Commit Graph

3528 Commits

Author SHA1 Message Date
rcourtman d2bcfac2f6 Govern Stripe commercial remediation preparation 2026-07-14 21:46:32 +01:00
rcourtman c11bf5c757 Claim Stripe commercial remediation preparation 2026-07-14 21:37:29 +01:00
rcourtman 5d506d69a0 Release Patrol final lifecycle turn work 2026-07-14 21:32:30 +01:00
rcourtman b540025ef1 Reserve Patrol final finding decision turn 2026-07-14 21:07:49 +01:00
rcourtman f80439501b Claim Patrol final lifecycle turn work 2026-07-14 20:59:27 +01:00
rcourtman 4efcf8b218 Release production Stripe proof claim 2026-07-14 20:54:41 +01:00
rcourtman f2ac5f63f8 Record blocked production commercial audit 2026-07-14 20:52:31 +01:00
rcourtman 5ac8357da3 Claim production Stripe read-only proof 2026-07-14 20:41:27 +01:00
rcourtman 7b520abbaa Release Patrol Watch evidence work claim 2026-07-14 20:34:30 +01:00
rcourtman 3487b9a98e Require collected negative control convergence 2026-07-14 20:14:35 +01:00
rcourtman 960e9f5e89 Bound Patrol finding verbosity 2026-07-14 19:58:03 +01:00
rcourtman 12f317364a Separate Watch restart detection from investigation 2026-07-14 19:51:53 +01:00
rcourtman 3f94a8f302 Preserve restart evidence in Patrol scope 2026-07-14 19:47:16 +01:00
rcourtman 6e71bcb151 Preserve resolved provider in qualification scoring 2026-07-14 19:38:25 +01:00
rcourtman 739b0c92d4 Align Patrol quiet-run tool contracts 2026-07-14 19:30:45 +01:00
rcourtman 9ea8cb2aa1 Clarify Patrol scope identities and finding reads 2026-07-14 19:23:36 +01:00
rcourtman e008343b7a Align Docker host query schema and executor 2026-07-14 19:13:11 +01:00
rcourtman 3b1bc65b43 Separate Watch symptoms from injected fault targets 2026-07-14 19:02:32 +01:00
rcourtman aa0f9ea5a7 Require collected fault convergence before Patrol 2026-07-14 18:56:06 +01:00
rcourtman 2b271e3e20 Repair disposable dependency qualification fixtures 2026-07-14 18:49:25 +01:00
rcourtman 44d8614330 Bound Patrol finding summary turns 2026-07-14 18:35:17 +01:00
rcourtman d1e8aece7d Price reviewed OpenRouter qualification routes 2026-07-14 18:24:33 +01:00
rcourtman 090e6fde64 Separate finding writes from infrastructure verification 2026-07-14 18:19:03 +01:00
rcourtman ee9d4b1071 Reserve Patrol reporting turn for confirmed symptoms 2026-07-14 18:10:00 +01:00
rcourtman e0edc520b7 Release Stripe proof audit work claim 2026-07-14 18:07:53 +01:00
rcourtman f6a289f72d Make Patrol report confirmed health failures 2026-07-14 18:04:09 +01:00
rcourtman 7f2c0380c6 Claim read-only Stripe proof audit 2026-07-14 17:59:51 +01:00
rcourtman dc416dd9be Claim Patrol Watch evidence contract work 2026-07-14 17:49:52 +01:00
rcourtman 1f9410a10b Release commercial coherence work claim 2026-07-14 17:39:49 +01:00
rcourtman f63a58b9a8 Release Patrol provider resilience work claim 2026-07-14 17:36:58 +01:00
rcourtman 728d09769c Preserve qualification artifacts for bounded transcripts 2026-07-14 17:31:05 +01:00
rcourtman f1adb00d90 Govern license runtime commercial config 2026-07-14 17:29:05 +01:00
rcourtman 7deaf60b37 Harden Patrol provider streams and runtime scoring 2026-07-14 17:20:56 +01:00
rcourtman 206b68cc94 Clarify commercial offer boundaries 2026-07-14 17:18:14 +01:00
rcourtman 085f5abe0d Claim Patrol provider stream resilience work 2026-07-14 17:11:45 +01:00
rcourtman 8f31fec341 Release Patrol headless projection work claim 2026-07-14 17:08:43 +01:00
rcourtman e56561b76a Refresh canonical resources after headless agent reports 2026-07-14 17:03:14 +01:00
rcourtman a05e905381 Govern commercial transition convergence 2026-07-14 16:59:28 +01:00
rcourtman e98eaebf43 Claim commercial transition coherence work 2026-07-14 16:47:56 +01:00
rcourtman 630481aeca Release Patrol qualification evidence work claim 2026-07-14 16:45:33 +01:00
rcourtman 93fff4f1d8 Add an explicit operator override for plaintext HTTP to non-local Pulse hosts
Fleets on networks numbered from nominally public IP space (issue
#1522: an AD estate on 192.20.0.0/16) cannot pass the agent's
local-network plaintext heuristic, and the only workaround was pointing
a .internal DNS alias at the server, which bypasses the same control
less visibly than a flag would. --allow-plaintext-http
(PULSE_AGENT_ALLOW_PLAINTEXT_HTTP) records process-wide consent once at
agent startup before any module validates a URL, covers every agent
transport including the websocket command channel, warns at startup
that the API token travels in cleartext, defaults closed, and is never
emitted by generated install commands or settable by the server.
2026-07-14 16:42:02 +01:00
rcourtman 84eff17578 Preserve Patrol evidence on provider errors 2026-07-14 16:34:19 +01:00
rcourtman 8e417010eb Release commercial invalidation work claim 2026-07-14 16:20:23 +01:00
rcourtman ae4162f8f2 Enforce installation-scoped license invalidation 2026-07-14 16:18:21 +01:00
rcourtman 623000b933 Release Patrol runtime work claim 2026-07-14 15:37:36 +01:00
rcourtman 3f45953866 Complete Patrol autonomous qualification loop 2026-07-14 15:35:48 +01:00
rcourtman f50bcce2dc Govern Relay commercial invalidation 2026-07-14 14:38:58 +01:00
rcourtman acd5637485 Drive executing-action restart recovery at startup and agent registration
RecoverExecutingActions existed with full test coverage but had no
production caller, so any typed action mid-dispatch across a server
restart (container update, start/stop/restart, host update, storage
cleanup) stayed in the executing state forever and sat in the Actions
inbox as live work, even after the agent persisted its terminal durable
receipt. Reproduced live on the dev instance with a Docker container
update (act_bf77dfe860ad3d8e4e0a91dc8eb83b44).

