Files
archy/docs/indeehub-private-delivery-runbook-20261008.md
T

196 lines
12 KiB
Markdown

# IndeeHub private Yaya delivery — 8 October 2026
Status: optimized production build, inert Yaya backend/helper staging, existing-node public pin and fresh seven-member plan preparation passed; **not activated**.
This is private free/authenticated app testing;
paid viewing, publication and payment UAT remain separate. No funds or public
announcements are authorized by this runbook. Separately authorized inert Yaya
worker import and read-only preflight are completed (`6afb6abc`); no backend
deployment, app lifecycle change or catalog activation has occurred.
## Frozen inputs and prerequisite evidence
- Full same-boot post-target rollback: operation `5bd06edc`, qualified fixture
executable `dd94dc6d…`, embedded helper `6fc3f978…`, 2,031 backend tests passed.
- Successful full cutover and independent final checks now pass for `8b53579c`:
Committed/cleanup complete, Released maintenance, exact seven target images and
saved units, new runtime IDs, fresh DB/four-volume restore proofs and no holds.
Historical `f39bd824` timed out before target startup under host pressure, then
natively recovered cleanly; that failure is retained separately.
- Matching optimized backend build passed against all 536 unchanged inputs from
the 2,031-test snapshot. The production artifact and actual Yaya inert staging/
public-pin/fresh-plan evidence are recorded in the latest checkpoint below.
- Unsigned delivery catalog: worker runtime evidence directory,
`unsigned-full-candidate-with-worker-29627fc.json`, SHA256
`9967d06c8809d69cce6057b9f45a630e9ce21fd5cd33541e352e23336cd8eb07`.
Its frontend hooks exactly match qualified authoritative source, SHA256
`64015f79ca84c604cecd22e9e4a892644d485988f163c01e3d47277a64282747`.
- Existing frontend/API import evidence is in
`~/.local/state/archipelago/session-recovery/indeehub-yaya-private-staging-5d0ea64/`.
Worker import is complete (`6afb6abc`): qualified OCI SHA256
`6db29188c0e68ed8e9e8d84ea2e9c5c70695518e0930775bf6b3200d14d99527`.
Exact archive/blobs/image were verified; all 30 existing container identities,
start times/statuses, node identity/session, operator intent, management service
and catalogs were preserved. Receipt:
`~/.local/state/archipelago/release-qualification/worker-runtime-29627fc-20261008/yaya-worker-import-receipt-20261008.json`.
This is inert staging, not an app update or signed catalog selection.
- Preserve historical catalog signatures and all old failure journals. Require
reviewed local/ngit/Gitea main and applicable release refs to match before
catalog activation. Parent owns source acceptance and signature coordination;
check the existing signature request before requesting a new one.
## Fresh preflight before delivery mutations
The retained fresh inventory is
`~/.local/state/archipelago/release-qualification/indeehub-yaya-fresh-preflight-20261008/`.
It confirmed all seven legacy members running, original Quadlet hashes unchanged
and frontend/API pins matching their import receipt. Refresh relevant bindings
before generating/applying the final plan; an earlier snapshot is not a lease.
1. Verify actual hostname `yaya-server`, rootless Podman owner/storage, current
backend artifact/helper hashes and free durable disk capacity. The qualified
executable above is a fixture build, not an optimized release artifact.
2. Capture fresh seven-container IDs/images/start times, original Quadlet bytes,
exact volume identities, package state, lifecycle lock/journals/holds, operator
stop/uninstall intent, node identity/session hashes, active catalogs/drop-ins
and unrelated app/service identities. Compare to the retained baseline; any
unexpected drift requires review. Never print private manifests or secrets.
3. Verify frontend/API local alias@digest IDs against their import receipt. Verify
the worker archive, all OCI blob hashes and exact qualified digest. Do not pull
an unreviewed replacement or repoint an existing alias to another image.
4. Resolve the API registration manifest using the existing node identity through
the qualified registration-pin path. Registration and publication flags remain
false. Preserve existing secrets, JWT identity and public installation pin.
5. Generate a new exact original-hash-bound seven-member plan from fresh units,
using the frozen candidate for frontend, API **and worker**, with existing
dependency image digests preserved. Review the full unit/manifest delta.
Merely changing image tags or reusing the archived October 7 plan is invalid.
The offline draft planner is in
`~/.local/state/archipelago/release-qualification/indeehub-delivery-tools-20261008/`.
It explicitly reports `activation_ready=false`: its original-state inputs are
archived, public registration pins are unresolved, and signature/final live
plan checks remain open. The earlier draft predates the completed worker import;
its false readiness flag is preserved rather than presented as a current import
failure. A new plan must bind fresh live evidence. Draft SHA256
`aae8cdeca470b30481042c62f040435aa2292180cb54f0f4496d86a2204c4b8b`.
All three delivery image pins and frontend hooks match the frozen candidate.
This corrects an old planner assumption that would otherwise retain the legacy
worker. It is preparation, not an executable deployment authorization flag.
## Qualified activation sequence
Native success/rollback qualification and inert worker import are complete.
Do not repeat import merely because the earlier prepared plan still records false
flags. Reverify the exact staged alias/digest against its receipt before delivery.
After the production artifact finishes and passes its frozen-input/hash checks,
the reviewed inert staging and existing-node API registration pin preparation
completed using `/tmp/indeehub-stage-production-and-prepare-pin.py`; do not repeat
that completed step.
Finish source/mirror/signature gates and review the fresh seven-member plan.
Deploy the reviewed matching backend/helper artifact through the existing
preserving deployment procedure. Install only the exact reviewed plan and
verified signed private candidate; preserve previous catalog/drop-in bytes.
