REITs · Architecture Control Room
Cut 78 / 10426 left
D05 · G04 · Cut 78 · repository evidence only

Six packages. One candidate mode. One no-listener dry boot.

The exact Cut 77 ConfigRef→client→Adapter binder now drives the exact Cut 76 six-component composer. Every component preserves its fixture contract, adds a separate digest-bound candidate surface, and participates in one reversible joint transaction. This is executable integration evidence—not a live production install.

P43 admitted 5 / 5P44 live installation held
6 / 6component modes migrated
12→6→6refs → adapters → components
120 / 120joint cases passed
1verify-only key resolve / boot
0source reader calls
0production effects
Current EC2 truth

Repository integration is green; the host remains intentionally empty

These are separate truths. Candidate construction can pass without turning an absent manifest, identity or listener into production evidence.

01
ABSENTroot runtime manifest
0 / 6live client constructors
0Controller identities
0systemd units / processes
0agent + journal sockets
0port 8110 listeners
Global architecture · six lanes

Every reference lands on one least-authority Adapter and one reviewed component

The lane cards are the development directory: ownership, operation vocabulary, reference count and live-install status are visible without opening source.

02
01 · DATA PLATFORM · 2 ConfigRefs

Reservation read lane

Table + Role→GetItem Adapter→ReservationReader
candidate acceptedlive absent
02 · PLATFORM SRE · 2 ConfigRefs

Capacity read lane

Table + Role→GetItem Adapter→CapacityReader
candidate acceptedlive absent
03 · PLATFORM SRE · 2 ConfigRefs

Worker read lane

Region + Role→EC2 Describe→WorkerReader
candidate acceptedlive absent
04 · DEVEX · 3 ConfigRefs

Runner composite lane

Origin + SecretRef + Socket→3 GET ports→RunnerReader
vocabulary repairedlive absent
05 · AUDIT · 2 ConfigRefs

Journal read lane

Table + Role→Query Adapter→JournalReader
candidate acceptedlive absent
06 · SECURITY · 1 KeyRef

Readiness trust lane

P-256 KeyRef→Verify-only resolver→AttestationVerifier
1 resolve / bootlive absent
12 → 6 → 6 joint flow

Two proven transactions are joined without broadening authority

The binder owns references and client lifetime. The composer owns component lifetime. The joint candidate owns ordering and cross-layer rollback.

03
12 typed refsrepository bundle
6 clientsclosed shapes
6 adaptersbinding digests
5 readersno read invoked
1 verifierkey resolved once
joint receipttwo digests
reverse disposecomponents → adapters
Dual-mode contract

Fixture and candidate surfaces are both exact—and intentionally different

A candidate Adapter is not accepted because its label looks right. It must add exactly one canonical binding digest and keep every prior permission, operation, reference and method fence.

04
Repository fixture surfacepreserved for component regression labs
mode: REPOSITORY_FIXTURE_ONLY
kind · operation(s) · permission
configRefs · read method(s) · dispose
No binding digest is allowed on the fixture shape. Existing 584 component regressions retain their original boundary.
Production binding candidate surfacenew Cut 78 repository-only admission
mode: PRODUCTION_BINDING_CANDIDATE_REVIEWED
kind · operation(s) · permission
configRefs · bindingDigest · read method(s) · dispose
The digest binds the Adapter to its exact reference descriptors. Live credentials and raw values remain outside the surface.
Architecture finding

Runner operation vocabulary drift was caught before installation

Cut 77 emitted method-style labels while RunnerReader’s reviewed contract requires uppercase protocol constants. The joint boot failed closed, so the binder vocabulary was aligned without weakening either side.

05
Rejected at first joint bootsame methods, incompatible contract tokens
GetOrganizationRunner
GetRepositoryJob
GetRootAgentState
Canonical protocol vocabularymethods remain camelCase at the code edge
GET_ORGANIZATION_RUNNER
GET_REPOSITORY_JOB
GET_ROOT_AGENT_STATE
Content-addressed requalification

Six changed source trees received six new evidence chains

Each package binds source tree, artifact, SBOM, provenance and detached role review. The review explicitly states that candidate mode is repository-qualified and live binding remains forbidden.

06
PackageOwner → reviewerEvidence chainMode decisionProduction
ReservationReaderData → Securitysource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
CapacityReaderSRE → Securitysource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
WorkerReaderSRE → QAsource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
RunnerReaderDevEx → Securitysource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
JournalReaderAudit → Securitysource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
ReadinessVerifierSecurity → Architectsource · artifact · SBOM · SLSA · reviewREQUALIFIEDNOT BOUND
Deterministic joint transaction

Construction and rollback have one explicit layer order

Failure at any component closes the already-created components, then closes all bound Adapters. The readiness resolver is consumed exactly once during construction; the five source ports remain untouched.

