docs(ql3): record automation rollback artifact

This commit is contained in:
whyour
2026-09-02 00:25:43 +08:00
parent c8d9eed95d
commit 37801d2f30
3 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
# QingLong 3.0 Architecture RFC
- D-426c2/ADR-0527源码与本地 exact arm64 演练已闭合,双架构阶段实物交付):downloadable Trial Kit 新增三阶段 canonical `reconciliation-rehearsal.sh``prepare` 从 D-426c1 stopped capture 建立 bounded plan/diagnostics/strong-auth review prepare 后停在 `operator_decision_required``review` 只消费 owner-private 外部 NDJSON,完成 authorization commit/verify、application plan 与 Automation plan 后停在 `automation_decision_required``apply-rollback` 再消费独立外部 Automation row NDJSON,只应用一个无冲突 Automation 行、验证正式 Task/Trigger 投影并显式回滚,终态固定 `reconciliation_automation_rolled_back`。交付脚本永不生成 decisionCI fixture 不进入 bundleLegacy Run History 固定 `manual_external`。decision 父目录必须 current-UID `0700`、恰好一个 canonical file、与所有 authority roots 不重叠,并整体只读挂载;60 秒 authorization 不得晚于 strong principalauthentication database 必须在异步 confirm 完成后才关闭。target SQLite 必须位于 deployment root 下且避开 reconciliation sibling rootsapply/rollback 额外只读挂载 exact Legacy root,运行在 128 MiB/0.5 CPU/32 PID、无网络、只读 rootfs、drop-all/no-new-privileges 的短生命周期 Operator 中。带时间 command 和成功 result 支持中断后的 exact replay,不得静默重写。Trial Kit/verification/auditor 升为 `@v10/@v8/@v7`、manifest schemaVersion 11milestone 升为 `@v6`/schemaVersion 6,并增加 required `legacyUpgradeReconciliationAutomationRollback=passed` 与双架构 reconciliation script digest。最终本地 arm64 exact bundle 使用 Application `sha256:eec404d24b5c101871e000caac902d3866e5fe3f0e6dcef31366cb526ef32f80`、无源码覆盖 Operator `sha256:10f75f12d185e5796dcc4a230b6684c074bd9a6e6156ee1110fff1c2d8dd3390`offline audit 返回 `compatible=true`;全新 2.x fixture 贯通 readiness→stage→cutover→capture→437 条外部 review decision→1 条 Automation decision→apply/verify→rollback/verify,实际采用 1 Task/1 Trigger 后恢复应用前快照,未尝试 Secret/Config、Run History、completion 或任一重启。Docker Desktop 的只读 bind mount UID 瞬时漂移仅通过同一 inspect 一次有界重试收敛,持续错误仍 fail-closed,不放宽 Linux owner proof。该切片不新增 package、production dependency、daemon/listener/timer/watcher/连接或稳态资源;低配路由设备默认 headless 不变,Cluster 不复用 Local SQLite/POSIX/Docker authority2.x 老面板仍需独立 API/认证/领域 adapter,不能零改直连。
- D-426c2/ADR-0527exact headless 双架构阶段实物交付):downloadable Trial Kit 新增三阶段 canonical `reconciliation-rehearsal.sh``prepare` 从 D-426c1 stopped capture 建立 bounded plan/diagnostics/strong-auth review prepare 后停在 `operator_decision_required``review` 只消费 owner-private 外部 NDJSON,完成 authorization commit/verify、application plan 与 Automation plan 后停在 `automation_decision_required``apply-rollback` 再消费独立外部 Automation row NDJSON,只应用一个无冲突 Automation 行、验证正式 Task/Trigger 投影并显式回滚,终态固定 `reconciliation_automation_rolled_back`。交付脚本永不生成 decisionCI fixture 不进入 bundleLegacy Run History 固定 `manual_external`。decision 父目录必须 current-UID `0700`、恰好一个 canonical file、与所有 authority roots 不重叠,并整体只读挂载;60 秒 authorization 不得晚于 strong principalauthentication database 必须在异步 confirm 完成后才关闭。target SQLite 必须位于 deployment root 下且避开 reconciliation sibling rootsapply/rollback 额外只读挂载 exact Legacy root,运行在 128 MiB/0.5 CPU/32 PID、无网络、只读 rootfs、drop-all/no-new-privileges 的短生命周期 Operator 中。带时间 command 和成功 result 支持中断后的 exact replay,不得静默重写。