Commit Graph

3260 Commits

Author SHA1 Message Date
rcourtman 3487b9a98e Require collected negative control convergence 2026-07-14 20:14:35 +01:00
rcourtman 960e9f5e89 Bound Patrol finding verbosity 2026-07-14 19:58:03 +01:00
rcourtman 12f317364a Separate Watch restart detection from investigation 2026-07-14 19:51:53 +01:00
rcourtman 3f94a8f302 Preserve restart evidence in Patrol scope 2026-07-14 19:47:16 +01:00
rcourtman 6e71bcb151 Preserve resolved provider in qualification scoring 2026-07-14 19:38:25 +01:00
rcourtman 739b0c92d4 Align Patrol quiet-run tool contracts 2026-07-14 19:30:45 +01:00
rcourtman 9ea8cb2aa1 Clarify Patrol scope identities and finding reads 2026-07-14 19:23:36 +01:00
rcourtman e008343b7a Align Docker host query schema and executor 2026-07-14 19:13:11 +01:00
rcourtman 3b1bc65b43 Separate Watch symptoms from injected fault targets 2026-07-14 19:02:32 +01:00
rcourtman aa0f9ea5a7 Require collected fault convergence before Patrol 2026-07-14 18:56:06 +01:00
rcourtman 2b271e3e20 Repair disposable dependency qualification fixtures 2026-07-14 18:49:25 +01:00
rcourtman 44d8614330 Bound Patrol finding summary turns 2026-07-14 18:35:17 +01:00
rcourtman d1e8aece7d Price reviewed OpenRouter qualification routes 2026-07-14 18:24:33 +01:00
rcourtman 090e6fde64 Separate finding writes from infrastructure verification 2026-07-14 18:19:03 +01:00
rcourtman ee9d4b1071 Reserve Patrol reporting turn for confirmed symptoms 2026-07-14 18:10:00 +01:00
rcourtman e0edc520b7 Release Stripe proof audit work claim 2026-07-14 18:07:53 +01:00
rcourtman f6a289f72d Make Patrol report confirmed health failures 2026-07-14 18:04:09 +01:00
rcourtman 7f2c0380c6 Claim read-only Stripe proof audit 2026-07-14 17:59:51 +01:00
rcourtman dc416dd9be Claim Patrol Watch evidence contract work 2026-07-14 17:49:52 +01:00
rcourtman 1f9410a10b Release commercial coherence work claim 2026-07-14 17:39:49 +01:00
rcourtman f63a58b9a8 Release Patrol provider resilience work claim 2026-07-14 17:36:58 +01:00
rcourtman 728d09769c Preserve qualification artifacts for bounded transcripts 2026-07-14 17:31:05 +01:00
rcourtman f1adb00d90 Govern license runtime commercial config 2026-07-14 17:29:05 +01:00
rcourtman 7deaf60b37 Harden Patrol provider streams and runtime scoring 2026-07-14 17:20:56 +01:00
rcourtman 206b68cc94 Clarify commercial offer boundaries 2026-07-14 17:18:14 +01:00
rcourtman 085f5abe0d Claim Patrol provider stream resilience work 2026-07-14 17:11:45 +01:00
rcourtman 8f31fec341 Release Patrol headless projection work claim 2026-07-14 17:08:43 +01:00
rcourtman e56561b76a Refresh canonical resources after headless agent reports 2026-07-14 17:03:14 +01:00
rcourtman a05e905381 Govern commercial transition convergence 2026-07-14 16:59:28 +01:00
rcourtman e98eaebf43 Claim commercial transition coherence work 2026-07-14 16:47:56 +01:00
rcourtman 630481aeca Release Patrol qualification evidence work claim 2026-07-14 16:45:33 +01:00
rcourtman 93fff4f1d8 Add an explicit operator override for plaintext HTTP to non-local Pulse hosts
Fleets on networks numbered from nominally public IP space (issue
#1522: an AD estate on 192.20.0.0/16) cannot pass the agent's
local-network plaintext heuristic, and the only workaround was pointing
a .internal DNS alias at the server, which bypasses the same control
less visibly than a flag would. --allow-plaintext-http
(PULSE_AGENT_ALLOW_PLAINTEXT_HTTP) records process-wide consent once at
agent startup before any module validates a URL, covers every agent
transport including the websocket command channel, warns at startup
that the API token travels in cleartext, defaults closed, and is never
emitted by generated install commands or settable by the server.
2026-07-14 16:42:02 +01:00
rcourtman 84eff17578 Preserve Patrol evidence on provider errors 2026-07-14 16:34:19 +01:00
rcourtman 8e417010eb Release commercial invalidation work claim 2026-07-14 16:20:23 +01:00
rcourtman ae4162f8f2 Enforce installation-scoped license invalidation 2026-07-14 16:18:21 +01:00
rcourtman 623000b933 Release Patrol runtime work claim 2026-07-14 15:37:36 +01:00
rcourtman 3f45953866 Complete Patrol autonomous qualification loop 2026-07-14 15:35:48 +01:00
rcourtman f50bcce2dc Govern Relay commercial invalidation 2026-07-14 14:38:58 +01:00
rcourtman acd5637485 Drive executing-action restart recovery at startup and agent registration
RecoverExecutingActions existed with full test coverage but had no
production caller, so any typed action mid-dispatch across a server
restart (container update, start/stop/restart, host update, storage
cleanup) stayed in the executing state forever and sat in the Actions
inbox as live work, even after the agent persisted its terminal durable
receipt. Reproduced live on the dev instance with a Docker container
update (act_bf77dfe860ad3d8e4e0a91dc8eb83b44).

