dedicated non-production VPC, subnet, security group and deny-by-default egress policy must exist.REQUIRED
06An immutable image and every execution-package digest must be staged and re-verified on the target host.REQUIRED
07The job credential, cloud credential and registration secret closures must be observed on a real disposable host.REQUIRED
08Instance and root-volume retirement must be independently observed within the 120-second cleanup deadline.REQUIRED
09Ambiguous launch, timeout and retirement drills must prove whole-pool freeze without orphaned capacity.REQUIRED
10Controller 0/11 production readiness gates must pass with signed runtime evidence and rollback proof.REQUIRED
11An explicit change window must authorize production wiring while port 8110, proxy and public routes remain separately controlled.REQUIRED
两个幂等键必须一起生、一起变、一起进入终态
Delivery 与 Job Attempt 分别占一行,但所有状态变更都在同一个 DynamoDB transaction 中完成。120 秒租约只允许同一 Plan 恢复;接管必须轮换 token 并递增 epoch,旧 Controller 永远不能完成新租约。
TRANSACT
ABSENTreserveRESERVED
leaseEpoch=1RESERVEDrenewRESERVED
same lease tokenRESERVED_EXPIREDrecoverExpiredRESERVED
new token + epoch incrementRESERVEDcompleteCOMPLETED
current unexpired tokenRESERVEDfailFAILED
current unexpired tokenreserveTransactWriteItemsattribute_not_exists(pk)
lease epoch 1renewTransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired
same epoch, extended expiryrecoverExpiredBatchGetItem + TransactWriteItemspair + scope + same plan + exact expired token/epoch/expiry
new lease token, epoch + 1completeTransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired
COMPLETED + receipt digestfailTransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired
FAILED + terminal phase01delivery and job-attempt keys change atomicallyPASS_TEST_ONLY
02replay never overwrites an existing or terminal pairPASS_TEST_ONLY
03expired leases require same-plan recovery, never fresh reservePASS_TEST_ONLY
04recovery rotates the lease token and increments the fencing epochPASS_TEST_ONLY
05stale token or epoch cannot renew, complete or failPASS_TEST_ONLY
06pair reads are strongly consistent and corruption fails closedPASS_TEST_ONLY
07terminal rows retain replay evidence for seven daysPASS_TEST_ONLY
08lease token values never enter public evidence or structured logsPASS_TEST_ONLY
01reviewed DynamoDB table with PITR, encryption and TTLREQUIRED
02least-privilege controller IAM role scoped to one tableREQUIRED
03conditional-conflict, corruption and throttling metricsREQUIRED
04expired-lease reconciler with single-owner electionREQUIRED
05backup restore and region-failure drill receiptsREQUIRED
06security, runtime and cost owner approvalREQUIRED
先钉住公钥,再签摘要;每一张收据离开 Adapter 前都必须本地验真
生产目标只接受精确 KMS Key ARN、SIGN_VERIFY / P-256 公钥与固定 SPKI 指纹。当前 Saga 使用 TEST_ONLY P-256 driver 运行真实 ECDSA 链;没有创建 KMS Key、没有 IAM 权限,也没有一张 runtime receipt。
只证明 webhook dry-run 决策;共享密钥测试签名不能成为生命周期收据。
trust / TEST_ONLY10 阶段真实签名并本地验链;private test key 不进入公开证据。
algorithm / ECDSA_SHA_256真实 Key、IAM、告警与轮换演练缺失,Signer readiness 必须 fail closed。
runtime receipts / 0UNINITIALIZEDinitializeKEY_PINNED
all key metadata and SPKI fingerprint matchKEY_PINNEDsign genesisCHAIN_OPEN
sequence 0 + previousDigest nullCHAIN_OPENsign nextCHAIN_OPEN
sequence N + previous digestCHAIN_OPENverifyVERIFIED
digest + ECDSA + continuity passANYmismatch or outageFAIL_CLOSED
no unsigned receipt emittedinitializeGetPublicKeyexact ARN + SIGN_VERIFY + ECC_NIST_P256 + ECDSA_SHA_256 + pinned SPKI fingerprint
cached local verifiersignSignexact ARN + DIGEST + ECDSA_SHA_256 + canonical SHA-256
DER signature bound to key metadataverifyLOCALcanonical digest + chain predecessor + pinned public key
cryptographic receipt verdict01signing uses an exact KMS key ARN, never a mutable aliasPASS_TEST_ONLY
02the KMS key must be SIGN_VERIFY on ECC_NIST_P256PASS_TEST_ONLY
03the SPKI SHA-256 fingerprint is pinned before signingPASS_TEST_ONLY
04KMS signs exactly 32 digest bytes with MessageType DIGESTPASS_TEST_ONLY
05the returned key ARN and algorithm must match the requestPASS_TEST_ONLY
06every receipt is locally verified before it leaves the adapterPASS_TEST_ONLY
07sequence and predecessor digest make chain reordering fail closedPASS_TEST_ONLY
08canonical facts are bounded plain JSON and secret-like string fields are deniedPASS_TEST_ONLY
09private key material never enters public evidence or runtime logsPASS_TEST_ONLY
10TEST_ONLY signatures never increment runtime receipt truthPASS_TEST_ONLY
01reviewed asymmetric KMS SIGN_VERIFY key with rotation policyREQUIRED
02least-privilege kms:GetPublicKey and kms:Sign controller IAM roleREQUIRED
03approved exact key ARN and SPKI fingerprint configurationREQUIRED
04sign latency, throttling, invalid-signature and key-drift alarmsREQUIRED
05key-disable, rotation, rollback and verification drill receiptsREQUIRED
06security, runtime and cost owner approvalREQUIRED
Token 只在一次受控调用中存在;不是 JSON、不是字符串、也不是可回放凭证
