D05 ACTIVE / RELEASE FOUNDATION

同一份发布身份,从源码一直活到回滚

最新源码与 EC2 盘点识别出 10 个真实部署单元:10 个能回指 exact source,9 个绑定完整制品,3 个公开运行态身份;SBOM、配置、迁移、SecretRef 与签名 provenance 仍未全局闭合。

ACCEPTEDD01–D04manifest · contract · UI · CI
CURRENT KNIFED05 / 36release identity + isolated runner
AFTER ACCEPTANCED06browser auth SDK / BFF
D05 VERDICTACTIVEdedicated compute not provisioned
DEPLOYMENT UNITS10systemd · OCI · Sites
EXACT SOURCE10/1040-char revision
FULL ARTIFACT9/101 incomplete package
RUNTIME META3/10public + secret-free
SBOM / SIGNED1/0both fail closed

LIVE CHANGE CONTROL · AUTH

候选、必需检查与生产真值分开显示

auth 的发布身份实现已经形成可审查候选;生产安全漂移已恢复,但候选没有通过受保护分支,因此没有被冒充为线上 release。

CURRENT PRODUCTIONSAFE
157b8590e462

environment · production

productionSafe
true
previewEnabled
false
release receipt
MISSING
Observed 2026-07-20T09:54:01Z
PROTECTED MAIN
!

REITS Minimum CI / gate (pull_request)QUEUED · no eligible org runner

!

reits-auth security CI / verify (pull_request)QUEUED · no eligible org runner

direct push · DENIED
MERGE CANDIDATE · PR #6BLOCKED_REQUIRED_CHECKS
b697a726c1b9

feat/d05-release-identity

artifact startup check
IMPLEMENTED
SBOM / config / migration
IMPLEMENTED
SecretRef / provenance
PARTIAL
打开 Gitea 合并请求 →
01

Required pull-request checks complete on isolated runner.

02

Protected main contains the exact candidate revision or its merge commit.

03

Linux artifact and receipt are generated together in an immutable release directory.

04

Production smoke passes, predecessor rollback is exercised, then the candidate is re-promoted.

为什么不部署No eligible organization runner can claim either required check.production ≠ candidate

LIVE CHANGE CONTROL · DATA SOURCES

先证明候选,再替换原地覆盖式生产

data-sources 的 main 与生产仍精确一致且服务正常,但当前二进制位于可变目录。新候选已经把运行二进制、SBOM、公开配置、40 份 SQLite/PostgreSQL 迁移和 SecretRef 绑定到同一 release ID;保护分支检查未运行,因此没有切换生产。

CURRENT PRODUCTIONACTIVE
a01a445d0a10

mutable-in-place-binary

service
RUNNING
artifact
eb553e7188da
runtime receipt
MISSING
Observed 2026-07-20T10:23:00Z
PROTECTED MAIN
!

REITS Minimum CI / gate (pull_request)QUEUED · no eligible Linux runner

!

REITS Minimum CI / minimum (pull_request)BLOCKED_BY_GATE · no eligible Linux runner

direct push · DENIED
MERGE CANDIDATE · PR #1BLOCKED_REQUIRED_CHECKS
fd9b873244d6

reits-data-sources@fd9b873244d6-0eab4831edfe

exact executable
BOUND
SBOM / config / 40 migrations
BOUND
SecretRef / provenance
PARTIAL
打开 data-sources PR →
01

The protected required gate and dependent minimum job complete on an isolated Linux runner.

02

Protected main contains the reviewed candidate or its merge commit; rebuild from that exact clean revision.

03

Provision the dedicated service account, systemd credential and immutable release directory without mutating crawler data.

04

Pass local health and release identity probes, exercise the named rollback, then atomically move current.

为什么不部署The required gate is waiting because data-sources has no eligible repository or organization Linux runner; the minimum job cannot start before that gate.main = production ≠ candidate

P0 · EXECUTION PLANE

Runner 必须离开生产共享故障域

现有在线 Linux runner 只属于 im-core;组织 runner 为 0,Mac runner 离线。承载 Gitea、IM、业务、数据库和日志的生产 EC2 明确不可用于不受信任 CI。

CURRENT · VERIFIEDACTIVE_BLOCKED
1

Linux online
repo-scoped · im-core only

0

organization runners
17 gates queued

0

Mac online
native lanes unavailable

The only accessible EC2 hosts public web, Gitea, IM, business services, databases and logging; CI workloads must not share this failure and trust domain.
TARGET · REQUIREDDEDICATED
2

Linux org runners
concurrency 1 each

1

Mac runner
Swift / iOS lane

0

production co-location
socket + subnet denied

Ephemeral workspace · restricted egress · resource limits · registration token by root-owned file.
01

Dedicated CI compute account or VM; no production service is co-located.

02

Untrusted pull-request jobs cannot access home directories, cloud credentials, Docker sockets or production subnets.

03

The organization registration secret exists only during offline bootstrap, is never committed/logged and is reset before any daemon starts.

04

CPU, memory, process, disk and job duration limits are enforced; workspaces are destroyed after every job.

05

The job UID can reach only loopback; outbound CONNECT requests pass through a root-managed proxy allowlist that denies private destinations and direct sockets.

LIVE RUNNER ADMISSION LEDGER

两台已注册,不等于一台可用于 D05

Gitea 组织、21 个仓库与 AWS 账户已重新盘点。每台 Runner 必须逐项通过 scope、短生命周期、平台标签与隔离证明;“online”只是信号,不是准入结论。

DENIED_NO_ELIGIBLE_CAPACITY
REGISTERED2admin inventory
ONLINE1not automatically trusted
ELIGIBLE0admission result
ORG ONLINE0reits scope
AWS REUSABLE00 ASG · 1 prod EC2
AWS / ap-southeast-2CC · c8i-flex.xlargei-09a6dae0352cff5af

Shared production failure domain for Gitea, business services, IM, databases and logs.

RUNNER ELIGIBLE · FALSE
LIVE FILTER2 / 2 registered
eligible · 0
RUNNER #2 · ONLINE

reits-im-core-linux-arm64

Visible only from reits/im-core after scanning all 21 reits repositories; absent from the reits organization inventory.

DENIED
scope repositoryephemeral falsebusy falserepository reits/im-core

Runner onlineGitea admin API reports online and idle.

PASS
!

Organization scopeRepository-scoped to reits/im-core.

FAIL
!

Ephemeral workspaceGitea reports ephemeral=false.

FAIL
!

Dedicated compute attestationNo reviewed host or network attestation is bound.

MISSING
!

Reviewed architectureRunner name declares arm64; reviewed D05 Linux template is x86_64.

FAIL
ubuntu-latestubuntu-24.04ubuntu-22.04
PROTECTED CHANGE QUEUE2 candidates
reits/data-sourcesPR #1 · fd9b873244d6
WAITING_RUNNER

!REITS Minimum CI / gate (pull_request)REQUIRED · Waiting to run

!REITS Minimum CI / minimum (pull_request)DEPENDENT · Blocked by required conditions

reits/reits-authPR #6 · b697a726c1b9
WAITING_RUNNER

!reits-auth security CI / verify (pull_request)REQUIRED · Waiting to run

!REITS Minimum CI / gate (pull_request)REQUIRED · Waiting to run

OPERATOR DECISION

Do not expand the im-core runner scope or schedule CI on the shared production EC2.

Provision the reviewed two-node organization runner stack after explicit cost approval, then rotate the registration token and execute the isolation drill.
FAIL-CLOSED PROVISIONING PACKET

双 AZ 模板已被凭证边界闩锁,禁止创建付费资源

隔离 VPC、零入站、单端点出站与任务后清理已经落到模板;但 host executor 与 daemon 共用 UID,任务可以读取可复用 Runner 凭证,因此 deploy 在访问 AWS 和 Secret 前直接退出。

REVISION_REQUIRED
CI-ONLY VPC10.91.0.0/16no peering · no production route
AZ-Arunner-01Ubuntu 24.04 · capacity 1
AZ-Brunner-02Ubuntu 24.04 · capacity 1
ACTIVATION GATEprofile detached + IMDS offotherwise daemon refuses to start
JOB CREDENTIAL BOUNDARY · LIVE DESIGN AUDIT

清空工作目录,不等于隔离 Runner 凭证

Gitea 1.25.4 与最新模板 Runner 2.0.0 已核对;当前 host 模式让 daemon 和不受信任任务使用同一 UID,`.runner` 文件仍在任务信任域内。

BLOCKED_HOST_EXECUTOR_SHARED_UID
GITEA SERVER1.25.4live API
TEMPLATE RUNNER2.0.0latest stable · digest pinned
EXECUTORHOSTno encapsulation
JOB READS CREDENTIALTRUE/var/lib/reits-runner/.runner
DEPLOY PERMITTEDFALSEexit 78 before AWS
CURRENT TEMPLATEreits-runner daemonsame UIDreits-runner jobreusable credential · not revoked before job
→ BLOCKED →
REQUIRED FACTORYsingle-use credentialrevoked before untrusted codereplace boundary after jobsingle-use ephemeral VM factory with the rootless DinD lifecycle contract at /api/runner-factory
POST-TASK CLEANUPHOOK_READY_UNTRUSTED_RECEIPTRunner 2.0.0 · timeout 1m

/var/lib/reits-runner/work/var/lib/reits-runner/tmp

TRUSTED RECEIPT · FALSE
SINGLE-USE RUNNER FACTORY · DRY-RUN CONTROL PLANE

事件先验真、容量先占位、任务只跑一次、失败必须回到安全态

Controller 服务包、七个运行时端口、持久预留、非对称收据、Token Broker、EC2 Worker、Gitea 精确分配与全局两槽容量控制均已有可执行实现;生产 webhook、持久账本、KMS Key、Gitea 凭证、Launch Template、CI 网络和真实 Worker 仍全部明确不存在。

DISPOSABLE_HOST_NO_SHELL_EXECUTOR_READY_NOT_CONFIGURED
LIVE WORKERS0runtime observed
LIFECYCLE STAGES10ordered · fail closed
MAX JOBS / WORKER1second assignment denied
ATTACK FIXTURES12/12contract denial
RUNTIME RECEIPTS0BLOCKED_RUNTIME
DEPLOY PERMITTEDFALSEno paid resource created
FACTORY CONTROLLER · REAL EXECUTION SURFACE
一条 webhook 只能得到一个 PLAN_ONLY,不可能从客户端打开 apply

当前实现只做可信入口、策略判定、幂等预留和测试收据。所有值都来自机器契约,不用“已设计”冒充“已运行”。

DRY_RUN_READY
LIVE ENDPOINTFALSEruntime absent
RAW BODY SIGNATUREHMAC-SHA256256 KiB maximum
ADMITTED REPOS18D04 registry exact match
CONTROLLER FIXTURES19/20deny · 1 plan-only
DRY-RUN RECEIPTS4TEST_ONLY
CLOUD MUTATIONS0apply path absent
01 · VERIFYraw body HMAC

X-Gitea-Signature · constant-time compare

invalid → 401 / no reservation
02 · NORMALIZEworkflow_job / queued

delivery · run · job · attempt

other transitions → deny
03 · ADMITreits + ubuntu-latest

18 exact repositories · Mac split

unregistered scope → deny
04 · RESERVEdual SHA-256 locks

delivery + job attempt · repository + job attempt

runtime store · DYNAMODB_ADAPTER_IMPLEMENTED_NOT_CONFIGURED
05 · PLANworker plan + chain

4 TEST_ONLY receipts · no secrets

apply supported · FALSE
INGRESS ENVELOPErequired / secret-free log

X-Gitea-SignatureHMAC over exact raw bytesREQUIRED

X-Gitea-Deliveryunique UUID deliveryREQUIRED

X-Gitea-Eventworkflow_jobREQUIRED

X-Gitea-Event-Typeworkflow_jobREQUIRED

Content-Type: application/jsonaction: queuedlabel: ubuntu-latest
WORKER PLAN · NON-APPLICABLEPLAN_ONLY_NOT_APPLIED

COMPUTEc7i-flex.largelinux-amd64 · ap-southeast-2

NETWORKPRIVATE / 0 INGRESSprivate-ci-only-no-production-route

CREDENTIALROOT TMPFSroot-owned-tmpfs-vs-reits-job

JOBROOTLESS DIND0 host mounts · max 1 job

VOLUMEDELETE ON RETIREencrypted-gp3-delete-on-termination

AUTHORIZATIONFALSE / FALSEcost approval · runtime approval

PROVIDER · aws-ec2RESOURCES CREATED · 0APPLY · FALSE
RUNTIME ADAPTER PORTS · EXECUTABLE / UNCONFIGURED
业务编排已经能完整跑完;容量在 EC2 前占位,所有外部副作用仍被端口边界锁死

DynamoDB、Gitea 与 EC2 请求由纯函数生成;Receipt Signer 校验精确 KMS 身份,Token Broker 只接受 Gitea token header 可清零字节,Capacity Controller 则用代际栅栏阻止第三个并发计划。未配置端口仍 fail closed,TEST_ONLY driver 只证明生命周期和补偿。

PORTS_EXECUTABLE_NOT_CONFIGURED
ADAPTER PORTS7configured · 0
SAGA CASES131 complete · 12 safe terminal
COMPENSATED11reservation failure needs no undo
RECEIPT CHAIN10TEST_ONLY
EXTERNAL WRITES0AWS 0 · Gitea 0
SECRET EXPOSURE0token handle zeroized
01reservation-storeDEFAULT DENY
dynamodb-transact-write

reserve + renew + recoverExpired + complete + fail

dual conditional rows + 120s lease + rotating fencing epoch
TEST DOUBLE · memory-dynamodb-driver
02receipt-signerDEFAULT DENY
aws-kms-asymmetric

GetPublicKey + Sign + local verify

exact key ARN + pinned SPKI + DIGEST + ECDSA_SHA_256 + chain continuity
TEST DOUBLE · memory-kms-driver
03token-brokerDEFAULT DENY
gitea-organization-runner-token

POST /orgs/reits/actions/runners/registration-token

HTTP 200 token header → owned mutable bytes → 30s single-consumer handle → zeroize
TEST DOUBLE · memory-gitea-token-driver
04worker-providerDEFAULT DENY
aws-ec2 + one-job worker agent

launch + closeCloudBoundary + runJob + terminate

immutable template + private one-instance launch + profile/IMDS closure + one exact job + instance/root-volume retirement proof
TEST DOUBLE · memory-ec2-driver
05gitea-control-planeDEFAULT DENY
gitea-actions + root-owned worker agent

registerEphemeral + verifyAssignment + deleteRunner

register only after cloud closure + exact org/repo/job/runner + reusable credential removed before code + Gitea 204/404 and local-state terminal proof
TEST DOUBLE · memory-gitea-control-driver
06capacity-controllerDEFAULT DENY
durable-ephemeral-worker-capacity-ledger

acquire + confirmReplacement + freeze + inspect

global two-slot claim occurs before launch; only signed terminal replacement reopens generation N+1; ambiguity freezes the pool
TEST DOUBLE · memory-capacity-driver
07audit-sinkDEFAULT DENY
append-only-receipt-journal

open + appendReceipt + sealFailure + inspect + verify

exact plan/job scope + pinned signatures + dual hash chain + CAS head + terminal seal
TEST DOUBLE · memory-audit-driver
ATOMIC RESERVEDynamoDB TransactWriteItemstwo attribute_not_exists(pk)
SIGN EVIDENCEKMS Sign / DIGESTexact key ARN + pinned SPKI
ONE-TIME TOKENGitea organization brokersingle consumer · never logged
WORKER LIFECYCLEEC2 ClientTokenone instance · idempotent retire
RECONCILEconfirm or freezemissing proof blocks capacity
PRODUCTION PREREQUISITESall blocked · explicit owner approval required
PERSISTENCE

DynamoDB reservation and capacity ledgersapproval · cost-and-runtime

NOT_CREATED
SIGNING

asymmetric KMS SIGN_VERIFY keyapproval · security-and-cost

NOT_CREATED
TOKEN

root-scoped Gitea broker credentialapproval · security-owner

NOT_CONFIGURED
COMPUTE

EC2 launch template and CI-only networkapproval · cost-and-runtime

NOT_CREATED
JOURNAL

durable append-only receipt journalapproval · security-and-cost

NOT_CREATED
ONCALL

five-source reconciliation reader, metrics exporter, paging provider and ownerapproval · platform-owner

NOT_CONFIGURED
ZERO-RUNTIME PROOFAdapter 代码存在,但 webhook endpoint、DynamoDB table、KMS key、broker credential、launch template、receipt journal 与 on-call alarm 均不存在。paid resources · FALSE
CONTROLLER SERVICE PACKAGE · EXECUTABLE / NOT DEPLOYED
可启动不等于可上线:服务先回答“我活着”,再精确说明“我为什么未就绪”

Node 入口、HTTP 边界与 systemd 加固模板已经闭合。环境变量只能选择 EVIDENCE_ONLY,监听只允许 loopback;生产 webhook 在 JSON 解析与策略处理前返回 503,测试模式只能由代码显式注入。

PACKAGE_EXECUTABLE_NOT_DEPLOYED
HTTP ROUTES3health · ready · webhook
READINESS0/11BLOCKED_CONFIGURATION
REQUEST FIXTURES15real handler + HTTP listener
CONFIG FIXTURES5wildcard · apply · inline secret denied
LIVE LISTENERS0unit installed · FALSE
PROD ACCEPTED0public route · FALSE
UNTRUSTED EVENTGitea workflow_jobexact raw bytes · UUID delivery
NETWORK BOUNDARYreverse proxy → loopback127.0.0.1:8110 · CORS absent
PROCESS BOUNDARYHMAC + 256 KiB + inflight 4secret file reference · values never logged
PRODUCTION ACTION503 DEFAULT DENYapply false · external writes 0
ROUTE CONTRACT3 routes
GET

/healthzprocess liveness without readiness claims

200 ALIVE
GET

/readyzall production prerequisites must be receipted

503 BLOCKED
POST

/webhooks/gitearaw-body HMAC admission; production path currently blocked

503 PROD / 202 FIXTURE
READINESS MATRIX0/11 · fail closed

01DEDICATED_HOSTBLOCKED

02SERVICE_IDENTITYBLOCKED

03WEBHOOK_SECRETBLOCKED

04RESERVATION_STOREBLOCKED

05RECEIPT_SIGNERBLOCKED

06TOKEN_BROKERBLOCKED

07WORKER_PROVIDERBLOCKED

08GITEA_CONTROLBLOCKED

09CAPACITY_CONTROLLERBLOCKED

10AUDIT_SINKBLOCKED

11OWNER_APPROVALBLOCKED

SYSTEMD HARDENING · TEMPLATE ONLY

dedicated non-login identityshared production host condition denycredential file referenceno new privilegesstrict filesystem protectionempty capabilitiesloopback-only IP policy0077 process umask

ZERO DEPLOYMENT PROOFUnit 未安装 · credential files 0 · live replicas 0 · external writes 0permission · FALSE
CONTROLLER RUNTIME ASSEMBLY · EXECUTABLE / NOT CONFIGURED
Readiness 不再是一排可以手填的布尔值,而是一张能回指身份、配置与证据的收据

装配器先钉住 dedicated host、非登录服务身份与五个只读 Reader,再逐条验证 11 个 Gate attestation。缺一条就是 503;重复、过期、错 scope、错签名或 secret-like 字段直接拒绝,不能靠环境变量把 Controller 变成 READY。

ASSEMBLY_VERIFIER_IMPLEMENTED_NOT_CONFIGURED
ASSEMBLY OPS4plan · assemble · verify · project
READER BINDINGS5configured · 0
LIVE READINESS0/11receipt verified · FALSE
FIXTURE PACKETS321 ready · 5 blocked
DENIED INPUTS26boolean escalations · 1
LISTENERS / RECEIPTS0/0external writes · 0
01 · MANIFESTservice + 5 readersConfigRef / KeyRef only
02 · IDENTITYdedicated host + UID 991fresh boot-bound observation
03 · ATTEST11 signed gatessubject + evidence + expiry
04 · RECEIPTdigest-backed projectionno raw boolean ingress
05 · /readyz0/11 · HTTP 503production remains absent
REFERENCE MANIFEST · SHAPE ONLYNOT INSTALLED

controllerrfctl1:…c64

servicereits-runner-factory · 991:991

bind / mode127.0.0.1:8110 · EVIDENCE_ONLY

attestation keykeyref://…/production-p256-v1

01

Reservationreservation-ledger

dynamodb-consistent-getCONFIGREF · NOT RESOLVED
02

Capacitycapacity-ledger

dynamodb-consistent-getCONFIGREF · NOT RESOLVED
03

Workerec2-worker-read-model

ec2-describeCONFIGREF · NOT RESOLVED
04

Runnergitea-runner-read-model

gitea-root-agent-compositeCONFIGREF · NOT RESOLVED
05

Journalappend-only-journal

dynamodb-consistent-queryCONFIGREF · NOT RESOLVED
SELECTED FIXTURE · RFRA-0610/11 · BLOCKED_CONFIGURATION

manifestDigestsha256:…manifest

identityDigestsha256:…identity

receiptDigestsha256:…receipt

expiresT+300s max

01DEDICATED_HOSTTEST_VERIFIED

02SERVICE_IDENTITYTEST_VERIFIED

03WEBHOOK_SECRETTEST_VERIFIED

04RESERVATION_STORETEST_VERIFIED

05RECEIPT_SIGNERTEST_VERIFIED

06TOKEN_BROKERTEST_VERIFIED

07WORKER_PROVIDERTEST_VERIFIED

08GITEA_CONTROLTEST_VERIFIED

09CAPACITY_CONTROLLERTEST_VERIFIED

10AUDIT_SINKTEST_VERIFIED

11OWNER_APPROVALMISSING

OWNER_APPROVAL missing即使前十条 fixture 证据成立,receipt 仍保持 BLOCKED;生产当前不是 10/11,而是 0/11。
FOUR RECEIPT-BOUND OPERATIONSadapter construction absent
plan

exact service identity, five ordered readers and reference-only configurationimmutable assembly plan and manifest digest

assemble

fresh dedicated-host identity plus zero to eleven verified gate attestationsblocked or ready receipt without constructing an adapter

verify

recompute plan, identity, receipt and packet digests and reverify attestationslocal integrity verdict with no external call

toControllerRuntime

only a verified packet may project ordered readiness gatesreceipt-backed service readiness snapshot

FIVE ASSEMBLY STATESpartial never means ready

01MANIFEST_PLANNEDservice, reader and attestation boundaries have one digest

02IDENTITY_BOUNDfresh dedicated-host and non-login service identity matches the manifest

03GATES_PARTIALone or more required attestations remain missing and readiness stays blocked

04READY_VERIFIEDall eleven fresh attestations verify under the pinned key reference

05DENIED_INTEGRITYidentity, scope, time, signature, shape or digest verification failed

20 READINESS INVARIANTSfixture-only · all enforced

01readiness cannot be enabled by environment booleans or caller-provided gate flagsPASS

02one manifest binds one production controller identity and one immutable assembly identifierPASS

