REITs · Architecture Control Room
Cut 80 / 10424 left
D05 · G04 · Cut 80 · P45 execution / witness pre-admission

Qualify the host.
Separate the witness.
Keep production stopped.

The privileged installation packet is now executable in an isolated root namespace, but the current EC2 is correctly denied. A dedicated staging host, four-party change authority, argv-only executor, independent eight-artifact readback and reverse rollback must all agree before a live install can exist.

P45 packet admitted 6 / 6Current EC2 denied · live install held
144 / 144execution / witness cases
8 + 8 + 8install · readback · rollback
4current host hard denials
64 / 65quality gates bound
1,220cumulative regressions
0production host contacts
Current EC2 evidence

The shared Portal host fails before sudo is considered

Read-only observation found four independent blockers. Identity collisions make the Cut 79 fixed 991:991 descriptor unsafe here even if every file path is still absent.

01
ip-172-31-19-46 · developer.reits.techINSTALL DENIED
host class
SHARED_PRODUCTION_PORTAL
Portal source
9214f9f46baf…
Portal listener
127.0.0.1:8100 · 1
Controller files
ABSENT · 0 / 8
Controller runtime
0 process · 0 :8110
D1Production marker present/etc/reits-production-host makes the host class incompatible.
D2Portal owns 8100A shared product runtime is already active on this machine.
D3UID 991 = redis6The fixed Controller identity would alias an existing service account.
D4GID 991 = nginxThe fixed Controller group would inherit an unrelated web boundary.
Target qualification profile

“EC2 reachable” is not a host qualification

The target profile requires a dedicated non-production control-plane host with both markers absent, ports 8100 and 8110 closed, 991:991 free and all Controller state absent.

02

Current shared Portal EC2

classSHARED_PRODUCTION_PORTALmarkersproduction presentports8100 = 1 · 8110 = 0991:991redis6 : nginxdecisionDENY BEFORE EXECUTION
MUST
NOT
CONVERGE

Required dedicated staging host

classDEDICATED_NON_PRODUCTION_CONTROL_PLANEmarkersboth absentports8100 = 0 · 8110 = 0991:991FREE : FREEdecisionELIGIBLE FOR AUTHORIZATION
Four-party change envelope

Scope, time and authority become one immutable ticket

The repository envelope is fixture-only. A production envelope must name the exact dedicated host, source commit, eight artifacts, thirty-minute window, rollback plan and four independent roles.

03
chg-fixture-cut80-p45NOT PRODUCTION AUTHORITY
source
Cut 79 · 9214f9f46baf…
window
06:00 → 06:30 UTC
scope
8 install artifacts
executor
EXECVE_ARGV_ONLY_NO_SHELL
activation
false · false
Platform SREOwn window and abortcannot self-witness
Release AuthorityBind source and artifactscannot change target
Security ReviewerApprove identity and privilege boundarycannot execute
Independent AuditorReread post-install stateread-only · separate
Authority separation

No actor can qualify, install, witness and activate alone

Six operational lanes prevent one privileged process from manufacturing its own evidence. Listener authority remains deliberately absent.

04
Target qualifierHost class · markers · ports · ID collisionsNO INSTALL
Change window ownerTimebox · abort · rollback triggerNO WITNESS
No-shell executorExact argv operations onlyNO VERDICT
Independent witnessIdentity + eight file rereadsNO MUTATION
Rollback ownerPrior-state restorationNO SCOPE EXPANSION
Listener authorityLater activation gateABSENT IN CUT 80
Eight installation artifacts

The transaction is atomic at the identity + manifest + six-module boundary

Every target has a reviewed digest and a different independent readback requirement. No systemd unit, Secret value or production driver is included.

05
01Dedicated identity991:991 · nologin · no groups · no caps
02Root manifest/etc/reits-runner-factory/controller-runtime.json · 0640
03ReservationClient346c…0332 · GetItem only
04CapacityClient2c87…f689 · GetItem only
05WorkerClientd0b8…10ff · Describe ×2
06RunnerClient14fb…b566 · exact GET ×3
07JournalClient4b1e…0e57 · Query only
08ReadinessKeyCliente7a7…861c · verify-only
No-shell privileged executor

Executable argv is data; generic shell strings are rejected

The future driver must invoke an allowlisted binary with an exact argument vector. No command substitution, pipe, wildcard, variable expansion or interactive shell exists in the interface.

06
CREATE_GROUP[groupadd, --gid, 991, --system, reits-runner-factory]Requires GID 991 FREE
CREATE_USER[useradd, --uid, 991, --gid, 991, --shell, /sbin/nologin, …]Requires UID 991 FREE
INSTALL_MANIFEST[install, -o, root, -g, reits-runner-factory, -m, 0640, …]Canonical bytes only
INSTALL_MODULES[install, -o, root, -g, reits-runner-factory, -m, 0640, six files]Six digests exact
READBACK_IDENTITY[getent, passwd, reits-runner-factory]Independent witness lane
READBACK_FILES[stat, --format, %u:%g:%a:%h:%i, eight paths]Never trust write return values
VERIFY_STOPPED[systemctl, is-active, reits-runner-factory-controller.service]Must be absent or inactive
VERIFY_8110[ss, -ltnH, sport = :8110]Must return zero listeners
Bounded maintenance window

Every exit path closes the window

Qualification and authority happen before the window. Installation, witness and rollback live inside it. Success means “rolled back rehearsal and closed,” not “left installed.”

