REITs · Architecture Control Room
Cut 79 / 10425 left
D05 · G04 · Cut 79 · repository installation candidate

Installable source.
Reversible transaction.
Zero host mutation.

The canonical root manifest, dedicated non-login identity and six independently loadable client modules now enter one eight-stage sandbox transaction. Every artifact is read back, the actual modules drive the Cut 78 joint dry boot, and rollback restores the prior absent state. No privileged host installation is claimed.

P44 admitted 6 / 6P45 privileged install held
8ordered install artifacts
6 / 6loadable client modules
132 / 132installation cases
8readback proofs / tx
18actual-module joint boots
0production host mutations
Current EC2 truth

Repository evidence advanced; the host deliberately did not

The evidence probe now checks the one canonical runtime path. Repository artifacts are real; host installation remains absent and separately authorized.

01
Canonical manifestABSENT/etc/reits-runner-factory/controller-runtime.json
service identityABSENTreits-runner-factory
client modules0 / 6production root
Controller unit0not installed
Controller process0not started
127.0.0.1:81100no listener
Canonical root manifest

One path, one owner boundary, twelve references

The file holds typed references and assembly intent—not token values. Strict canonical bytes, single trailing LF and an assembly-contract digest remove serializer and path ambiguity.

02
FILE CONTRACT
path /etc/reits-runner-factory/controller-runtime.json
owner root:reits-runner-factory
mode 0640 · regular · nlink=1
encoding UTF-8 · canonical JSON · LF
size 1…65536 bytes
read O_NOFOLLOW · O_CLOEXEC
REFERENCE CONTRACT
11 typed ConfigRefs
1 P-256 KeyRef · VERIFY_ONLY
5 strongly-consistent Reader declarations
1 loopback bind declaration
0 inline secrets / private keys
0 production resolutions
Dedicated Controller identity

UID/GID is part of the manifest digest, not an ops convention

The candidate has no login, supplementary group or Linux capability path. The future installer must prove the same subject before and after writing any file.

03
991
reits-runner-factorydedicated control-plane subject
UID / GID
991 / 991
shell
/sbin/nologin
home
/var/lib/reits-runner-factory
host class
DEDICATED_CONTROL_PLANE
Non-loginPASS · candidate
No capabilities0 ambient / 0 bounding
No extra groups[] exact
NoNewPrivilegestrue
Production userABSENT
Listener authorityDENIED
Eight install artifacts

Identity + manifest + six modules form one atomic set

No artifact can be promoted alone. The plan and terminal receipt bind all eight positions and their strict order.

04
01HOST ABSENTDedicated identityreits-runner-factory · 991:991
02HOST ABSENTRoot manifest/etc/reits-runner-factory/controller-runtime.json
03HOST ABSENTReservationClientdynamodb:GetItem
04HOST ABSENTCapacityClientdynamodb:GetItem
05HOST ABSENTWorkerClientDescribeInstances + DescribeVolumes
06HOST ABSENTRunnerClientGitea GET ×2 + agent read
07HOST ABSENTJournalClientdynamodb:Query
08HOST ABSENTReadinessKeyClientverify-only public key
Six loadable client modules

Each module owns one exact scope and one injected driver port

These are real ESM modules, imported independently and hashed from source. Construction validates authority but does not invoke a data-source method.

05
ReservationClientSHA · 346c…0332
2 ConfigRefs→GetItem driver→ReservationAdapter
dynamodb:GetItem0 calls
CapacityClientSHA · 2c87…f689
2 ConfigRefs→GetItem driver→CapacityAdapter
dynamodb:GetItem0 calls
WorkerClientSHA · d0b8…0ff
2 ConfigRefs→EC2 read driver→WorkerAdapter
Describe ×20 calls
RunnerClientSHA · 14fb…b566
3 ConfigRefs→Gitea + agent→RunnerAdapter
3 exact GETs0 calls
JournalClientSHA · 4b1e…0e57
2 ConfigRefs→Query driver→JournalAdapter
dynamodb:Query0 calls
ReadinessKeyClientSHA · e7a7…861c
1 KeyRef→trust driver→KeyResolver
VERIFY_ONLY1 fixture resolve
Driver injection boundary

Loadable client does not mean configured production SDK

The module freezes the contract around an injected read-only driver. AWS SDK, Gitea transport, Unix socket and trust-store implementations remain a separate P45 dependency.

06
Client module ownsreviewed, content-addressed source
inputexact binding descriptorauthorityoperation + permission + refslifecycleactive → disposedguardno excess keys
INJECT
EXACT
PORT
Production driver must ownnot configured in Cut 79
transportAWS / HTTPS / AF_UNIX / filecredentialsrole or opaque SecretReftimeoutsbounded + abortabletelemetryno values or key bytes
12 → 6 → 6 actual-module flow

The Cut 78 graph now starts from real module exports

Eleven ConfigRefs and one KeyRef select six modules; the existing binder creates six Adapters; the existing composer creates five Readers and one verifier. Only the repository key fixture resolves once.