03the service identity is a dedicated non-login user with an exact UID and GIDPASS

04the manifest only permits loopback port 8110 in EVIDENCE_ONLY modePASS

05the runtime host must attest dedicated control-plane use and no production workload sharingPASS

06runtime identity freshness is bounded by the manifest attestation agePASS

07exactly five ordered source-reader descriptors exist without wildcard fallbackPASS

08every reader is strongly consistent and has read-only least-privilege operationsPASS

09reader configuration uses ConfigRef values and never embeds credentials or secret materialPASS

10the attestation verifier key is an exact KeyRef and cannot be supplied inlinePASS

11exactly eleven named readiness gates exist and unknown gate names are deniedPASS

12gate readiness comes from the presence of a verified attestation rather than a boolean fieldPASS

13every attestation binds controller, manifest, runtime identity and evidence digestPASS

14every attestation is fresh, unexpired and verified by the injected pinned verifierPASS

15duplicate gate attestations are denied instead of last-write-wins replacementPASS

16partial evidence produces BLOCKED_CONFIGURATION with an exact missing-gate listPASS

17READY_VERIFIED requires eleven of eleven verified attestationsPASS

18plan, identity, readiness receipt and packet digests are independently recomputedPASS

19a runtime projection can only be derived from a fully verified assembly packetPASS

20assembly owns no install, listener, source call, adapter construction, external write or mutationPASS

FAILURE → SERVICE EFFECTintegrity deny · absence blocks
RF_ASSEMBLY_MANIFEST|SERVICE|READERSdeny unsafe service or reader assembly before identity evaluation
RF_ASSEMBLY_IDENTITY|IDENTITY_TIMEdeny shared, stale or scope-drifted controller runtime identity
RF_ASSEMBLY_ATTESTATION|ATTESTATION_SET|ATTESTATION_TIMEdeny malformed, duplicate, unknown, stale or expired Gate evidence
RF_ASSEMBLY_SIGNATUREdeny when the injected pinned verifier rejects or fails
RF_ASSEMBLY_RECEIPT|RUNTIME|PACKET|DIGESTdeny any readiness projection or digest inconsistency
RF_ASSEMBLY_SECRETdeny secret-like fields before plan, receipt or packet materialization
PRODUCTION ASSEMBLY GAPMANIFEST 0 · READERS 0/5 · GATES 0/11

01install one reviewed root-owned production assembly manifestREQUIRED

02attest a dedicated control-plane host with no shared production workloadREQUIRED

03install the exact non-login reits-runner-factory service identityREQUIRED

04resolve all five reader ConfigRefs under a read-only IAM and local-agent boundaryREQUIRED

05configure the pinned asymmetric readiness-attestation verifierREQUIRED

06issue and verify all eleven scope-bound readiness attestationsREQUIRED

07persist and expose the readiness receipt digest through loopback health onlyREQUIRED

08obtain security, runtime and cost owner approvals before any Controller activationREQUIRED

VERIFIER ≠ ACTIVATION装配、32 个案例、30 条已验证 fixture attestation 与 6 次 Controller projection 已实现;生产 manifest、runtime identity、五个 Reader、签名 verifier、readiness receipt、systemd unit 和 8110 listener 仍全部为 0。
ROOT-OWNED RUNTIME CONFIGURATION · EXECUTABLE / NOT INSTALLED
Controller 不能相信“调用者给我的 JSON”,它只相信同一个文件描述符上的所有权、字节与引用证明

Loader 只打开一个精确路径,拒绝 symlink、hard link、权限放宽、读中换 inode、非 canonical JSON 和任意类型回退;11 个 ConfigRef 与 1 个 VERIFY_ONLY KeyRef 必须逐项匹配,缺失只会得到 BLOCKED_CONFIGURATION。

CONFIGURATION_LOADER_IMPLEMENTED_NOT_INSTALLED
LOADER OPS5load · resolve · prepare · verify
REFERENCE SET11+17 exact types
FIXTURE CASES362 resolved · 5 blocked
DENIED INPUTS29tampered bundle · 1
PRODUCTION REFS0/11KeyRef · 0/1
BUNDLES / LISTENERS0/0external writes · 0
01 · OPENO_NOFOLLOW · O_CLOEXECexact path only
02 · PROVE FILEroot:service · 0640same fd · inode stable
03 · PARSEUTF-8 canonical JSON≤ 65,536 bytes
04 · RESOLVE11 ConfigRef + 1 KeyReffresh · typed · versioned
05 · BOOTNOT INSTALLEDadapters 0 · ready 0/11
MANIFEST FILE PROOFREFERENCE SHAPE · ABSENT
canonical path/etc/reits-runner-factory/controller-runtime.json
owner / group
root:reits-runner-factory
mode / links
0640 · nlink 1
bytes
1–65,536
descriptor
dev + ino + mtimeNs stable
content
UTF-8 · canonical JSON + LF
proof
contentDigest + fileProofDigest
TOCTOU CLOSEDbefore/after metadata 来自同一个已打开的 descriptor;路径替换不能偷换已验证字节。
TYPED REFERENCE LEDGERCONFIGURED 0/12
01

DYNAMODB_TABLE_ARNap-southeast-2 and exact reviewed table name

×3NOT CONFIGURED
02

IAM_ROLE_ARNexact read-only role suffix without wildcard

×4NOT CONFIGURED
03

AWS_REGIONap-southeast-2

×1NOT CONFIGURED
04

HTTPS_ORIGINhttps://gitea.reits.tech

×1NOT CONFIGURED
05

SECRET_REFopaque SecretRef only; never a credential value

×1NOT CONFIGURED
06

ROOT_AGENT_SOCKETexact /run read-only agent socket

×1NOT CONFIGURED
07

ECDSA_P256_SHA256VERIFY_ONLY metadata and pinned SPKI digest

×1NOT CONFIGURED
SECRET_REF ≠ SECRET唯一 credential 项只能解析为 opaque SecretRef;bundle、日志、API 与 fixture 都不接触 Token 值。
SELECTED FIXTURE · RFRC-06BLOCKED_CONFIGURATION

fileProofVERIFIED · TEST_ONLY

ConfigRef11/11 · TYPED

KeyRefMISSING · VERIFY_ONLY

adapter construction0 · DENIED

缺少 KeyRef 时仍能给出精确 missing list,但不能创建 verifier、Reader、receipt 或 listener。
SIX CONFIGURATION STATESpartial never boots
01

UNLOADEDno production manifest or reference has been read

02

FILE_VERIFIEDpath, ownership, mode, link count and same-descriptor metadata passed

03

MANIFEST_VALIDATEDcanonical JSON passed the runtime assembly manifest planner

04

REFERENCES_PARTIALone or more typed references are absent and activation remains blocked

05

CONFIGURATION_RESOLVEDeleven ConfigRefs and one KeyRef are fresh, typed and digest-bound

06

DENIED_INTEGRITYfile, encoding, manifest, reference, time or digest contract failed

FIVE FAIL-CLOSED CLASSESabsence blocks · drift denies
RF_RUNTIME_CONFIG_PATH|FILE_READ|FILE_METADATA|FILE_SIZE|TOCTOU

deny an untrusted path, link, owner, mode, size or changing descriptor

RF_RUNTIME_CONFIG_ENCODING|JSON|CANONICAL|MANIFEST

deny malformed bytes or a manifest outside the assembly contract

RF_RUNTIME_CONFIG_REF_SET|RESOLVER|RESOLUTION|RESOLUTION_TIME

deny missing inventory, unsafe type/source/value or stale ConfigRef metadata

RF_RUNTIME_CONFIG_KEY_REF|KEY_RESOLVER|KEY|KEY_TIME

deny an unpinned, signing-capable, private or stale trust descriptor

RF_RUNTIME_CONFIG_BUNDLE|FILE_PROOF|MISSING|STATUS|DIGEST

deny any bundle truth or digest inconsistency

24 FILE + REFERENCE INVARIANTSall fixture-enforced

01only /etc/reits-runner-factory/controller-runtime.json may be openedPASS

02the production driver opens with O_NOFOLLOW and O_CLOEXECPASS

03the manifest must be a regular file rather than a symlink, directory or devicePASS

04the file owner is root and the group is the dedicated reits-runner-factory identityPASS

05the file mode is exactly 0640 and the hard-link count is exactly onePASS

06the manifest is non-empty and bounded to 65536 bytesPASS

07before and after metadata from the same open descriptor must match exactlyPASS

08the verified byte length must equal the file size metadataPASS

09the file is strict UTF-8 without NUL bytesPASS

10the file is canonical JSON with exactly one trailing newlinePASS

11the parsed manifest must pass the existing runtime assembly plannerPASS

12the file proof binds path, inode, device, mtime, size and content digestPASS

13the manifest contains exactly eleven ordered ConfigRefsPASS

14every ConfigRef has one expected semantic type and no generic fallbackPASS

15DynamoDB and IAM ARNs are exact-suffix and wildcard-freePASS

16the Gitea origin is HTTPS and pinned to gitea.reits.techPASS

17the credential configuration resolves only to a SecretRef, never a credential valuePASS

18the root-agent socket is pinned beneath /run/reits-runner-factoryPASS

19the readiness KeyRef resolves to VERIFY_ONLY P-256 metadata without private materialPASS

20all resolution metadata is no older than five minutes and never from the futurePASS

21missing references produce BLOCKED_CONFIGURATION rather than a partial runtime adapterPASS

22file, reference-set, resolution, assembly-plan and bundle digests are independently recomputedPASS

23bundle verification never constructs a reader, signer, credential or listenerPASS

24production installation, reads, adapters, writes, mutations and paid resources remain zeroPASS

PRODUCTION INSTALL GAPFILE 0 · CONFIGREF 0/11 · KEYREF 0/1 · BUNDLE 0

01install the reviewed canonical manifest as root:reits-runner-factory mode 0640REQUIRED

02provision the eleven exact ConfigRef records in a root-owned read-only storeREQUIRED

03provision the verify-only KeyRef descriptor and pinned public SPKI digestREQUIRED

04bind ConfigRef resolution to read-only IAM roles and the root-agent socket ACLREQUIRED

05attach the verified configuration bundle to Controller boot before readiness evaluationREQUIRED

06issue the eleven readiness attestations only after live configuration checksREQUIRED

07install and supervise the Controller on its dedicated host while keeping loopback-only bindREQUIRED

08obtain security, runtime and cost owner approvals before activationREQUIRED

LOADER ≠ INSTALLATION文件驱动、类型解析、36 个案例、deterministic replay 与 bundle tamper denial 已实现;生产 manifest、store、trust descriptor、adapter、receipt、systemd unit 和 8110 listener 仍全部为 0。
CONTROLLER BOOTSTRAP COMPOSITION · EXECUTABLE / NOT INSTALLED
把 12 个已验证引用,收敛成六个最小权限组件;任何半成品都必须逆序清理

Composer 只接收处于有效窗口内的 resolved bundle,固定构造五个只读 Reader 与一个 VERIFY_ONLY attestation verifier。Bundle 只能消费一次、Capability 不可伪造、投影只能一次;生产 entrypoint 仍保持 unconfigured。

BOOTSTRAP_COMPOSER_IMPLEMENTED_NOT_INSTALLED
BOOTSTRAP OPS5plan · compose · verify · project · dispose
FACTORY SET65 readers · 1 verifier
FIXTURE CASES457 accepted · 38 denied
INTEGRATIONS3/3snapshot · assembly · readiness
PROD COMPONENTS0/6projections · 0
LISTENERS / WRITES0/0ready · 0/11
01 · VERIFIED BUNDLE11 ConfigRef + 1 KeyReffresh · digest-bound · single use
02 · CLOSED FACTORY SETsix exact constructorscaller cannot extend authority
03 · OPAQUE CAPABILITYWeakMap-backed handlenon-forgeable · project once
04 · GUARDED PROJECTION5 read + 1 verifypost-dispose calls denied
05 · PRODUCTION BOOTNOT INSTALLEDentrypoint unchanged · :8110 absent
SIX-COMPONENT CAPABILITY RACKTEST_ONLY · PRODUCTION 0/6
01

ReservationReaderreservation-ledger

2 REFSREAD ONLY READERNOT CONSTRUCTED
02

CapacityReadercapacity-ledger

2 REFSREAD ONLY READERNOT CONSTRUCTED
03

WorkerReaderec2-worker-read-model

2 REFSREAD ONLY READERNOT CONSTRUCTED
04

RunnerReadergitea-runner-read-model

3 REFSREAD ONLY READERNOT CONSTRUCTED
05

JournalReaderappend-only-journal

2 REFSREAD ONLY READERNOT CONSTRUCTED
06

ReadinessAttestationVerifierroot-owned-trust-store

1 REFATTESTATION VERIFIERNOT CONSTRUCTED
SELECTED FIXTURE · RFBC-30DENY · RF_BOOTSTRAP_FACTORY

bundleVERIFIED · CONSUMED

failurefactory 06 / verifier

constructed05 TEST_ONLY readers

cleanup05 → 01 · REVERSE

  1. 01ReservationReader.dispose()5th
  2. 02CapacityReader.dispose()4th
  3. 03WorkerReader.dispose()3rd
  4. 04RunnerReader.dispose()2nd
  5. 05JournalReader.dispose()1st
NO PARTIAL CAPABILITYVerifier 构造失败时,已构造 Reader 全部逆序关闭;旧 bundle 不得重放,listener/read/write/mutation 均为 0。
THREE DOWNSTREAM HANDOFFSfixture integration only
01

snapshot-coordinatorfive authority-pinned read functions

one complete five-source TEST_ONLY capturePROVEN TEST_ONLY
02

runtime-assemblyone verify-only P-256 attestation function

one signed-gate TEST_ONLY assembly packetPROVEN TEST_ONLY
03

controller-readinessreceipt-backed runtime projection

one 1/11 blocked service readiness projectionPROVEN TEST_ONLY
SEVEN CAPABILITY STATESone-way · fail closed

01UNPLANNEDno configuration bundle has been verified or consumed

02CONFIGURATION_VERIFIEDthe resolved bundle and validity window passed again

03COMPOSINGsix factories are executing in deterministic order

04COMPOSEDone opaque capability owns all six TEST_ONLY components

05PROJECTEDguarded readers and verifier were exposed exactly once

06DISPOSEDall components closed in reverse and future calls are denied

07DENIEDconfiguration, factory, component, handle, receipt or cleanup failed closed

SIX FAILURE CLASSESno authority leakage
RF_BOOTSTRAP_CONFIGURATION_VERIFY|CONFIGURATION_BLOCKED|CONFIGURATION_TIME|CONFIGURATION_BINDINGdeny unverified, partial, expired, future or rebound configuration
RF_BOOTSTRAP_FACTORY|FACTORY_SET|COMPONENTdeny missing factories, constructor failures and components with excess authority
RF_BOOTSTRAP_REPLAY|HANDLEdeny bundle reuse, projected capability reuse and forged handles
RF_BOOTSTRAP_PLAN|RECEIPT|DIGESTdeny component inventory, plan, composition or receipt drift
RF_BOOTSTRAP_CLEANUP|DISPOSEDdeny ambiguous cleanup and every call after terminal disposal
RF_RECON_SOURCE_*|RF_ASSEMBLY_SIGNATUREdownstream readers and verifier remain fail closed after projection
28 COMPOSITION INVARIANTS45 fixtures · all enforced

01only a positively verified CONFIGURATION_RESOLVED bundle may be plannedPASS

02all twelve references must be present before composition beginsPASS

03the bundle must be current at the bootstrap clock and not merely internally well formedPASS

04the configuration bundle digest binds every component planPASS

05the manifest and assembly-plan digests remain unchanged across bootstrapPASS

06exactly five read-only Reader components and one attestation verifier are requiredPASS

07factory names and ordering are closed rather than caller extensiblePASS

08Reservation Reader receives exactly its table and read-role referencesPASS

09Capacity Reader receives exactly its table and read-role referencesPASS

10Worker Reader receives exactly its region and read-role referencesPASS

11Runner Reader receives only origin, opaque SecretRef and root-agent socket referencesPASS

12Journal Reader receives exactly its table and read-role referencesPASS

13the attestation verifier receives verify-only public trust metadata without private materialPASS

14configuration values are represented publicly only by a configuration digestPASS

15all constructed components must identify as TEST_ONLYPASS

16Reader components expose only read and dispose callablesPASS

17the verifier component exposes only verify and dispose callablesPASS

18no component may expose a listen, server, start, write or mutation surfacePASS

19one bundle digest may create only one bootstrap capabilityPASS

20a bootstrap capability cannot be forged from its public fieldsPASS

21a capability may project dependencies exactly oncePASS

22projected calls are guarded by the live capability statePASS

23partial factory failure disposes every completed component in reverse orderPASS

24terminal disposal attempts every component in reverse orderPASS

25post-disposal Reader and verifier calls are deniedPASS

26plan, component, composition and receipt digests are independently recomputedPASS

27composition performs zero external reads, writes, mutations and listener startsPASS

28the production service entrypoint remains unconfigured and production truth remains zeroPASS

PRODUCTION BOOTSTRAP GAPMANIFEST 0 · FACTORIES 0/6 · PROJECTION 0 · LISTENER 0

01install the reviewed root-owned runtime manifest and resolve all twelve referencesREQUIRED

02implement five production read-only factories with exact IAM and network boundariesREQUIRED

03implement the production P-256 public-key verifier without signing authorityREQUIRED

04prove constructor and disposal behavior for every real SDK and root-agent clientREQUIRED

05bind the projected readers to the production snapshot coordinatorREQUIRED

06bind the projected verifier to runtime assembly before readiness evaluationREQUIRED

07issue a dedicated host and service identity receipt for the Controller processREQUIRED

08install and supervise the loopback-only Controller only after all eleven Gates attestREQUIRED

09obtain security, runtime and cost owner approvals before activationREQUIRED

COMPOSITION ≠ ACTIVATION单次 bundle、六组件闭包、逆序清理、45 个案例与三条下游 fixture 集成已经实现;生产 factories、components、bootstrap receipt、runtime projection、systemd unit 与 8110 listener 仍全部为 0。
CONTROLLER SERVICE RUNTIME BOOTSTRAP · EXECUTABLE / NOT INSTALLED
11 张 Gate 收据先闭环,再投影内存 Handler;网络监听权永远不随 Handler 一起下发

这一层把 resolved configuration、六组件 capability、runtime assembly 与 service core 接成真实可执行链。只有 11/11 签名证据全部通过,才会产生一次性内存请求处理器;生产 webhook 仍返回 503,代码没有 listenstartServer 或安装路径。

SERVICE_RUNTIME_BOOTSTRAP_IMPLEMENTED_NOT_INSTALLED
ORCHESTRATION OPS4prepare · verify · project · dispose
TRUST STAGES5config → components → assembly → handler → network
FIXTURE CASES407 accepted · 33 denied
HANDLER PROJECTIONS4TEST_ONLY · health / ready / deny webhook
PRODUCTION GATES0/11runtime handlers · 0
LISTENER / WRITES0/0deployment permitted · FALSE
01 · configurationroot-owned manifest + 11 ConfigRef + 1 KeyRefCONFIGURATION_RESOLVED bundle digest
02 · compositionsix closed TEST_ONLY factoriesbootstrap receipt + opaque capability
03 · assemblyruntime identity + 11 signed Gate attestationsREADY_VERIFIED packet + receipt-backed runtime
04 · servicesafe config + frozen policy/template + verified runtimeready in-memory handler; webhook remains blocked
05 · networknonelistener authorization absent and listener starts zero
SELECTED FIXTURE · RFSB-03READY 11/11 · TEST_ONLY
01

CONFIGURATIONCONFIGURATION_RESOLVEDbundleDigest · sha256:…

VERIFIED
02

COMPOSITIONCOMPOSED_TEST_ONLYcompositionId · rfboot1:…

6/6 BOUND
03

ASSEMBLYREADY_VERIFIEDpacketDigest · sha256:…

11 SIGNATURES
04

SERVICE CORESERVICE_HANDLER_READY_TEST_ONLYruntimeBootstrapId · rfsrv1:…

IN MEMORY
receipt source
VERIFIED_ASSEMBLY_RECEIPT_ONLY
handler created
TRUE · TEST_ONLY
production webhook
FALSE · 503
listener authorized
FALSE · NO API
external reads / writes
0 / 0
secret values
0
ONE DIGEST CHAINBootstrap receipt、assembly packet 与 readiness receipt 的 digest 被绑定进同一张 service runtime receipt;任何字段漂移都不能投影 Handler。
IN-MEMORY HANDLER CONSOLENO SOCKET · NO LISTENER

MODEEVIDENCE_ONLY

BIND INTENT127.0.0.1:8110

ACTUAL LISTENERABSENT

GET /healthz

200 · ALIVE_READYliveness + receipt-backed ready

FIXTURE PASS
GET /readyz

200 · READY · 11/11manifest + identity + receipt digests

FIXTURE PASS
POST /webhooks/gitea

503 · RF_CONTROLLER_NOT_READYready Handler 也没有 production action 权

EXPECTED DENY
listen(8110)

NOT A FUNCTIONnetwork authority is a separate future receipt

STRUCTURAL DENY
HANDLER ≠ DEPLOYMENT请求函数可在 fixture 内验证 HTTP 语义,但没有 socket、systemd、reverse proxy、credential file 或生产 Adapter。
ELEVEN RECEIPT-BACKED GATESFIXTURE 11/11 · PRODUCTION 0/11
01RF_READY_DEDICATED_HOST

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

02RF_READY_SERVICE_IDENTITY

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

03RF_READY_WEBHOOK_SECRET

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

04RF_READY_RESERVATION_STORE

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

05RF_READY_RECEIPT_SIGNER

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

06RF_READY_TOKEN_BROKER

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

07RF_READY_WORKER_PROVIDER

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

08RF_READY_GITEA_CONTROL

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

09RF_READY_CAPACITY_CONTROLLER

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

10RF_READY_AUDIT_SINK

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

11RF_READY_OWNER_APPROVAL

selected fixtureSIGNED + VERIFIED

production runtimeMISSING

EIGHT ONE-WAY STATEShandler revoked before cleanup
01UNPREPAREDno configuration bundle or component capability has been consumed
02COMPOSINGthe six-component TEST_ONLY closure is being built
03ASSEMBLINGidentity and all Gate attestations are being verified
04READY_HANDLERa receipt-backed service core exists only in memory
05PROJECTEDone guarded request function has been projected
06DISPOSINGfuture request calls are denied before reverse cleanup starts
07DISPOSEDall six components are closed and the handler is revoked
08DENIEDconfiguration, composition, assembly, service, receipt or cleanup failed closed
SEVEN DENIAL CLASSES33 adversarial cases
RF_SERVICE_BOOTSTRAP_DEPENDENCIES|CONFIG|INPUTdeny incomplete, extended or authority-bearing orchestration inputs
RF_BOOTSTRAP_*deny unverified configuration, factory drift, replay and component cleanup ambiguity
RF_ASSEMBLY_*deny runtime identity, attestation, signature, time and packet drift
RF_SERVICE_BOOTSTRAP_READINESS|TIMEdeny partial or expired readiness before a handler exists
RF_SERVICE_BOOTSTRAP_SERVICEdeny service factories that throw, stay unready or expose excess authority
RF_SERVICE_BOOTSTRAP_HANDLE|DISPOSED|CLEANUPdeny forged, replayed, revoked or ambiguously disposed capabilities
RF_SERVICE_BOOTSTRAP_RECEIPT|DIGESTdeny runtime bootstrap truth, identity and provenance drift
30 ORCHESTRATION INVARIANTS40 fixtures · all enforced

