ochenstarik-ui
2ab32490a5
Merge pull request #13 from ochenstarik-ui/docs/product-horizons-and-integration
...
docs: product horizons, approval policies and KAgent integration spec
2026-08-09 19:07:55 +07:00
ochenstarik-ui
00dadf27ce
feat(control): reconcile links from factual state ( #16 )
...
Add fact-first Link reconciliation, duplicate and orphan cleanup, generation-aware scheduling, retention, Desktop drift visibility, and strict helper contracts. Preserve exact B-3R batching and lock-safe finalization with Linux/native trimmed evidence.
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-08-09 12:53:49 +07:00
Ochenstarik
4de849e3bf
docs: add product horizons, approval policies and KAgent integration spec
...
Adopt the reviewed parts of the external vision document as repository
specifications, and record the work-order gates that keep unimplemented
subsystems from starting before their prerequisites are closed.
- product-horizons.md: four horizons with hard exit criteria; Horizon 0
closes physical acceptance, signed delivery, the Monitor role and
certificate rotation before anything new begins.
- approval-policies.md: nine approval modes over the existing binary
confirmation, mapped onto ProvisioningJob, TTL and execution grants.
- integration-kagent.md: capability model split into read, request and
never-grantable; untrusted-executor invariant for KAgent Worker;
SO_PEERCRED on the discovery socket; API designed against entities
that exist today.
- security-model.md: untrusted executors on a Node, the public web
surface decision that must be recorded before that work starts, and
never-grantable capabilities.
- roadmap.md: stages 14-18 for the adopted scope, pinned to horizons.
All three new documents state that nothing in them is implemented.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 18:31:09 +07:00
ochenstarik-ui
b11c277ac7
feat(control): add background link reconciliation ( #12 )
...
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-08-03 13:55:48 +07:00
ochenstarik-ui
2d28b8d19c
Execute confirmed timezone provisioning safely ( #6 )
...
* Add standalone Linux bootstrap foundation
* Record bootstrap foundation progress
* Add single-code Node enrollment
* Validate bootstrap release payloads
* Add managed WireGuard mesh bootstrap
* Exercise repeated systemd installation in CI
* Expose systemd smoke failure diagnostics
* Fix bootstrap os-release variable collision
* Create policy helper directory during install
* Capture systemd smoke healthcheck errors
* Report Control listener diagnostics in CI
* Capture stalled Control process diagnostics
* Set service working directories
* Run protected CA healthcheck as root
* Add local Mesh emergency recovery
* Add multi-architecture Linux system matrix
* Add provisioning job control plane
* Stabilize Debian systemd smoke files
* Add node-scoped provisioning job channel
* Add provisioning progress state machine
* Reconcile expired provisioning jobs
* Add provisioning rollback workflow
* Add redacted provisioning event history
* Add restricted provisioning preflight helper
* Persist typed provisioning preflight facts
* Add preflight desired state drift detection
* Define strict base install schema catalog
* Add safe base install plan generation
* Add pre-confirmation base install plans
* Test base install plan API flow
* Authorize confirmed provisioning execution
* Execute confirmed timezone provisioning safely
* test: stabilize execution grant expiry boundary
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-30 21:40:30 +07:00
ochenstarik-ui
3851d87534
Add standalone Linux bootstrap foundation ( #5 )
...
* Add standalone Linux bootstrap foundation
* Record bootstrap foundation progress
* Add single-code Node enrollment
* Validate bootstrap release payloads
* Add managed WireGuard mesh bootstrap
* Exercise repeated systemd installation in CI
* Expose systemd smoke failure diagnostics
* Fix bootstrap os-release variable collision
* Create policy helper directory during install
* Capture systemd smoke healthcheck errors
* Report Control listener diagnostics in CI
* Capture stalled Control process diagnostics
* Set service working directories
* Run protected CA healthcheck as root
* Add local Mesh emergency recovery
* Add multi-architecture Linux system matrix
* Add provisioning job control plane
* Stabilize Debian systemd smoke files
* Add node-scoped provisioning job channel
* Add provisioning progress state machine
* Reconcile expired provisioning jobs
* Add provisioning rollback workflow
* Add redacted provisioning event history
* Add restricted provisioning preflight helper
* Persist typed provisioning preflight facts
* Add preflight desired state drift detection
* Define strict base install schema catalog
* Add safe base install plan generation
* Add pre-confirmation base install plans
* Test base install plan API flow
* Authorize confirmed provisioning execution
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-30 21:18:39 +07:00
ochenstarik-ui
95c919ecbe
Define standalone Server Monitor Manager roadmap
...
* Remove unrelated repository references
* Define standalone provisioning and VPN roadmap
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-19 12:59:27 +07:00
ochenstarik-ui
266900115c
Harden Link lifecycle and Control operations
...
* Harden link lifecycle and control operations
* Complete three-server acceptance lifecycle
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
2026-07-19 12:25:10 +07:00
Ochenstarik
b3dd5f0a5d
Record completed installer and mesh validation
2026-07-17 09:53:28 +07:00
Ochenstarik
a8978c085e
Add dedicated desktop management pages
2026-07-17 08:51:21 +07:00
Ochenstarik
199e70c804
Add 100-node Hub load test
2026-07-17 08:28:31 +07:00
Ochenstarik
f34f902f3b
Add source-scoped automation identity
2026-07-17 08:15:35 +07:00
Ochenstarik
160a5c683d
Export redacted desktop diagnostics
2026-07-17 00:56:29 +07:00
Ochenstarik
2fe570afd8
Test kill switch helper failures
2026-07-17 00:38:54 +07:00
Ochenstarik
7cffd04d2f
Enforce disabled links after reconnect
2026-07-17 00:27:42 +07:00
Ochenstarik
d63554c629
Add certificate re-enrollment lifecycle
2026-07-16 23:59:52 +07:00
Ochenstarik
9efd8324eb
Buffer offline agent metrics
2026-07-16 23:07:36 +07:00
Ochenstarik
1e5e44a6ad
Move Links to SQLite control plane
2026-07-16 21:59:20 +07:00
Ochenstarik
46a1c393c7
Add persistent mTLS control layer
2026-07-16 20:35:05 +07:00
Ochenstarik
7bd7c950a6
Protect monitoring key and add SSH terminal
2026-07-16 19:57:31 +07:00
Ochenstarik
0b642cf9a3
Persist and chart short metrics history
2026-07-16 19:46:37 +07:00
Ochenstarik
594b9aaced
Show health warnings and refresh automatically
2026-07-16 19:23:47 +07:00
Ochenstarik
46f00afb7d
Add server profile editing and deletion
2026-07-16 19:13:44 +07:00
Ochenstarik
bd94af38e7
Mark installer lifecycle complete
2026-07-16 19:08:16 +07:00
Ochenstarik
b19e3e8b31
Confirm applied Link state in Windows client
2026-07-16 19:02:05 +07:00
Ochenstarik
231ba69754
Add restricted Link policy controls
2026-07-16 18:43:51 +07:00
Ochenstarik
b92bb75b08
Document secure node enrollment
2026-07-16 18:31:11 +07:00
Ochenstarik
27e71a9831
Align specification with Hub and Node architecture
2026-07-16 18:12:40 +07:00
Ochenstarik
2708a0a786
Replace Hermes with generic AI agent
2026-07-15 23:42:29 +07:00
Ochenstarik
e8db9f46aa
Add Windows SSH monitoring MVP
2026-07-15 13:27:27 +07:00