The router now runs a bounded, serialized recovery pass per organization
from a startup background worker, and again whenever an agent
(re)registers on the agentexec command server via a new registration
notifier, because a receipt-pending attempt can only be reconciled while
the owning agent is connected. Both triggers reuse the existing
query-only reconciliation semantics; nothing gains a resend authority.

Task 07 owns this residual; the api-contracts and agent-lifecycle
subsystem contracts now record the production trigger. The
rg-07-durable-delivery gate suite stays green, and a new router-level
test pins that a receipt-pending executing action completes from the
agent receipt without a second dispatch.
2026-07-14 14:19:19 +01:00
rcourtman 098ba4eaa9 Hash relationship identity, not observation stamps, into plan resource versions
Docker adapters restamp relationship ObservedAt/LastSeenAt on every
~15s report, and the action planner folded those stamps into the plan's
resource version, so any reviewed action against a relationship-bearing
container (start, stop, restart, and the restored update) drifted to a
409 action_plan_drift before a human could read the review dialog and
click approve. Relationship edges now count by identity (source,
target, type, active, discoverer, metadata), the same
identity-versus-timestamp boundary change emission drew for issue
#1496. Found live: the UI update journey failed with plan drift on
every attempt slower than one report cycle.
2026-07-14 12:22:02 +01:00
rcourtman 3c778e2b26 Restore one-click Docker container updates through the typed action plane
v6.1.0-rc.1 retired the legacy update endpoints before a replacement
existed, so the UI's Update button failed with an internal-jargon 410
(issue #1564). This lands the replacement end to end: update_container
is a typed agentexec operation with its own strict codec, durable
receipts, and a request digest bound to the image digest the plan
observed; the unified agent bridges execution to the Docker module's
existing pull/backup/recreate/verify/rollback implementation (which now
reports rollback attempt and outcome); and the container action
executor plans, dispatches, and reconciles the operation with declared
backup/rollback compensation truth. Containers advertise an
admin-approval update capability while an image update with a stated
current digest is detected. The legacy endpoints stay retired but
return actionable copy.

Proven live against a Colima daemon: single-container update, the
issue-1564 shared-network-namespace update, and the full UI journey
(Update button, governed review, approve, run) all completed with the
namespace preserved and the backup retained.
2026-07-14 12:19:04 +01:00