01the orchestrator accepts only the exact TEST_ONLY bootstrap composer surfacePASS

02service configuration remains EVIDENCE_ONLY on loopback port 8110PASS

03apply, public routing and external writes remain disabledPASS

04policy, worker template and service configuration are cloned and deeply frozenPASS

05a resolved configuration bundle is consumed only through the reviewed composerPASS

06exactly five read-only Readers and one verify-only attestation component remain underneath the capabilityPASS

07runtime assembly uses only the verifier projected by the live composition capabilityPASS

08runtime identity remains bound to the manifest controller, host and service identityPASS

09all eleven readiness Gate attestations are required before service constructionPASS

10duplicate, stale, future, wrong-scope and bad-signature attestations deny bootstrapPASS

11a BLOCKED_CONFIGURATION assembly packet never creates a service handlerPASS

12the runtime projection is reconstructed only from the verified readiness receiptPASS

13service readiness must report 11 of 11 with a verified receiptPASS

14the service factory may expose only handle, readiness, response headers and modePASS

15the projected capability exposes one guarded request function and no socket functionPASS

16no listen, server or start operation is accepted from the service factoryPASS

17production webhook handling remains 503 even inside a ready TEST_ONLY handlerPASS

18health and readiness requests remain loopback-context onlyPASS

19one runtime capability may project a handler exactly oncePASS

20forged and replayed handles are rejectedPASS

21expired readiness evidence cannot be prepared or projectedPASS

22disposal revokes the request guard before component cleanup beginsPASS

23post-disposal handler calls are rejectedPASS

24prepare failure disposes every successfully composed componentPASS

25cleanup ambiguity fails closed and never emits a capabilityPASS

26bootstrap, assembly and readiness receipt digests remain linked in one receiptPASS

27runtime bootstrap identity is deterministic for composition, assembly packet and observed timePASS

28receipt verification rejects shape, truth, identity and digest driftPASS

29external reads, writes, mutations and listener starts remain zero during orchestrationPASS

30the production Controller entrypoint remains unconfigured and port 8110 remains absentPASS

PRODUCTION ACTIVATION GAPMANIFEST 0 · FACTORIES 0/6 · GATES 0/11 · HANDLER 0 · LISTENER 0

01install and verify the root-owned runtime manifest and all twelve typed referencesREQUIRED

02replace all six TEST_ONLY factories with reviewed production read-only implementationsREQUIRED

03issue a dedicated host and non-login service identity receiptREQUIRED

04produce fresh signed evidence for all eleven readiness GatesREQUIRED

05prove the production service handler against real read adapters without granting write authorityREQUIRED

06add an independent owner-approved listener authorization receipt with expiry and rollback bindingREQUIRED

07install the hardened systemd unit only on the dedicated control-plane hostREQUIRED

08expose loopback through an authenticated reverse proxy only after security and runtime reviewREQUIRED

09run live readiness, webhook denial, incident, rollback and cost-control acceptance before activationREQUIRED

RUNTIME BOOTSTRAP ≠ LISTENER AUTHORIZATION40 个案例证明 11/11 Gate 才能创建 TEST_ONLY Handler,部分证据、签名漂移、过期、扩权 factory、重放和清理失败全部拒绝;生产 Handler、bootstrap receipt、systemd unit、8110 listener 与 webhook acceptance 仍为 0。
PRODUCTION EVIDENCE ADMISSION · EXECUTABLE / NOT CONFIGURED
生产证据必须先成为一份可验证、不可部署的档案,才有资格进入监听授权评审

发布单元、专用主机、非登录服务身份、五个只读 Reader、一个验签器和十一张 Gate 收据在这里形成同一条短时效信任链。通过只代表“证据结构合格”,不会创建 Handler、安装 systemd、访问外部系统或打开 8110。

PRODUCTION_EVIDENCE_ADMISSION_IMPLEMENTED_NOT_CONFIGURED
ADMISSION OPS4admit · verify · project · dispose
SIGNED FACTS19host + service + 6 adapters + 11 Gates
FIXTURE CASES566 accepted · 50 denied
QUALIFIED SHAPE6 + 11adapter contracts · readiness evidence
PRODUCTION RECEIPTS0adapters 0/6 · Gates 0/11
LISTENER / WRITES0/0deployment permitted · FALSE
01 · release1 REQUIREDsigned exact source, artifact, configuration and rollback identity
02 · host1 REQUIREDdedicated control-plane host, production marker, zero Runner service and loopback bind
03 · service1 REQUIREDnon-login UID/GID, no capabilities, credential references only and hardened unit digest
04 · adapters6 REQUIREDfive READ_ONLY Readers plus one VERIFY_ONLY attestation verifier
05 · gates11 REQUIREDordered issuer-pinned attestations bound to the exact manifest and runtime identity
06 · readiness1 REQUIREDREADY_VERIFIED receipt that reconstructs all eleven Gate facts
DEDICATED HOST RECEIPTFIXTURE VERIFIED · PRODUCTION MISSING
host class
DEDICATED_CONTROL_PLANE
shared workloads
FALSE
production marker
REQUIRED
active Runner service
0
bind
127.0.0.1:8110
validity
≤ 300 seconds
LIVE COUNT · 0当前共享生产 EC2 不满足 dedicated host 条件,不能拿现有 8100 门户主机替代 Controller 主机。
NON-LOGIN SERVICE IDENTITYFIXTURE VERIFIED · PRODUCTION MISSING
user / group
reits-runner-factory
root account
DENIED
shell
/usr/sbin/nologin
capabilities
[]
credentials
REFS ONLY
NoNewPrivileges
TRUE
LIVE COUNT · 0Unit digest、UID/GID、Host ID 与 Release ID 必须共同签名;配置文件存在不能代替身份回执。
SIX PRODUCTION ADAPTER QUALIFICATION SLOTSFIXTURE 6/6 · PRODUCTION 0/6
01

ReservationReaderreservation ledger

READ_ONLYimplementation + config digestNOT QUALIFIED
02

CapacityReadercapacity ledger

READ_ONLYimplementation + config digestNOT QUALIFIED
03

WorkerReaderEC2 read model

READ_ONLYimplementation + config digestNOT QUALIFIED
04

RunnerReaderGitea + root agent

READ_ONLYimplementation + config digestNOT QUALIFIED
05

JournalReaderappend-only journal

READ_ONLYimplementation + config digestNOT QUALIFIED
06

ReadinessAttestationVerifierroot-owned trust store

VERIFY_ONLYimplementation + config digestNOT QUALIFIED
ELEVEN SIGNED GATE EVIDENCE OBJECTSFIXTURE 11/11 · PRODUCTION 0/11
01RF_READY_DEDICATED_HOST

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
02RF_READY_SERVICE_IDENTITY

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
03RF_READY_WEBHOOK_SECRET

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
04RF_READY_RESERVATION_STORE

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
05RF_READY_RECEIPT_SIGNER

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
06RF_READY_TOKEN_BROKER

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
07RF_READY_WORKER_PROVIDER

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
08RF_READY_GITEA_CONTROL

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
09RF_READY_CAPACITY_CONTROLLER

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
10RF_READY_AUDIT_SINK

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
11RF_READY_OWNER_APPROVAL

identity bindingcontroller + manifest + host

validity≤ 300s

MISSING
EIGHT ONE-WAY STATESno activation transition
01UNVERIFIEDcandidate facts have no authority
02VERIFYING_IDENTITIESrelease, host and service bindings are checked
03VERIFYING_ADAPTERSsix production implementation qualifications are checked
04VERIFYING_GATESeleven attestations and readiness reconstruction are checked
05ADMITTED_EVIDENCE_ONLYa non-deployable evidence capability exists in memory
06PROJECTEDone frozen dossier has been projected
07DISPOSEDthe capability and retained dossier are revoked
08DENIEDany identity, authority, time, signature or digest drift fails closed
SELECTED DENIAL TRACE · RFEA-38LISTENER AUTHORITY REJECTED
  1. 01Adapter qualification arriveslistenerAuthority=true
  2. 02Secret/authority scanner runsSTRUCTURAL DENY
  3. 03Signature chain is not promotedNO CAPABILITY
  4. 04Production counters remain0 / 0 / 0
RF_PRODUCTION_EVIDENCE_SECRET证据层不能偷偷携带 listener、server-start、write 或 Secret value 字段。
34 ADMISSION INVARIANTS56 fixtures · 339 signature checks

01release identity binds one signed production source, artifact, configuration and distinct rollback targetPASS

02runtime identity is no older than five minutesPASS

03the host is dedicated to the control plane and reports no shared production workloadsPASS

04the immutable production marker must be presentPASS

05no Runner service may be active on the Controller hostPASS

06the only admissible Controller bind is 127.0.0.1:8110PASS

07the service user and group are reits-runner-factoryPASS

08the service account is non-root and non-loginPASS

09the service home and unit name are exactPASS

10inline secret values remain zero and only credential references are allowedPASS

11the service has no Linux capabilities and NoNewPrivileges is truePASS

12exactly five read-only Readers and one verify-only component are admittedPASS

13adapter order, authority, operation, permission and ConfigRef sets are exactPASS

14every adapter implementation and configuration evidence is digest-boundPASS

15no adapter grants external write or listener authorityPASS

16adapter qualifications bind the exact release and hostPASS

17exactly eleven ordered readiness attestations are requiredPASS

18every Gate binds the exact controller, manifest and runtime identityPASS

19the readiness issuer is pinned to the reviewed production P-256 KeyRefPASS

20every signed receipt is current and valid for at most five minutesPASS

21nineteen signatures must verify positivelyPASS

22the READY_VERIFIED receipt reconstructs the same eleven Gate evidence digestsPASS

23the readiness receipt identity digest is derived from the exact runtime identityPASS

24the admission expiry is the earliest upstream expiryPASS

25one admission capability can project only oncePASS

26forged, replayed and disposed capabilities are deniedPASS

27the projected dossier contains no function or mutable authorityPASS

28the admission receipt always sets deploymentAuthorized=falsePASS

29the admission receipt always sets listenerAuthorized=false and handlerCreated=falsePASS

30external reads, writes, mutations and listener starts remain zeroPASS

31secret-like fields are structurally rejectedPASS

32production webhook acceptance remains zeroPASS

33the existing unconfigured production entrypoint is unchangedPASS

34port 8110 remains absent until a separate owner-approved listener receipt existsPASS

PRODUCTION ACTIVATION GAPRELEASE 0 · HOST 0 · IDENTITY 0 · ADAPTERS 0/6 · GATES 0/11 · LISTENER RECEIPT 0

01publish a signed Controller release unit with an exercised rollback targetREQUIRED

02provision and attest a dedicated non-production control-plane hostREQUIRED

03install the reviewed non-login service identity and hardened unit without starting itREQUIRED

04implement and independently review the five production read adaptersREQUIRED

05install the verify-only readiness public key through a root-owned KeyRefREQUIRED

06collect nineteen fresh signatures and all eleven Gate evidence objectsREQUIRED

07run the admission verifier on the target host with external calls still disabledREQUIRED

08obtain a separate expiring owner-approved listener authorizationREQUIRED

09perform live negative-webhook, rollback, incident, security and cost acceptance before activationREQUIRED

EVIDENCE ADMISSION ≠ DEPLOYMENT APPROVAL56 个确定性案例验证证据身份、时效、签名、最小权限、重放和摘要边界;即便 fixture 19/19 通过,输出也只有冻结档案,没有 Handler、listener、systemd 或外部调用权限。
LISTENER AUTHORIZATION BOUNDARY · EXECUTABLE / NOT CONFIGURED
监听不是布尔开关:它是一份绑定 Release、Host、Config、Rollback、演练和四位 Owner 的两分钟一次性候选能力

这一层把证据准入之后最危险的“开端口”动作拆成独立控制面。fixture 可以验证 127.0.0.1:8110 的候选计划,但输出没有执行器,不能启动 systemd、创建反向代理、接受 webhook 或写入外部系统。

LISTENER_AUTHORIZATION_BOUNDARY_IMPLEMENTED_NOT_CONFIGURED
AUTHORIZATION OPS4authorize · verify · project · dispose
OWNER SIGNATURES4security · runtime · cost · operations
VALIDITY WINDOW120searliest upstream expiry wins
FIXTURE CASES536 accept · 47 deny
PRODUCTION RECEIPTS0owner approvals · 0/4
LISTENER STARTS08110 absent · deployment false
01 · admission1 REQUIREDauthority-verified unexpired production-evidence admission receipt
02 · request1 REQUIREDexact release, host, config, unit and loopback endpoint request
03 · rollback1 REQUIREDsigned distinct-target rollback rehearsal within 300 seconds
04 · negative-webhook1 REQUIREDsigned rejection proof for unsigned, invalid and stale deliveries
05 · operational-drills2 REQUIREDordered rollback and incident drill receipts
06 · owner-approvals4 REQUIREDsecurity, runtime, cost and operations approvals
07 · nonce1 REQUIREDsingle-use scope-bound authorization nonce
08 · expiry1 REQUIREDearliest upstream expiry with a 120-second maximum
EXACT ACTIVATION SCOPEALL FIELDS DIGEST-BOUND
release
runner-factory@revision-artifact
rollback
distinct signed release
controller / host
admission receipt identity
configuration
sha256 exact match
systemd unit
sha256 exact match
service identity
reits-runner-factory
bind
127.0.0.1:8110
network exposure
public FALSE · proxy FALSE
CANDIDATE ONLY计划里没有 shell command、函数、socket handle 或 systemd executor;候选回执明确写入 activationAuthorized=false。
RECOVERY & ABUSE PROOFFIXTURE PASS · PRODUCTION 0
01

ROLLBACK REHEARSALdistinct target · restore ≤ 300s

0 LIVE
02

NEGATIVE WEBHOOKunsigned · invalid · stale rejected

0 LIVE
03

ROLLBACK DRILLPASS · no data loss · no writes

0 LIVE
04

INCIDENT DRILLPASS · no data loss · no writes

0 LIVE
FAIL-CLOSED演练证据任何一个过期、换序、摘要漂移、数据丢失或出现外部写入,授权链立即终止。
FOUR INDEPENDENT OWNER APPROVALSSAME SCOPE DIGEST · SAME NONCE · APPROVE_CANDIDATE_ONLY
01

SECURITY_OWNERkeys · signature · abuse boundary

signature ≤ 120sscope + release + host + noncePRODUCTION MISSING
02

RUNTIME_OWNERhost · unit · rollback · on-call

signature ≤ 120sscope + release + host + noncePRODUCTION MISSING
03

COST_OWNERzero paid resource · zero scale

signature ≤ 120sscope + release + host + noncePRODUCTION MISSING
04

OPERATIONS_OWNERmaintenance window · incident command

signature ≤ 120sscope + release + host + noncePRODUCTION MISSING
EIGHT ONE-WAY STATESno transition to LISTENING
01UNTRUSTEDthe packet has no listener-candidate standing
02ADMISSION_BOUNDthe exact upstream admission digest is current
03TARGET_BOUNDrelease, host, config, unit and loopback endpoint match
04RECOVERY_PROVENrollback, negative webhook and two drills pass
05OWNERS_APPROVEDfour independent approvals bind the same scope and nonce
06CANDIDATEone opaque, two-minute, fixture-only capability exists
07PROJECTED_OR_DISPOSEDthe capability cannot be consumed again
08DENIEDany drift fails closed without activation or mutation
SELECTED DENIAL TRACE · RFLA-14PUBLIC ROUTE REQUESTED
  1. 01Request binds the admitted release and hostIDENTITY PASS
  2. 02publicRoute=true enters exact request validationSTRUCTURAL DRIFT
  3. 03Rollback and owner signatures are not promotedNO CAPABILITY
  4. 04Listener, proxy, route and writes remain0 / 0 / 0 / 0
RF_LISTENER_AUTH_REQUEST端点不是可自由填写的配置;任何非 loopback 地址、非 8110 端口、公共路由或反向代理都被拒绝。
36 LISTENER-AUTHORIZATION INVARIANTS53 fixtures · 132 signature checks

01the upstream admission receipt is exact, digest-bound, unexpired and positively verified by its authorityPASS

02fixture-only admission can produce only a fixture-only listener candidatePASS

03release identity is unchanged from the admission receiptPASS

04rollback release is valid and distinct from the active releasePASS

05controller identity is unchanged from the admission receiptPASS

06host identity is unchanged from the admission receiptPASS

07manifest digest is unchanged from the admission receiptPASS

08configuration digest is exact and scope-boundPASS

09systemd unit digest is exact and scope-boundPASS

10service user is exactly reits-runner-factoryPASS

11service unit is exactly reits-runner-factory-controller.servicePASS

12bind host is exactly 127.0.0.1PASS

13port is exactly 8110PASS

14public route is always falsePASS

15reverse proxy is always falsePASS

16the request window is no longer than 120 secondsPASS

17the candidate expires at the earliest upstream expiryPASS

18the nonce is format-checked and single-usePASS

19rollback evidence binds the exact release, target, host and configurationPASS

20rollback restore time is at most 300 secondsPASS

21unsigned webhook delivery is rejectedPASS

22invalid webhook signature is rejectedPASS

23stale webhook delivery is rejectedPASS

24negative webhook rehearsal accepts zero requests and performs zero writesPASS

25rollback and incident drills are both required in canonical orderPASS

26drills report PASS, no data loss and zero external writesPASS

27security, runtime, cost and operations owners are all requiredPASS

28each owner signs APPROVE_CANDIDATE_ONLY for the same scope and noncePASS

29eight evidence signatures must verify positivelyPASS

30secret-like and executable fields are structurally rejectedPASS

31the candidate handle is opaque, one-shot and WeakMap-backedPASS

32the projected plan exposes no function and zero executable stepsPASS

33activationAuthorized and listenerStartAuthorized remain falsePASS

34listener starts, external reads, writes and mutations remain zeroPASS

35no paid resource or public route can be createdPASS

36the production entrypoint remains unconfigured and port 8110 remains absentPASS

PRODUCTION ACTIVATION GAPADMISSION 0 · ROLLBACK 0 · WEBHOOK 0 · DRILLS 0/2 · OWNERS 0/4 · LISTENER 0

01replace fixture admission with a live target-host admission receiptREQUIRED

02exercise rollback on the exact signed production release pairREQUIRED

03run negative webhook tests against the stopped loopback service harnessREQUIRED

04complete incident and rollback drills with retained evidenceREQUIRED

05collect independent security, runtime, cost and operations signaturesREQUIRED

06issue a live 120-second nonce only inside the approved maintenance windowREQUIRED

07rerun verification on the target host without starting the serviceREQUIRED

08obtain a separate activation executor implementation and reviewREQUIRED

09activate only after an auditable production receipt and immediate rollback guard existREQUIRED

LISTENER CANDIDATE ≠ ACTIVATION53 个确定性案例覆盖准入来源伪造、公共绑定、端口漂移、代理扩权、回滚缺失、负向 webhook 失败、Owner 不一致、签名伪造、nonce 重放和回执篡改。生产授权回执与 8110 listener 仍为 0。
ACTIVATION EXECUTOR · DRY-RUN BOUNDARY / NO EXECUTOR
把“上线”拆成可审阅的八步运行手册;每一步都看得见,但没有一步能执行

Listener 候选之后新增独立的激活规划层。它只接受精确候选、已打开的 15 分钟变更窗口、目标机停机态证明、60 秒即时回滚守卫,以及两个不同人员对同一 scope 的确认。输出是一次性冻结 runbook,不安装 Unit、不启动 Service、不打开 8110。

ACTIVATION_EXECUTOR_DRY_RUN_IMPLEMENTED_NOT_CONFIGURED
DRY-RUN OPERATIONS4prepare · verify · project · dispose
RUNBOOK STEPS8all declarative · NO_EXECUTOR
CHANGE WINDOW15mrequest capability · 60s
ROLLBACK SLA60s5 mandatory triggers
FIXTURE CASES686 accept · 62 deny
PRODUCTION STARTS0executor · 0 · listener · 0
01 · listener-candidate1 REQUIREDauthority-verified unexpired listener candidate with zero activation authority
02 · plan-request1 REQUIREDPLAN_ACTIVATION_ONLY bound to exact release, host, config, unit and loopback target
03 · maintenance-window1 REQUIREDsigned open change window no longer than 15 minutes
04 · preflight1 REQUIREDsigned stopped-state proof for 8110, unit, proxy, portal 8100 and rollback
05 · rollback-guard1 REQUIREDsigned 60-second health/readiness/identity/bind/proxy trigger policy
06 · runtime-confirmations2 REQUIREDdistinct change owner and incident commander confirmations
07 · nonce1 REQUIREDsingle-use scope-bound activation-planning nonce
08 · expiry1 REQUIREDearliest upstream expiry with a 60-second request maximum
CHANGE CONTROLCHG-YYYYMMDD-XXXXXXAPPROVED_TEST_WINDOW · OPEN ≤ 15m
TARGET127.0.0.1:8110systemd · loopback only · no proxy
AUTHORITYPLAN_ACTIVATION_ONLYactivationAuthorized · FALSE
EIGHT-STEP ACTIVATION RUNBOOK0 EXECUTABLE STEPS
01

VERIFY_CANDIDATEcandidate digest + authority + expiry

NO_EXECUTORBLOCKED
02

VERIFY_WINDOWwindow + scope + two-person check

NO_EXECUTORBLOCKED
03

SNAPSHOT_ROLLBACKportal 8100 + rollback release

NO_EXECUTORBLOCKED
04

INSTALL_UNITfuture unit install boundary

NO_EXECUTORBLOCKED
05

START_LOOPBACKfuture loopback start boundary

NO_EXECUTORBLOCKED
06

PROBE_HEALTH/healthz + /readyz

NO_EXECUTORBLOCKED
07

AUTO_ROLLBACKwatchdog ≤ 60 seconds

NO_EXECUTORBLOCKED
08

SEAL_RECEIPTobserved truth receipt

NO_EXECUTORBLOCKED
TARGET-HOST PREFLIGHTALL MUST MATCH
portal :8100
HEALTHY
port :8110
ABSENT
systemd unit
NOT INSTALLED
controller service
INACTIVE
reverse proxy
ABSENT
public route
ABSENT
rollback release
PRESENT · EXACT
disk headroom
≥ 1 GiB
PRODUCTION PREFLIGHT · 0这些是合同定义,不是当前主机已经取得的证据。
IMMEDIATE ROLLBACK WATCHDOG≤ 60 SECONDS
01START_ERRORsystemd start returns non-zeroROLL BACK
02READINESS_TIMEOUTtwo probes do not become readyROLL BACK
03IDENTITY_DRIFTrelease / config / unit identity changesROLL BACK
04UNEXPECTED_BINDanything binds beyond loopback :8110ROLL BACK
05PROXY_DRIFTproxy or public routing appearsROLL BACK
GUARD DEFINED · EXECUTOR ABSENT回滚策略本身也不能携带命令或函数。
TWO-PERSON RUNTIME CONFIRMATIONSEPARATION OF DUTIES
01