Trial Kit/verification/auditor 升为 `@v10/@v8/@v7`、manifest schemaVersion 11milestone 升为 `@v6`/schemaVersion 6,并增加 required `legacyUpgradeReconciliationAutomationRollback=passed` 与双架构 reconciliation script digest。最终本地 arm64 exact bundle 使用 Application `sha256:eec404d24b5c101871e000caac902d3866e5fe3f0e6dcef31366cb526ef32f80`、无源码覆盖 Operator `sha256:10f75f12d185e5796dcc4a230b6684c074bd9a6e6156ee1110fff1c2d8dd3390`offline audit 返回 `compatible=true`;全新 2.x fixture 贯通 readiness→stage→cutover→capture→437 条外部 review decision→1 条 Automation decision→apply/verify→rollback/verify,实际采用 1 Task/1 Trigger 后恢复应用前快照,未尝试 Secret/Config、Run History、completion 或任一重启。Docker Desktop 的只读 bind mount UID 瞬时漂移仅通过同一 inspect 一次有界重试收敛,持续错误仍 fail-closed,不放宽 Linux owner proof。首次普通 CI run `33525269537` 在 x64 暴露既有兼容测试的 module-scope `TaskLimit` 异步 SQLite 初始化与临时目录清理竞态,未以重跑掩盖;隔离测试副作用的提交 `c8d9eed95d402aae642e81e60fce336670ac06a0` 后,普通主 CI [run 33526720941](https://github.com/whyour/qinglong/actions/runs/33526720941) 为 41 success/3 expected skip/0 failKubernetes [run 33526721040](https://github.com/whyour/qinglong/actions/runs/33526721040) 成功,显式 Local headless [run 33528370769](https://github.com/whyour/qinglong/actions/runs/33528370769) 为 42 success/2 scope skip/0 fail。该 run 交付 amd64/arm64/milestone artifact `9809046864`/`9809000920`/`9809293769`,大小 `226266116`/`221665796`/`6734` bytesGitHub digest 为 `sha256:bffabf76c9d7b599c5ac65dd4ff7aa8f65af6a3167a68afb497a9c8967f34c36``sha256:8b74e5e9e1437962185fb87e7b0208bf157d063af28dfb1676c59b9785b937b8``sha256:a69de90a07bc36a397b08bb567739a001ac2f830fed73860255db7de175b3527`,保留至 2026-10-01milestone v6 下载后 auditor 返回 `compatible=true`,并绑定双架构 reconciliation script digest。该切片不新增 package、production dependency、daemon/listener/timer/watcher/连接或稳态资源;低配路由设备默认 headless 不变,Cluster 不复用 Local SQLite/POSIX/Docker authority2.x 老面板仍需独立 API/认证/领域 adapter,不能零改直连。
- D-426c1/ADR-0526exact Console 双架构阶段实物已交付):downloadable `upgrade-cutover-rehearsal.sh` 保留既有 clean rollback 默认路径,并新增显式 `--capture-after-write <独立私有根>`。同一 reviewed stage/Owner/apply/target-active 链先通过正式 `task.put` 提交固定、无网络/Secret 的业务 Task,再要求 target stop 返回 `reconciliation_required`;随后以现有短生命周期 Operator 串行执行 reconciliation capture prepare/commit/verify,把 legacy、target、recovery、Application config、activation 与 exact stopped head/record 密封到外置 root。对 v4 adopted targetcapture proof 必须以 stopped evidence 中的 exact baseline digest 重新加载并核对 durable post-apply baseline,不允许丢失 baseline 维度后再比较。成功 summary 固定 `reconciliation_captured``legacySource=unchanged``target=stopped``rollback=not_authorized``next=review_required`,不自动回退或应用。Trial Kit/verification/auditor 升为 `@v9/@v7/@v6`、manifest schemaVersion 10,并增加 required `legacyUpgradeReconciliationCapture=passed`;原生 artifact job 必须在保留 clean rollback 演练的同时,用独立目录/容器第二次实跑写后 capture 并验证 manifest/receipt/assets 后才能上传。首次 artifact run `33467541901` 在真实 arm64 上走到 `reconciliation_required` 后暴露 adopted baseline 重算缺口,finalizer 正确未形成;修复提交 `0235973c9b54a2f22de09b6487ea9f184f0b8bfd` 的普通主 CI [run 33469372499](https://github.com/whyour/qinglong/actions/runs/33469372499) 为 41 success/3 expected skip/0 failKubernetes [run 33469372500](https://github.com/whyour/qinglong/actions/runs/33469372500) 成功,显式 Console [run 33469435652](https://github.com/whyour/qinglong/actions/runs/33469435652) 为 42 success/2 scope skip/0 fail。