07
1Bind + project12 refs → 6 clients → 6 guarded Adapters
2Construct componentsfive Readers, then resolve one public key and construct verifier
3Compose + projectopaque component handle, five read ports and one verify port
4Seal + disposerecompute joint receipt; components reverse, then Adapters reverse
P43 subgate ladder

Five repository gates close together

P43 closure says “the pieces fit under dry boot.” It does not say production services exist.

08
P43A · 6/6dual-mode package requalification
P43B · boundexact binder + composer join
P43C · 1verify-only key resolution
P43D · onceopaque handle and projection
P43E · zerolayered cleanup, no listener
Digest-bound joint receipt

One receipt joins binding identity, composition identity and six mode proofs

No ConfigRef value, SecretRef payload, private key or callable reference is serialized into the receipt.

09
Receipt identitycanonical SHA-256 recomputation
bindingIdrfg04b1:<64 hex>compositionIdrfg04c1:<64 hex>dryBootIdrfg04j1:<64 hex>modeJOINT_REPOSITORY_DRY_BOOT_NO_LIVE_ROOT_INSTALL_NO_LISTENERmode receipts6 exact component ↔ Adapter ↔ bindingDigest rows
Authority truthclosed-world receipt fields

productionConfigRefsResolved = 0
productionClientsConstructed = 0
productionAdaptersConstructed = 0
productionExternalReads = 0
productionListenerStarts = 0
productionBindingObserved = false

Trust boundary matrix

What is proven, what is simulated, what is absent

The design keeps repository observations separate from EC2 state so developers and AI agents cannot mistake a green fixture for production.

10
BoundaryRepository proofProduction observationOwner
Component source contract6 / 6 REQUALIFIEDnot applicablePackage owners + reviewers
Reference bundle12 / 12 injected fixtures0 / 12Configuration Root + Security
Client constructors6 closed fixture shapes0 / 6Runtime Adapter
Controller identitycontract onlyABSENTIdentity Owner
Listenerauthority denied0 on :8110Platform SRE
Visible integration debt

Six concrete production fragments remain

These are owned development items, not vague “future work.” P44 should tackle the first four as one still-no-listener installation transaction.

11
01 · Root manifestInstall canonical root:service 0640 bytes and verify file identity.
02 · Live referencesResolve 11 ConfigRefs + one verify-only KeyRef without recording secrets.
03 · Live clientsInstall six exact AWS/Gitea/agent/trust constructors.
04 · Controller identityCreate dedicated non-login UID/GID with least privilege.
05 · Durable auditBind encrypted PITR append-only journal driver.
06 · Service installationUnit, process and :8110 remain later-gate work.
120-case executable QA lab

Filter the exact failure family instead of reading a green total

18 full transactions, 30 mode/surface fences, 24 failure-containment cases, 24 capability/receipt/disposal cases and 24 admission/replay/zero-effect cases.

12
52 / 53 quality gates

The only red gate is an honest production-install boundary

All source, mode, surface, ordering, receipt, cleanup and zero-effect gates are repository-bound. P44 has no evidence and stays red.

13
Q01–Q20upstream + requalification
Q21–Q34bind + construct + compose
Q35–Q42capability + cleanup
Q43–Q51regression + zero effect
P43joint dry boot bound
P44live install absent
Zero-effect production firewall

Every production-effect counter remains zero

The only allowed candidate invocation is the injected repository public-key resolver, once per successful dry boot. It reports zero source reads, secret reads and network calls.

14
0live ConfigRefs
0live clients
0live Adapters
0external reads
0external writes
0secret reads
0source reader calls
0listener starts
0port 8110 calls
0units/processes
0resources created
0paid resources
P44 failure · Cut 79 handoff

Next: atomic root manifest, six live clients and dedicated identity binding—still without starting 8110

Cut 79 should define installation inputs, file/UID/GID ownership, six client constructor modules, SecretRef custody, readback proofs, partial rollback and a no-listener installed-state receipt. Starting the Controller process belongs to a later, separately authorized gate.

15
Cut 79 must producerepository plan + install-candidate evidence
manifestcontent-addressed root:service 0640identitydedicated non-login user/groupclientssix exact loadable modulesrollbackrestore prior absent state on any failure
Cut 79 must not doexplicit authority fence
listenerdo not bind 127.0.0.1:8110processdo not start Controllerwritesdo not mutate production ledgerssecretsdo not serialize token material