CHANGE_OWNERowns change scope and maintenance window

CONFIRM_DRY_RUN_ONLYPRODUCTION MISSING
02

INCIDENT_COMMANDERowns rollback call and incident command

CONFIRM_DRY_RUN_ONLYPRODUCTION MISSING
SUBJECT A ≠ SUBJECT B同一人、同一 subject、不同 scope 或不同 nonce 都会失败。
NINE ONE-WAY STATESno transition to INSTALLED or STARTED
01UNTRUSTEDthe packet has no activation-planning standing
02CANDIDATE_BOUNDthe authoritative listener candidate is current and unmodified
03WINDOW_OPENthe signed change window is open and no longer than 15 minutes
04STOPPED_STATE_PROVEN8110, unit, service, proxy and route are absent while portal 8100 is healthy
05ROLLBACK_GUARDEDthe complete fail trigger set has a 60-second recovery deadline
06TWO_PERSON_CONFIRMEDtwo different subjects confirm the same dry-run scope
07RUNBOOK_CANDIDATEone opaque fixture-only zero-executor capability exists
08PROJECTED_OR_DISPOSEDthe capability cannot be consumed again
09DENIEDany drift fails closed without install, start, listener or mutation
SELECTED DENIAL TRACE · RFAE-40PORT 8110 ALREADY PRESENT
  1. 01Listener candidate and change window verifyAUTHORITY PASS
  2. 02port8110Absent=false enters signed preflightSTATE CONFLICT
  3. 03Confirmations are not promotedNO HANDLE
  4. 04Install, start, listener and mutations remain0 / 0 / 0 / 0
RF_ACTIVATION_PREFLIGHT已有 8110 进程不能被接管或覆盖;必须先查明身份并重新取得全套证据。
42 ACTIVATION INVARIANTS68 fixtures · 110 signature checks

01the upstream listener candidate is exact, digest-bound, unexpired and positively verified by its authorityPASS

02fixture-only listener authority can produce only a fixture-only dry-run runbookPASS

03the listener candidate carries activationAuthorized=false and listenerStartAuthorized=falsePASS

04release identity is unchanged from the listener candidatePASS

05rollback release is unchanged from the listener candidate and remains distinctPASS

06controller identity is unchanged from the listener candidatePASS

07host identity is unchanged from the listener candidatePASS

08manifest digest is unchanged from the listener candidatePASS

09configuration digest is unchanged from the listener candidatePASS

10systemd unit digest is unchanged from the listener candidatePASS

11the only request action is PLAN_ACTIVATION_ONLYPASS

12service user is exactly reits-runner-factoryPASS

13service unit is exactly reits-runner-factory-controller.servicePASS

14bind host is exactly 127.0.0.1 and port is exactly 8110PASS

15public route and reverse proxy requests are always falsePASS

16the plan request window is no longer than 60 secondsPASS

17the maintenance window is signed, currently open and no longer than 15 minutesPASS

18the maintenance change identifier is format constrainedPASS

19preflight proves port 8110 is absentPASS

20preflight proves the Controller unit is not installedPASS

21preflight proves the Controller service is not activePASS

22preflight proves no proxy or public route is configuredPASS

23preflight proves the existing portal on 8100 is healthyPASS

24preflight proves the exact rollback release is presentPASS

25preflight requires at least one GiB of disk headroomPASS

26rollback deadline is no longer than 60 secondsPASS

27rollback probes are exactly /healthz and /readyzPASS

28rollback requires two healthy probesPASS

29start error, readiness timeout, identity drift, unexpected bind and proxy drift all trigger rollbackPASS

30the rollback guard itself exposes no executorPASS

31change owner and incident commander are both required in canonical orderPASS

32change owner and incident commander must be different subjectsPASS

33both subjects sign CONFIRM_DRY_RUN_ONLY for the same scope and noncePASS

34five evidence signatures must verify positivelyPASS

35the nonce is format-checked and single-usePASS

36secret-like and executable fields are structurally rejectedPASS

37the runbook handle is opaque, one-shot and WeakMap-backedPASS

38the projected runbook contains eight declarative NO_EXECUTOR stepsPASS

39the projected runbook exposes no function and zero executable stepsPASS

40activation, unit install, service start and listener start remain falsePASS

41external reads, writes, mutations, paid resources, proxy and public routes remain zeroPASS

42the production entrypoint remains unconfigured and port 8110 remains absentPASS

PRODUCTION EXECUTION GAPPLAN RECEIPT 0 · WINDOW 0 · CONFIRMERS 0/2 · GUARD 0 · UNIT 0 · SERVICE 0 · LISTENER 0

01replace the fixture listener candidate with an authority-verified target-host candidateREQUIRED

02open an approved production maintenance window with an immutable change identifierREQUIRED

03capture signed target-host preflight while 8110, unit, service, proxy and route are absentREQUIRED

04prove portal 8100 health and the exact rollback release before any install actionREQUIRED

05collect different change owner and incident commander subjects for the exact scopeREQUIRED

06implement a separately reviewed least-privilege executor without shell interpolationREQUIRED

07implement an independently testable rollback executor and 60-second watchdogREQUIRED

08exercise install, start, health, readiness and every rollback trigger on a non-production hostREQUIRED

09obtain a new authority receipt before activation; this dry-run runbook can never be promotedREQUIRED

RUNBOOK ≠ EXECUTION AUTHORITY68 个确定性案例覆盖上游来源伪造、窗口关闭、端口占用、Unit/Service 已存在、8100 不健康、回滚缺失、身份与摘要漂移、双人职责冲突、签名伪造、nonce 重放和回执篡改。生产安装、启动、8110 listener、代理与外部写入均为 0。
ACTIVATION TRANSACTION · CLOSED TEST DRIVER / PRODUCTION DISCONNECTED
把安装、启动、探针和补偿拼成可验证事务;真实主机仍然没有执行入口

上一步的零权限 runbook 不能成为生产授权。本工作台只在内存驱动中复现严格顺序:锁定、快照、安装、loopback 启动、双探针、释放;任何漂移进入反向补偿,补偿本身异常则封存为 CONTAINED。

ACTIVATION_TRANSACTION_EXECUTOR_IMPLEMENTED_NOT_CONFIGURED
TYPED DRIVER PORTS9exact methods · no generic shell
FIXTURE CASES7218 safe · 54 deny
COMMITTED5fixture-only healthy state
ROLLED BACK9reverse sequence clean
CONTAINED4manual-review test outcome
PRODUCTION EXECUTORS0unit · 0 · listener · 0
UPSTREAMACTIVATION_RUNBOOK_CANDIDATE_TEST_ONLYactivationAuthorized · FALSE
TRANSACTION MODEIN_MEMORY_TEST_DRIVERone-shot capability · ≤ 30s
PRODUCTION COMPOSITIONNOT IMPORTEDnetworkAuthority · NONE
FORWARD TRANSACTION7 VERIFIED STEPS
01

ACQUIRE_LOCKexclusive fixture fence

STEP RECEIPT
02

SNAPSHOT_ROLLBACKcapture rollback baseline

STEP RECEIPT
03

INSTALL_UNITdigest-bound fixture unit

STEP RECEIPT
04

START_LOOPBACK127.0.0.1:8110 only

STEP RECEIPT
05

PROBE_HEALTHpositive /healthz receipt

STEP RECEIPT
06

PROBE_READYpositive /readyz receipt

STEP RECEIPT
07

RELEASE_LOCKrelease fixture fence

STEP RECEIPT
REVERSE COMPENSATIONFAIL-CLOSED ORDER
01

STOP_LOOPBACKstop fixture listener first

IF REACHED
02

REMOVE_UNITremove fixture unit second

IF REACHED
03

RESTORE_SNAPSHOTrestore snapshot third

IF REACHED
04

RELEASE_LOCKrelease fence last

ALWAYS
ROLLBACK CLEAN → ROLLED_BACK任一补偿或解锁状态不明确 → CONTAINED,不伪装成功。
NINE CLOSED PORTSNO spawn · execFile · shellCommand
01acquireLockACQUIRE_LOCKFIXTURE ONLY
02snapshotRollbackSNAPSHOT_ROLLBACKFIXTURE ONLY
03installUnitINSTALL_UNITFIXTURE ONLY
04startLoopbackSTART_LOOPBACKFIXTURE ONLY
05probeHealthPROBE_HEALTH_OR_READYFIXTURE ONLY
06stopLoopbackSTOP_LOOPBACKFIXTURE ONLY
07removeUnitREMOVE_UNITFIXTURE ONLY
08restoreSnapshotRESTORE_SNAPSHOTFIXTURE ONLY
09releaseLockRELEASE_LOCKFIXTURE ONLY
RESULT LEDGERTHREE EXPLICIT TERMINALS
01

COMMITTEDunit + listener exist only inside the memory driver

5
02

ROLLED_BACKsnapshot + unit + listener all prove absent

9
03

CONTAINEDcompound failure code retained for manual review

4
SELECTED TRACE · RFATX-12HEALTH FAIL + STOP FAIL
  1. 01lock → snapshot → install → startRECEIPTS PASS
  2. 02/healthz driver call failsROLLBACK
  3. 03STOP_LOOPBACK compensation failsAMBIGUOUS
  4. 04remove + restore + release continueCONTAINED
NO PRODUCTION EFFECT失败链只改变内存状态,生产读写与 mutation 均为 0。
TWELVE TRANSACTION STATES114 VERIFIED STEP RECEIPTS
01UNTRUSTEDthe packet has no transaction standing
02PLAN_BOUNDthe authoritative fixture-only plan is exact and current
03PREPAREDone opaque 30-second fixture capability exists
04LOCKEDthe in-memory host fence was acquired
05SNAPSHOTTEDthe in-memory rollback state was captured
06UNIT_INSTALLED_FIXTUREthe digest-bound unit exists only inside the memory driver
07LOOPBACK_STARTED_FIXTUREthe memory driver reports only 127.0.0.1:8110
08HEALTHY_FIXTUREboth fixture health paths positively verified
09COMMITTED_FIXTUREthe success receipt is test-only and grants no production authority
10ROLLED_BACK_FIXTUREreverse-order compensation proved a clean memory state
11CONTAINED_FIXTUREambiguous compensation is sealed for manual review without production effect
12DENIEDinput, provenance, sequence or receipt drift failed closed
PRODUCTION EXECUTION GAPPLAN 0 · REQUEST 0 · EXECUTOR 0 · UNIT 0 · SERVICE 0 · LISTENER 0

01replace the fixture-only activation plan with a newly reviewed production authority receiptREQUIRED

02implement a target-host driver as a separate least-privilege package with no shell interpolationREQUIRED

03bind every target-host effect receipt to an asymmetric production signer and monotonic journalREQUIRED

04run the transaction and every compensation branch on a disposable non-production hostREQUIRED

05prove the 60-second rollback watchdog independently from the forward executorREQUIRED

06prove systemd sandbox, filesystem ownership and configuration references on the target hostREQUIRED

07capture live negative evidence that no public route or reverse proxy existsREQUIRED

08obtain a new two-person change authorization for the exact target-host transactionREQUIRED

09wire the production executor only through a separately reviewed composition rootREQUIRED

10repeat EC2 inventory and port audit immediately before any production activationREQUIRED

TEST TRANSACTION ≠ PRODUCTION ACTIVATION130 次内存驱动调用、30 次 fixture mutation 与 25 次补偿只证明事务编排;Controller 未安装、8110 未监听、代理与公网路由为 0。
TARGET-HOST DRIVER QUALIFICATION · DOSSIER ONLY / PACKAGE NOT LOADED
先审驱动边界与反证,再允许候选包进入独立测试主机

工作台消费上游事务回执、独立包描述符、9 份端口证据和 8 份拒绝证据,只签发测试资格回执。它不 import 候选包、不调用驱动、不读取凭据,也不能安装 Unit、启动服务或创建 8110 listener。

TARGET_HOST_DRIVER_QUALIFICATION_IMPLEMENTED_NOT_CONFIGURED
TYPED PORTS9ordered · exact · signed
DENIAL PROBES8negative evidence required
SIGNED CHECKS198fixture asymmetric verifies
FIXTURES648 accept · 56 deny
QUALIFIED DOSSIERS6test-only fixture outcomes
PRODUCTION DRIVERS0package · 0 · unit · 0
01 · EXACT UPSTREAMACTIVATION TRANSACTION RECEIPT49 fixture verifications
02 · DOSSIER EVALUATORDESCRIPTOR + 17 EVIDENCE RECEIPTSone-shot capability · ≤ 60s
03 · OUTPUTQUALIFIED_TEST_ONLYdeployment authority · NONE
PRODUCTION PACKAGENOT LOADED / NOT CONFIGUREDdriver execution · ZERO
CANDIDATE DESCRIPTORSEPARATE PACKAGE · EXACT SHAPE
package
@reits/runner-factory-target-host-driver
platform
linux/amd64
service user
reits-runner-factory
systemd unit
reits-runner-factory-controller.service
bind
127.0.0.1:8110
health
/healthz → /readyz
generic command · FALSEshell interpolation · FALSEnetwork client · FALSEcredential reads · FALSE
NINE CLOSED OPERATION PORTSNO COMMAND ESCAPE HATCH
01

acquireLockACQUIRE_LOCK

SIGNED EVIDENCE
02

snapshotRollbackSNAPSHOT_ROLLBACK

SIGNED EVIDENCE
03

installUnitINSTALL_UNIT

SIGNED EVIDENCE
04

startLoopbackSTART_LOOPBACK

SIGNED EVIDENCE
05

probeHealthPROBE_HEALTH_OR_READY

SIGNED EVIDENCE
06

stopLoopbackSTOP_LOOPBACK

SIGNED EVIDENCE
07

removeUnitREMOVE_UNIT

SIGNED EVIDENCE
08

restoreSnapshotRESTORE_SNAPSHOT

SIGNED EVIDENCE
09

releaseLockRELEASE_LOCK

SIGNED EVIDENCE
HOST EFFECT ALLOWLIST4 PATHS · 5 ACTIONS
P1

/run/lock/reits-runner-factory-controller.lockcreate-exclusive + remove

P2

/opt/reits-runner-factory/releases/{releaseId}read immutable candidate only

P3

/var/lib/reits-runner-factory/rollback/{changeId}.jsoncreate-exact + restore-exact

P4

/etc/systemd/system/reits-runner-factory-controller.serviceinstall exact digest + remove exact

S1

daemon-reloadafter exact unit install or removal only

EXACT UNIT
S2

is-activeexact controller unit only

EXACT UNIT
S3

showallowlisted unit properties only

EXACT UNIT
S4

startexact unit after lock and snapshot

EXACT UNIT
S5

stopexact unit during compensation

EXACT UNIT
NEGATIVE-GUARD RADARALL 8 MUST DENY
01GENERIC_COMMAND_PORTno generic execution surfaceDENY PROVED
02SHELL_INTERPOLATIONarguments never become shell textDENY PROVED
03PATH_TRAVERSALpaths stay inside exact templatesDENY PROVED
04DYNAMIC_UNIT_NAMEcaller cannot select a unitDENY PROVED
05PUBLIC_BINDbind must remain 127.0.0.1DENY PROVED
06REVERSE_PROXYno proxy or route authorityDENY PROVED
07CREDENTIAL_READdriver cannot fetch secretsDENY PROVED
08UNSIGNED_STEP_RECEIPTevery effect returns signed proofDENY PROVED
EVIDENCE RAILSELECTED TRACE · RFDQ-40
  1. 01

    UPSTREAM RECEIPTexact activation-transaction digest

    VERIFIED
  2. 02

    PACKAGE DESCRIPTORseparate artifact · linux/amd64 · test-only

    BOUND
  3. 03

    9 PORT RECEIPTScandidate + descriptor + contract identity

    SIGNED
  4. 04

    GENERIC_COMMAND_PORTforbidden field injected by fixture RFDQ-40

    DENIED
  5. 05

    QUALIFICATION HANDLEnever minted after negative evidence drift

    ABSENT
PACKAGE LOAD 0 · DRIVER CALL 0失败发生在 dossier 边界,候选代码从未进入进程。
EIGHT QUALIFICATION STATES2 RECEIPT RE-VERIFICATIONS
01UNTRUSTEDthe candidate has no qualification standing
02TRANSACTION_BOUNDthe exact fixture transaction contract was positively verified
03DESCRIPTOR_BOUNDthe separate package exposes only the exact typed surface
04EVIDENCE_BOUNDnine port and eight denial receipts are exact and signed
05PREPAREDone opaque 60-second dossier capability exists
06QUALIFIED_TEST_ONLYthe dossier passed without package loading or execution
07DISPOSEDan unused capability was revoked
08DENIEDshape, provenance, scope or receipt drift failed closed
PRODUCTION READINESS GAPPACKAGE 0 · SIGNER 0 · JOURNAL 0 · HOST TEST 0 · UNIT 0 · SERVICE 0 · LISTENER 0

01implement the driver in a separate repository from this dossier evaluatorREQUIRED

02review every filesystem and systemd syscall in the candidate packageREQUIRED

03attach an asymmetric production step signer without exporting private materialREQUIRED

04attach a durable monotonic journal with ambiguity containmentREQUIRED

05run all nine ports and eight denials on a disposable non-production hostREQUIRED

06prove every compensation branch inside the independent sixty-second watchdogREQUIRED

07prove the installed systemd sandbox and exact filesystem ownershipREQUIRED

08capture live negative route, proxy, credential and public-bind evidenceREQUIRED

09obtain a fresh production authority receipt and separate composition reviewREQUIRED

DOSSIER QUALIFIED ≠ DRIVER ACTIVATED64 个确定性案例与 198 次签名校验只证明候选边界可审计;生产驱动、Unit、Service、8110 listener、代理、公网路由、外部读写和 mutation 全部为 0。
DISPOSABLE-HOST CONFORMANCE · PLAN ADMISSION / NO HOST EXECUTION
把候选驱动送上测试主机之前,先冻结隔离拓扑、12 阶段证据链与独立看门狗

这一工作台只准入“如何测试”的不可变计划:它验证上游资格回执、非生产主机轮廓、证据空槽与失败收敛规则,不创建 EC2、不加载候选包、不调用驱动,也不启动 watchdog。真正的主机测试仍需要独立授权。

DISPOSABLE_HOST_CONFORMANCE_ADMISSION_IMPLEMENTED_NOT_CONFIGURED
CONFORMANCE PHASES12ordered · immutable · unexecuted
WATCHDOG TRIGGERS8independent fail-closed observer
TERMINAL ASSERTIONS8process → host retirement
EVIDENCE SLOTS12required · currently unobserved
FIXTURE MATRIX688 accept · 60 deny
PRODUCTION HOST CLAIMS0paid resources · FALSE
01 · INPUTQUALIFIED TEST-ONLY DOSSIER54 fixture verifications
02 · CURRENT BOUNDARYPLAN_ADMISSION_ONLY5 admitted fixture plans
03 · SEPARATE AUTHORITYDISPOSABLE HOST RUNnot requested · not executed
PRODUCTION ACTIVATIONNO AUTHORITYUnit · Service · 8110 · route = 0
ISOLATED HOST PROFILEONE PLAN · ONE HOST · TERMINATE
provider
AWS_EC2_DISPOSABLE_TEST_HOST
platform
linux/amd64
environment
NON_PRODUCTION_CONFORMANCE
artifact
PRESTAGED_IMMUTABLE_IMAGE
identity
reits-runner-factory
loopback
127.0.0.1:8110
PROD ACCOUNT / VPCFALSE / FALSEPUBLIC IP / INGRESSFALSE / 0IMDS / PROFILEFALSE / FALSEROOT VOLUMEENCRYPTED · DELETE
INDEPENDENT WATCHDOG60s DEADLINE · +10s KILL
PROCESS OWNERDISPOSABLE_HOST_WATCHDOG
SHARES CONTROLLERFALSE
SHARES USERFALSE
STARTED NOWFALSE