该 run 交付 amd64/arm64/milestone artifact `9786301280`/`9786374284`/`9786520389`,大小 `226683392`/`222083072`/`6489` bytes,保留至 2026-10-01;两个原生 job 在上传前离线审计 exact bundlefinalizer 再下载并复核二者,本机重新下载的 milestone v5 通过 `SHA256SUMS` 与 auditor,返回 `compatible=true` 并绑定 `3.0.0-alpha.2``console`、同一 source/workflow/run/attempt。内部 Docker archive digest 为 amd64 `sha256:3c9f7dac623bacd4b88b933a3668cfe74526a9fc4fe73823f821535a11aba3f4`、arm64 `sha256:68ee76d6f0a20f876da4ccfef96bb58f08aa965969d44ed587f3df37536529db`。该切片不修改核心 classifier、不新增 package/依赖/daemon/listener/timer/watcher/连接或稳态资源;低配路由器默认 headless 不变。它证明的是 active target 数据权威经 Owner 产品入口发生写入后的 fail-closed capture,不冒充普通 Local API listener、2.x 老面板、自动 reconciliation、生产升级或 Public Release。
@@ -45,7 +45,7 @@ ADR-0526 已把 active target 的真实产品写入密封为独立 reconciliatio
- 聚焦回归覆盖 strong-principal expiry、authentication database close fence、target path containment、短 authorization namespace、decision file private parent、命令/结果精确重放,以及 CI fixture 不进入 bundle。
- 本机完整 backend 回归为 `1667 total / 1665 pass / 0 fail / 2 conditional skip`18 个 QL3 package clean build、package boundary、cluster dependency 与 image audit 均通过。PostgreSQL 18.6 arm64 HA Docker 门进一步完成 timeline `1→2` promotion 与 147 项检查,私有报告摘要为 `sha256:68e2f60b962ac62cee3c70bf759fccb6f8080541264427a4ea66bf8f586707db`
- 本机 exact arm64 headless Trial Kit 使用最终 Application `sha256:eec404d24b5c101871e000caac902d3866e5fe3f0e6dcef31366cb526ef32f80` 与无源码覆盖的 Operator `sha256:10f75f12d185e5796dcc4a230b6684c074bd9a6e6156ee1110fff1c2d8dd3390`,离线 audit v7 返回 `compatible=true`。全新 2.x fixture 已贯通 readiness、stage、cutover、post-write capture、437 条外部 review 决定、1 条外部 Automation 决定、apply/verify 与 explicit rollback/verify;最终实际采用 1 个 Task、1 个 Trigger并返回 `reconciliation_automation_rolled_back`,且未尝试 completion、restart、Secret/Config 或 Run History mutation。
- 该本机证据是工程闭合,不冒充 GitHub workflow provenance 或双架构阶段实物。只有普通 CI、Kubernetes/Cluster 门与显式 amd64/arm64 artifact finalizer 全部成功后,D-426c2 才升级为可下载阶段产物。
- 提交 `c8d9eed95d402aae642e81e60fce336670ac06a0` 的普通主 CI [run 33526720941](https://github.com/whyour/qinglong/actions/runs/33526720941) 为 41 success/3 expected skip/0 failKubernetes [run 33526721040](https://github.com/whyour/qinglong/actions/runs/33526721040) 成功;显式 Local headless [run 33528370769](https://github.com/whyour/qinglong/actions/runs/33528370769) 为 42 success/2 scope skip/0 fail。amd64/arm64/milestone artifact `9809046864`/`9809000920`/`9809293769` 保留至 2026-10-01,下载后的 milestone v6 auditor 返回 `compatible=true` 并绑定 exact source/run/attempt、两个不同 archive digest 与两个不同 reconciliation script digest。D-426c2 因此已是可下载阶段产物,但仍不是 Public Release 或生产升级授权
## 后续
+2 -2
View File
@@ -35,7 +35,7 @@
| D-426b2b Exact headless 切换链 | 同源 v8 Trial Kit 已交付 amd64/arm64 headless 阶段实物;exact 上传包完成 readiness、reviewed stage、Owner 强认证 transform/apply、真实 legacy stop、只读 target probe start/stop 与 clean `rollback_candidate`milestone v5 和三个离线 auditor 均闭合 | 仅授权 fresh/隔离数据演练;不停止用户真实 2.x、不执行 Legacy restart、写后 reconciliation 或生产 cutover;仍不是 Public Release |
