Record three-node purchase deployment and remaining live acceptance gates
This commit is contained in:
@@ -109,3 +109,28 @@ staging/rollback before using it as repair. Preserve existing CA identities and
|
|||||||
custom certificates; do not blindly regenerate trust. A client must explicitly
|
custom certificates; do not blindly regenerate trust. A client must explicitly
|
||||||
trust the node's public CA for normal browser validation. Keep normal-trust
|
trust the node's public CA for normal browser validation. Keep normal-trust
|
||||||
acceptance open pending a tested provisioning repair and the operator's access URL.
|
acceptance open pending a tested provisioning repair and the operator's access URL.
|
||||||
|
|
||||||
|
### Dev nginx reload mismatch found during the integrated purchase rollout
|
||||||
|
|
||||||
|
On 7 October UTC, the new backend wrote its playback proxy route but requests
|
||||||
|
still reached the old SPA. `nginx -t` and `systemctl reload nginx` both reported
|
||||||
|
success; the master error log showed wildcard IPv4/IPv6 port 443 bind failures.
|
||||||
|
Tailscale owned its tailnet port 443, while the old nginx workers still served the
|
||||||
|
original address-specific LAN/WireGuard listeners. The wildcard disk configuration
|
||||||
|
was already present in the pre-deployment backup.
|
||||||
|
|
||||||
|
`sites-available/archipelago` and `sites-enabled/archipelago` were separate regular
|
||||||
|
files. Both were backed up, and only their canonical wildcard HTTPS listeners
|
||||||
|
were changed to the two addresses already served by nginx: 192.168.63.240 and
|
||||||
|
10.44.0.1. Validation and reload then succeeded in practice: the new proxy returned
|
||||||
|
401 for unauthenticated GET and 405 for HEAD/POST, and owner RPC access passed.
|
||||||
|
Tailscale was not restarted or reconfigured. Original configs are in the dev
|
||||||
|
`support/integrated-purchase-backend-20261007T030942Z-2791483` backup directory.
|
||||||
|
|
||||||
|
Durable source/upgrade handling remains required before release: preserve the
|
||||||
|
recognized address-specific node-HTTPS profile when a template is installed,
|
||||||
|
account for enabled files that are not symlinks, and verify effective route/listener
|
||||||
|
behavior rather than treating a successful reload command as proof that nginx
|
||||||
|
accepted the new configuration. The existing per-address retarget helper ignores
|
||||||
|
wildcard-only configs. This live repair is not a claim that the general migration
|
||||||
|
or IPv6 HTTPS/companion trust acceptance is complete.
|
||||||
|
|||||||
@@ -735,3 +735,40 @@ The deployable UI and evidence are preserved under
|
|||||||
Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`.
|
Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`.
|
||||||
It requires the matching purchase backend and is not yet deployed. The prior
|
It requires the matching purchase backend and is not yet deployed. The prior
|
||||||
qualified backend and dashboard remain live on dev, Yaya and Framework.
|
qualified backend and dashboard remain live on dev, Yaya and Framework.
|
||||||
|
|
||||||
|
### Integrated purchase candidate deployed — 7 October UTC
|
||||||
|
|
||||||
|
Local source commit `49703d7e` passed 1,889 isolated backend tests with zero
|
||||||
|
failures and five existing skips; 406 inputs remained unchanged through the
|
||||||
|
22m24s production build. Binary SHA256:
|
||||||
|
`f150ffd6007639a672844a8d450c9564dc41d820440655319d67d3df2a332250`.
|
||||||
|
The matching dashboard's 1,375 tests, typecheck, build and 21 local responsive
|
||||||
|
cases are recorded above.
|
||||||
|
|
||||||
|
Both layers are now deployed to dev, Yaya and the actual Framework. Health,
|
||||||
|
node identity, remembered session key, private node catalog, app container IDs
|
||||||
|
and start times, and stopped/uninstalled decisions were preserved on all three.
|
||||||
|
Each layer has its own rollback receipt. The new route returns 401 to anonymous
|
||||||
|
GET and 405 to HEAD/POST on all three nodes. Owner RPC passed on dev/Yaya;
|
||||||
|
Framework's normal authenticated browser acceptance still needs TOTP.
|
||||||
|
|
||||||
|
Actual Apps screens passed at 390px and 1440px on dev and Yaya, with no JavaScript
|
||||||
|
page errors or horizontal overflow. Initial smoke failures were harness selectors
|
||||||
|
for hidden responsive tabs/images; screenshots showed the rendered app grid.
|
||||||
|
Visible selectors were corrected without extending timeouts; earlier logs remain.
|
||||||
|
Dev also required the pre-existing nginx/Tailscale listener correction documented
|
||||||
|
in `https-app-gate-followup-20261006.md`. Yaya's V4V remained running and its
|
||||||
|
private signed catalog was byte-for-byte preserved.
|
||||||
|
|
||||||
|
All deployment scripts, receipts and browser/endpoint evidence are retained at
|
||||||
|
`~/.local/state/archipelago/release-qualification/deployed-purchase-49703d7e/`.
|
||||||
|
No new real payment, OTA, public catalog or source publication occurred.
|
||||||
|
|
||||||
|
This is incremental deployment, not complete payment/rental acceptance. Durable
|
||||||
|
external-invoice and on-chain recovery remain unfinished. Large-film rental
|
||||||
|
activation remains off: the current integrity guard can scan the whole film on
|
||||||
|
every range request, exceed the header deadline and commit a lease after timeout.
|
||||||
|
The separate readiness/index work must remove those scans from request paths,
|
||||||
|
verify chunks and start the original clock only after explicit ready/start.
|
||||||
|
IndeeHub private app packaging, distributed announcement delivery and actual
|
||||||
|
registration/payment/playback acceptance remain open.
|
||||||
|
|||||||
Reference in New Issue
Block a user