W1PROCESS_EXIT_NON_ZEROPLANNED

W2HEALTH_DEADLINE_EXCEEDEDPLANNED

W3READY_DEADLINE_EXCEEDEDPLANNED

W4PUBLIC_BIND_DETECTEDPLANNED

W5REVERSE_PROXY_DETECTEDPLANNED

W6UNIT_DIGEST_DRIFTPLANNED

W7ROLLBACK_EVIDENCE_MISSINGPLANNED

W8MONOTONIC_JOURNAL_GAPPLANNED

12-PHASE CONFORMANCE RAILEVERY PHASE · PLANNED_NOT_EXECUTED
01

claimHostHOST_CLAIM

PLANNED_NOT_EXECUTED
02

verifyIsolationISOLATION_ATTESTATION

PLANNED_NOT_EXECUTED
03

verifyBaselineBASELINE_ATTESTATION

PLANNED_NOT_EXECUTED
04

stageArtifactARTIFACT_ATTESTATION

PLANNED_NOT_EXECUTED
05

exerciseForwardFORWARD_TRACE

PLANNED_NOT_EXECUTED
06

exerciseDenialsNEGATIVE_GUARD_TRACE

PLANNED_NOT_EXECUTED
07

triggerWatchdogWATCHDOG_TRACE

PLANNED_NOT_EXECUTED
08

exerciseCompensationCOMPENSATION_TRACE

PLANNED_NOT_EXECUTED
09

verifyHostCleanHOST_CLEAN_ATTESTATION

PLANNED_NOT_EXECUTED
10

verifyNetworkCleanNETWORK_CLEAN_ATTESTATION

PLANNED_NOT_EXECUTED
11

retireHostRETIREMENT_ATTESTATION

PLANNED_NOT_EXECUTED
12

sealDossierDOSSIER_SEAL

PLANNED_NOT_EXECUTED
FUTURE EVIDENCE MANIFEST0 / 12 OBSERVED
E01

HOST_CLAIMclaimHost · asymmetric signer required

REQUIRED_NOT_OBSERVED
E02

ISOLATION_ATTESTATIONverifyIsolation · asymmetric signer required

REQUIRED_NOT_OBSERVED
E03

BASELINE_ATTESTATIONverifyBaseline · asymmetric signer required

REQUIRED_NOT_OBSERVED
E04

ARTIFACT_ATTESTATIONstageArtifact · asymmetric signer required

REQUIRED_NOT_OBSERVED
E05

FORWARD_TRACEexerciseForward · asymmetric signer required

REQUIRED_NOT_OBSERVED
E06

NEGATIVE_GUARD_TRACEexerciseDenials · asymmetric signer required

REQUIRED_NOT_OBSERVED
E07

WATCHDOG_TRACEtriggerWatchdog · asymmetric signer required

REQUIRED_NOT_OBSERVED
E08

COMPENSATION_TRACEexerciseCompensation · asymmetric signer required

REQUIRED_NOT_OBSERVED
E09

HOST_CLEAN_ATTESTATIONverifyHostClean · asymmetric signer required

REQUIRED_NOT_OBSERVED
E10

NETWORK_CLEAN_ATTESTATIONverifyNetworkClean · asymmetric signer required

REQUIRED_NOT_OBSERVED
E11

RETIREMENT_ATTESTATIONretireHost · asymmetric signer required

REQUIRED_NOT_OBSERVED
E12

DOSSIER_SEALsealDossier · asymmetric signer required

REQUIRED_NOT_OBSERVED
SELECTED DENIAL TRACERFDHCA-41 · HOST_PUBLIC_BIND
  1. 01

    UPSTREAM RECEIPTexact test-only driver qualification

    VERIFIED
  2. 02

    HOST PROFILEbindHost mutated to 0.0.0.0

    DRIFT
  3. 03

    ISOLATION GUARDexact 127.0.0.1:8110 required

    DENIED
  4. 04

    ADMISSION HANDLEnever minted

    ABSENT
  5. 05

    HOST / DRIVER / WATCHDOGno downstream action possible

    0 / 0 / 0
PUBLIC BIND IS A STRUCTURAL DENIAL拒绝发生在计划边界;没有主机、进程或网络副作用。
TERMINAL-SAFE ASSERTIONSALL 8 REQUIRED AFTER A FUTURE HOST RUN
T1CONTROLLER_PROCESS_ABSENTREQUIRED_NOT_OBSERVED
T2PORT_8110_ABSENTREQUIRED_NOT_OBSERVED
T3PUBLIC_BIND_ABSENTREQUIRED_NOT_OBSERVED
T4REVERSE_PROXY_ABSENTREQUIRED_NOT_OBSERVED
T5UNIT_REMOVED_OR_EXACTLY_RESTOREDREQUIRED_NOT_OBSERVED
T6ROLLBACK_SNAPSHOT_EXACTLY_RESTOREDREQUIRED_NOT_OBSERVED
T7EXCLUSIVE_LOCK_RELEASEDREQUIRED_NOT_OBSERVED
T8HOST_AND_ROOT_VOLUME_RETIREDREQUIRED_NOT_OBSERVED
NINE ADMISSION STATES3 RECEIPT RE-VERIFICATIONS · 1 DISPOSED HANDLE
01UNTRUSTEDno upstream qualification standing exists
02QUALIFICATION_BOUNDthe exact target-host driver qualification was positively verified
03HOST_PROFILE_BOUNDthe non-production disposable-host boundary is exact
04PLAN_BOUNDtwelve phases and the independent watchdog are frozen without commands
05EVIDENCE_MANIFEST_BOUNDall twelve future evidence slots are explicit and unobserved
06PREPAREDone opaque sixty-second admission capability exists
07ADMITTED_TEST_ONLYthe plan may proceed only to a separately authorized disposable-host run
08DISPOSEDan unused capability was revoked
09DENIEDshape, isolation, provenance, execution material or receipt drift failed closed
PRODUCTION READINESS GAPHOST 0 · PACKAGE 0 · DRIVER 0 · UNIT 0 · SERVICE 0 · 8110 0 · ROUTE 0

01obtain explicit cost and runtime approval for a disposable non-production hostREQUIRED

02create a dedicated non-production account and VPC with no production connectivityREQUIRED

03build and sign the prestaged immutable conformance imageREQUIRED

04implement the separate target-host driver package and complete syscall reviewREQUIRED

05configure an asymmetric evidence signer without exporting private materialREQUIRED

06configure a durable monotonic journal and independent watchdog identityREQUIRED

07execute all twelve phases and eight watchdog triggers on the disposable hostREQUIRED

08capture signed terminal evidence for process, port, proxy, unit, snapshot and lock cleanupREQUIRED

09prove instance and root-volume retirement from an independent authorityREQUIRED

10review the sealed conformance dossier before any production activation discussionREQUIRED

PLAN ADMITTED ≠ HOST CLAIMED68 个案例只证明隔离轮廓、失败收敛和证据槽可被机器验证;生产主机、候选包、驱动、Unit、Service、8110、代理、公网路由、外部读写和 mutation 全部为 0。
CONFORMANCE DOSSIER SEALER · FIXTURE EVIDENCE ONLY
谁可以宣布一次主机测试可信:不是 Controller 自报,而是完整签名证据链共同裁决

工作台把已准入计划、fixture 执行回执、12 份阶段回执与 8 份独立终态证明拼成一份只读卷宗。任一身份、顺序、前驱摘要、签名或 watchdog authority 漂移都会拒绝封存;输出只代表 fixture conformance,不授予生产晋级权。

DISPOSABLE_HOST_CONFORMANCE_DOSSIER_SEALER_IMPLEMENTED_NOT_CONFIGURED
PHASE RECEIPTS12ordered · hash chained
TERMINAL PROOFS8independent watchdog
SIGNATURES / DOSSIER211 execution + 12 + 8
FIXTURE MATRIX728 seal · 64 deny
SEALED FIXTURES53 receipt verifications
PRODUCTION HOST RUNS0promotion authority · NONE
01 · EXACT UPSTREAMPLAN ADMISSION RECEIPT58 fixture provenance checks
02 · FIXTURE RUNEXECUTION + IMMUTABLE IMAGEin-memory evidence · no host contact
03 · CURRENT BOUNDARYEVIDENCE DOSSIER SEALER338 signature checks across matrix
PRODUCTION PROMOTIONNO AUTHORITYservice · 8110 · proxy · route = 0
EXECUTION RECEIPTEXACT SHAPE · FIXTURE ONLY
execution id
rfdhcx1:…fixture
mode
IN_MEMORY_HOST_EVIDENCE_FIXTURE_ONLY
host claim
sha256:…bound
image
sha256:…immutable
journal head
phase[12].receiptDigest
timebox
≤ 15 minutes
commands []network IN_MEMORY_FIXTURE_ONLYdeployment NONERECEIPT VERIFIED
PROVENANCE RAIL21 / DOSSIER
01

EXECUTION SIGNERfixture-p256-conformance-execution

1 VERIFIED
02

PHASE SIGNERfixture-p256-conformance-evidence

12 VERIFIED
03

TERMINAL AUTHORITYINDEPENDENT_FIXTURE_WATCHDOG

8 VERIFIED
FALSE OR EXCEPTION → DENY没有“部分可信”卷宗,也没有本地自签降级。
12-PHASE MONOTONIC LEDGERGENESIS 00…00 → JOURNAL HEAD
01

claimHostHOST_CLAIM

GENESIS · sha256:…01VERIFIED_FIXTURE_ONLY
02

verifyIsolationISOLATION_ATTESTATION

← 01 · sha256:…02VERIFIED_FIXTURE_ONLY
03

verifyBaselineBASELINE_ATTESTATION

← 02 · sha256:…03VERIFIED_FIXTURE_ONLY
04

stageArtifactARTIFACT_ATTESTATION

← 03 · sha256:…04VERIFIED_FIXTURE_ONLY
05

exerciseForwardFORWARD_TRACE

← 04 · sha256:…05VERIFIED_FIXTURE_ONLY
06

exerciseDenialsNEGATIVE_GUARD_TRACE

← 05 · sha256:…06VERIFIED_FIXTURE_ONLY
07

triggerWatchdogWATCHDOG_TRACE

← 06 · sha256:…07VERIFIED_FIXTURE_ONLY
08

exerciseCompensationCOMPENSATION_TRACE

← 07 · sha256:…08VERIFIED_FIXTURE_ONLY
09

verifyHostCleanHOST_CLEAN_ATTESTATION

← 08 · sha256:…09VERIFIED_FIXTURE_ONLY
10

verifyNetworkCleanNETWORK_CLEAN_ATTESTATION

← 09 · sha256:…10VERIFIED_FIXTURE_ONLY
11

retireHostRETIREMENT_ATTESTATION

← 10 · sha256:…11VERIFIED_FIXTURE_ONLY
12

sealDossierDOSSIER_SEAL

← 11 · sha256:…12VERIFIED_FIXTURE_ONLY
INDEPENDENT TERMINAL ATTESTATIONS8 / 8 REQUIRED
T1CONTROLLER_PROCESS_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T2PORT_8110_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T3PUBLIC_BIND_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T4REVERSE_PROXY_ABSENTINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T5UNIT_REMOVED_OR_EXACTLY_RESTOREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T6ROLLBACK_SNAPSHOT_EXACTLY_RESTOREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T7EXCLUSIVE_LOCK_RELEASEDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
T8HOST_AND_ROOT_VOLUME_RETIREDINDEPENDENT_FIXTURE_WATCHDOGPROVED_FIXTURE_ONLY
SELECTED DENIAL TRACERFDHCDS-58
  1. 01

    PLAN + EXECUTIONexact upstream digests

    VERIFIED
  2. 02

    PHASE CHAIN12 ordered receipts · journal closes

    VERIFIED
  3. 03

    TERMINAL AUTHORITYmutated to CONTROLLER_SELF_REPORT

    DRIFT
  4. 04

    INDEPENDENCE GUARDController self-report cannot replace the independent terminal watchdog authority.

    DENIED
  5. 05

    DOSSIER HANDLEnever minted after proof drift

    ABSENT
SELF-ATTESTATION CANNOT CLOSE THE RUN生产证据、晋级权限与外部副作用保持为零。
TEN DOSSIER STATESONE-SHOT HANDLE · REPLAY DENIED
01UNTRUSTEDpacket not trusted
02PLAN_ADMISSION_BOUNDexact plan admission verified
03EXECUTION_RECEIPT_BOUNDfixture execution identity bound
04PHASE_CHAIN_BOUND12 receipts form one chain
05TERMINAL_PROOF_BOUND8 independent terminal proofs bound
06PREPAREDopaque handle minted
07SEALED_TEST_ONLYfixture-only seal issued
08VERIFIEDseal digest re-verified
09DISPOSEDunused handle retired
10DENIEDfail-closed terminal state
PRODUCTION READINESS GAPHOST RUN 0 · PACKAGE 0 · DRIVER 0 · UNIT 0 · SERVICE 0 · 8110 0 · ROUTE 0

01obtain explicit cost and runtime approval for a disposable non-production hostREQUIRED

02create a dedicated non-production account and VPC with no production connectivityREQUIRED

03build and sign the prestaged immutable conformance imageREQUIRED

04implement the separate target-host driver package and complete syscall reviewREQUIRED

05configure asymmetric evidence signers without exporting private materialREQUIRED

06configure a durable monotonic journal and independent watchdog identityREQUIRED

07execute all twelve phases and eight watchdog assertions on the disposable hostREQUIRED

08capture signed terminal evidence for process, port, proxy, unit, snapshot and lock cleanupREQUIRED

09prove instance and root-volume retirement from an independent authorityREQUIRED

10review the sealed production dossier under a separately approved promotion policyREQUIRED

DOSSIER SEALED ≠ PRODUCTION CONFORMANCE72 条确定性夹具只证明卷宗封存边界可审计;当前没有真实主机执行、候选包、驱动、Unit、Service、8110 listener、代理、公网路由、外部读写、mutation 或付费资源。
DISPOSABLE-HOST EXECUTION ENVELOPE · TEST-ONLY / NO LAUNCH
把“可以测试”拆成三份独立批准:谁付钱、允许跑多久、谁负责证明彻底销毁

这不是创建 EC2 的按钮。工作台只把已封存的 fixture 卷宗、合成成本上限、隔离运行时边界和独立退役预留绑定为一份不可变执行信封。任一批准过期、预算越界、镜像漂移或销毁责任缺失,信封都不会生成。

DISPOSABLE_HOST_EXECUTION_ENVELOPE_AUTHORIZER_IMPLEMENTED_NOT_CONFIGURED
INDEPENDENT AUTHORITIES3cost · runtime · retirement
IMMUTABLE BINDINGS8dossier → cleanup policy
SYNTHETIC CEILING$0.50fixture budget · not a live quote
RUN DEADLINE15mhard maximum
CLEANUP DEADLINE120sinstance + root volume
PRODUCTION HOST RUNS0launch authority · NONE
01 · EXACT UPSTREAMSEALED FIXTURE DOSSIER65 provenance checks
02 · SEPARATE OWNERSCOST + RUNTIME + RETIREMENT62 approval checks across matrix
03 · CURRENT BOUNDARYIMMUTABLE NO-LAUNCH ENVELOPE5 fixture envelopes authorized
HOST EXECUTORNOT PRESENTAWS · package load · driver call = 0
THREE-KEY APPROVAL MATRIXNO SELF-APPROVAL
01

INDEPENDENT_COST_OWNERsynthetic estimate is inside a 500 milli-USD test ceilingfixture-p256-cost-owner

FIXTURE VERIFIED
02

INDEPENDENT_RUNTIME_OWNER900-second isolated non-production run and 120-second cleanup boundaryfixture-p256-runtime-owner

FIXTURE VERIFIED
03

INDEPENDENT_RETIREMENT_WATCHDOGinstance and root-volume retirement proof is mandatoryfixture-p256-retirement-watchdog

FIXTURE VERIFIED
3 DISTINCT SIGNERS任意 false、异常、过期或同一主体替代独立批准都会 fail closed。
COST + TIME ENVELOPESYNTHETIC / TEST ONLY
140milli-USD estimateof 500 approved max

28%fixture estimate / approved ceiling

pricing basis
SYNTHETIC_FIXTURE_NOT_LIVE_QUOTE
live price reads
0
run window
900s
cleanup window
120s
production connectivity
FALSE
public network
FALSE
IMMUTABLE EXECUTION PACKAGE MANIFEST8 DIGEST-BOUND INPUTS
01

sealed dossier receiptsha256:… exact subject binding

UPSTREAM VERIFIED
02

immutable imagesha256:… exact subject binding

BOUND_NOT_LOADED
03

target-host driver artifactsha256:… exact subject binding

BOUND_NOT_LOADED
04

Controller service bundlesha256:… exact subject binding

BOUND_NOT_LOADED
05

twelve-phase conformance plan bundlesha256:… exact subject binding

BOUND_NOT_LOADED
06

independent watchdog bundlesha256:… exact subject binding

BOUND_NOT_LOADED
07

deny-by-default network policysha256:… exact subject binding

BOUND_NOT_LOADED
08

instance-and-volume cleanup policysha256:… exact subject binding

BOUND_NOT_LOADED
artifact · PRESTAGED_IMMUTABLE_IMAGEcommands · NONE_IN_AUTHORIZATION_LAYERsecrets · CONFIGREFS_ONLY_NOT_RESOLVEDLAUNCH AUTHORITY · NONE
TIME-BOUND HANDOFFAUTHORIZATION DOES NOT EXECUTE
  1. 00s

    REQUEST WINDOW OPENSnonce-bound authorization request

    ≤ 60s
  2. 01

    FOUR TRUST RECEIPTS VERIFIEDdossier + three independent owners

    FIXTURE
  3. 02

    PACKAGE DIGEST FROZENcost and runtime limits become immutable

    BOUND
  4. 03

    NO-LAUNCH ENVELOPE MINTEDeligible only for a separately approved fixture executor

    TEST_ONLY
  5. HOST LAUNCH BARRIERno executor, IAM, quote or paid-resource authority

    STOP
SELECTED DENIAL TRACERFDHEA-31
  1. 01

    SEALED DOSSIERexact receipt and pinned contract digest

    VERIFIED
  2. 02

    COST APPROVALmaximum 500 milli-USD

    BOUND
  3. 03

    ESTIMATED COSTmutated to 501 milli-USD

    OVER CAP
  4. 04

    BUDGET GUARDA synthetic estimate above the independently approved maximum cannot mint an execution envelope.

    DENIED
  5. 05

    ENVELOPE / HOST / BILLINGno downstream capability or side effect

    0 / 0 / 0
预算不是提示,是结构性闸门越界请求在 package handle 生成前被拒绝。
ELEVEN AUTHORIZATION STATESONE-SHOT HANDLE · 60s NONCE · REPLAY DENIED
01UNTRUSTEDpacket not trusted
02DOSSIER_BOUNDsealed dossier provenance verified
03COST_APPROVED_TEST_ONLYsynthetic cost ceiling accepted
04RUNTIME_APPROVED_TEST_ONLYisolated runtime envelope accepted
05RETIREMENT_RESERVED_TEST_ONLYindependent cleanup owner reserved
06PACKAGE_MANIFEST_BOUNDall package and policy digests frozen
07PREPAREDopaque capability minted
08AUTHORIZED_TEST_ONLY_NO_LAUNCHtest-only no-launch receipt issued
09VERIFIEDreceipt digest re-verified
10DISPOSEDunused capability revoked
11DENIEDfail-closed terminal state
REAL-HOST EXECUTION GAPQUOTE 0 · APPROVER KEYS 0 · EXECUTOR 0 · HOST 0 · PACKAGE LOAD 0 · DRIVER CALL 0

01obtain explicit user authorization for paid disposable non-production computeREQUIRED

02replace synthetic cost evidence with a reviewed immutable pricing quote sourceREQUIRED

03create a dedicated non-production account and VPC with no production connectivityREQUIRED

04build and sign the prestaged immutable conformance image and all package artifactsREQUIRED

05configure independent cost, runtime and retirement signing authoritiesREQUIRED

06implement and syscall-review a separate host executor with no shell surfaceREQUIRED

07configure a durable monotonic execution journal and independent watchdog runtimeREQUIRED

08execute the package on one disposable host under the exact cost and time envelopeREQUIRED

09capture independent process, port, proxy, unit, snapshot, lock, instance and volume retirement proofREQUIRED

10review the resulting real-host dossier before any production activation discussionREQUIRED

ENVELOPE AUTHORIZED ≠ HOST LAUNCHED76 条确定性夹具只证明成本、时间、包身份和销毁责任可以被机器锁死;真实价格读取、EC2、候选包加载、驱动、Unit、Service、8110、代理、公网路由、外部写入、mutation 与付费资源仍全部为 0。
NO-SHELL FIXTURE EXECUTOR · CLOSED TYPED PORTS / NO HOST
执行器不是一个 Shell:每一步只能走命名端口,主机占位只允许一次,结束必须交出独立退役证明

工作台把上一层 no-launch 信封投影到内存 fixture 驱动。五个执行端口与三个独立 watchdog 端口分属不同 authority;任何 BASH、进程、主机接触、包加载或退役歧义都会中止前进,绝不会被解释为付费主机授权。

DISPOSABLE_HOST_NO_SHELL_EXECUTOR_IMPLEMENTED_NOT_CONFIGURED
CLOSED TYPED PORTS85 executor · 3 watchdog
FIXTURE MATRIX8012 safe terminal · 68 deny
RETIRED SESSIONS5host + root volume proof
CLEAN ROLLBACKS51 contained ambiguity
STEP SIGNATURES68positive verification only
PRODUCTION EXECUTORS0paid host authority · absent
SEPARATION OF EXECUTION AND RETIREMENT AUTHORITY2 IDENTITIES · NO SELF-ATTESTED CLEANUP
01

FIXTURE_NO_SHELL_EXECUTORfixture-p256-no-shell-executor

5 TYPED PORTScannot attest retirement
02

INDEPENDENT_RETIREMENT_WATCHDOGfixture-p256-independent-retirement-watchdog

3 TYPED PORTScannot open a session
IDEMPOTENT HOST CLAIMONE ENVELOPE → ONE FIXTURE CLAIM
DERIVATIONsha256(authorizationId + executionPackageId + dossierId)hostClaimKey
maximum claims
1
durable claim store
NOT CONFIGURED
AWS ClientToken
NOT DERIVED
fixture scope
TRUE
重复占位不会生成第二台主机当前只证明确定性 key 与一次性 handle;没有 DynamoDB 写入或 EC2 ClientToken。
DEADLINE CONTROLINDEPENDENT WATCHDOG
15:00MAX RUN WINDOW02:00 cleanup
  1. REQUEST30s authorization windowBOUND
  2. WATCHDOGreserved before session openFIXTURE
  3. RETIREMENTinstance + root volumeMANDATORY
runtime clock · NOT CONFIGURED
EIGHT-PORT NO-SHELL EXECUTION RAILFORWARD PROGRESS REQUIRES VERIFIED RECEIPT
01

CLAIM_HOSTclaimHost()derive one fixture-only host claim

EXECUTORSHELL · NONE
02

BIND_EXECUTION_PACKAGEbindPackage()bind without loading package bytes

EXECUTORSHELL · NONE
03

START_DEADLINE_WATCHDOGstartDeadlineWatchdog()reserve fixture deadline observation

WATCHDOGSHELL · NONE
04

ATTEST_ISOLATIONattestIsolation()prove modeled network and credential closure

EXECUTORSHELL · NONE
05

OPEN_FIXTURE_SESSIONopenSession()open an in-memory typed session only

EXECUTORSHELL · NONE
06

SEAL_FIXTURE_SESSIONsealSession()seal fixture evidence without a spawned process

EXECUTORSHELL · NONE
07

RETIRE_FIXTURE_HOSTretireHost()retire modeled instance and root volume

WATCHDOGSHELL · NONE
08

VERIFY_RETIREMENTverifyRetirement()positively verify terminal retirement

WATCHDOGSHELL · NONE
SHELL COMMANDS0accepted
PROCESSES0spawned
HOST CONTACTS0network or driver
PACKAGE LOADS0bytes loaded
PRICE READS0live quotes
PAID RESOURCESFALSEexplicit authority absent
TERMINAL OUTCOME LEDGERSAFE ≠ SUCCESS-ONLY

RETIRED5

ROLLED BACK5

CONTAINED1

RETIREMENT AMBIGUITY → CONTAINED不能证明实例与根卷均销毁时,状态不会伪装成 clean rollback。
SELECTED DENIAL TRACERFDHNS-69
  1. 01

    AUTHORIZED ENVELOPEexact no-launch receipt

    VERIFIED
  2. 02

    CLAIM STEPtyped fixture evidence expected

    OPEN
  3. 03

    SHELL SURFACEmutated from NONE to BASH

    DRIFT
  4. 04

    STEP VERIFIERA typed fixture step that exposes BASH is rejected before it can become trusted executor evidence.