Gitea 1.25.4 的组织 Runner 注册接口把 Token 放在 HTTP token 响应头。Adapter 只接受 200 + owned mutable bytes,再交付 30 秒单消费者能力句柄;公开证明只记录状态,不记录 Token 值或摘要。
UNISSUEDissue valid header bytesACTIVE
HTTP 200 + mutable token header + bounded ASCIIACTIVEinspectACTIVE
no token or digest exposedACTIVEconsumeCONSUMING
atomic single-consumer claimCONSUMINGconsumer exitsCONSUMED
zeroize in finally on success or failureACTIVEdestroyDESTROYED
zeroize without disclosureACTIVETTL elapsesEXPIRED
zeroize before denialCONSUMED|DESTROYED|EXPIREDconsumeDENY
replay never reopens capabilityissuecontrollerexact organization + plan scope + SecretRef-backed driver
ACTIVE opaque capabilityinspectcontrollermetadata only; expiry may advance state
secret-free lifecycle proofconsumetrusted Gitea registration adapterACTIVE + unexpired + single in-flight consumer
CONSUMED and zeroized even on callback failuredestroycontroller compensationnot concurrently CONSUMING
DESTROYED or idempotent terminal proof01the request is scoped to the configured organization and admitted factory planPASS_TEST_ONLY
02the broker credential is a SecretRef and never a caller-supplied valuePASS_TEST_ONLY
03Gitea 1.25.4 success is exactly HTTP 200 with the token response headerPASS_TEST_ONLY
04the runtime driver must transfer owned mutable bytes, never an immutable stringPASS_TEST_ONLY
05token bytes are bounded printable token characters and at most 512 bytesPASS_TEST_ONLY
06the capability ID is independent random data and is never derived from the tokenPASS_TEST_ONLY
07inspect and JSON serialization expose lifecycle metadata but no token or token digestPASS_TEST_ONLY
08only one consumer may claim the capability and reentrant consumption is deniedPASS_TEST_ONLY
09TTL expiry zeroizes bytes before returning an expired verdictPASS_TEST_ONLY
10consumer success and consumer failure both zeroize bytes in a finally boundaryPASS_TEST_ONLY
11explicit destroy is idempotent after a terminal state and cannot race consumptionPASS_TEST_ONLY
12TEST_ONLY token activity never increments runtime or Gitea-write truthPASS_TEST_ONLY
01root-scoped Gitea broker credential delivered by a systemd Credential fileREQUIRED
02isolated runtime driver that transfers the token header directly into owned mutable bytesREQUIRED
03exact Gitea base URL, organization and credential SecretRef configurationREQUIRED
04token issue latency, response-contract, replay and expiry alarmsREQUIRED
05credential rotation, broker outage and zeroization drill receiptsREQUIRED
06security and runtime owner approvalREQUIRED
启动不是成功;只有关掉云凭证、跑完唯一 Job、再证明机器与根卷消失,才算闭环
Adapter 将 launch / closeCloudBoundary / runJob / terminate 收敛为一个不可伪造的 Worker capability。Launch Template 必须使用精确 ID + 数字版本;Profile 脱离与 IMDS 关闭后必须重启复读,终止后必须同时看到 Instance terminal 与根卷 absent。
mutable $Default / $Latest deniedone subnet · one security group · no production routeexact profile ARN · detach association IDone handle · one admitted job · no replayDescribeInstances + DescribeVolumesUNALLOCATEDlaunchBOOTSTRAP_RUNNING
launch and attestation matchBOOTSTRAP_RUNNINGcloseCloudBoundaryCLOUD_BOUNDARY_CLOSED
profile absent + IMDS disabled + reboot verifiedCLOUD_BOUNDARY_CLOSEDrunJobJOB_RUNNING
exact job + zero prior jobsJOB_RUNNINGagent resultJOB_FINISHED
exact instance/job + one completionBOOTSTRAP_RUNNING|CLOUD_BOUNDARY_CLOSED|JOB_FINISHED|FAILED_NEEDS_TERMINATIONterminateTERMINATING
exact instance IDTERMINATINGretirement proofTERMINATED
instance terminated + root volume absentANY_MUTATINGdriver/proof failureFAILED_NEEDS_TERMINATION
no later admissionFAILED_NEEDS_TERMINATIONcompensateTERMINATING
termination remains retryableTERMINATEDterminateTERMINATED
return idempotent terminal prooflaunchEC2 RunInstances + DescribeInstancesone private instance + exact immutable template + job-bound tags + attached encrypted disposable root
BOOTSTRAP_RUNNINGcloseCloudBoundaryDescribeIamInstanceProfileAssociations + DisassociateIamInstanceProfile + ModifyInstanceMetadataOptions + RebootInstances + DescribeInstancesprofile absent and IMDS disabled after reboot
CLOUD_BOUNDARY_CLOSEDrunJobinjected one-job worker agentexact admitted job + boundary closed + jobsCompleted zero
JOB_FINISHEDterminateTerminateInstances + DescribeInstances + DescribeVolumesexact instance terminated + exact root volume absent
TERMINATED01launch uses an exact launch-template ID and numeric immutable versionPASS_TEST_ONLY
02ClientToken deterministically binds one admitted job attemptPASS_TEST_ONLY
03each request asks for exactly one on-demand private workerPASS_TEST_ONLY
04the worker receives no public IPv4, IPv6 or production routePASS_TEST_ONLY
05bootstrap IMDS requires v2 and a hop limit of onePASS_TEST_ONLY
06the bootstrap profile is exact and only present before admissionPASS_TEST_ONLY
07profile detachment and IMDS disablement are re-read after rebootPASS_TEST_ONLY
08untrusted work cannot start before the cloud boundary is closedPASS_TEST_ONLY
09the job identity must exactly match the launch planPASS_TEST_ONLY