| D-426b2c Console adopted entry | 同源 exact amd64/arm64 Console Trial Kit 与 milestone 已交付;Local API cutover probe 不启动 listener/credential/mutationcontroller 绑定双层配置、exact command/mount,原生 CI 完整演练且三个下载产物离线审计通过 | 仅授权 fresh/隔离数据演练;正常 Console 启动与只读 cutover probe 是不同模式;不承诺 2.x 老面板 API 零改动兼容、真实生产停机或写后回退 |
| D-426c1 写后 reconciliation capture | 同源 Console Trial Kit v9 的 amd64/arm64 实物与 milestone 已交付;active target 数据权威经 Owner `task.put` 发生业务写入后分类为 `reconciliation_required`,并在独立私有 root 完成 capture prepare/commit/verify;双架构原生审计和 milestone v5 均闭合 | 停在 `review_required`,不自动 plan/review/apply/rollback/restart;不证明普通 Local API 流量接管、用户真实 2.x 升级或 Public Release |
| D-426c2 受审核 Automation apply/rollback | Trial Kit v10 源码与本地 exact arm64 工程演练已闭合;三阶段脚本只消费外部 owner-private decision,贯通 capture→437 条 review decision→1 条 Automation decision→1 Task/1 Trigger apply/verify→explicit rollback/verify,保持 128 MiB/0.5 CPU/32 PID、无网络、只读 rootfs | 双架构 GitHub artifact/milestone v6 尚待本提交远程 CI不应用 Secret/Config、Run History,不执行 completion/restart,不是 2.x 老面板 compatibility layer 或生产升级包 |
| D-426c2 受审核 Automation apply/rollback | Trial Kit v10 exact amd64/arm64 headless 实物与 milestone v6 已交付;三阶段脚本只消费外部 owner-private decision,贯通 capture→437 条 review decision→1 条 Automation decision→1 Task/1 Trigger apply/verify→explicit rollback/verify,保持 128 MiB/0.5 CPU/32 PID、无网络、只读 rootfs | 不应用 Secret/Config、Run History,不执行 completion/restart,不是 2.x 老面板 compatibility layer 或生产升级包 |
D-421 已关闭 D-420 记录的“Web Task mutation 必须独立设计”缺口,而且没有改名复用 run `33173769047` 的旧 archive。修复提交 `dc1686bd6fb3505174dd9a14098ae5c2c92a1a7f` 的普通主 CI [run 33229592307](https://github.com/whyour/qinglong/actions/runs/33229592307) 为 41 success/3 expected artifact-finalizer skip/0 fail,同源 Kubernetes deployment [run 33229592293](https://github.com/whyour/qinglong/actions/runs/33229592293) 成功;随后显式 Local Console milestone [run 33230227006](https://github.com/whyour/qinglong/actions/runs/33230227006) 为 42 success/2 scope skip/0 fail。由此 Web 创建能力已进入新的阶段实物,而不再只是候选源码。
@@ -55,7 +55,7 @@ D-426b2c 已从“源码候选”升级为新的可交付 Console 阶段实物
D-426c1 已从失败关闭的源码候选升级为新的可交付 Console 阶段实物。首次 [run 33467541901](https://github.com/whyour/qinglong/actions/runs/33467541901) 在真实 arm64 上证明 `task.put``reconciliation_required` 后暴露 adopted baseline 重算缺口,finalizer 正确未形成;修复提交 `0235973c9b54a2f22de09b6487ea9f184f0b8bfd` 的普通主 CI [run 33469372499](https://github.com/whyour/qinglong/actions/runs/33469372499) 为 41 success/3 expected skip/0 fail,同源 Kubernetes [run 33469372500](https://github.com/whyour/qinglong/actions/runs/33469372500) 成功,显式 Console [run 33469435652](https://github.com/whyour/qinglong/actions/runs/33469435652) 为 42 success/2 scope skip/0 fail。amd64/arm64/milestone artifact ID 为 `9786301280`/`9786374284`/`9786520389`,大小为 `226683392`/`222083072`/`6489` bytesGitHub ZIP digest 为 `sha256:49e921cb251da8cec3dcee5308174dd8aca89ffa18a3df6e6c7d0f43095c6f70``sha256:4ff7d3fff5af16ca55350d0dbf14c35d8ddcdeecb7d395ba017a14081949e0e8``sha256:d69c769117268fe8559043bb62999549d215c12f353e34c51d32d22ce319dd4c`,保留至 2026-10-01。两个原生 job 在上传前各自执行 exact bundle offline auditorfinalizer 再下载并复核二者。本机重新下载的 milestone 通过 checksumauditor 返回 `compatible=true`,内部 Docker archive digest 为 amd64 `sha256:3c9f7dac623bacd4b88b933a3668cfe74526a9fc4fe73823f821535a11aba3f4`、arm64 `sha256:68ee76d6f0a20f876da4ccfef96bb58f08aa965969d44ed587f3df37536529db`。该产物已能 fresh 运行内置 3.0 Console,并证明隔离切换后的写入必须进入 capture/review;它仍不兼容 2.x 老面板协议、不自动应用 reconciliation,也不是生产升级包。