    DENY
  5. 05

    HOST / PROCESS / PACKAGEno trusted forward progress

    0 / 0 / 0
TWELVE EXECUTOR STATESRETIRED · ROLLED_BACK · CONTAINED
01UNTRUSTEDpacket not trusted
02ENVELOPE_VERIFIEDupstream provenance accepted
03REQUEST_BOUNDexact no-spend request frozen
04HOST_CLAIMED_FIXTURE_ONLYdeterministic fixture claim
05PACKAGE_BOUND_NOT_LOADEDidentity bound; bytes absent
06WATCHDOG_RESERVED_FIXTURE_ONLYindependent deadline reserved
07ISOLATION_ATTESTED_FIXTURE_ONLYmodeled closure attested
08SESSION_OPEN_IN_MEMORYtyped session only
09SESSION_SEALED_IN_MEMORYevidence sealed; no process
10HOST_RETIREMENT_REQUESTED_FIXTURE_ONLYmandatory cleanup invoked
11RETIREMENT_VERIFIED_FIXTURE_ONLYinstance + root volume proven
12ROLLED_BACK_OR_CONTAINEDsafe failure terminal
REAL DISPOSABLE-HOST GAPUSER COST AUTH 0 · DURABLE CLAIM 0 · DRIVER 0 · HOST 0 · PROCESS 0 · PACKAGE 0

01A user must explicitly authorize a reviewed real cost ceiling and quote source for a paid disposable host.REQUIRED

02A durable idempotent host-claim store with generation fencing must be deployed and recovery-drilled.REQUIRED

03A reviewed no-shell production worker driver must implement the exact closed typed-port interface.REQUIRED

04An independently owned deadline and retirement driver must be deployed with separate credentials.REQUIRED

05A dedicated non-production VPC, subnet, security group and deny-by-default egress policy must exist.REQUIRED

06An immutable image and every execution-package digest must be staged and re-verified on the target host.REQUIRED

07The job credential, cloud credential and registration secret closures must be observed on a real disposable host.REQUIRED

08Instance and root-volume retirement must be independently observed within the 120-second cleanup deadline.REQUIRED

09Ambiguous launch, timeout and retirement drills must prove whole-pool freeze without orphaned capacity.REQUIRED

10Controller 0/11 production readiness gates must pass with signed runtime evidence and rollback proof.REQUIRED

11An explicit change window must authorize production wiring while port 8110, proxy and public routes remain separately controlled.REQUIRED

FIXTURE SESSION RETIRED ≠ PAID HOST EXECUTED80 条场景证明封闭端口、幂等占位、deadline 和补偿终态可被机器审计;真实成本批准、价格读取、EC2、进程、包加载、驱动、Unit、Service、8110、代理、公网路由和付费资源仍全部为 0。
DURABLE RESERVATION ADAPTER · IMPLEMENTED / NOT CONFIGURED
两个幂等键必须一起生、一起变、一起进入终态

Delivery 与 Job Attempt 分别占一行,但所有状态变更都在同一个 DynamoDB transaction 中完成。120 秒租约只允许同一 Plan 恢复;接管必须轮换 token 并递增 epoch,旧 Controller 永远不能完成新租约。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
ATOMIC RECORDS2delivery + job attempt
OPERATIONS5reserve · renew · recover · terminal
LEASE120sseven-day replay retention
FIXTURES165 allow · 11 deny
LIVE DYNAMO WRITES0table created · FALSE
READINESS GATEBLOCKEDconfigured · FALSE
PK · DELIVERYrf1:sha256(delivery + job)scope DELIVERY · pairKey → job attempt
ATOMIC
TRANSACT
PK · JOB ATTEMPTrfj1:sha256(repo + job)scope JOB_ATTEMPT · pairKey → delivery
LEASE CAPABILITY
FENCINGtoken rotates · epoch 1 → 2stale renew / complete / fail denied
01

ABSENTreserveRESERVED

leaseEpoch=1
02

RESERVEDrenewRESERVED

same lease token
03

RESERVED_EXPIREDrecoverExpiredRESERVED

new token + epoch increment
04

RESERVEDcompleteCOMPLETED

current unexpired token
05

RESERVEDfailFAILED

current unexpired token
TRANSACTION CONTRACTSall paired
reserve

TransactWriteItemsattribute_not_exists(pk)

lease epoch 1
renew

TransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired

same epoch, extended expiry
recoverExpired

BatchGetItem + TransactWriteItemspair + scope + same plan + exact expired token/epoch/expiry

new lease token, epoch + 1
complete

TransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired

COMPLETED + receipt digest
fail

TransactWriteItemspair + scope + RESERVED + plan + lease token + epoch + unexpired

FAILED + terminal phase
FAIL-CLOSED INVARIANTS8/8 test evidence

01delivery and job-attempt keys change atomicallyPASS_TEST_ONLY

02replay never overwrites an existing or terminal pairPASS_TEST_ONLY

03expired leases require same-plan recovery, never fresh reservePASS_TEST_ONLY

04recovery rotates the lease token and increments the fencing epochPASS_TEST_ONLY

05stale token or epoch cannot renew, complete or failPASS_TEST_ONLY

06pair reads are strongly consistent and corruption fails closedPASS_TEST_ONLY

07terminal rows retain replay evidence for seven daysPASS_TEST_ONLY

08lease token values never enter public evidence or structured logsPASS_TEST_ONLY

PRODUCTION READINESS GAPRF_READY_RESERVATION_STORE · BLOCKED

01reviewed DynamoDB table with PITR, encryption and TTLREQUIRED

02least-privilege controller IAM role scoped to one tableREQUIRED

03conditional-conflict, corruption and throttling metricsREQUIRED

04expired-lease reconciler with single-owner electionREQUIRED

05backup restore and region-failure drill receiptsREQUIRED

06security, runtime and cost owner approvalREQUIRED

IMPLEMENTATION ≠ RUNTIMEAdapter 已实现;DynamoDB table、IAM、监控、恢复演练和 owner approval 均不存在。Live reservations 0 · external calls 0readiness · FALSE
ASYMMETRIC RECEIPT SIGNER · IMPLEMENTED / NOT CONFIGURED
先钉住公钥,再签摘要;每一张收据离开 Adapter 前都必须本地验真

生产目标只接受精确 KMS Key ARN、SIGN_VERIFY / P-256 公钥与固定 SPKI 指纹。当前 Saga 使用 TEST_ONLY P-256 driver 运行真实 ECDSA 链;没有创建 KMS Key、没有 IAM 权限,也没有一张 runtime receipt。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
SIGNER OPERATIONS3initialize · sign · verify
KEY POLICYP-256SIGN_VERIFY · exact ARN
ADVERSARIAL FIXTURES205 allow · 15 deny
CRYPTO EVIDENCE2/1signed receipts / verified chains
LIVE KMS CALLS0key created · FALSE
RUNTIME RECEIPTS0readiness · BLOCKED
CONTROLLER INGRESSHMAC-SHA256 · PLAN_ONLY

只证明 webhook dry-run 决策;共享密钥测试签名不能成为生命周期收据。

trust / TEST_ONLY
SAGA LIFECYCLEECDSA P-256 · TEST_ONLY

10 阶段真实签名并本地验链;private test key 不进入公开证据。

algorithm / ECDSA_SHA_256
PRODUCTION KMSNOT CONFIGURED

真实 Key、IAM、告警与轮换演练缺失,Signer readiness 必须 fail closed。

runtime receipts / 0
01 · GET PUBLIC KEYexact key ARNalias drift denied
02 · PIN IDENTITYARN + SHA256 SPKIECC_NIST_P256
03 · CANONICALIZErecursive key orderbounded plain JSON · no secrets
04 · KMS SIGN32-byte SHA-256DIGEST · ECDSA_SHA_256
05 · LOCAL VERIFYDER + predecessorbad chain emits nothing
01

UNINITIALIZEDinitializeKEY_PINNED

all key metadata and SPKI fingerprint match
02

KEY_PINNEDsign genesisCHAIN_OPEN

sequence 0 + previousDigest null
03

CHAIN_OPENsign nextCHAIN_OPEN

sequence N + previous digest
04

CHAIN_OPENverifyVERIFIED

digest + ECDSA + continuity pass
05

ANYmismatch or outageFAIL_CLOSED

no unsigned receipt emitted
SIGNER PORT CONTRACT3 operations · fail closed
initialize

GetPublicKeyexact ARN + SIGN_VERIFY + ECC_NIST_P256 + ECDSA_SHA_256 + pinned SPKI fingerprint

cached local verifier
sign

Signexact ARN + DIGEST + ECDSA_SHA_256 + canonical SHA-256

DER signature bound to key metadata
verify

LOCALcanonical digest + chain predecessor + pinned public key

cryptographic receipt verdict
CRYPTOGRAPHIC INVARIANTS10/10 test evidence

01signing uses an exact KMS key ARN, never a mutable aliasPASS_TEST_ONLY

02the KMS key must be SIGN_VERIFY on ECC_NIST_P256PASS_TEST_ONLY

03the SPKI SHA-256 fingerprint is pinned before signingPASS_TEST_ONLY

04KMS signs exactly 32 digest bytes with MessageType DIGESTPASS_TEST_ONLY

05the returned key ARN and algorithm must match the requestPASS_TEST_ONLY

06every receipt is locally verified before it leaves the adapterPASS_TEST_ONLY

07sequence and predecessor digest make chain reordering fail closedPASS_TEST_ONLY

08canonical facts are bounded plain JSON and secret-like string fields are deniedPASS_TEST_ONLY

09private key material never enters public evidence or runtime logsPASS_TEST_ONLY

10TEST_ONLY signatures never increment runtime receipt truthPASS_TEST_ONLY

PRODUCTION READINESS GAPRF_READY_RECEIPT_SIGNER · BLOCKED

01reviewed asymmetric KMS SIGN_VERIFY key with rotation policyREQUIRED

02least-privilege kms:GetPublicKey and kms:Sign controller IAM roleREQUIRED

03approved exact key ARN and SPKI fingerprint configurationREQUIRED

04sign latency, throttling, invalid-signature and key-drift alarmsREQUIRED

05key-disable, rotation, rollback and verification drill receiptsREQUIRED

06security, runtime and cost owner approvalREQUIRED

IMPLEMENTATION ≠ KMS RUNTIMEAdapter 和 ECDSA 验证链已经实现;真实 KMS Key、IAM、限流告警、轮换与回滚演练仍为 0。Key selection · EXACT_KEY_ARN;public key pin · SHA256_SPKIconfigured · FALSE
ONE-TIME REGISTRATION TOKEN BROKER · IMPLEMENTED / NOT CONFIGURED
Token 只在一次受控调用中存在;不是 JSON、不是字符串、也不是可回放凭证

Gitea 1.25.4 的组织 Runner 注册接口把 Token 放在 HTTP token 响应头。Adapter 只接受 200 + owned mutable bytes,再交付 30 秒单消费者能力句柄;公开证明只记录状态,不记录 Token 值或摘要。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
BROKER OPERATIONS4issue · inspect · consume · destroy
CAPABILITY TTL30s5–60s bounded configuration
ADVERSARIAL FIXTURES226 allow · 16 deny
MAX HEADER BYTES512bounded token ASCII
LIVE HANDLES0credential configured · FALSE
GITEA TOKEN CALLS0runtime driver · NOT_CONFIGURED
ROOT IDENTITYsystemd CredentialSecretRef only · caller cannot inject value
GITEA 1.25.4HTTP 200 / token headerbody must be empty · string rejected
MUTABLE BOUNDARYowned Buffer ≤ 512 Bindependent 128-bit handle ID
TRUSTED CONSUMERregisterEphemeral()one in-flight callback · reentry denied
TERMINAL PROOFzeroized bytesconsumed · destroyed · expired
01

UNISSUEDissue valid header bytesACTIVE

HTTP 200 + mutable token header + bounded ASCII
02

ACTIVEinspectACTIVE

no token or digest exposed
03

ACTIVEconsumeCONSUMING

atomic single-consumer claim
04

CONSUMINGconsumer exitsCONSUMED

zeroize in finally on success or failure
05

ACTIVEdestroyDESTROYED

zeroize without disclosure
06

ACTIVETTL elapsesEXPIRED

zeroize before denial
07

CONSUMED|DESTROYED|EXPIREDconsumeDENY

replay never reopens capability
CAPABILITY PORT4 operations · no raw return
issue

controllerexact organization + plan scope + SecretRef-backed driver

ACTIVE opaque capability
inspect

controllermetadata only; expiry may advance state

secret-free lifecycle proof
consume

trusted Gitea registration adapterACTIVE + unexpired + single in-flight consumer

CONSUMED and zeroized even on callback failure
destroy

controller compensationnot concurrently CONSUMING

DESTROYED or idempotent terminal proof
SECRET-SAFETY INVARIANTS12/12 test evidence

01the request is scoped to the configured organization and admitted factory planPASS_TEST_ONLY

02the broker credential is a SecretRef and never a caller-supplied valuePASS_TEST_ONLY

03Gitea 1.25.4 success is exactly HTTP 200 with the token response headerPASS_TEST_ONLY

04the runtime driver must transfer owned mutable bytes, never an immutable stringPASS_TEST_ONLY

05token bytes are bounded printable token characters and at most 512 bytesPASS_TEST_ONLY

06the capability ID is independent random data and is never derived from the tokenPASS_TEST_ONLY

07inspect and JSON serialization expose lifecycle metadata but no token or token digestPASS_TEST_ONLY

08only one consumer may claim the capability and reentrant consumption is deniedPASS_TEST_ONLY

09TTL expiry zeroizes bytes before returning an expired verdictPASS_TEST_ONLY

10consumer success and consumer failure both zeroize bytes in a finally boundaryPASS_TEST_ONLY

11explicit destroy is idempotent after a terminal state and cannot race consumptionPASS_TEST_ONLY

12TEST_ONLY token activity never increments runtime or Gitea-write truthPASS_TEST_ONLY

SUCCESS PATHACTIVE → CONSUMING → CONSUMEDCallback exit always zeroizes the same owned byte buffer.
REPLAY / REENTRYDENY · 409A second or concurrent consumer never reopens the capability.
EXPIRY / DESTROYDENY · 410Bytes are zeroized before the terminal verdict is exposed.
RUNTIME READINESSRF_READY_TOKEN_BROKER · BLOCKEDDriver, root credential, alarms and drills remain absent.
PRODUCTION READINESS GAP0 LIVE TOKENS · 0 EXTERNAL CALLS

01root-scoped Gitea broker credential delivered by a systemd Credential fileREQUIRED

02isolated runtime driver that transfers the token header directly into owned mutable bytesREQUIRED

03exact Gitea base URL, organization and credential SecretRef configurationREQUIRED

04token issue latency, response-contract, replay and expiry alarmsREQUIRED

05credential rotation, broker outage and zeroization drill receiptsREQUIRED

06security and runtime owner approvalREQUIRED

IMPLEMENTATION ≠ BROKER RUNTIMEAdapter、TEST_ONLY driver 与 22 个夹具已经实现;真实 Gitea credential、隔离 header-byte driver、告警、轮换和 owner approval 仍未配置。Public token values · 0;digests · 0configured · FALSE
EC2 ONE-JOB WORKER PROVIDER · IMPLEMENTED / NOT CONFIGURED
启动不是成功;只有关掉云凭证、跑完唯一 Job、再证明机器与根卷消失,才算闭环

Adapter 将 launch / closeCloudBoundary / runJob / terminate 收敛为一个不可伪造的 Worker capability。Launch Template 必须使用精确 ID + 数字版本;Profile 脱离与 IMDS 关闭后必须重启复读,终止后必须同时看到 Instance terminal 与根卷 absent。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
PORT OPERATIONS4launch · boundary · job · terminate
STATE TRANSITIONS9failure remains non-admissible
ADVERSARIAL FIXTURES348 allow · 26 deny
EC2 OPERATIONS8plus one injected job-agent call
LIVE WORKERS / JOBS0/0runtime driver · NOT_CONFIGURED
LIVE EC2 CALLS0paid resources · FALSE
01 · LAUNCHexact LT ID + numeric versionClientToken · 1 private instance · job-bound tags
02 · BOOTSTRAPprofile attached · IMDSv2hop limit 1 · untrusted code absent
03 · CLOSE BOUNDARYdetach + IMDS off + rebootDescribeInstances must read both controls back
04 · EXACT JOBjobId bound · max 1cloud credentials false · replay denied
05 · RETIREinstance terminal + volume absentmissing proof freezes capacity
LAUNCH REQUEST ANATOMYall fields verified before a capability is emitted
TEMPLATEEXACT_ID_AND_NUMERIC_VERSIONmutable $Default / $Latest denied
NETWORKPRIVATE · NO IPv4 / IPv6one subnet · one security group · no production route
BOOTSTRAP IDENTITYIMDSV2_REQUIRED_HOP_LIMIT_1exact profile ARN · detach association ID
JOB IDENTITYPLAN + REPOSITORY + JOB TAGSone handle · one admitted job · no replay
RETIREMENTENCRYPTED_GP3_DELETE_ON_TERMINATIONDescribeInstances + DescribeVolumes
01

UNALLOCATEDlaunchBOOTSTRAP_RUNNING

launch and attestation match
02

BOOTSTRAP_RUNNINGcloseCloudBoundaryCLOUD_BOUNDARY_CLOSED

profile absent + IMDS disabled + reboot verified
03

CLOUD_BOUNDARY_CLOSEDrunJobJOB_RUNNING

exact job + zero prior jobs
04

JOB_RUNNINGagent resultJOB_FINISHED

exact instance/job + one completion
05

BOOTSTRAP_RUNNING|CLOUD_BOUNDARY_CLOSED|JOB_FINISHED|FAILED_NEEDS_TERMINATIONterminateTERMINATING

exact instance ID
06

TERMINATINGretirement proofTERMINATED

instance terminated + root volume absent
07

ANY_MUTATINGdriver/proof failureFAILED_NEEDS_TERMINATION

no later admission
08

FAILED_NEEDS_TERMINATIONcompensateTERMINATING

termination remains retryable
09

TERMINATEDterminateTERMINATED

return idempotent terminal proof
PROVIDER PORT CONTRACT4 fail-closed operations
launch

EC2 RunInstances + DescribeInstancesone private instance + exact immutable template + job-bound tags + attached encrypted disposable root

BOOTSTRAP_RUNNING
closeCloudBoundary

DescribeIamInstanceProfileAssociations + DisassociateIamInstanceProfile + ModifyInstanceMetadataOptions + RebootInstances + DescribeInstancesprofile absent and IMDS disabled after reboot

CLOUD_BOUNDARY_CLOSED
runJob

injected one-job worker agentexact admitted job + boundary closed + jobsCompleted zero

JOB_FINISHED
terminate

TerminateInstances + DescribeInstances + DescribeVolumesexact instance terminated + exact root volume absent

TERMINATED
WORKER SECURITY INVARIANTS14/14 test evidence

01launch uses an exact launch-template ID and numeric immutable versionPASS_TEST_ONLY

02ClientToken deterministically binds one admitted job attemptPASS_TEST_ONLY

03each request asks for exactly one on-demand private workerPASS_TEST_ONLY

04the worker receives no public IPv4, IPv6 or production routePASS_TEST_ONLY

05bootstrap IMDS requires v2 and a hop limit of onePASS_TEST_ONLY

06the bootstrap profile is exact and only present before admissionPASS_TEST_ONLY

07profile detachment and IMDS disablement are re-read after rebootPASS_TEST_ONLY

08untrusted work cannot start before the cloud boundary is closedPASS_TEST_ONLY

09the job identity must exactly match the launch planPASS_TEST_ONLY

10a worker completes at most one job and replay is deniedPASS_TEST_ONLY

11the root gp3 volume is encrypted and delete-on-terminationPASS_TEST_ONLY

12retirement requires both instance termination and volume absencePASS_TEST_ONLY

13failed boundary, job or retirement proofs remain non-admissiblePASS_TEST_ONLY

14public proof excludes credentials, user data and mutable capabilitiesPASS_TEST_ONLY

FAILURE → SAFE TERMINAL错误分类直接决定补偿与值班动作
RF_WORKER_CONFIG|DRIVER|SCOPE|HANDLEPRE_MUTATIONdeny without EC2 call
RF_WORKER_LAUNCH_*LAUNCHfail reservation and reconcile launch request ID
RF_WORKER_BOUNDARY_*BOUNDARYkeep offline and terminate
RF_WORKER_JOB_*EXECUTIONdeny reuse and terminate
RF_WORKER_TERMINATION_*RETIREMENTfreeze capacity and page owner
PRODUCTION READINESS GAPRF_READY_WORKER_PROVIDER · BLOCKED

01approved immutable launch template, AMI digest and numeric template versionREQUIRED

02dedicated private CI subnet, zero-ingress security group and verified no-production routesREQUIRED

03least-privilege bootstrap instance profile with detach permission owned by the controllerREQUIRED

04AWS SDK runtime driver with bounded waiters, retry budgets and request-ID journalingREQUIRED

05worker-agent authenticated channel that cannot mint cloud credentialsREQUIRED

06instance and root-volume orphan reconciliation alarms with a named on-call ownerREQUIRED

07security, runtime and cost-owner approvalREQUIRED

IMPLEMENTATION ≠ EC2 RUNTIMEAdapter、内存 EC2 driver 与 34 个案例已实现;真实 Launch Template、私有 CI 网络、Bootstrap Profile、AWS SDK waiter、Worker Agent 通道、孤儿资源告警和 owner approval 均不存在。
GITEA EXACT-ASSIGNMENT CONTROL PLANE · IMPLEMENTED / NOT CONFIGURED
Runner 在线不等于 Job 可执行;Gitea 分配事实与 root 凭证封存必须同时成立

本刀把旧的三段无状态假方法收敛为不可伪造的 Runner capability。顺序已纠正为 关闭 Profile / IMDS → 重启复读 → 再签发 Token → 注册;避免 tmpfs 凭证被重启清空,也避免 30 秒 Token 跨越 EC2 启动窗口。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
CONTROL OPERATIONS3register · assign · retire
STATE TRANSITIONS10failure stays non-admissible
ADVERSARIAL FIXTURES348 allow · 26 deny
MODELED BOUNDARY CALLS63 Gitea REST · 3 root agent
LIVE RUNNERS / ASSIGNMENTS0/0runtime driver · NOT_CONFIGURED
LIVE GITEA READS / WRITES0/0worker agent · FALSE
01 · EC2 BOOTSTRAPProfile + IMDSv2no registration secret has been issued
02 · CLOUD CLOSEDdetach + IMDS off + rebootread back before any runner credential exists
03 · EPHEMERAL REGISTER30s Buffer → root agentsame bytes · no copy · no digest · zeroize
04 · EXACT ASSIGNMENTjob.runner_id + namerepository job GET · status in_progress
05 · AUTHORITY SEALEDfile absent · exact-job leaseroot memory only · reits-job denied
06 · DUAL RETIREMENT204/404 + local destroyboth proofs required · retry is idempotent
GITEA CONTROL-PLANE FACTnecessary · not sufficient

GET /repos/reits/:repo/actions/jobs/:jobid = admitted jobrunner_id = capability runnerrunner_name = deterministic namestatus = in_progresslabels = exact allowlist

Gitea 1.25.4 OpenAPI exposes assignment identity; it does not attest local filesystem permissions.
ROOT WORKER-AGENT FACTseparate mandatory proof

SealAssignment(worker, runner, job, maxJobs=1).runner file = absentreusable credential = falsejob UID read = deniedlease = root memory / exact jobsecond assignment = denied