10a worker completes at most one job and replay is deniedPASS_TEST_ONLY
11the root gp3 volume is encrypted and delete-on-terminationPASS_TEST_ONLY
12retirement requires both instance termination and volume absencePASS_TEST_ONLY
13failed boundary, job or retirement proofs remain non-admissiblePASS_TEST_ONLY
14public proof excludes credentials, user data and mutable capabilitiesPASS_TEST_ONLY
RF_WORKER_CONFIG|DRIVER|SCOPE|HANDLEPRE_MUTATIONdeny without EC2 callRF_WORKER_LAUNCH_*LAUNCHfail reservation and reconcile launch request IDRF_WORKER_BOUNDARY_*BOUNDARYkeep offline and terminateRF_WORKER_JOB_*EXECUTIONdeny reuse and terminateRF_WORKER_TERMINATION_*RETIREMENTfreeze capacity and page owner01approved immutable launch template, AMI digest and numeric template versionREQUIRED
02dedicated private CI subnet, zero-ingress security group and verified no-production routesREQUIRED
03least-privilege bootstrap instance profile with detach permission owned by the controllerREQUIRED
04AWS SDK runtime driver with bounded waiters, retry budgets and request-ID journalingREQUIRED
05worker-agent authenticated channel that cannot mint cloud credentialsREQUIRED
06instance and root-volume orphan reconciliation alarms with a named on-call ownerREQUIRED
07security, runtime and cost-owner approvalREQUIRED
Runner 在线不等于 Job 可执行;Gitea 分配事实与 root 凭证封存必须同时成立
本刀把旧的三段无状态假方法收敛为不可伪造的 Runner capability。顺序已纠正为 关闭 Profile / IMDS → 重启复读 → 再签发 Token → 注册;避免 tmpfs 凭证被重启清空,也避免 30 秒 Token 跨越 EC2 启动窗口。
GET /repos/reits/:repo/actions/jobs/:jobid = admitted jobrunner_id = capability runnerrunner_name = deterministic namestatus = in_progresslabels = exact allowlist
SealAssignment(worker, runner, job, maxJobs=1).runner file = absentreusable credential = falsejob UID read = deniedlease = root memory / exact jobsecond assignment = denied
RegisterRunnerone-time mutable token bytesAUTHORITY NOT RECORDEDGET /orgs/reits/actions/runners/{runner_id}control credential referenceSECRETREF ONLYGET /repos/{owner}/{repo}/actions/jobs/{job_id}control credential referenceSECRETREF ONLYSealAssignmentroot-owned unix socketSECRETREF ONLYDELETE /orgs/reits/actions/runners/{runner_id}control credential referenceSECRETREF ONLYDestroyRunnerStateroot-owned unix socketSECRETREF ONLYregisterEphemeralcloud-closed worker + mutable one-time token bytes + exact org/repo/job/plan/labelsworker-agent attestation + org-scoped Gitea runner GET
retire unemitted runner or report cleanup unprovenverifyAssignmentopaque runner capability + admitted job + maxJobs=1repo job GET binds runner_id/name + root agent removes reusable file and holds one exact-job memory lease
FAILED_NEEDS_DELETEdeleteRunneropaque runner capabilityorg runner DELETE returns 204/404 + root agent destroys credential and assignment state
FAILED_NEEDS_DELETE and retryable01registration occurs only after the EC2 profile is detached, IMDS is disabled and reboot readback passesPASS_TEST_ONLY
02the 30-second registration-token handle is issued after cloud-boundary closure, never across launch or rebootPASS_TEST_ONLY
03registration secret is passed as the same mutable Buffer and is never copied, serialized, hashed or retainedPASS_TEST_ONLY
04organization, repository, job, plan, worker, labels and maxJobs are exact rather than caller-selectedPASS_TEST_ONLY
05runner registration must be ephemeral and independently re-read through the organization-scoped Gitea APIPASS_TEST_ONLY
06public runner capability excludes control credentials, registration bytes and reusable runner credentialsPASS_TEST_ONLY
07assignment requires Gitea job status in_progress with exact runner_id, runner_name and labelsPASS_TEST_ONLY
08Gitea assignment proof and root-owned worker-agent credential proof are distinct and both mandatoryPASS_TEST_ONLY
09the reusable .runner file is absent before untrusted code while one exact-job lease remains in root daemon memoryPASS_TEST_ONLY
10reits-job cannot read the runner credential file, agent socket or assignment leasePASS_TEST_ONLY
11a second assignment or wrong job is permanently deniedPASS_TEST_ONLY
12runner deletion accepts only Gitea 204 or already-absent 404 as control-plane terminalPASS_TEST_ONLY
13retirement additionally destroys credential files, the in-memory lease and worker-local runner statePASS_TEST_ONLY
14registration failures after runner creation attempt cleanup before any capability can escapePASS_TEST_ONLY
15failed assignment or deletion stays non-admissible and requires retry or worker terminationPASS_TEST_ONLY
16no test-driver call counts as a Gitea read, write, live runner or runtime assignmentPASS_TEST_ONLY
