Record three-node purchase deployment and remaining live acceptance gates

This commit is contained in:
archipelago
2026-10-06 23:39:39 -04:00
parent 49703d7e88
commit 13d1b459fc
2 changed files with 62 additions and 0 deletions
+25
View File
@@ -109,3 +109,28 @@ staging/rollback before using it as repair. Preserve existing CA identities and
custom certificates; do not blindly regenerate trust. A client must explicitly custom certificates; do not blindly regenerate trust. A client must explicitly
trust the node's public CA for normal browser validation. Keep normal-trust trust the node's public CA for normal browser validation. Keep normal-trust
acceptance open pending a tested provisioning repair and the operator's access URL. acceptance open pending a tested provisioning repair and the operator's access URL.
### Dev nginx reload mismatch found during the integrated purchase rollout
On 7 October UTC, the new backend wrote its playback proxy route but requests
still reached the old SPA. `nginx -t` and `systemctl reload nginx` both reported
success; the master error log showed wildcard IPv4/IPv6 port 443 bind failures.
Tailscale owned its tailnet port 443, while the old nginx workers still served the
original address-specific LAN/WireGuard listeners. The wildcard disk configuration
was already present in the pre-deployment backup.
`sites-available/archipelago` and `sites-enabled/archipelago` were separate regular
files. Both were backed up, and only their canonical wildcard HTTPS listeners
were changed to the two addresses already served by nginx: 192.168.63.240 and
10.44.0.1. Validation and reload then succeeded in practice: the new proxy returned
401 for unauthenticated GET and 405 for HEAD/POST, and owner RPC access passed.
Tailscale was not restarted or reconfigured. Original configs are in the dev
`support/integrated-purchase-backend-20261007T030942Z-2791483` backup directory.
Durable source/upgrade handling remains required before release: preserve the
recognized address-specific node-HTTPS profile when a template is installed,
account for enabled files that are not symlinks, and verify effective route/listener
behavior rather than treating a successful reload command as proof that nginx
accepted the new configuration. The existing per-address retarget helper ignores
wildcard-only configs. This live repair is not a claim that the general migration
or IPv6 HTTPS/companion trust acceptance is complete.
+37
View File
@@ -735,3 +735,40 @@ The deployable UI and evidence are preserved under
Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`. Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`.
It requires the matching purchase backend and is not yet deployed. The prior It requires the matching purchase backend and is not yet deployed. The prior
qualified backend and dashboard remain live on dev, Yaya and Framework. qualified backend and dashboard remain live on dev, Yaya and Framework.
### Integrated purchase candidate deployed — 7 October UTC
Local source commit `49703d7e` passed 1,889 isolated backend tests with zero
failures and five existing skips; 406 inputs remained unchanged through the
22m24s production build. Binary SHA256:
`f150ffd6007639a672844a8d450c9564dc41d820440655319d67d3df2a332250`.
The matching dashboard's 1,375 tests, typecheck, build and 21 local responsive
cases are recorded above.
Both layers are now deployed to dev, Yaya and the actual Framework. Health,
node identity, remembered session key, private node catalog, app container IDs
and start times, and stopped/uninstalled decisions were preserved on all three.
Each layer has its own rollback receipt. The new route returns 401 to anonymous
GET and 405 to HEAD/POST on all three nodes. Owner RPC passed on dev/Yaya;
Framework's normal authenticated browser acceptance still needs TOTP.
Actual Apps screens passed at 390px and 1440px on dev and Yaya, with no JavaScript
page errors or horizontal overflow. Initial smoke failures were harness selectors
for hidden responsive tabs/images; screenshots showed the rendered app grid.
Visible selectors were corrected without extending timeouts; earlier logs remain.
Dev also required the pre-existing nginx/Tailscale listener correction documented
in `https-app-gate-followup-20261006.md`. Yaya's V4V remained running and its
private signed catalog was byte-for-byte preserved.
All deployment scripts, receipts and browser/endpoint evidence are retained at
`~/.local/state/archipelago/release-qualification/deployed-purchase-49703d7e/`.
No new real payment, OTA, public catalog or source publication occurred.
This is incremental deployment, not complete payment/rental acceptance. Durable
external-invoice and on-chain recovery remain unfinished. Large-film rental
activation remains off: the current integrity guard can scan the whole film on
every range request, exceed the header deadline and commit a lease after timeout.
The separate readiness/index work must remove those scans from request paths,
verify chunks and start the original clock only after explicit ready/start.
IndeeHub private app packaging, distributed announcement delivery and actual
registration/payment/playback acceptance remain open.