07
QUALIFYhost + IDs + ports
AUTHORIZEfour-party receipt
OPENbounded transaction
REHEARSE8 → witness → rollback
CLOSEsuccess or failure
Prior-state witness

The rehearsal starts from an exact absent and stopped state

An unexpected identity, manifest, module root, unit, process or listener denies the transaction before the first artifact operation.

08
ABSENTidentity
ABSENTmanifest + modules
0Controller unit / process
0127.0.0.1:8110
Fourteen-view transaction

The write lane is only one segment of the proof chain

Cut 80 makes target qualification, authorization, independent evidence and rollback first-class transaction stages instead of post-hoc runbook notes.

09
01Bind Cut 79P44 · 6/6
02Qualify host12 checks
03Verify change4 roles
04Verify materials8 digests
05Open windowreceipt
06Prior stateabsent
07Identityproof
08Manifestproof
09Six modules6 proofs
10Readback8/8
11Stopped state0/0/0
12Rollback8 reverse
13Close windowreceipt
14Sealone handle
Independent readback boundary

The executor cannot sign its own success

Eight executor proofs are inputs to a separate read-only witness. The witness rereads identity and filesystem state, then seals a new digest without mutation authority.

10
Privileged executormutation lane · exact argv
creates8 rehearsal proofsmay readcaptured prior statemay decidenothingmay listennever
8 PROOFS
↓
DIGEST SET
Independent witnessread-only lane · separate role
rereadsidentity + 7 file classeschecksowner · mode · inode · digestsealsindependent readback digestmay mutatenever
Eight readback proofs

Write return values are never acceptance evidence

The stopped-state proof is additional: it verifies that no unit, process, Portal change or 8110 listener appeared during the rehearsal.

11
Identityuid · gid · shell · groups · caps
Manifestinode · owner · 0640 · digest
Six modulespath · regular · owner · digest ×6
Stopped stateunit=0 · process=0 · 8110=0
Stopped-state firewall

Installation rehearsal grants no activation authority

Even a perfect artifact readback cannot install a unit, start a process, resolve a live Secret or open a listener.

12
0systemd units installed
0Controller processes
0port 8110 listeners
0Secret values read
0Portal 8100 changes
Strict reverse rollback rehearsal

Identity is created first and removed last

Partial failure reverts only completed stages. Full rehearsal removes readiness first, then five Readers, manifest and identity, restoring the exact prior absence.

13
08 →Readiness module
07 →Journal module
06 →Runner module
05 →Worker module
04 →Capacity module
03 →Reservation module
02 →Root manifest
01Identity
Failure containment

Target, authority, executor, witness and rollback fail independently

A rollback or window-close failure is not hidden behind the original error. The terminal outcome remains denied and carries the containment failure.

14
Host qualification failureZero window · zero executor calls.
Authority failureFixture envelope cannot become production authority.
Install failureReverse only completed proofs; close window.
Witness failureRollback all eight; no self-attestation.
Rollback failureEscalate containment failure; never seal success.
Window-close failureTerminal receipt denied; activation stays impossible.
P45 subgate ladder

Six repository gates are green; live installation is still red

These subgates qualify the packet, not a real host mutation. A production receipt must be sourced from a separately approved dedicated host.

15
P45Adedicated host profile
P45Bchange envelope
P45Cno-shell executor
P45Dindependent witness
P45Erollback rehearsal
P45Fstopped-state firewall
Trust boundary matrix

Repository rehearsal, current EC2 and future dedicated host never share a status

The matrix prevents a fixture receipt or a reachable sudo account from being reported as production installation evidence.

16
BoundaryRepository rehearsalCurrent EC2Future dedicated host
Qualificationprofile validatedrequires signed claim
Authorityfixture envelope0 production receiptsfour-party receipt
Executorexact surface testednot invokedargv-only live driver
Readback8/8 fixture proofs0 installed artifactsindependent live reread
Rollback18 rehearsalsnot neededlive prior-state restoration
Activationdenied0 unit/process/8110still denied after install
144-case executable QA lab

Interrogate the exact P45 failure model

Filter complete rehearsals, target/authority denials, executor surface violations, witness tampering, rollback containment and capability/replay fences.

17
144 / 144 cases
64 / 65 quality gates

The only red gate is live dedicated-host execution

All prior P44 gates and six new P45 packet subgates are repository-bound. No production change authority or qualified host is implied.

18
Q01–Q26materials + authority
Q27–Q44transaction + rollback
Q45–Q52receipts + zero effect
P44A–FCut 79 packet
P45A–Bhost + change
P45C–Fexecutor + witness
LIVE P45host execution absent
Visible integration debt

Six production fragments remain owned and explicit

Cut 81 may close only these stopped-state installation dependencies. Service activation, live data access and public routing remain separate gates.

19
01 · Dedicated staging hostFree 991:991, no Portal marker, no production marker.
02 · Four-party authorityExact host, source, window, scope and rollback.
03 · Live argv executorAllowlisted binaries without shell interpolation.
04 · Independent witnessSeparate identity and eight-artifact reread.
05 · Live rollback rehearsalRestore captured prior state in-window.
06 · Activation authorityNot part of Cut 81; remains closed.
Cut 81 handoff

Next: approved dedicated-host stopped-state installation—and nothing more

Cut 81 should consume an exact dedicated staging host claim and production change receipt, run the no-shell executor, obtain independent live readback, rehearse rollback, and leave the host in a verified stopped state. It must not touch the shared Portal EC2, install a systemd unit, resolve production references, start Controller or bind 8110.

20
0qualified dedicated hosts
0production authorizations
0production host contacts
0production mutations
0service / listener starts