RF_GITEA_CONFIG|DRIVER|SCOPE|LABELS|WORKER|HANDLEPRE_MUTATIONdeny without registrationRF_GITEA_REGISTRATION_*REGISTRATIONdelete any identifiable unemitted runner, destroy local state and terminate workerRF_GITEA_ASSIGNMENT_*ASSIGNMENTdeny job, delete runner and terminate workerRF_GITEA_CREDENTIAL_SEAL_*CREDENTIAL_BOUNDARYdeny untrusted code, delete runner and terminate workerRF_GITEA_DELETE_*|RF_GITEA_LOCAL_RETIREMENT_PROOFRETIREMENTretry 204/404 reconciliation; freeze capacity if terminal proof remains missing01least-privilege Gitea credential reference restricted to reits organization runner read/delete and admitted repository job readREQUIRED
02root-owned worker-agent binary and unix socket with an authenticated controller channelREQUIRED
03runner version and labels pinned in the immutable AMI, with --ephemeral enforcedREQUIRED
04tmpfs credential path and filesystem/UID denial test proving reits-job cannot read root authorityREQUIRED
05bounded API retries, delete reconciliation journal and orphan-runner alarmREQUIRED
06registration/assignment/retirement runtime receipts joined to plan, worker, runner and job identitiesREQUIRED
07security owner, Gitea owner and runtime owner approvalREQUIRED
容量必须在启动 EC2 之前占用;终止证明不完整时,宁可冻结整个池也不重新放号
旧 Saga 只在任务结束后调用 replacement,无法阻止并发 webhook 超过目标两台。现在每个计划先原子占用一个 generation-fenced 槽位;只有 Worker capability 与 KMS 验证的终止收据同时通过,槽位才以 N → N+1 恢复可用。
generation 7opaque leasegeneration 12one job maxClientToken reconcilegeneration mismatchoperator pageexact plan + job + instance
Profile absent · IMDS disabled
root volume deleted · jobs 0/1
normal or compensation retirement
exact worker + plan + job facts
canonical digest + KMS public key
lease cleared · plan cleared
same slot consistently readable
next admission can proceed
AcquireSlotMUTATIONpool active + available slot + unique plan/job attemptReadSlotCONSISTENT READconsistent exact-slot readbackReplaceSlotMUTATIONlease + generation + plan/job + signed retirement digestFreezePoolMUTATIONuncertain slot causes global scheduling denialReadPoolCONSISTENT READconsistent freeze readbackacquireACQUIREDone exact slot claimed atomicallyconfirmReplacementREPLACINGworker terminal + signed retirement receipt verifiedCAS + readbackREPLACEDsame slot available at generation N+1driver/proof failureFAILED_NEEDS_FREEZEcapacity cannot be admittedunsafe lifecycle failureFAILED_NEEDS_FREEZEno silent slot releasefreezeFROZENwhole-pool freeze read backconfirmReplacementREPLACEDside-effect-free terminal retryfreezeFROZENside-effect-free terminal retrylate conflicting mutationDENIEDterminal capability cannot cross stateacquireexact plan + one slot + one job + atomic available-slot claimopaque ACQUIRED capacity capability
confirmReplacementterminal Worker proof + verified normal/compensation retirement receipt + generation CAS + consistent readbacksame slot AVAILABLE at generation N+1
freezeoccupied or uncertain slot + bounded reason + durable whole-pool readbackFROZEN scheduling pool
inspectunforgeable in-process capabilitysecret-free slot proof
01global pool size is enforced before EC2 launch, not inferred after launchPASS
02capacity means concurrent ephemeral-worker budget and never claims warm instancesPASS
03each admitted plan consumes exactly one slot for one job attemptPASS
04plan and job-attempt replay cannot acquire another slotPASS
05slot authority is an opaque capability and its lease token is never serializedPASS
06replacement requires the Worker capability to prove terminal instance and deleted root volumePASS
07replacement also requires a cryptographically verified normal or compensation retirement receiptPASS
08receipt facts bind the exact plan, job, worker ID and storage terminal statePASS
09replacement uses the current lease and generation as a fencing conditionPASS
10replacement is accepted only after a consistent read shows generation N+1 availablePASS
11an ambiguous replacement never reopens capacity and must freezePASS
12an unsafe lifecycle failure freezes the whole scheduling poolPASS
13freeze is accepted only after an independent pool readbackPASS
14terminal replacement and freeze retries are side-effect freePASS
15there is no adapter path that unfreezes production capacityPASS
16TEST_ONLY driver operations never count as runtime capacity evidencePASS
RF_CAPACITY_CONFIG|DRIVER|VERIFIER|SCOPEPRE_MUTATIONdeny before capacity claimRF_CAPACITY_ACQUIRE_*|REPLAYADMISSIONdeny launch; reconcile any ambiguous claimRF_CAPACITY_RECEIPT_*|WORKER_PROOFRETIREMENTkeep slot non-admissible and freezeRF_CAPACITY_REPLACE_*REPLACEMENTfreeze whole pool; page ownerRF_CAPACITY_FREEZE_*CONTAINMENTdeny all scheduling externally; require operator reconciliation01durable strongly consistent capacity ledger with atomic slot claim and generation CASREQUIRED
02runtime driver identity restricted to one reviewed pool and no unfreeze permissionREQUIRED
03pinned KMS public verifier for normal and compensation retirement receiptsREQUIRED
04Controller Saga integration that acquires capacity before EC2 launchREQUIRED
05alarm and named on-call owner for acquire ambiguity, replacement drift and freeze failureREQUIRED
06operator runbook requiring orphan reconciliation before a separate approved unfreeze pathREQUIRED
