feat: rootless podman, session hardening, boot stability, sidebar fix
Rootless podman migration (TASK-11): - Remove sudo from all podman calls in PodmanClient + 8 backend files - Remove sudo from all podman/docker calls in deploy script - Restore full systemd security hardening: NoNewPrivileges, RestrictAddressFamilies, MemoryDenyWriteExecute, RestrictRealtime, RestrictNamespaces, RestrictSUIDSGID, SystemCallFilter, ProtectSystem=strict - Enable loginctl linger for rootless container persistence - Remove Ollama from auto-deploy (marketplace-only) Session & auth hardening: - Increase MAX_CONCURRENT_SESSIONS 20→50 (prevents eviction storms) - Debounced 401 redirect in rpc-client.ts (prevents redirect storms) Boot stability: - optimize-debian.sh: adds chrony, swap, removes policy-rc.d - deploy script: pre-restart chrony + swap setup - ISO build: chrony package, swap file creation - BootScreen: no longer clears localStorage (prevents splash replay) - RootRedirect: sole owner of localStorage clearing on server ready UI fixes: - Sidebar opacity default changed from 0→visible (fixes missing sidebar after page-persistence login without entrance animation) - Console.log/error wrapped in import.meta.env.DEV guards - Remove unused route import from RootRedirect Beta tracking: - CLAUDE.md: beta freeze protocol added - MASTER_PLAN.md: TASK-11, TASK-17, phase structure - BETA-PROGRESS.md: initial tracking doc - Tagged v1.2.0-alpha.1 as pre-rootless baseline Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
b89808862c
commit
39c7ac1924
@@ -8,6 +8,54 @@ Archipelago is a **Bitcoin Node OS** — a bootable, self-sovereign personal ser
|
||||
**Target OS**: Debian 12 (Bookworm) — x86_64 and ARM64
|
||||
**Current version**: 0.1.0
|
||||
|
||||
---
|
||||
|
||||
## BETA FREEZE — ACTIVE (2026-03-18)
|
||||
|
||||
**Goal: Ship a flawless beta that works perfectly on every machine we install it on.**
|
||||
|
||||
We are in **beta stabilization mode**. The current feature set is LOCKED. Every session must push toward this goal.
|
||||
|
||||
### Pipeline
|
||||
|
||||
```
|
||||
PHASE 1: Feature Testing (internal) ← WE ARE HERE
|
||||
↓ Gate: every feature works, bugs fixed, security hardened, ISO verified
|
||||
PHASE 2: User Testing (real users on real hardware we don't control)
|
||||
↓ Gate: user-reported issues resolved, telemetry shows stable fleet
|
||||
PHASE 3: Beta Live (public release)
|
||||
```
|
||||
|
||||
### What IS allowed
|
||||
- Bug fixes for existing features
|
||||
- Security hardening and testing
|
||||
- Beta telemetry / node reporting (TASK-12 — needed for user testing)
|
||||
- UI/layout rearrangements (moving things around, improving flow)
|
||||
- Boot screen completion (FEATURE-4 — already in progress)
|
||||
- Testing all features end-to-end on fresh installs
|
||||
- Performance and reliability improvements to existing code
|
||||
- ISO build hardening
|
||||
|
||||
### What is NOT allowed
|
||||
- New features (watch-only wallet, mesh balance check, etc. are POST-BETA)
|
||||
- New app integrations
|
||||
- New backend modules or RPC endpoints (unless fixing existing bugs or beta telemetry)
|
||||
- New dependencies (unless required for beta infrastructure)
|
||||
- Scope creep of any kind
|
||||
|
||||
### Status tracking
|
||||
- **Progress tracker**: `docs/BETA-PROGRESS.md` — updated every session
|
||||
- **Beta checklist**: `docs/BETA-RELEASE-CHECKLIST.md` — the acceptance criteria
|
||||
- **Master plan**: `docs/MASTER_PLAN.md` — phased roadmap (Phase 1/2/3)
|
||||
|
||||
### Session protocol
|
||||
1. Read `docs/BETA-PROGRESS.md` at start of every session
|
||||
2. Report current phase and status before starting work
|
||||
3. Work only on current-phase items
|
||||
4. Update `docs/BETA-PROGRESS.md` at end of every session with what changed
|
||||
|
||||
---
|
||||
|
||||
## Quick Reference
|
||||
|
||||
```bash
|
||||
|
||||
Reference in New Issue
Block a user