fix: validate deployment rollback and server topology

This commit is contained in:
2026-08-05 15:15:06 +02:00
parent 5f015a5a37
commit ece9cfda50
16 changed files with 571 additions and 52 deletions
+11 -7
View File
@@ -33,13 +33,17 @@
Review round 1 ran each Docker smoke exactly once without retry. Unified (`103.86s`) and
update-only (`46.45s`) passed build/start, core/Pi/registry/persistence setup and the stopped
candidate preflight, but `thothctl` stopped before mutation at its active-session inventory gate.
A test-first fix now scopes local inventory to `mine` and supplies the fixture's missing direct
DWH/vector/embedding runtime bindings; the final rollback path was not rerun, so compensation
and all-sentinel preservation remain unproven. Server-profile execution (`12.88s`) built both
images but Docker Desktop/VirtioFS rejected the real profile's parent Pi-state bind plus nested
tracked agent-file binds before service startup. Every run's exact labelled cleanup passed.
Native-Linux server startup and native Windows PowerShell/Docker execution remain explicit
CI/manual release gates; no local success is claimed for either platform.
Round 2 replaces presence-only fixture checks with generated Compose renders plus the production
workspace resolver; this found and fixed missing explicit direct transport selections. The
clean-server preflight now atomically initializes the three hidden Pi-agent targets under the
writable parent bind while protected/tracked sources remain separate read-only mounts. Clean
empty-root render/setup and wrong-service/value/mount mutations are green. The corrected server
one-shot built and started both healthy services from an empty Pi-state root, then stopped at an
incorrectly addressed authenticated frontend hop; the trusted-hop fixture correction is
deterministic-only. The corrected rollback one-shot passed runtime/Pi/registry/persistence and
stopped-candidate preflight, then stopped at active-session inventory before mutation. Exact
cleanup passed for both. Full server behavior, compensation/all-sentinel preservation, and
native Windows PowerShell/Docker execution remain explicit release gates.
## Portable deployment decoupling — LIVE 2026-08-05