07security, runtime, reliability and cost-owner approvalREQUIRED
一条 KMS 回执链还不够;必须再证明每次写入没有漏、没有重排、没有覆盖、没有跨 Job 串链
旧实现只把 stage、digest 和 trust 推进内存数组,无法独立复核。现在每个 plan / job attempt 拥有独立 journal;签名回执形成内层链,CAS entry digest 形成外层链,成功只接受 F9 replacement,失败先补齐已签回执再写入枚举化终态。
instance-termination
展示的是确定性 TEST_ONLY 结构,不是生产 Runner 日志。
rfjrn1:…scope hashplan rfp_…job attempt rfj1:…repository reits/reits-authjob 905sequence08
previousEntryDigestsha256:…e07
entryDigestsha256:…e08
receipt.sequence8 / F8
previousDigestsha256:…f07
signatureECDSA_SHA_256 / pinned SPKI
✓journal scope equals signed plan/job factsPASS_TEST_ONLYV-01
✓entry indexes are contiguous from zeroPASS_TEST_ONLYV-02
✓every outer predecessor digest recomputesPASS_TEST_ONLYV-03
✓every receipt signature uses the pinned public keyPASS_TEST_ONLYV-04
✓receipt sequence and predecessor remain contiguousPASS_TEST_ONLYV-05
✓head digest/count/status equal the verified rangePASS_TEST_ONLYV-06
CreateJournalCONDITIONAL_CREATEhead absent or exact same scopeReadHeadCONSISTENT_READscope, writer, sequence, digest and terminal state agreeAppendEntryATOMIC_CASexpected head sequence + digest + OPEN and new entry absentReadEntryCONSISTENT_READambiguous-write recovery and exact replay onlyReadRangeCONSISTENT_READcomplete ordered range for independent verificationopenOPEN_EMPTYconditional journal creationopen replayOPEN_EMPTYsame exact scopeappend F0OPEN_ACTIVEsigned genesis receiptappend F1-F8OPEN_ACTIVEboth chains remain contiguousappend exact F9SEALED_SUCCESSreplacement-capacity receiptsealFailureSEALED_FAILUREno signed receipt existsreconcile + sealFailureSEALED_FAILUREall signed receipts are present firstexact seal replaySEALED_FAILUREterminal payload is byte-equivalentinspectSAMEconsistent head proofverifyVERIFIED_SAMEfull dual-chain verificationopenexact plan, job attempt, repository and job scopeopaque journal capability
appendReceiptpinned signature + exact scope + contiguous receipt and entry predecessorsCAS-appended dual-chain entry
sealFailurereconcile signed receipts + bounded phase, code and compensation factsterminal failure entry
inspectopaque capability + consistent head readsecret-free head proof
verifyconsistent full range + entry hashes + signatures + both predecessor chainsindependent chain verdict
01one journal is deterministically partitioned by exact plan and job-attempt scopePASS
02journal capabilities are opaque object identities and never serialize write authorityPASS
03the runtime writer must be one exact controller IAM role rather than a mutable aliasPASS
04entries are created only through expected-sequence, expected-digest and OPEN-state CASPASS
05the driver surface exposes no entry update, journal delete or adapter-side unseal operationPASS
06every receipt is verified by the pinned asymmetric public key before persistencePASS
07every signed receipt binds plan, job attempt, repository and job identityPASS
08receipt sequence and receipt predecessor digest must be contiguousPASS
09entry sequence and entry predecessor digest form an independent outer chainPASS
10ambiguous append is accepted only after exact entry and consistent-head readbackPASS
11same sequence with different content is a terminal conflict rather than an overwritePASS
12only signed sequence F9 kind replacement-capacity may seal successful completionPASS
13failure sealing first reconciles every signed receipt supplied by the SagaPASS
14terminal failure facts accept only bounded codes and enumerated compensation identifiersPASS
15a terminal journal accepts only byte-equivalent replay and never new entriesPASS
16full verification rereads the complete range and recomputes every digestPASS
17secret-like arbitrary strings, credentials and token material never enter the journal contractPASS
18TEST_ONLY driver evidence never increments runtime journal, read, write or readiness truthPASS
SCOPE_OR_HANDLEdeny before journal authority is usedSIGNATURE_OR_RECEIPT_CHAINdeny untrusted, cross-job or reordered receiptAPPEND_AMBIGUITYrecover only exact committed entry, otherwise fail closedHEAD_OR_RANGE_DRIFTdeny independent verification and page operatorTERMINAL_CONFLICTpreserve first terminal fact and deny mutationDRIVER_UNAVAILABLEblock admission or compensate the Saga without claiming audit durability01reviewed durable journal table with point-in-time recovery and encryptionREQUIRED
02transactional head CAS plus immutable entry rows with no update or delete APIREQUIRED
03least-privilege controller writer role pinned by exact IAM ARNREQUIRED
04separate read-only verifier role and scheduled full-chain verificationREQUIRED
05retention, export, legal-hold and disaster-recovery policyREQUIRED
06append conflict, verification drift, stale-open-journal and seal-failure pagingREQUIRED
07security, runtime, retention and cost owner approvalREQUIRED
Controller 重启后不能靠单表猜测清理;五个权威源必须在同一个 Job 边界里重新对齐
