Session: pool manager bring-up (HITL-gated) #45
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Ting/Vedanta#45
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Why
The freeholder's 2026-09-03 ruling on Ting/Ting#2 (Q1/Q3) decomposes the pool-manager Epic into two Sessions: this one covers bring-up — creating the pool's identities and their grants — the other covers the steady-state checkout/return cycle.
Scope
Bring-up of the
swarm-alphaidentity pool's ten stable slots: reserved final names of the formswarm-alpha-drone-<word>-<word>-<word>-<word>, principal creation with swarm/slot metadata, UUID observation and pinning (no rename pass), and one distinct immutableAssignmentGrantper slot delegated toswarm-alpha/queen. Per the ratified contract, pool provisioning creates no per-drone Forgejo account, standing token, or active lease.Gate: the realized name/UUID/grant mapping requires explicit freeholder ratification before activation — this Session produces that mapping for review, it does not activate it unilaterally.
Design
Projects from the delivered OpenSpec 61 — forge identity lifecycle contract and its transcription as
contracts.identity.forge-lifecycle(must.contracts.identity.forge-lifecycle.provisioning-creates-identity-without-credentials,...drone-capability-uses-no-per-drone-account,...pilot-lease-timing-is-bounded). Per the ruling, this gets its own OpenSpec package rather than amending #61 — that package is not yet authored; this issue tracks the delivery-facing slice pending it.Vedanta is the implementer (
Ting/Ting#2's original "a new service, parallel to the steward, neither the queen nor Jostoph" predates this repo's naming — flake-ops#96: "Vedanta mints and allocates").Tasks
AssignmentGrants delegated toswarm-alpha/queen.Provenance
Filed by a grooming pass, freeholder-authorized, citing the 2026-09-03 ruling recorded in the grooming log.
Grooming state: Closed — re-homed by ruling.
Evidence: Freeholder ruling (Larandar, 2026-09-05, in-session, delivery run for Ting/Ting#60): "Vedanta MUST NOT [reserve names, create principals, pin UUIDs, or author grants] — this is a provider job." This matches the ratified
contracts.identity.openbao-lease-backendrequirementthe-realized-drone-pool-is-read-only-input-to-vedantaand the pilot spec's assignment of pool realization to flake-ops#427 over nixops4-providers#27.Consequence: this Session's scope (name reservation, principal creation with slot metadata, UUID pinning, grant generation, the ratification mapping) is owned by flake-ops#427 + providers#29/#30. The bring-up code Vedanta merged under #30 / PR #38 (
src/pool.rs) is outside Vedanta's boundary and is retired by the continuation Session filed today. Slot allocation at session time (#46) is a separate question and stays open.Related evidence: Vedanta#30, PR #38, flake-ops#427, providers#27, contracts store
contracts.identity.openbao-lease-backend/spec.md.larandar referenced this issue2026-09-05 21:22:48 +00:00