The router now runs a bounded, serialized recovery pass per organization
from a startup background worker, and again whenever an agent
(re)registers on the agentexec command server via a new registration
notifier, because a receipt-pending attempt can only be reconciled while
the owning agent is connected. Both triggers reuse the existing
query-only reconciliation semantics; nothing gains a resend authority.

Task 07 owns this residual; the api-contracts and agent-lifecycle
subsystem contracts now record the production trigger. The
rg-07-durable-delivery gate suite stays green, and a new router-level
test pins that a receipt-pending executing action completes from the
agent receipt without a second dispatch.
2026-07-14 14:19:19 +01:00
rcourtman 098ba4eaa9 Hash relationship identity, not observation stamps, into plan resource versions
Docker adapters restamp relationship ObservedAt/LastSeenAt on every
~15s report, and the action planner folded those stamps into the plan's
resource version, so any reviewed action against a relationship-bearing
container (start, stop, restart, and the restored update) drifted to a
409 action_plan_drift before a human could read the review dialog and
click approve. Relationship edges now count by identity (source,
target, type, active, discoverer, metadata), the same
identity-versus-timestamp boundary change emission drew for issue
#1496. Found live: the UI update journey failed with plan drift on
every attempt slower than one report cycle.
2026-07-14 12:22:02 +01:00
rcourtman 3c778e2b26 Restore one-click Docker container updates through the typed action plane
v6.1.0-rc.1 retired the legacy update endpoints before a replacement
existed, so the UI's Update button failed with an internal-jargon 410
(issue #1564). This lands the replacement end to end: update_container
is a typed agentexec operation with its own strict codec, durable
receipts, and a request digest bound to the image digest the plan
observed; the unified agent bridges execution to the Docker module's
existing pull/backup/recreate/verify/rollback implementation (which now
reports rollback attempt and outcome); and the container action
executor plans, dispatches, and reconciles the operation with declared
backup/rollback compensation truth. Containers advertise an
admin-approval update capability while an image update with a stated
current digest is detected. The legacy endpoints stay retired but
return actionable copy.

Proven live against a Colima daemon: single-container update, the
issue-1564 shared-network-namespace update, and the full UI journey
(Update button, governed review, approve, run) all completed with the
namespace preserved and the backup retained.
2026-07-14 12:19:04 +01:00
rcourtman 99c2ef22a6 Govern commercial offer and lifecycle 2026-07-14 11:54:22 +01:00
rcourtman 5d4f51c027 Key TrueNAS systems by configured connection, not reported hostname
Two TrueNAS systems that report the same hostname collapsed into one
flapping resource (#1573, #1575): systemSourceID keyed the system by the
snapshot-reported hostname, every child pool/dataset/app/VM/share/disk
was scoped under it, and the client minted the system's machine key from
the DMI serial with a hostname fallback, so serial-less systems sharing
a hostname (and DR clones sharing a serial) also fully merged in the
identity matcher.

The system source ID now scopes to the connection ID the poller passes
through NewLiveProviderForConnection; the hostname arm survives only for
fixture snapshots, which carry no connection. The ingest identity drops
the machine key entirely (DR clones share DMI serials, and vendor
placeholder serials collide across unrelated machines), the client no
longer falls back to the hostname for MachineID, and ingest skips
identity-pin completion for SourceTrueNAS so a stale pre-fix pin or a
same-named agent host's pin cannot lend the system a machine key and
re-merge what connection scoping keeps apart. Agent.AgentID and the
native metric history keys follow the source ID minus its system:
prefix, so BuildMetricsTarget keeps resolving one series.

Rows minted under the retired hostname-keyed derivation re-key once via
record-declared succession: records name their old canonical IDs in
IngestRecord.SupersededCanonicalIDs and IngestRecords applies the
existing ApplyCanonicalIDSuccessions semantics (operator state and
action audits re-key, the superseded pin drops, never while the old ID
still belongs to a live resource, journal rows are never rewritten).
Alert identities and persisted metric series under old child IDs are
not re-keyed: active alerts re-arm under the new IDs and TrueNAS host
charts are backed by native read-through history.
2026-07-14 11:51:55 +01:00
rcourtman 848b4d5038 Preserve customer data across plan downgrades 2026-07-14 11:47:25 +01:00
rcourtman 71a3b6ebcd Restore release-blocking backend contracts 2026-07-13 21:51:33 +01:00
rcourtman 252754ee4f Refresh Pulse 6.1 RC1 mobile coordinates 2026-07-13 20:27:42 +01:00
rcourtman 310ee94b0d Refresh Pulse 6.1 RC1 mobile evidence 2026-07-13 19:41:41 +01:00
rcourtman e2ec59a840 Prepare v6.1.0 RC1 release 2026-07-13 18:35:08 +01:00
rcourtman a393744894 Add in-app release highlights 2026-07-13 18:30:29 +01:00
rcourtman 7b114f4d5a Connect Patrol action handoffs to Actions 2026-07-13 17:34:12 +01:00