Reservation、Capacity、Worker、Runner 与 Journal 各自只能证明一部分事实。本工作台把五份只读快照收敛为 SAFE 或 CONTAIN,并生成整池冻结与值班通知计划;它没有终止实例、删除 Runner、封存 Journal 或发送告警的权限。
先证明五次读取属于同一次捕获,再允许 Planner 判断 SAFE 或 CONTAIN
每路请求共享 capture、plan、job attempt、pool、slot、scope digest 和 2 秒 deadline。Reader 必须回显固定 authority、STRONGLY_CONSISTENT 与 request digest;超时不会被静默丢弃,而是正规化为 UNKNOWN 后交给 Planner 隔离。
capturerfcap1:…d64
planrfp_0123…4567
job attemptrfj1:…a64
repositoryreits/reits-auth
pool / slotlinux-amd64 / 01
deadlineT+2000ms
reservation-ledgerexact dual-key reservation, lease and terminal state
- consistency
- STRONG
- request digest
- MATCH
- outcome
- UNKNOWN
capacity-ledgerexact pool slot, generation, occupancy and freeze state
- consistency
- STRONG
- request digest
- MATCH
- outcome
- OBSERVED
ec2-worker-read-modelexact instance lifecycle and root-volume retirement state
- consistency
- STRONG
- request digest
- MATCH
- outcome
- OBSERVED
gitea-runner-read-modelexact Gitea plus root-agent credential and local-state facts
- consistency
- STRONG
- request digest
- MATCH
- outcome
- UNKNOWN
append-only-journalexact consistent head, terminal state and receipt count
- consistency
- STRONG
- request digest
- MATCH
- outcome
- OBSERVED
reservationUNAVAILABLE / UNKNOWNRF_SOURCE_TIMEOUT
capacityOBSERVED / OCCUPIEDgeneration 4
workerOBSERVED / RUNNINGinstance + root volume
runnerUNAVAILABLE / UNKNOWNRF_SOURCE_UNAVAILABLE
journalOBSERVED / OPEN7 receipts · head digest
readPlanDigestscope + five requests + deadline
snapshotDigestnormalized facts + ordered receipts
packetDigestplan + snapshot + capture outcome
01PLANNEDfive read requests share one scope digest and deadline
02READINGall five read-only ports execute concurrently
03COMPLETEfive observed authority-pinned results fit the skew window
04PARTIAL_UNAVAILABLEone to four sources normalized to UNKNOWN for containment
05ALL_UNAVAILABLEzero sources observed and scheduling must contain
06DENIED_INTEGRITYidentity, consistency, shape, time, secret or digest guard failed
planexact capture, plan, job-attempt, repository, pool and slot scopefive immutable strongly-consistent read requests with one deadline
capturefive authority-pinned reader functions and bounded response identitiescomplete or explicitly unavailable normalized snapshot packet
verifyexact packet shape, source order and recomputed read/snapshot/packet digestslocal boolean verification without external reads or writes
01one capture binds an exact plan, job attempt, repository, pool and slot scopePASS
02exactly five named reader ports are required and no wildcard reader is acceptedPASS
03all source queries request strongly consistent reads under one bounded deadlinePASS
04source name and authority are pinned independently of driver-returned payload dataPASS
05every response must echo the exact immutable request digestPASS
06every observed read timestamp must fall inside the capture deadlinePASS
07the maximum skew between observed source reads cannot exceed two secondsPASS
08reader rejection or timeout becomes explicit UNAVAILABLE and UNKNOWN evidencePASS
09partial reads are never omitted, substituted with cache data or treated as safePASS
10cross-source scope drift is preserved for the reconciliation planner to containPASS
11secret-like keys are rejected before snapshot or receipt materializationPASS
12source records use exact bounded fields and enum states without extension bagsPASS
13source receipts are ordered Reservation, Capacity, Worker, Runner and JournalPASS
14snapshot identity commits to scope, normalized facts and all source receiptsPASS
15read-plan, snapshot and packet digests are independently recomputed on verifyPASS
16deterministic replay of the same capture and source facts yields the same digestsPASS
17the coordinator owns no terminate, delete, seal, release, freeze or page operationPASS
18runtime source reads, writes, mutations, snapshots and secret values remain zeroPASS
RF_SOURCE_TIMEOUT|RF_SOURCE_UNAVAILABLEnormalize that source to UNKNOWN and force planner containmentRF_RECON_SOURCE_IDENTITYdeny response with wrong source, authority, consistency, digest or timestamp identityRF_RECON_SOURCE_SHAPEdeny malformed or extension-bearing source factsRF_RECON_CAPTURE_SKEW|RF_RECON_SOURCE_TIMEdeny incoherent capture timing instead of joining unrelated readsRF_RECON_CAPTURE_SECRETdeny secret-like input before it can enter receipts or snapshot evidenceRF_RECON_CAPTURE_DIGESTdeny any read-plan, snapshot or packet evidence tamper01dedicated loopback Controller runtime identity and root-owned configurationREQUIRED
02strongly consistent Reservation reader with exact dual-key scopeREQUIRED
03strongly consistent Capacity reader with pool generation fencingREQUIRED
04credential-free EC2 Worker read model with volume retirement proofREQUIRED
05read-only Gitea and root-agent Runner evidence aggregationREQUIRED
06consistent append-only Journal head and range verifierREQUIRED
07deadline, retry-budget and partial-read telemetry with fixed labelsREQUIRED