Confirm catalog selection alone has not replaced any existing app runtimes.
Run **one** `package.update` for `indeedhub`. The native supervised operation must
capture local writable-layer recovery images, acquire its maintenance barrier,
drain all seven writers, create fresh coherent backups and prove fresh database
and volume restore before target startup. Do not substitute an ad hoc volume tar,
manually pause live writers, or perform a separate API update. Monitor the same
operation to a proven terminal outcome; a caller timeout is not proof that
background recovery failed or completed. Never start another update to recover
an unfinished one.
## Acceptance before handing over the test link
Require Committed with cleanup complete, released maintenance, exact saved target
units/images, seven healthy runtimes, and unchanged identity/session, volumes,
unrelated apps and operator intent. Verify original107 migrations are retained
with exactly3 approved additions, data/media preserved, new API settings/pins
actually used, one current provider script, and publication flags still false.
On Yaya's real desktop/mobile UI, check original Nostr login identity, Browse,
Backstage saved media/projects and free authenticated playback. Give the user
Yaya's actual launch link only after these checks pass. Keep paid checkout,
producer payout, discovery/announcement and timed paid viewing acceptance open;
none is required to spend funds merely to expose private app testing.
If failure occurs, use only the supported operation-bound native recovery and
inspect its exact journal/holds. Preserve data written after cutover; never
reinstall, wipe/recreate wallets, run migration-down or restore old DB/media over
new writes automatically. Retain private recovery images, backups and receipts.
## Concrete operator-signing preparation
The current worker-inclusive unsigned catalog has not been signed. The prior
October7 signing request was unanswered and named the older frontend/API-only
candidate; it cannot establish approval/signature for the current payload.
The independently reviewed helper is:
`~/.local/state/archipelago/release-qualification/indeehub-delivery-tools-20261008/sign-reviewed-worker-catalog.py`.
Helper SHA256: `2711cfc060b71dcb7c7397a62a65971645ff861e8db3670f960c5b13baf5c13f`.
Canonical unsigned payload SHA256:
`d373968ee7043242fc954c3b1f114e236dc21f8749ea584a00360bb4db48fe30`.
Read-only pinned-input/verifier preflight passes. Noninteractive signing refuses.
The helper uses hidden operator-terminal input, makes terminal-echo fallback
fatal, passes the phrase only through the pinned ceremony executable's stdin,
and verifies the expected root and exact payload. It preserves the immutable
unsigned input and creates a separate signed output without replacing an existing
file. No secret was read, signing performed or new operator request sent during
preparation. Finish the build/source/review gates before requesting this final
operator step; never request a mnemonic in chat.
## Passed production artifact and live preparation
The optimized release build exited successfully with all 536 qualified inputs
unchanged against the 2,031-test snapshot. Executable SHA256:
`75d4562ba606c48704ffe886f31de2b2fbe6fee81a5eb2d46371118df29ef50b`
(75,754,632 bytes). Exact embedded helper SHA256:
`6fc3f978cb88dbf022dc5bc07eaf0337c6b6b79ff42b20cee7b33ed7c100b879`.
An independent inode copy, helper and build receipt are retained privately at
`~/.local/state/archipelago/private-artifacts/indeehub-production-backend-75d4562b-20261008/`.
The reviewed staging/pin runner completed on actual `yaya-server`. It verified
the executable contains the exact helper bytes, staged both without activation,
and used only the existing node identity to prepare the stable public API pin.
All 31 runtime IDs/start times/statuses, identity/session, operator intents,
catalogs and management service remained unchanged. Registration/publication
remain false. Relative to the earlier 30-runtime import baseline, an unrelated
`justworks` runtime was added (`localhost/archipelago-justworks:0.1.0`, created
2026-10-08T12:42:16.228360672Z); all original 30 were independently unchanged.
The new app must also be preserved by deployment. Pin evidence:
`~/.local/state/archipelago/release-qualification/indeehub-production-pin-preparation-20261008/`.
Fresh live original units remain unchanged, all seven target image references
resolve locally, and the four unchanged dependency references resolve to their
current runtime image IDs. The exact fresh seven-member plan is retained under
`~/.local/state/archipelago/release-qualification/indeehub-yaya-final-plan-20261008/`:
`reviewed-unit-plan.draft.private.json`, SHA256
`f26b469a84833121db8df7e23e709d08eb6f40d9d12ddcb1b4263b685b398816`.
Worker app version is 1.0.1. API typed defaults were checked using the reviewed
strict canonicalization and all three public values bind to the live Yaya pin.
The plan has not been installed; final source/mirror, signature and plan review
remain required before activation.
Reviewed concrete tools are archived at
`~/.local/state/archipelago/release-qualification/indeehub-yaya-delivery-tools-reviewed-20261008/`.
They are source/syntax reviewed, not executed: preserving backend/helper/catalog
activation; one-shot native update with a durable no-resubmission marker;
independent runtime/identity/unit/image checks; and read-only database comparison.
Activation first refuses stopped/missing runtimes, existing plans/selectors,
pending journals/holds and inconsistent crash snapshots. It backs up the old
artifacts, stops management only, installs the matching helper before native
original-recipe preparation, then starts the matching backend with the reviewed
signed private selector. All existing app runtimes must remain unchanged until
the separate native update is explicitly submitted. Partial failures retain
private logs and do not automatically restore data or retry.
Execute database acceptance **before browser authentication**, since login can
legitimately change original database rows. It requires the exact committed
operation, original 107 migrations plus exactly three approved additions,
unchanged original table schemas/rows and all persistent volume identities.
Unexplained drift is a failed/inconclusive acceptance check, never authorization
to migrate, erase or restore data. Media/browser acceptance remains separate.