Only the two proofs together can advance F5; either failure deletes the Runner and terminates the Worker.
SIX BOUNDARY CALLSauthority owner and recorded truth are explicit
01worker-agentRegisterRunnerone-time mutable token bytesAUTHORITY NOT RECORDED
02gitea-restGET /orgs/reits/actions/runners/{runner_id}control credential referenceSECRETREF ONLY
03gitea-restGET /repos/{owner}/{repo}/actions/jobs/{job_id}control credential referenceSECRETREF ONLY
04worker-agentSealAssignmentroot-owned unix socketSECRETREF ONLY
05gitea-restDELETE /orgs/reits/actions/runners/{runner_id}control credential referenceSECRETREF ONLY
06worker-agentDestroyRunnerStateroot-owned unix socketSECRETREF ONLY
OPAQUE CAPABILITY OPERATIONS3 fail-closed ports
registerEphemeral

cloud-closed worker + mutable one-time token bytes + exact org/repo/job/plan/labelsworker-agent attestation + org-scoped Gitea runner GET

retire unemitted runner or report cleanup unproven
verifyAssignment

opaque runner capability + admitted job + maxJobs=1repo job GET binds runner_id/name + root agent removes reusable file and holds one exact-job memory lease

FAILED_NEEDS_DELETE
deleteRunner

opaque runner capabilityorg runner DELETE returns 204/404 + root agent destroys credential and assignment state

FAILED_NEEDS_DELETE and retryable
CONTROL-PLANE INVARIANTS16/16 test evidence

01registration occurs only after the EC2 profile is detached, IMDS is disabled and reboot readback passesPASS_TEST_ONLY

02the 30-second registration-token handle is issued after cloud-boundary closure, never across launch or rebootPASS_TEST_ONLY

03registration secret is passed as the same mutable Buffer and is never copied, serialized, hashed or retainedPASS_TEST_ONLY

04organization, repository, job, plan, worker, labels and maxJobs are exact rather than caller-selectedPASS_TEST_ONLY

05runner registration must be ephemeral and independently re-read through the organization-scoped Gitea APIPASS_TEST_ONLY

06public runner capability excludes control credentials, registration bytes and reusable runner credentialsPASS_TEST_ONLY

07assignment requires Gitea job status in_progress with exact runner_id, runner_name and labelsPASS_TEST_ONLY

08Gitea assignment proof and root-owned worker-agent credential proof are distinct and both mandatoryPASS_TEST_ONLY

09the reusable .runner file is absent before untrusted code while one exact-job lease remains in root daemon memoryPASS_TEST_ONLY

10reits-job cannot read the runner credential file, agent socket or assignment leasePASS_TEST_ONLY

11a second assignment or wrong job is permanently deniedPASS_TEST_ONLY

12runner deletion accepts only Gitea 204 or already-absent 404 as control-plane terminalPASS_TEST_ONLY

13retirement additionally destroys credential files, the in-memory lease and worker-local runner statePASS_TEST_ONLY

14registration failures after runner creation attempt cleanup before any capability can escapePASS_TEST_ONLY

15failed assignment or deletion stays non-admissible and requires retry or worker terminationPASS_TEST_ONLY

16no test-driver call counts as a Gitea read, write, live runner or runtime assignmentPASS_TEST_ONLY

FAILURE → COMPENSATIONunemitted Runner also has an internal cleanup path
RF_GITEA_CONFIG|DRIVER|SCOPE|LABELS|WORKER|HANDLEPRE_MUTATIONdeny without registration
RF_GITEA_REGISTRATION_*REGISTRATIONdelete any identifiable unemitted runner, destroy local state and terminate worker
RF_GITEA_ASSIGNMENT_*ASSIGNMENTdeny job, delete runner and terminate worker
RF_GITEA_CREDENTIAL_SEAL_*CREDENTIAL_BOUNDARYdeny untrusted code, delete runner and terminate worker
RF_GITEA_DELETE_*|RF_GITEA_LOCAL_RETIREMENT_PROOFRETIREMENTretry 204/404 reconciliation; freeze capacity if terminal proof remains missing
PRODUCTION READINESS GAPRF_READY_GITEA_CONTROL · BLOCKED

01least-privilege Gitea credential reference restricted to reits organization runner read/delete and admitted repository job readREQUIRED

02root-owned worker-agent binary and unix socket with an authenticated controller channelREQUIRED

03runner version and labels pinned in the immutable AMI, with --ephemeral enforcedREQUIRED

04tmpfs credential path and filesystem/UID denial test proving reits-job cannot read root authorityREQUIRED

05bounded API retries, delete reconciliation journal and orphan-runner alarmREQUIRED

06registration/assignment/retirement runtime receipts joined to plan, worker, runner and job identitiesREQUIRED

07security owner, Gitea owner and runtime owner approvalREQUIRED

IMPLEMENTATION ≠ GITEA RUNTIMEAdapter、内存 driver、34 个案例与 Saga 顺序修正已经实现;真实 Gitea control credential、root Worker Agent、runtime receipts、孤儿告警与三方审批仍为 0。
GLOBAL EPHEMERAL-WORKER CAPACITY · IMPLEMENTED / NOT CONFIGURED
容量必须在启动 EC2 之前占用;终止证明不完整时,宁可冻结整个池也不重新放号

旧 Saga 只在任务结束后调用 replacement,无法阻止并发 webhook 超过目标两台。现在每个计划先原子占用一个 generation-fenced 槽位;只有 Worker capability 与 KMS 验证的终止收据同时通过,槽位才以 N → N+1 恢复可用。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
PUBLIC OPERATIONS4acquire · replace · freeze · inspect
POOL / SLOTS1 / 2one global Linux lane · one slot per plan
STATE TRANSITIONS9no adapter-side unfreeze path
ADVERSARIAL FIXTURES308 allow · 22 deny
LIVE POOLS / SLOTS0/0durable ledger · FALSE
RUNTIME REPLACE / FREEZE0/0driver · NOT_CONFIGURED
01 · VERIFIED QUEUEexact plan + job attemptdurable reservation succeeds first
02 · CAPACITY CLAIMrfslot_01 / generation Natomic one-of-two claim before launch
03 · ONE-JOB WORKERlaunch → seal → executeslot stays occupied for the whole lifecycle
04 · DUAL RETIREMENT PROOFWorker terminal + signed receiptinstance and root volume both absent
05 · GENERATION REPLACEAVAILABLE / N+1consistent readback before next admission
REVIEWED CONCURRENCY BUDGETrfpool_linux-amd64
SLOT 01 · ACQUIREDplan Ageneration 7opaque lease
SLOT 02 · AVAILABLEnext plangeneration 12one job max
Capacity means two concurrent ephemeral-worker budgets—not two warm or already-paid instances.
AMBIGUITY CONTAINMENTWHOLE_POOL_FREEZE
LAUNCH UNKNOWNdo not releaseClientToken reconcile
REPLACEMENT DRIFTdo not admitgeneration mismatch
FREEZE READBACKmust be durableoperator page
No runtime adapter method can unfreeze the pool; recovery requires a separate reviewed operator path.
WORKER CAPABILITYTERMINATED

exact plan + job + instance
Profile absent · IMDS disabled
root volume deleted · jobs 0/1

necessary
+
PINNED RECEIPT VERIFIERECDSA P-256

normal or compensation retirement
exact worker + plan + job facts
canonical digest + KMS public key

necessary
=
CAPACITY REPLACEMENTGENERATION N+1

lease cleared · plan cleared
same slot consistently readable
next admission can proceed

only valid result
FIVE DRIVER BOUNDARIESmutation and independent readback remain separate
01AcquireSlotMUTATIONpool active + available slot + unique plan/job attempt
02ReadSlotCONSISTENT READconsistent exact-slot readback
03ReplaceSlotMUTATIONlease + generation + plan/job + signed retirement digest
04FreezePoolMUTATIONuncertain slot causes global scheduling denial
05ReadPoolCONSISTENT READconsistent freeze readback
CAPACITY STATE MACHINE9 transitions · terminal retries do not mutate
01AVAILABLEacquireACQUIREDone exact slot claimed atomically
02ACQUIREDconfirmReplacementREPLACINGworker terminal + signed retirement receipt verified
03REPLACINGCAS + readbackREPLACEDsame slot available at generation N+1
04REPLACINGdriver/proof failureFAILED_NEEDS_FREEZEcapacity cannot be admitted
05ACQUIREDunsafe lifecycle failureFAILED_NEEDS_FREEZEno silent slot release
06ACQUIRED|REPLACING|FAILED_NEEDS_FREEZEfreezeFROZENwhole-pool freeze read back
07REPLACEDconfirmReplacementREPLACEDside-effect-free terminal retry
08FROZENfreezeFROZENside-effect-free terminal retry
09REPLACED|FROZENlate conflicting mutationDENIEDterminal capability cannot cross state
OPAQUE CAPABILITY OPERATIONS4 public methods
acquire

exact plan + one slot + one job + atomic available-slot claimopaque ACQUIRED capacity capability

confirmReplacement

terminal Worker proof + verified normal/compensation retirement receipt + generation CAS + consistent readbacksame slot AVAILABLE at generation N+1

freeze

occupied or uncertain slot + bounded reason + durable whole-pool readbackFROZEN scheduling pool

inspect

unforgeable in-process capabilitysecret-free slot proof

CAPACITY INVARIANTS16/16 TEST_ONLY

01global pool size is enforced before EC2 launch, not inferred after launchPASS

02capacity means concurrent ephemeral-worker budget and never claims warm instancesPASS

03each admitted plan consumes exactly one slot for one job attemptPASS

04plan and job-attempt replay cannot acquire another slotPASS

05slot authority is an opaque capability and its lease token is never serializedPASS

06replacement requires the Worker capability to prove terminal instance and deleted root volumePASS

07replacement also requires a cryptographically verified normal or compensation retirement receiptPASS

08receipt facts bind the exact plan, job, worker ID and storage terminal statePASS

09replacement uses the current lease and generation as a fencing conditionPASS

10replacement is accepted only after a consistent read shows generation N+1 availablePASS

11an ambiguous replacement never reopens capacity and must freezePASS

12an unsafe lifecycle failure freezes the whole scheduling poolPASS

13freeze is accepted only after an independent pool readbackPASS

14terminal replacement and freeze retries are side-effect freePASS

15there is no adapter path that unfreezes production capacityPASS

16TEST_ONLY driver operations never count as runtime capacity evidencePASS

FAILURE → CONTAINMENTavailability never outranks orphan/over-capacity safety
RF_CAPACITY_CONFIG|DRIVER|VERIFIER|SCOPEPRE_MUTATIONdeny before capacity claim
RF_CAPACITY_ACQUIRE_*|REPLAYADMISSIONdeny launch; reconcile any ambiguous claim
RF_CAPACITY_RECEIPT_*|WORKER_PROOFRETIREMENTkeep slot non-admissible and freeze
RF_CAPACITY_REPLACE_*REPLACEMENTfreeze whole pool; page owner
RF_CAPACITY_FREEZE_*CONTAINMENTdeny all scheduling externally; require operator reconciliation
PRODUCTION READINESS GAPRF_READY_CAPACITY_CONTROLLER · BLOCKED

01durable strongly consistent capacity ledger with atomic slot claim and generation CASREQUIRED

02runtime driver identity restricted to one reviewed pool and no unfreeze permissionREQUIRED

03pinned KMS public verifier for normal and compensation retirement receiptsREQUIRED

04Controller Saga integration that acquires capacity before EC2 launchREQUIRED

05alarm and named on-call owner for acquire ambiguity, replacement drift and freeze failureREQUIRED

06operator runbook requiring orphan reconciliation before a separate approved unfreeze pathREQUIRED

07security, runtime, reliability and cost-owner approvalREQUIRED

IMPLEMENTATION ≠ DURABLE CAPACITYAdapter、两槽内存 driver、30 个案例与 Saga 前置占位已经实现;真实强一致账本、runtime identity、KMS verifier、告警、值班人与独立解冻流程仍为 0。
APPEND-ONLY LIFECYCLE JOURNAL · IMPLEMENTED / NOT CONFIGURED
一条 KMS 回执链还不够;必须再证明每次写入没有漏、没有重排、没有覆盖、没有跨 Job 串链

旧实现只把 stage、digest 和 trust 推进内存数组,无法独立复核。现在每个 plan / job attempt 拥有独立 journal;签名回执形成内层链,CAS entry digest 形成外层链,成功只接受 F9 replacement,失败先补齐已签回执再写入枚举化终态。

ADAPTER_IMPLEMENTED_NOT_CONFIGURED
PUBLIC OPERATIONS5open · append · seal · inspect · verify
STATE TRANSITIONS10no update · delete · unseal
DUAL HASH CHAINS2signed receipt + journal entry
ADVERSARIAL FIXTURES3610 allow · 26 deny
LIVE JOURNALS / ENTRIES0/0durable store · FALSE
RUNTIME SEALS0/0writer IAM · FALSE
01 · EXACT SCOPEplan + job attemptrepository and job ID are immutable
02 · OPEN JOURNALconditional head createsame scope replay only
03 · CAS APPENDexpected sequence + digestentry absent and head OPEN
04 · FULL READBACKsignature + two chainsconsistent head and ordered range
05 · TERMINAL SEALF9 success / coded failureonly byte-equivalent replay remains
ENTRY 08 / RECEIPT F8 · STRUCTURE SAMPLE
instance-termination

展示的是确定性 TEST_ONLY 结构,不是生产 Runner 日志。

DUAL CHAIN VERIFIED
journal rfjrn1:…scope hashplan rfp_…job attempt rfj1:…repository reits/reits-authjob 905
OUTER ENTRY CHAIN

sequence08

previousEntryDigestsha256:…e07

entryDigestsha256:…e08

CAS HEAD MATCH
+
INNER SIGNED RECEIPT

receipt.sequence8 / F8

previousDigestsha256:…f07

signatureECDSA_SHA_256 / pinned SPKI

LOCAL VERIFY PASS
INDEPENDENT VERIFICATIONall checks are mandatory

journal scope equals signed plan/job factsPASS_TEST_ONLYV-01

entry indexes are contiguous from zeroPASS_TEST_ONLYV-02

every outer predecessor digest recomputesPASS_TEST_ONLYV-03

every receipt signature uses the pinned public keyPASS_TEST_ONLYV-04

receipt sequence and predecessor remain contiguousPASS_TEST_ONLYV-05

head digest/count/status equal the verified rangePASS_TEST_ONLYV-06

FIVE DURABLE DRIVER BOUNDARIESmutation, recovery and independent verification are separate
01CreateJournalCONDITIONAL_CREATEhead absent or exact same scope
02ReadHeadCONSISTENT_READscope, writer, sequence, digest and terminal state agree
03AppendEntryATOMIC_CASexpected head sequence + digest + OPEN and new entry absent
04ReadEntryCONSISTENT_READambiguous-write recovery and exact replay only
05ReadRangeCONSISTENT_READcomplete ordered range for independent verification
JOURNAL STATE MACHINE10 transitions · terminal state cannot reopen
01ABSENTopenOPEN_EMPTYconditional journal creation
02OPEN_EMPTYopen replayOPEN_EMPTYsame exact scope
03OPEN_EMPTYappend F0OPEN_ACTIVEsigned genesis receipt
04OPEN_ACTIVEappend F1-F8OPEN_ACTIVEboth chains remain contiguous
05OPEN_ACTIVEappend exact F9SEALED_SUCCESSreplacement-capacity receipt
06OPEN_EMPTYsealFailureSEALED_FAILUREno signed receipt exists
07OPEN_ACTIVEreconcile + sealFailureSEALED_FAILUREall signed receipts are present first
08SEALED_FAILUREexact seal replaySEALED_FAILUREterminal payload is byte-equivalent
09OPEN_OR_TERMINALinspectSAMEconsistent head proof
10OPEN_OR_TERMINALverifyVERIFIED_SAMEfull dual-chain verification
OPAQUE JOURNAL OPERATIONS5 fail-closed methods
open

exact plan, job attempt, repository and job scopeopaque journal capability

appendReceipt

pinned signature + exact scope + contiguous receipt and entry predecessorsCAS-appended dual-chain entry

sealFailure

reconcile signed receipts + bounded phase, code and compensation factsterminal failure entry

inspect

opaque capability + consistent head readsecret-free head proof

verify

consistent full range + entry hashes + signatures + both predecessor chainsindependent chain verdict

AUDIT INVARIANTS18/18 TEST_ONLY

01one journal is deterministically partitioned by exact plan and job-attempt scopePASS

02journal capabilities are opaque object identities and never serialize write authorityPASS

03the runtime writer must be one exact controller IAM role rather than a mutable aliasPASS

04entries are created only through expected-sequence, expected-digest and OPEN-state CASPASS

05the driver surface exposes no entry update, journal delete or adapter-side unseal operationPASS

06every receipt is verified by the pinned asymmetric public key before persistencePASS

07every signed receipt binds plan, job attempt, repository and job identityPASS

08receipt sequence and receipt predecessor digest must be contiguousPASS

09entry sequence and entry predecessor digest form an independent outer chainPASS

10ambiguous append is accepted only after exact entry and consistent-head readbackPASS

11same sequence with different content is a terminal conflict rather than an overwritePASS

12only signed sequence F9 kind replacement-capacity may seal successful completionPASS

13failure sealing first reconciles every signed receipt supplied by the SagaPASS

14terminal failure facts accept only bounded codes and enumerated compensation identifiersPASS

15a terminal journal accepts only byte-equivalent replay and never new entriesPASS

16full verification rereads the complete range and recomputes every digestPASS

17secret-like arbitrary strings, credentials and token material never enter the journal contractPASS

18TEST_ONLY driver evidence never increments runtime journal, read, write or readiness truthPASS

FAILURE → JOURNAL VERDICTfirst durable fact wins; ambiguity never authorizes overwrite
SCOPE_OR_HANDLEdeny before journal authority is used
SIGNATURE_OR_RECEIPT_CHAINdeny untrusted, cross-job or reordered receipt
APPEND_AMBIGUITYrecover only exact committed entry, otherwise fail closed
HEAD_OR_RANGE_DRIFTdeny independent verification and page operator
TERMINAL_CONFLICTpreserve first terminal fact and deny mutation
DRIVER_UNAVAILABLEblock admission or compensate the Saga without claiming audit durability
PRODUCTION READINESS GAPRF_READY_AUDIT_SINK · BLOCKED

01reviewed durable journal table with point-in-time recovery and encryptionREQUIRED

02transactional head CAS plus immutable entry rows with no update or delete APIREQUIRED

03least-privilege controller writer role pinned by exact IAM ARNREQUIRED

04separate read-only verifier role and scheduled full-chain verificationREQUIRED

05retention, export, legal-hold and disaster-recovery policyREQUIRED

06append conflict, verification drift, stale-open-journal and seal-failure pagingREQUIRED

07security, runtime, retention and cost owner approvalREQUIRED

IMPLEMENTATION ≠ DURABLE JOURNALAdapter、内存 driver、36 个案例、13 条 Saga 与双链复核已经实现;真实表、不可变 IAM、PITR、只读 verifier、保留/导出策略、告警和值班审批仍为 0。
CROSS-PORT RUNTIME RECONCILIATION · IMPLEMENTED / NOT CONFIGURED
Controller 重启后不能靠单表猜测清理;五个权威源必须在同一个 Job 边界里重新对齐

Reservation、Capacity、Worker、Runner 与 Journal 各自只能证明一部分事实。本工作台把五份只读快照收敛为 SAFE 或 CONTAIN,并生成整池冻结与值班通知计划;它没有终止实例、删除 Runner、封存 Journal 或发送告警的权限。

PLANNER_IMPLEMENTED_NOT_CONFIGURED
AUTHORITATIVE SOURCES5separate consistent reads
PLANNER OPERATIONS4assess · summarize · metrics · page
FIXTURE VERDICTS327 safe · 24 contain · 1 deny
FREEZE PLANS23planned · never executed
LOW-CARD METRICS8one fixed controller label
LIVE REPORTS / PAGES0/0runtime sources · 0
01Reservationconsistent dual-row reservation state, lease and terminal reasonREAD-ONLY · NOT CONFIGURED
02Capacityconsistent pool/slot state, exact scope and fenced generationREAD-ONLY · NOT CONFIGURED
03Workerinstance lifecycle, root-volume retirement and exact job bindingREAD-ONLY · NOT CONFIGURED
04RunnerGitea state plus root-agent credential and local-state proofREAD-ONLY · NOT CONFIGURED
05Journalconsistent head, exact scope, receipt count and immutable terminal stateREAD-ONLY · NOT CONFIGURED
FIVE-SOURCE SNAPSHOT COORDINATOR · EXECUTABLE / NOT CONFIGURED
先证明五次读取属于同一次捕获,再允许 Planner 判断 SAFE 或 CONTAIN

每路请求共享 capture、plan、job attempt、pool、slot、scope digest 和 2 秒 deadline。Reader 必须回显固定 authority、STRONGLY_CONSISTENT 与 request digest;超时不会被静默丢弃,而是正规化为 UNKNOWN 后交给 Planner 隔离。

COORDINATOR_IMPLEMENTED_NOT_CONFIGURED
READ-ONLY OPERATIONS3plan · capture · verify
PINNED READERS5no wildcard · runtime 0/5
DEADLINE / MAX SKEW2s2s coherent window
FIXTURE CAPTURES303 complete · 7 partial · 1 unavailable
INTEGRITY DENIALS19identity · time · shape · digest
RUNTIME CAPTURES / READS0/0external writes · 0
CAPTURE REQUEST · RFS-08 / TEST_ONLYONE DEADLINE · ONE SCOPE DIGEST

capturerfcap1:…d64

planrfp_0123…4567

job attemptrfj1:…a64

repositoryreits/reits-auth

pool / slotlinux-amd64 / 01

deadlineT+2000ms

01ReservationTIMEOUT
reservation-ledger

exact dual-key reservation, lease and terminal state

consistency
STRONG
request digest
MATCH
outcome
UNKNOWN
02CapacityT+2ms
capacity-ledger

exact pool slot, generation, occupancy and freeze state

consistency
STRONG
request digest
MATCH
outcome
OBSERVED
03WorkerT+3ms
ec2-worker-read-model

exact instance lifecycle and root-volume retirement state

consistency
STRONG
request digest
MATCH
outcome
OBSERVED
04RunnerERROR
gitea-runner-read-model

exact Gitea plus root-agent credential and local-state facts

consistency
STRONG
request digest
MATCH
outcome
UNKNOWN
05JournalT+5ms
append-only-journal

exact consistent head, terminal state and receipt count

consistency
STRONG
request digest
MATCH
outcome
OBSERVED
CAPTURE BARRIER3 / 5 OBSERVEDtwo failures remain explicit evidence
PACKET STATUSPARTIAL_UNAVAILABLEsource receipts remain ordered 01–05
PLANNER VERDICTSOURCE_UNAVAILABLECONTAIN · freeze plan · page plan
NORMALIZED SNAPSHOTabsence is data, never omission

reservationUNAVAILABLE / UNKNOWNRF_SOURCE_TIMEOUT

capacityOBSERVED / OCCUPIEDgeneration 4

workerOBSERVED / RUNNINGinstance + root volume

runnerUNAVAILABLE / UNKNOWNRF_SOURCE_UNAVAILABLE

journalOBSERVED / OPEN7 receipts · head digest

snapshotIdrfsnp1:…deterministic digestSECRET VALUES · 0
THREE-LAYER DIGEST PACKETlocal verify before Planner
01

readPlanDigestscope + five requests + deadline

RECOMPUTE
02

snapshotDigestnormalized facts + ordered receipts

RECOMPUTE
03

packetDigestplan + snapshot + capture outcome

RECOMPUTE
CAPTURE STATE MODEL6 terminally classified states

01PLANNEDfive read requests share one scope digest and deadline

02READINGall five read-only ports execute concurrently

03COMPLETEfive observed authority-pinned results fit the skew window

04PARTIAL_UNAVAILABLEone to four sources normalized to UNKNOWN for containment

05ALL_UNAVAILABLEzero sources observed and scheduling must contain

06DENIED_INTEGRITYidentity, consistency, shape, time, secret or digest guard failed