08security, platform, reliability and cost-owner approvalREQUIRED
ORPHAN_WORKER
Reservation 已终止,但 Worker 仍存活。任何自动终止都可能删错资源,因此先冻结调度、保留证据,再把执行动作交给独立审批器。
sha256:…fixtureexternal reads 0ReservationFAILEDlease closedCONFLICT
CapacityOCCUPIEDgeneration NBLOCK
WorkerRUNNINGroot volume attachedORPHAN
RunnerABSENTlocal state absentCLEAR
JournalSEALED_FAILUREconsistent headEVIDENCE
known unsafe combination · automatic cleanup denied
scheduler integration · NOT CONFIGURED
identifier-free P0 page · manual proof required
assessexact bounded five-source snapshot and no secret-like keysdeterministic SAFE or CONTAIN report
summarizeone to 1000 verified reportsbounded severity and containment totals
buildMetricsfixed metric names and controller-only labeleight low-cardinality gauge samples
buildPageCONTAIN report only; stable category dedupeidentifier-free PLANNED_NOT_SENT page
reits_rf_reconciliation_reports{controller="runner-factory"}FIXED
reits_rf_reconciliation_safe{controller="runner-factory"}FIXED
reits_rf_reconciliation_contained{controller="runner-factory"}FIXED
reits_rf_reconciliation_freeze_required{controller="runner-factory"}FIXED
reits_rf_reconciliation_page_p0{controller="runner-factory"}FIXED
reits_rf_reconciliation_page_p1{controller="runner-factory"}FIXED
reits_rf_reconciliation_page_p2{controller="runner-factory"}FIXED
reits_rf_reconciliation_unclassified{controller="runner-factory"}FIXED
01reconciliation reads reservation, capacity, worker, runner and journal as separate authoritiesPASS
02every observed non-absent authority binds the exact plan and job scopePASS
03unavailable or unknown source data can never produce a safe verdictPASS
04an expired active lease cannot remain schedulablePASS
05a live worker without an active reservation is an orphanPASS
06a live runner without a live exact worker is an orphanPASS
07registered or online runner authority must already be sealed from untrusted codePASS
08available capacity with a live worker is an overcommit riskPASS
09occupied capacity after worker termination is stranded until replacement proofPASS
10worker termination is incomplete until root-volume deletion is provedPASS
11runner retirement is incomplete until both Gitea and local state are absentPASS
12success journal state requires a completed reservationPASS
13failure journal state requires a failed reservationPASS
14an open journal older than five minutes is stalePASS
15any unclassified cross-source combination fails closedPASS
16metrics use fixed names and no repository, job, runner, instance or plan labelsPASS
17page plans contain only verdict, severity, digest and category dedupe identityPASS
18the planner performs zero mutations, external reads, writes or page deliveriesPASS
SOURCE_UNAVAILABLEplatform-oncallfreeze scheduling and retry consistent reads
SCOPE_MISMATCHsecurity-oncallfreeze, preserve evidence and deny all automatic cleanup
ORPHAN_WORKER|CAPACITY_*platform-oncallfreeze and require terminal Worker plus root-volume proof
ORPHAN_RUNNER|CREDENTIAL_*security-oncallfreeze and require Gitea plus root-agent deletion proof
SUCCESS_CONFLICT|FAILURE_CONFLICT|JOURNAL_STALEplatform-and-securitypreserve both chains and require manual reconciliation
UNCLASSIFIED_DRIFTplatform-oncallfreeze because absence of a known-safe state is unsafe
01strongly consistent read-only identities for all five authoritative sourcesREQUIRED
02bounded snapshot coordinator with skew, timeout and partial-read controlsREQUIRED
03scheduler freeze integration that cannot be bypassed by webhook admissionREQUIRED
04separate approved executors for termination, deletion, sealing and lease recoveryREQUIRED
05Prometheus-compatible exporter with the fixed eight-series label policyREQUIRED
06paging provider, dedupe window, escalation policy, owner and recovery runbookREQUIRED
07security, platform, reliability and cost-owner approvalREQUIRED
RC-01INGRESSsignature-or-payload-deniedreturn-denial-without-reservation
NO_RESOURCENOT_OBSERVEDRC-02RESERVATIONduplicate-or-conditional-write-conflictreturn-existing-plan-reference
NO_SECOND_WORKERNOT_OBSERVEDRC-03LAUNCHinstance-launch-failed-or-ambiguousfreeze-whole-pool-and-reconcile-idempotent-launch
NO_NEW_SCHEDULING_ON_AMBIGUITYNOT_OBSERVEDRC-04REGISTRATIONephemeral-registration-failedrevoke-secret-and-terminate-worker
NO_LIVE_REGISTRATION_SECRETNOT_OBSERVEDRC-05BOUNDARYprofile-detach-imds-disable-or-reboot-failedkeep-runner-offline-and-terminate-worker
NO_JOB_WITH_CLOUD_CREDENTIALNOT_OBSERVEDRC-06ASSIGNMENTwrong-job-or-second-assignmentrevoke-runner-and-terminate-worker
ONE_JOB_MAXIMUMNOT_OBSERVEDRC-07EXECUTIONjob-timeout-or-runner-lossterminate-worker-and-record-terminal-failure
NO_REUSED_WORKERNOT_OBSERVEDRC-08RETIREMENTtermination-or-replacement-receipt-missingfreeze-whole-pool-and-page-operator
POOL_FAILS_CLOSEDNOT_OBSERVEDdeliveryId + runId + jobId + attempt
replay accepted · FALSEephemeral registration · no persistent data
