Record three-node purchase deployment and remaining live acceptance gates
This commit is contained in:
@@ -109,3 +109,28 @@ staging/rollback before using it as repair. Preserve existing CA identities and
|
||||
custom certificates; do not blindly regenerate trust. A client must explicitly
|
||||
trust the node's public CA for normal browser validation. Keep normal-trust
|
||||
acceptance open pending a tested provisioning repair and the operator's access URL.
|
||||
|
||||
### Dev nginx reload mismatch found during the integrated purchase rollout
|
||||
|
||||
On 7 October UTC, the new backend wrote its playback proxy route but requests
|
||||
still reached the old SPA. `nginx -t` and `systemctl reload nginx` both reported
|
||||
success; the master error log showed wildcard IPv4/IPv6 port 443 bind failures.
|
||||
Tailscale owned its tailnet port 443, while the old nginx workers still served the
|
||||
original address-specific LAN/WireGuard listeners. The wildcard disk configuration
|
||||
was already present in the pre-deployment backup.
|
||||
|
||||
`sites-available/archipelago` and `sites-enabled/archipelago` were separate regular
|
||||
files. Both were backed up, and only their canonical wildcard HTTPS listeners
|
||||
were changed to the two addresses already served by nginx: 192.168.63.240 and
|
||||
10.44.0.1. Validation and reload then succeeded in practice: the new proxy returned
|
||||
401 for unauthenticated GET and 405 for HEAD/POST, and owner RPC access passed.
|
||||
Tailscale was not restarted or reconfigured. Original configs are in the dev
|
||||
`support/integrated-purchase-backend-20261007T030942Z-2791483` backup directory.
|
||||
|
||||
Durable source/upgrade handling remains required before release: preserve the
|
||||
recognized address-specific node-HTTPS profile when a template is installed,
|
||||
account for enabled files that are not symlinks, and verify effective route/listener
|
||||
behavior rather than treating a successful reload command as proof that nginx
|
||||
accepted the new configuration. The existing per-address retarget helper ignores
|
||||
wildcard-only configs. This live repair is not a claim that the general migration
|
||||
or IPv6 HTTPS/companion trust acceptance is complete.
|
||||
|
||||
@@ -735,3 +735,40 @@ The deployable UI and evidence are preserved under
|
||||
Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`.
|
||||
It requires the matching purchase backend and is not yet deployed. The prior
|
||||
qualified backend and dashboard remain live on dev, Yaya and Framework.
|
||||
|
||||
### Integrated purchase candidate deployed — 7 October UTC
|
||||
|
||||
Local source commit `49703d7e` passed 1,889 isolated backend tests with zero
|
||||
failures and five existing skips; 406 inputs remained unchanged through the
|
||||
22m24s production build. Binary SHA256:
|
||||
`f150ffd6007639a672844a8d450c9564dc41d820440655319d67d3df2a332250`.
|
||||
The matching dashboard's 1,375 tests, typecheck, build and 21 local responsive
|
||||
cases are recorded above.
|
||||
|
||||
Both layers are now deployed to dev, Yaya and the actual Framework. Health,
|
||||
node identity, remembered session key, private node catalog, app container IDs
|
||||
and start times, and stopped/uninstalled decisions were preserved on all three.
|
||||
Each layer has its own rollback receipt. The new route returns 401 to anonymous
|
||||
GET and 405 to HEAD/POST on all three nodes. Owner RPC passed on dev/Yaya;
|
||||
Framework's normal authenticated browser acceptance still needs TOTP.
|
||||
|
||||
Actual Apps screens passed at 390px and 1440px on dev and Yaya, with no JavaScript
|
||||
page errors or horizontal overflow. Initial smoke failures were harness selectors
|
||||
for hidden responsive tabs/images; screenshots showed the rendered app grid.
|
||||
Visible selectors were corrected without extending timeouts; earlier logs remain.
|
||||
Dev also required the pre-existing nginx/Tailscale listener correction documented
|
||||
in `https-app-gate-followup-20261006.md`. Yaya's V4V remained running and its
|
||||
private signed catalog was byte-for-byte preserved.
|
||||
|
||||
All deployment scripts, receipts and browser/endpoint evidence are retained at
|
||||
`~/.local/state/archipelago/release-qualification/deployed-purchase-49703d7e/`.
|
||||
No new real payment, OTA, public catalog or source publication occurred.
|
||||
|
||||
This is incremental deployment, not complete payment/rental acceptance. Durable
|
||||
external-invoice and on-chain recovery remain unfinished. Large-film rental
|
||||
activation remains off: the current integrity guard can scan the whole film on
|
||||
every range request, exceed the header deadline and commit a lease after timeout.
|
||||
The separate readiness/index work must remove those scans from request paths,
|
||||
verify chunks and start the original clock only after explicit ready/start.
|
||||
IndeeHub private app packaging, distributed announcement delivery and actual
|
||||
registration/payment/playback acceptance remain open.
|
||||
|
||||
Reference in New Issue
Block a user