COORDINATOR OPERATIONSinjected readers · no network fallback
plan

exact capture, plan, job-attempt, repository, pool and slot scopefive immutable strongly-consistent read requests with one deadline

capture

five authority-pinned reader functions and bounded response identitiescomplete or explicitly unavailable normalized snapshot packet

verify

exact packet shape, source order and recomputed read/snapshot/packet digestslocal boolean verification without external reads or writes

18 CAPTURE INVARIANTSTEST_ONLY · all pass

01one capture binds an exact plan, job attempt, repository, pool and slot scopePASS

02exactly five named reader ports are required and no wildcard reader is acceptedPASS

03all source queries request strongly consistent reads under one bounded deadlinePASS

04source name and authority are pinned independently of driver-returned payload dataPASS

05every response must echo the exact immutable request digestPASS

06every observed read timestamp must fall inside the capture deadlinePASS

07the maximum skew between observed source reads cannot exceed two secondsPASS

08reader rejection or timeout becomes explicit UNAVAILABLE and UNKNOWN evidencePASS

09partial reads are never omitted, substituted with cache data or treated as safePASS

10cross-source scope drift is preserved for the reconciliation planner to containPASS

11secret-like keys are rejected before snapshot or receipt materializationPASS

12source records use exact bounded fields and enum states without extension bagsPASS

13source receipts are ordered Reservation, Capacity, Worker, Runner and JournalPASS

14snapshot identity commits to scope, normalized facts and all source receiptsPASS

15read-plan, snapshot and packet digests are independently recomputed on verifyPASS

16deterministic replay of the same capture and source facts yields the same digestsPASS

17the coordinator owns no terminate, delete, seal, release, freeze or page operationPASS

18runtime source reads, writes, mutations, snapshots and secret values remain zeroPASS

FAILURE → EVIDENCE POLICYtimeout contains; integrity denies
RF_SOURCE_TIMEOUT|RF_SOURCE_UNAVAILABLEnormalize that source to UNKNOWN and force planner containment
RF_RECON_SOURCE_IDENTITYdeny response with wrong source, authority, consistency, digest or timestamp identity
RF_RECON_SOURCE_SHAPEdeny malformed or extension-bearing source facts
RF_RECON_CAPTURE_SKEW|RF_RECON_SOURCE_TIMEdeny incoherent capture timing instead of joining unrelated reads
RF_RECON_CAPTURE_SECRETdeny secret-like input before it can enter receipts or snapshot evidence
RF_RECON_CAPTURE_DIGESTdeny any read-plan, snapshot or packet evidence tamper
RUNTIME ASSEMBLY GAPREADERS 0/5 · CAPTURES 0 · READY FALSE

01dedicated loopback Controller runtime identity and root-owned configurationREQUIRED

02strongly consistent Reservation reader with exact dual-key scopeREQUIRED

03strongly consistent Capacity reader with pool generation fencingREQUIRED

04credential-free EC2 Worker read model with volume retirement proofREQUIRED

05read-only Gitea and root-agent Runner evidence aggregationREQUIRED

06consistent append-only Journal head and range verifierREQUIRED

07deadline, retry-budget and partial-read telemetry with fixed labelsREQUIRED

08security, platform, reliability and cost-owner approvalREQUIRED

COORDINATOR ≠ LIVE SOURCE ACCESS并发读取、authority 钉扎、超时正规化、三层摘要和 30 个案例已经实现;真实 DynamoDB、EC2、Gitea、Journal reader、Controller runtime identity 与遥测仍均为 0。
SELECTED REPORT · RFR-14
ORPHAN_WORKER

Reservation 已终止,但 Worker 仍存活。任何自动终止都可能删错资源,因此先冻结调度、保留证据,再把执行动作交给独立审批器。

P0 · CONTAIN
scope match EXACTsnapshot skew ≤ 300sreport digest sha256:…fixtureexternal reads 0
CROSS-SOURCE TRUTH MATRIXno source can overrule another

ReservationFAILEDlease closedCONFLICT

CapacityOCCUPIEDgeneration NBLOCK

WorkerRUNNINGroot volume attachedORPHAN

RunnerABSENTlocal state absentCLEAR

JournalSEALED_FAILUREconsistent headEVIDENCE

DETERMINISTIC VERDICTORPHAN_AUTHORITY

known unsafe combination · automatic cleanup denied

CONTAINMENT PLANFREEZE WHOLE POOL

scheduler integration · NOT CONFIGURED

RECOVERY HANDOFFPLANNED_NOT_SENT

identifier-free P0 page · manual proof required

RECONCILIATION STATE MACHINE12 complete classifications · unknown means contain
01SNAPSHOTall sources exact and prelaunchHEALTHY_PRELAUNCH
02SNAPSHOTworker bootstrap and no runnerHEALTHY_BOOTSTRAP
03SNAPSHOTactive reservation, occupied slot, live worker, sealed runner authorityHEALTHY_IN_FLIGHT
04SNAPSHOTcomplete reservation, replacement, double retirement and success journalHEALTHY_COMPLETE
05SNAPSHOTfailed reservation, no live resources and failure journalHEALTHY_FAILED
06SNAPSHOTpool already frozenCONTAINED_FROZEN
07SNAPSHOTsource unavailable or unknownSOURCE_UNAVAILABLE
08SNAPSHOTany cross-source plan/job mismatchSCOPE_MISMATCH
09SNAPSHOTexpired lease or stale open journalSTALE_CONTROL_STATE
10SNAPSHOTorphan worker/runner or credential authority remains liveORPHAN_AUTHORITY
11SNAPSHOTcapacity, retirement or journal terminal contradictionTERMINAL_CONFLICT
12SNAPSHOTno exact safe state matchesUNCLASSIFIED_DRIFT
FOUR READ-ONLY OPERATIONSno hidden apply flag
assess

exact bounded five-source snapshot and no secret-like keysdeterministic SAFE or CONTAIN report

summarize

one to 1000 verified reportsbounded severity and containment totals

buildMetrics

fixed metric names and controller-only labeleight low-cardinality gauge samples

buildPage

CONTAIN report only; stable category dedupeidentifier-free PLANNED_NOT_SENT page

FIXED METRIC SURFACE8 series · high-cardinality labels 0

reits_rf_reconciliation_reports{controller="runner-factory"}FIXED

reits_rf_reconciliation_safe{controller="runner-factory"}FIXED

reits_rf_reconciliation_contained{controller="runner-factory"}FIXED

reits_rf_reconciliation_freeze_required{controller="runner-factory"}FIXED

reits_rf_reconciliation_page_p0{controller="runner-factory"}FIXED

reits_rf_reconciliation_page_p1{controller="runner-factory"}FIXED

reits_rf_reconciliation_page_p2{controller="runner-factory"}FIXED

reits_rf_reconciliation_unclassified{controller="runner-factory"}FIXED

18 FAIL-CLOSED INVARIANTSTEST_ONLY · all pass

01reconciliation reads reservation, capacity, worker, runner and journal as separate authoritiesPASS

02every observed non-absent authority binds the exact plan and job scopePASS

03unavailable or unknown source data can never produce a safe verdictPASS

04an expired active lease cannot remain schedulablePASS

05a live worker without an active reservation is an orphanPASS

06a live runner without a live exact worker is an orphanPASS

07registered or online runner authority must already be sealed from untrusted codePASS

08available capacity with a live worker is an overcommit riskPASS

09occupied capacity after worker termination is stranded until replacement proofPASS

10worker termination is incomplete until root-volume deletion is provedPASS

11runner retirement is incomplete until both Gitea and local state are absentPASS

12success journal state requires a completed reservationPASS

13failure journal state requires a failed reservationPASS

14an open journal older than five minutes is stalePASS

15any unclassified cross-source combination fails closedPASS

16metrics use fixed names and no repository, job, runner, instance or plan labelsPASS

17page plans contain only verdict, severity, digest and category dedupe identityPASS

18the planner performs zero mutations, external reads, writes or page deliveriesPASS

FAILURE OWNERSHIPcontainment is not recovery
SOURCE_UNAVAILABLE

platform-oncallfreeze scheduling and retry consistent reads

SCOPE_MISMATCH

security-oncallfreeze, preserve evidence and deny all automatic cleanup

ORPHAN_WORKER|CAPACITY_*

platform-oncallfreeze and require terminal Worker plus root-volume proof

ORPHAN_RUNNER|CREDENTIAL_*

security-oncallfreeze and require Gitea plus root-agent deletion proof

SUCCESS_CONFLICT|FAILURE_CONFLICT|JOURNAL_STALE

platform-and-securitypreserve both chains and require manual reconciliation

UNCLASSIFIED_DRIFT

platform-oncallfreeze because absence of a known-safe state is unsafe

PRODUCTION READINESS GAPRUNTIME SOURCES 0/5 · READY FALSE

01strongly consistent read-only identities for all five authoritative sourcesREQUIRED

02bounded snapshot coordinator with skew, timeout and partial-read controlsREQUIRED

03scheduler freeze integration that cannot be bypassed by webhook admissionREQUIRED

04separate approved executors for termination, deletion, sealing and lease recoveryREQUIRED

05Prometheus-compatible exporter with the fixed eight-series label policyREQUIRED

06paging provider, dedupe window, escalation policy, owner and recovery runbookREQUIRED

07security, platform, reliability and cost-owner approvalREQUIRED

IMPLEMENTATION ≠ RECOVERY RUNTIMEPlanner、32 个对抗案例、8 条低基数指标和 P0/P1/P2 通知计划已经实现;强一致源读取、调度冻结、独立恢复器、Prometheus exporter、paging provider、runbook 与值班审批仍全部为 0。
FAILURE COMPENSATION MATRIX8 terminal-safe branches · runtime 0/8
RC-01INGRESS

signature-or-payload-deniedreturn-denial-without-reservation

NO_RESOURCENOT_OBSERVED
RC-02RESERVATION

duplicate-or-conditional-write-conflictreturn-existing-plan-reference

NO_SECOND_WORKERNOT_OBSERVED
RC-03LAUNCH

instance-launch-failed-or-ambiguousfreeze-whole-pool-and-reconcile-idempotent-launch

NO_NEW_SCHEDULING_ON_AMBIGUITYNOT_OBSERVED
RC-04REGISTRATION

ephemeral-registration-failedrevoke-secret-and-terminate-worker

NO_LIVE_REGISTRATION_SECRETNOT_OBSERVED
RC-05BOUNDARY

profile-detach-imds-disable-or-reboot-failedkeep-runner-offline-and-terminate-worker

NO_JOB_WITH_CLOUD_CREDENTIALNOT_OBSERVED
RC-06ASSIGNMENT

wrong-job-or-second-assignmentrevoke-runner-and-terminate-worker

ONE_JOB_MAXIMUMNOT_OBSERVED
RC-07EXECUTION

job-timeout-or-runner-lossterminate-worker-and-record-terminal-failure

NO_REUSED_WORKERNOT_OBSERVED
RC-08RETIREMENT

termination-or-replacement-receipt-missingfreeze-whole-pool-and-page-operator

POOL_FAILS_CLOSEDNOT_OBSERVED
为什么仍不能上线生产端口的身份、资源、密钥、网络、日志和告警尚未配置;当前收据均为 TEST_ONLY,不能作为真实运行证据。runtime receipts · 0
01 · QUEUE CONTROLworkflow_job

deliveryId + runId + jobId + attempt

replay accepted · FALSE
02 · TEMPORARY WORKER2 desired slots

ephemeral registration · no persistent data

controller · IMPLEMENTED_DRY_RUN
03 · JOB BOUNDARYrootless-dind-container

no host socket · no cloud credential · no production route

runner 2.0.0
04 · RETIREMENTfactory-control-plane

power off worker · confirm replacement capacity

whole-worker replacement required
F0CONTROL
Queue + capacity admitted

QUEUE_CAPACITY_ACQUIRED

factory-control-plane
queue-capacity-admission
F1BOOTSTRAP
Worker bootstrap

WORKER_BOOTSTRAP

root-bootstrap
instance-attestation
F2CONTROL
Cloud boundary closed

CLOUD_BOUNDARY_CLOSED

factory-control-plane
profile-detached-imds-disabled-rebooted
F3CONTROL
Ephemeral registered

EPHEMERAL_REGISTERED

gitea-runner
ephemeral-registration
F4CONTROL
One-job ready

READY_FOR_ONE_JOB

admission-controller
worker-admission
F5CONTROL
Reusable credential sealed

ASSIGNED_REUSABLE_CREDENTIAL_SEALED

gitea-control-plane
assignment-credential-seal
F6UNTRUSTED
Untrusted job

JOB_CONTAINER_RUNNING

rootless-dind
job-start
F7UNTRUSTED
Job finished

JOB_FINISHED

gitea-runner
job-result-untrusted-cleanup
F8CONTROL
Worker retired

WORKER_RETIRED

factory-control-plane
instance-termination
F9CONTROL
Pool replaced

REPLACEMENT_CONFIRMED

factory-control-plane
replacement-capacity
SECURITY INVARIANTS10 contract pass · 0 runtime observed

RF_ONE_JOBWorker handles at most one jobPASSNOT_OBSERVED

RF_SEAL_BEFORE_CODEReusable runner credential is removed before untrusted code; exact-job lease remains root-onlyPASSNOT_OBSERVED

RF_NO_JOB_CLOUDJob runs without instance profile or IMDSPASSNOT_OBSERVED

RF_NO_REGISTRATION_SECRETRegistration secret is destroyed before admissionPASSNOT_OBSERVED

RF_ROOTLESS_DINDJob runs in rootless DinD, never host modePASSNOT_OBSERVED

RF_NO_HOST_SOCKETHost Docker socket is never mountedPASSNOT_OBSERVED

RF_NO_PERSISTENT_DATARunner credential volume is not persistedPASSNOT_OBSERVED

RF_NO_PRODUCTION_ROUTEWorker has no production network routePASSNOT_OBSERVED

RF_REPLACE_AFTER_JOBWhole worker is retired and replacedPASSNOT_OBSERVED

RF_CONTROL_PLANE_RECEIPTRetirement receipt is issued outside the job boundaryPASSNOT_OBSERVED

ADVERSARIAL FIXTURESall must deny

RF-A01F6 · reusableRunnerCredentialLive=trueDENYRF_SEAL_BEFORE_CODE

RF-A02F6 · cloudCredentials=trueDENYRF_NO_JOB_CLOUD

RF-A03F6 · registrationSecret=trueDENYRF_NO_REGISTRATION_SECRET

RF-A04F6 · executionMode=hostDENYRF_ROOTLESS_DIND

RF-A05F6 · hostDockerSocketMounted=trueDENYRF_NO_HOST_SOCKET

RF-A06F6 · persistentRunnerDataVolume=trueDENYRF_NO_PERSISTENT_DATA

RF-A07F6 · productionRoute=trueDENYRF_NO_PRODUCTION_ROUTE

RF-A08F7 · jobsCompleted=2DENYRF_ONE_JOB

RF-A09F9 · replacementReceipt=falseDENYRF_REPLACE_AFTER_JOB

RF-A10F0 · replayAccepted=trueDENYRF_WEBHOOK_REPLAY

RF-A11F4 · untrustedCode=trueDENYRF_SEAL_BEFORE_CODE

RF-A12F7 · cleanupWithoutRetirementAccepted=trueDENYRF_CONTROL_PLANE_RECEIPT

BLOCKED_RUNTIMEAn authorized test-only envelope can now enter a separate no-shell fixture executor with five closed executor ports, three independently owned retirement ports, deterministic one-claim idempotency, a 900-second deadline and mandatory host-plus-root-volume retirement. The evaluator accepts no paid-host authority, spawns no process, contacts no host, loads no package and is absent from the production composition root. Production host runs, claims, packages, drivers, units, services and listeners remain zero; port 8110, public routes, pricing reads, external calls, writes, runners, workers, paid resources and trusted runtime receipts remain absent.
EXECUTION EGRESS · REVIEWED TEMPLATE

Job 进程只准连接 127.0.0.1:3128,整个 loopback 不再默认可信

安全组仍保留 bootstrap/broker 的 HTTPS;`reits-runner` UID 只有一个 TCP socket 可达,DNS stub、本地服务、IPv6 与所有直连均由 nftables 拒绝,再由 CONNECT 代理审查目标。

TEMPLATE_READY
JOB SOCKET SURFACE1tcp://127.0.0.1:3128
DIRECT JOB NETWORKFALSEUID default reject
LOOPBACK DNSDENIEDUDP/TCP 53 unavailable
REVIEWED DOMAINS166 owner groups
POLICY FIXTURES13/13network requests · 0
CREDENTIAL LOGGINGFALSECONNECT authority only
UNTRUSTED JOBreits-runner UIDall sockets default reject
ONLY PERMITTED SOCKETtcp://127.0.0.1:3128DNS + local pivots denied
DESTINATION POLICY16 exact domainsprivate + unlisted denied
Gitea control2

gitea.reits.techdl.gitea.com

Node packages2

nodejs.orgregistry.npmjs.org

Go modules3

proxy.golang.orgsum.golang.orgstorage.googleapis.com

Source fixtures4

github.comapi.github.comobjects.githubusercontent.comraw.githubusercontent.com

Rust crates3

crates.iostatic.crates.ioindex.crates.io

Python packages2

pypi.orgfiles.pythonhosted.org

仍不能验收

!The template is not deployed, so runtime enforcement and recovery receipts do not yet exist.

!CONNECT authority filtering still requires an adversarial shared-CDN/SNI drill before acceptance.

!Allowlisted package and source domains remain possible exfiltration channels; untrusted pull requests must receive no reusable secret.

!Changing a package domain requires an owner-reviewed allowlist revision and a replacement rollout.

R1Policy + templateCOMPLETE
R2Local cfn-lintCOMPLETE
R3Egress guard staticCOMPLETE
R4Credential boundaryBLOCKED
R5AWS API validationBLOCKED_IAM
R6Cost-approved provisionAPPROVAL_REQUIRED
R718-gate isolation drillBLOCKED
R8Mac native laneBLOCKED
BOOTSTRAP SECURITY

Runner registrations remain offline while the bootstrap IAM profile and IMDS are present.

The reusable Gitea registration token is rotated and its SSM SecureString is deleted before activation.

Both instance profiles are detached and IMDS is disabled before the first runner daemon starts.

Any replacement node remains fail-closed until the explicit finalization sequence is repeated.

当前生产防线BOUND · /etc/reits-production-hostCFN LINT · PASS / AWS API · BLOCKED_IAMLIVE STACK · NOT_DEPLOYED

RELEASE STATE MACHINE

六站流水线,九类证据,任一缺失即停止晋级

D05 定义平台级发布单元;R25 仍负责逐屏 exact release、smoke 与 rollback 证明,两者不能互相冒充。

01dirty=false

Source

exact 40-char revision

02no production trust

Build

isolated builder

03sha256 bound

Package

full artifact + SBOM

04SecretRef only

Configure

public config + migration

05runtime identity

Promote

immutable target

06rollback verified

Recover

named previous release

RELEASE UNIT · REQUIREDdeveloper.reits.tech/release-unit/v1

SOURCEsource.revisionGit 真值,不接受短 SHA

ARTIFACTartifact.digest完整目录、二进制或 OCI image

SBOMsbom.digestCycloneDX JSON 与 artifact 同次构建

CONFIGconfiguration.digest仅公开配置和引用名

MIGRATIONmigration.digest数据库/存储变更集合

SECRETSsecrets.refs[]只记录 SecretRef,绝不记录值

DEPLOYdeployment.target环境、目标与观测时间

ROLLBACKrollback.targetReleaseId晋级前存在且已验证

PROVENANCEprovenance.builderId独立 builder 与签名状态

secret values are structurally forbidden

LIVE AUDIT WORKBENCH

逐单元查看哪里已绑定、哪里只是观察到

2026-07-20 生产盘点快照;Portal 参考单元已闭合到 unsigned provenance,其余入口文件摘要仍明确标记 PARTIAL,HTTP 200 明确不等于发布身份。

PRODUCTION UNIT REGISTRY10 个真实部署单元,不把 source SHA 当完整发布
10 / 10
SELECTED RELEASE UNIT

reits-auth

reits/reits-auth · production / systemd

D05 AUDITED
EXACT SOURCE157b8590e4625ad2fda802410303461a69a74bd3production release directory
DEPLOYMENT TARGETec2/systemd/reits-auth2026-07-20T08:53:00Z
ARTIFACTBOUND
541d2a4d515d

linux-amd64-binary

/opt/reits-auth/current/bin/reits-auth
SBOMMISSING
not bound

cyclonedx-json

receipt path missing
CONFIGMISSING
not bound

redacted-config-manifest

receipt path missing
MIGRATIONMISSING
not bound

migration-set

receipt path missing
RUNTIME IDENTITYPARTIAL

https://auth.reits.tech/v1/meta

SECRET BOUNDARYMISSING

referencesOnly=true · 0 refs

ROLLBACKPARTIAL

No named target

PROVENANCEMISSING

Builder identity missing

FAIL-CLOSED QA

错误码直接定位 source、制品、运行态或恢复责任人

ERROR阻断条件ACCOUNTABLE
RU_SOURCE_UNBOUND

部署无法回指一个干净的 40 位 source revision。

repository owner
RU_ARTIFACT_PARTIAL

只摘要入口文件,不能证明完整运行制品未漂移。

build owner
RU_SBOM_MISSING

依赖物料表未与该制品摘要绑定。

supply chain
RU_CONFIG_UNBOUND

公开配置、迁移集或 SecretRef 未形成独立摘要。

service owner
RU_RUNTIME_IDENTITY

运行态 health/meta 不返回同一份安全发布身份。

runtime owner
RU_ROLLBACK_UNVERIFIED

没有命名并验证可恢复的前一发布单元。

release owner
REFERENCE IMPLEMENTATION

Developer Portal 先实现安全 runtime receipt

本刀已经提供 release schema、公开配置、注册表、验证器接口和 /api/release-unit;部署时由不可变外部 receipt 注入 exact SHA 与摘要,避免“把当前 commit 写回当前 commit”的自引用循环。

D05 NOT ACCEPTED

当前 4 / 36 已验收,D05 是第 5 刀,项目仍剩 32 刀

要把 D05 切到 ACCEPTED,必须先提供专用 CI 计算资源,使 18 个仓 Gate 与 Mac 原生 lane 真实执行;再让全部部署单元闭合 artifact、SBOM、config、migration、SecretRef、runtime identity、provenance 与 rollback。生产 EC2 不会被拿来伪造这一结果。

0/10 release-ready