controller · IMPLEMENTED_DRY_RUNno host socket · no cloud credential · no production route
runner 2.0.0power off worker · confirm replacement capacity
whole-worker replacement requiredQUEUE_CAPACITY_ACQUIRED
factory-control-planeWORKER_BOOTSTRAP
root-bootstrapCLOUD_BOUNDARY_CLOSED
factory-control-planeEPHEMERAL_REGISTERED
gitea-runnerREADY_FOR_ONE_JOB
admission-controllerASSIGNED_REUSABLE_CREDENTIAL_SEALED
gitea-control-planeJOB_CONTAINER_RUNNING
rootless-dindJOB_FINISHED
gitea-runnerWORKER_RETIRED
factory-control-planeREPLACEMENT_CONFIRMED
factory-control-planeRF_ONE_JOBWorker handles at most one jobPASSNOT_OBSERVED
RF_SEAL_BEFORE_CODEReusable runner credential is removed before untrusted code; exact-job lease remains root-onlyPASSNOT_OBSERVED
RF_NO_JOB_CLOUDJob runs without instance profile or IMDSPASSNOT_OBSERVED
RF_NO_REGISTRATION_SECRETRegistration secret is destroyed before admissionPASSNOT_OBSERVED
RF_ROOTLESS_DINDJob runs in rootless DinD, never host modePASSNOT_OBSERVED
RF_NO_HOST_SOCKETHost Docker socket is never mountedPASSNOT_OBSERVED
RF_NO_PERSISTENT_DATARunner credential volume is not persistedPASSNOT_OBSERVED
RF_NO_PRODUCTION_ROUTEWorker has no production network routePASSNOT_OBSERVED
RF_REPLACE_AFTER_JOBWhole worker is retired and replacedPASSNOT_OBSERVED
RF_CONTROL_PLANE_RECEIPTRetirement receipt is issued outside the job boundaryPASSNOT_OBSERVED
RF-A01F6 · reusableRunnerCredentialLive=trueDENYRF_SEAL_BEFORE_CODE
RF-A02F6 · cloudCredentials=trueDENYRF_NO_JOB_CLOUD
RF-A03F6 · registrationSecret=trueDENYRF_NO_REGISTRATION_SECRET
RF-A04F6 · executionMode=hostDENYRF_ROOTLESS_DIND
RF-A05F6 · hostDockerSocketMounted=trueDENYRF_NO_HOST_SOCKET
RF-A06F6 · persistentRunnerDataVolume=trueDENYRF_NO_PERSISTENT_DATA
RF-A07F6 · productionRoute=trueDENYRF_NO_PRODUCTION_ROUTE
RF-A08F7 · jobsCompleted=2DENYRF_ONE_JOB
RF-A09F9 · replacementReceipt=falseDENYRF_REPLACE_AFTER_JOB
RF-A10F0 · replayAccepted=trueDENYRF_WEBHOOK_REPLAY
RF-A11F4 · untrustedCode=trueDENYRF_SEAL_BEFORE_CODE
RF-A12F7 · cleanupWithoutRetirementAccepted=trueDENYRF_CONTROL_PLANE_RECEIPT
Job 进程只准连接 127.0.0.1:3128,整个 loopback 不再默认可信
安全组仍保留 bootstrap/broker 的 HTTPS;`reits-runner` UID 只有一个 TCP socket 可达,DNS stub、本地服务、IPv6 与所有直连均由 nftables 拒绝,再由 CONNECT 代理审查目标。
gitea.reits.techdl.gitea.com
nodejs.orgregistry.npmjs.org
proxy.golang.orgsum.golang.orgstorage.googleapis.com
github.comapi.github.comobjects.githubusercontent.comraw.githubusercontent.com
crates.iostatic.crates.ioindex.crates.io
pypi.orgfiles.pythonhosted.org
✓Runner registrations remain offline while the bootstrap IAM profile and IMDS are present.
✓The reusable Gitea registration token is rotated and its SSM SecureString is deleted before activation.
✓Both instance profiles are detached and IMDS is disabled before the first runner daemon starts.
✓Any replacement node remains fail-closed until the explicit finalization sequence is repeated.
RELEASE STATE MACHINE
六站流水线,九类证据,任一缺失即停止晋级
D05 定义平台级发布单元;R25 仍负责逐屏 exact release、smoke 与 rollback 证明,两者不能互相冒充。
Source
exact 40-char revision
→Build
isolated builder
→Package
full artifact + SBOM
→Configure
public config + migration
→Promote
immutable target
→Recover
named previous release
SOURCEsource.revisionGit 真值,不接受短 SHA
ARTIFACTartifact.digest完整目录、二进制或 OCI image
SBOMsbom.digestCycloneDX JSON 与 artifact 同次构建
CONFIGconfiguration.digest仅公开配置和引用名
MIGRATIONmigration.digest数据库/存储变更集合
SECRETSsecrets.refs[]只记录 SecretRef,绝不记录值
DEPLOYdeployment.target环境、目标与观测时间
ROLLBACKrollback.targetReleaseId晋级前存在且已验证
PROVENANCEprovenance.builderId独立 builder 与签名状态
LIVE AUDIT WORKBENCH
逐单元查看哪里已绑定、哪里只是观察到
2026-07-20 生产盘点快照;Portal 参考单元已闭合到 unsigned provenance,其余入口文件摘要仍明确标记 PARTIAL,HTTP 200 明确不等于发布身份。
reits-auth
reits/reits-auth · production / systemd
157b8590e4625ad2fda802410303461a69a74bd3production release directoryec2/systemd/reits-auth2026-07-20T08:53:00Z541d2a4d515dlinux-amd64-binary
/opt/reits-auth/current/bin/reits-authnot boundcyclonedx-json
receipt path missingnot boundredacted-config-manifest
receipt path missingnot boundmigration-set
receipt path missinghttps://auth.reits.tech/v1/meta
referencesOnly=true · 0 refs
No named target
Builder identity missing
FAIL-CLOSED QA
错误码直接定位 source、制品、运行态或恢复责任人
RU_SOURCE_UNBOUND部署无法回指一个干净的 40 位 source revision。
repository ownerRU_ARTIFACT_PARTIAL只摘要入口文件,不能证明完整运行制品未漂移。
build ownerRU_SBOM_MISSING依赖物料表未与该制品摘要绑定。
supply chainRU_CONFIG_UNBOUND公开配置、迁移集或 SecretRef 未形成独立摘要。
service ownerRU_RUNTIME_IDENTITY运行态 health/meta 不返回同一份安全发布身份。
runtime ownerRU_ROLLBACK_UNVERIFIED没有命名并验证可恢复的前一发布单元。
release ownerDeveloper Portal 先实现安全 runtime receipt
本刀已经提供 release schema、公开配置、注册表、验证器接口和 /api/release-unit;部署时由不可变外部 receipt 注入 exact SHA 与摘要,避免“把当前 commit 写回当前 commit”的自引用循环。
当前 4 / 36 已验收,D05 是第 5 刀,项目仍剩 32 刀
要把 D05 切到 ACCEPTED,必须先提供专用 CI 计算资源,使 18 个仓 Gate 与 Mac 原生 lane 真实执行;再让全部部署单元闭合 artifact、SBOM、config、migration、SecretRef、runtime identity、provenance 与 rollback。生产 EC2 不会被拿来伪造这一结果。