Session: pool manager bring-up (HITL-gated) #45

Closed
opened 2026-09-04 19:12:11 +00:00 by larandar · 1 comment
Owner

Proposal

Why

The freeholder's 2026-09-03 ruling on Ting/Ting#2 (Q1/Q3) decomposes the pool-manager Epic into two Sessions: this one covers bring-up — creating the pool's identities and their grants — the other covers the steady-state checkout/return cycle.

Scope

Bring-up of the swarm-alpha identity pool's ten stable slots: reserved final names of the form swarm-alpha-drone-<word>-<word>-<word>-<word>, principal creation with swarm/slot metadata, UUID observation and pinning (no rename pass), and one distinct immutable AssignmentGrant per slot delegated to swarm-alpha/queen. Per the ratified contract, pool provisioning creates no per-drone Forgejo account, standing token, or active lease.

Gate: the realized name/UUID/grant mapping requires explicit freeholder ratification before activation — this Session produces that mapping for review, it does not activate it unilaterally.

Design

Projects from the delivered OpenSpec 61 — forge identity lifecycle contract and its transcription as contracts.identity.forge-lifecycle (must.contracts.identity.forge-lifecycle.provisioning-creates-identity-without-credentials, ...drone-capability-uses-no-per-drone-account, ...pilot-lease-timing-is-bounded). Per the ruling, this gets its own OpenSpec package rather than amending #61 — that package is not yet authored; this issue tracks the delivery-facing slice pending it.

Vedanta is the implementer (Ting/Ting#2's original "a new service, parallel to the steward, neither the queen nor Jostoph" predates this repo's naming — flake-ops#96: "Vedanta mints and allocates").

Tasks

  • Author this Session's own OpenSpec package (not an amendment to OpenSpec 61).
  • Implement ten-slot name reservation and idempotent UUID pinning.
  • Generate ten distinct immutable AssignmentGrants delegated to swarm-alpha/queen.
  • Prove bring-up mints no Forge account, token, or lease.
  • Produce the realized name/UUID/grant mapping for freeholder ratification.

Provenance

Filed by a grooming pass, freeholder-authorized, citing the 2026-09-03 ruling recorded in the grooming log.

## Proposal ### Why The freeholder's [2026-09-03 ruling on Ting/Ting#2](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15365) (Q1/Q3) decomposes the pool-manager Epic into two Sessions: this one covers **bring-up** — creating the pool's identities and their grants — the other covers the steady-state checkout/return cycle. ### Scope Bring-up of the `swarm-alpha` identity pool's ten stable slots: reserved final names of the form `swarm-alpha-drone-<word>-<word>-<word>-<word>`, principal creation with swarm/slot metadata, UUID observation and pinning (no rename pass), and one distinct immutable `AssignmentGrant` per slot delegated to `swarm-alpha/queen`. Per the ratified contract, pool provisioning creates no per-drone Forgejo account, standing token, or active lease. **Gate:** the realized name/UUID/grant mapping requires explicit freeholder ratification before activation — this Session produces that mapping for review, it does not activate it unilaterally. ## Design Projects from the delivered [OpenSpec 61 — forge identity lifecycle contract](https://jo.et0.pw/Ting/Ting/wiki/OpenSpec-61-forge-identity-lifecycle-contract) and its transcription as [`contracts.identity.forge-lifecycle`](https://jo.et0.pw/Ting/contracts/wiki/contracts.identity.forge-lifecycle) (`must.contracts.identity.forge-lifecycle.provisioning-creates-identity-without-credentials`, `...drone-capability-uses-no-per-drone-account`, `...pilot-lease-timing-is-bounded`). Per the ruling, this gets its own OpenSpec package rather than amending #61 — that package is not yet authored; this issue tracks the delivery-facing slice pending it. Vedanta is the implementer (`Ting/Ting#2`'s original "a new service, parallel to the steward, neither the queen nor Jostoph" predates this repo's naming — [flake-ops#96](https://jo.et0.pw/lar.ad/flake-ops/issues/96#issuecomment-3012): "Vedanta mints and allocates"). ## Tasks - [ ] Author this Session's own OpenSpec package (not an amendment to OpenSpec 61). - [ ] Implement ten-slot name reservation and idempotent UUID pinning. - [ ] Generate ten distinct immutable `AssignmentGrant`s delegated to `swarm-alpha/queen`. - [ ] Prove bring-up mints no Forge account, token, or lease. - [ ] Produce the realized name/UUID/grant mapping for freeholder ratification. ## Provenance Filed by a grooming pass, freeholder-authorized, citing the [2026-09-03 ruling](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15365) recorded in the [grooming log](https://jo.et0.pw/Ting/Ting/wiki/grooming-log).
Author
Owner

Grooming state: Closed — re-homed by ruling.
Evidence: Freeholder ruling (Larandar, 2026-09-05, in-session, delivery run for Ting/Ting#60): "Vedanta MUST NOT [reserve names, create principals, pin UUIDs, or author grants] — this is a provider job." This matches the ratified contracts.identity.openbao-lease-backend requirement the-realized-drone-pool-is-read-only-input-to-vedanta and the pilot spec's assignment of pool realization to flake-ops#427 over nixops4-providers#27.

Consequence: this Session's scope (name reservation, principal creation with slot metadata, UUID pinning, grant generation, the ratification mapping) is owned by flake-ops#427 + providers#29/#30. The bring-up code Vedanta merged under #30 / PR #38 (src/pool.rs) is outside Vedanta's boundary and is retired by the continuation Session filed today. Slot allocation at session time (#46) is a separate question and stays open.

Related evidence: Vedanta#30, PR #38, flake-ops#427, providers#27, contracts store contracts.identity.openbao-lease-backend/spec.md.

<!-- larandar:groom:v1 --> **Grooming state:** Closed — re-homed by ruling. **Evidence:** Freeholder ruling (Larandar, 2026-09-05, in-session, delivery run for Ting/Ting#60): *"Vedanta MUST NOT [reserve names, create principals, pin UUIDs, or author grants] — this is a provider job."* This matches the ratified `contracts.identity.openbao-lease-backend` requirement `the-realized-drone-pool-is-read-only-input-to-vedanta` and the pilot spec's assignment of pool realization to [flake-ops#427](https://jo.et0.pw/lar.ad/flake-ops/issues/427) over [nixops4-providers#27](https://jo.et0.pw/lar.ad/nixops4-providers/issues/27). **Consequence:** this Session's scope (name reservation, principal creation with slot metadata, UUID pinning, grant generation, the ratification mapping) is owned by flake-ops#427 + providers#29/#30. The bring-up code Vedanta merged under #30 / PR #38 (`src/pool.rs`) is outside Vedanta's boundary and is retired by the continuation Session filed today. Slot *allocation* at session time (#46) is a separate question and stays open. **Related evidence:** Vedanta#30, PR #38, flake-ops#427, providers#27, contracts store `contracts.identity.openbao-lease-backend/spec.md`.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Vedanta#45
No description provided.