07
12 refs11 config + 1 key
→
6 ESM modulesindependently imported
→
6 driver portsfixture-only injected
→
6 AdaptersCut 77 exact
→
6 componentsCut 76 exact
→
8110not started
Eight-stage reversible transaction

Every forward step has a deterministic inverse

The repository driver simulates root operations inside an isolated sandbox. It proves sequencing and rollback semantics without touching EC2 production paths.

08
01Identity991:991 candidate
02Manifestroot:991 · 0640
03Reservationmodule digest
04Capacitymodule digest
05Workermodule digest
06Runnermodule digest
07Journalmodule digest
08Readinessmodule digest
Readback proof set

No success from write return values alone

Eight independent proof digests are rebound into one readback-set digest, then joined with the Cut 78 receipt. P45 must reproduce this from the real host.

09
Identity proofuid · gid · shell · groups · caps
Manifest proofpath · inode · mode · content SHA
Six module proofsinstall path · source SHA × 6
Joint proofbinding + composition + install plan
Strict reverse rollback

Readiness comes off first; identity comes off last

Partial failure reverts only completed steps. Terminal disposal reverts all eight and must prove the same prior-absent state.

10
08 →Readiness module
07 →Journal module
06 →Runner module
05 →Worker module
04 →Capacity module
03 →Reservation module
02 →Root manifest
01Identity
P44 subgate ladder

Six repository gates close together

Manifest, identity, modules, transaction, joint boot and rollback/readback are all required. None is a production installation receipt.

11
P44Amanifest candidate
P44Bidentity candidate
P44Csix client modules
P44Dreversible transaction
P44Eactual-module joint boot
P44Freadback + rollback
Trust boundary matrix

Repository proof and host proof remain visibly separate

The table prevents “loadable,” “staged,” “resolved” and “installed” from collapsing into one misleading green state.

12
BoundaryRepository evidenceProduction evidenceDecision
Manifestcanonical bytes + assembly digestno inode / owner / mode proofHOLD
Identityexact 991:991 descriptorno passwd/group readbackHOLD
Modules6 imports + 6 source digests0 installed module proofsHOLD
Driversexact injected interfaces0 production implementationsHOLD
Joint boot18 actual-module dry boots0 production refs / callsP44 PASS
Listenerloopback declaration only0 process / 0 :8110DENY START
132-case executable QA lab

Filter the actual failure model

Six suites cover complete transactions, manifest/identity/module fences, driver surfaces, rollback containment, capabilities, receipts and replay. Every row carries zero production effects.

13
132 / 132 cases
58 / 59 quality gates

Only privileged host installation stays red

All source, identity, module, ordering, readback, rollback, receipt and zero-effect gates are repository-bound. P45 has no production receipt.

14
Q01–Q15manifest + identity
Q16–Q26modules + drivers
Q27–Q36staging + joint boot
Q37–Q52capability + zero effect
P44A–Cmaterials
P44D–Ftransaction proof
P45host install absent
Visible integration debt

Six owned production fragments remain

P45 must focus on a bounded privileged transaction and independent readback. Actual driver implementations and live references remain explicit prerequisites.

15
01 · Privileged host transactionRoot change authority, pre-state witness and immutable receipt.
02 · Production driversSix read-only AWS, Gitea, agent and trust implementations.
03 · Live reference stores11 ConfigRefs + one KeyRef without value leakage.
04 · Independent readbackUID/GID, inode, mode and six installed-module digests.
05 · Rollback rehearsalRestore observed prior state inside the maintenance window.
06 · Service / listenerRemain disabled after P45; activation is a later gate.
Zero-effect production firewall

Installable is not installed

All fixture work stayed inside injected memory/sandbox boundaries. No production value, call, process or resource crossed the line.

16
0host mutations
0production clients
0external reads / writes
0secret reads
0listener / :8110
P45 failure · Cut 80 handoff

Next: independently witnessed privileged installation—still without service activation

Cut 80 should bind explicit change authority, maintenance window, observed pre-state, root executor, production driver packages, readback auditor and rollback rehearsal into a non-starting host transaction. Installing does not authorize resolving secrets, calling data sources or listening on 8110.

17
Cut 80 must produceproduction installation evidence
authorityexplicit bounded change receiptexecutorroot operations without shell interpolationreadbackindependent identity/file/module witnessrollbackreal prior-state restoration rehearsal
Cut 80 must not doseparate activation authority
servicedo not start Controllerlistenerdo not bind 127.0.0.1:8110sourcesdo not call AWS/Gitea/agent storessecretsdo not materialize token values