D-426c2 当前已经形成可重建的工程候选,但尚未冒充远程阶段实物。本地 exact arm64 headless bundle 使用 Application `sha256:eec404d24b5c101871e000caac902d3866e5fe3f0e6dcef31366cb526ef32f80`无源码覆盖 Operator `sha256:10f75f12d185e5796dcc4a230b6684c074bd9a6e6156ee1110fff1c2d8dd3390`offline auditor v7 返回 `compatible=true`。全新 2.x fixture 已走通 readiness、reviewed stage、exact cutover、post-write capture、强认证 review、Automation apply/verify 与 explicit rollback/verify,终态 `reconciliation_automation_rolled_back`,采用 1 Task/1 Trigger 后恢复应用前快照completion、target/Legacy restart、Secret/Config 和 Run History mutation 均为 `not_attempted`本机完整 backend 为 `1667 total / 1665 pass / 0 fail / 2 conditional skip`PostgreSQL 18.6 arm64 HA Docker 门以 timeline `1→2` 和 147 项检查通过。远程普通 CI、Kubernetes 门、原生 amd64/arm64 artifact 和 milestone v6 finalizer 全部通过后,才能把这里的“工程候选”升级为可下载 D-426c2 阶段产物。
D-426c2 已从工程候选升级为可下载的 headless 双架构阶段实物。本地 exact arm64 演练使用 Application `sha256:eec404d24b5c101871e000caac902d3866e5fe3f0e6dcef31366cb526ef32f80` 与 Operator `sha256:10f75f12d185e5796dcc4a230b6684c074bd9a6e6156ee1110fff1c2d8dd3390`;完整 backend 为 `1667 total / 1665 pass / 0 fail / 2 conditional skip`PostgreSQL 18.6 arm64 HA Docker 门以 timeline `1→2` 和 147 项检查通过。首次普通 CI [run 33525269537](https://github.com/whyour/qinglong/actions/runs/33525269537) 在 x64 暴露既有兼容测试的异步 SQLite 初始化/临时目录清理竞态;没有用重跑掩盖,提交 `c8d9eed95d402aae642e81e60fce336670ac06a0` 隔离该测试副作用后,普通主 CI [run 33526720941](https://github.com/whyour/qinglong/actions/runs/33526720941) 为 41 success/3 expected skip/0 failKubernetes [run 33526721040](https://github.com/whyour/qinglong/actions/runs/33526721040) 成功。显式 Local headless [run 33528370769](https://github.com/whyour/qinglong/actions/runs/33528370769) 为 42 success/2 scope skip/0 fail,交付 amd64/arm64/milestone artifact `9809046864`/`9809000920`/`9809293769`,大小 `226266116`/`221665796`/`6734` bytesGitHub digest 为 `sha256:bffabf76c9d7b599c5ac65dd4ff7aa8f65af6a3167a68afb497a9c8967f34c36``sha256:8b74e5e9e1437962185fb87e7b0208bf157d063af28dfb1676c59b9785b937b8``sha256:a69de90a07bc36a397b08bb567739a001ac2f830fed73860255db7de175b3527`,保留至 2026-10-01。下载后的 milestone v6 auditor 返回 `compatible=true`,内部 archive digest 为 amd64 `sha256:c9ad0a09456defbb90a9e1e4aecbc5bf2da382173479a1db0eb50ec8e2c759c0`、arm64 `sha256:ba4e0965861b3064daee24ade6ac9316eed1d43be3037e77f2b92cdd1009942f`,并绑定两架构不同的 reconciliation script digest。该实物证明 437 条 review decision、1 条 Automation decision、1 Task/1 Trigger apply/verify 与 explicit rollback/verify,终态 `reconciliation_automation_rolled_back`completion、target/Legacy restart、Secret/Config 和 Run History mutation 均为 `not_attempted`
默认低配 headless v5 也已从“可生成”升级为独立阶段实物。绑定提交 `d459c3b45c36e856f4a1cb3ce5147905977d939d` 的显式 Local headless milestone [run 33258604609](https://github.com/whyour/qinglong/actions/runs/33258604609) 为 42 success/2 scope skip/0 fail,完整矩阵继续覆盖双架构资源、Local/Cluster image、PostgreSQL HA、CloudNativePG、Secret/provider rotation 与 Local Profiles。该 run 没有复用 Console archive;下载后的两个 `headless` Trial Kit 与 milestone 均通过 `SHA256SUMS` 和仓库 auditor,返回 `compatible=true`