docs(runbook): absorb durable knowledge from retired plans #528

Sammanfogat
supernaut sammanfogade 4 incheckningar från docs/runbook-absorb-plans in i main 2026-10-02 22:17:30 +00:00
Ägare

Move durable operational knowledge into the runbook and fix stale statements.

Runbook additions:

  • Kanidm delegation: how to prove one by hand, the 500 ReferentialIntegrity and read-only token (403) signatures (observed on 1.10.4).
  • Kanidm web UI: server-side rendered, templates compiled in. The Caddy replace-response route and its traps, and why it was rejected.
  • Account recovery paths, citation hygiene for the Kanidm book, and a link to the authentication-factors design doc in bitborg-docs.
  • The bitborg-web tile on the Kanidm dashboard cannot be hidden. Renaming a client display name is SSO-safe.
  • Self-hosted Renovate: compute guards (memory cap, window, sequential repos, metrics) and the escalation path with triggers.
  • Expected breakdown of a cold runner pickup.
  • New "Replace or shrink the services instance" subsection (state rm of the root, expected plan, abort gate, rollback).
  • New "DR key exercise" subsection (first run pending, infra#157).

Fixes:

  • Renovate section: schedule 00:30, tenant mode, bot bitborg-renovate (created by the forgejo role), bitborg_renovate_last_run_status.

  • Stale "Render app.ini diff always appears" (gone since ADR 0031).

  • Backups are encrypted to the verify recipient only when it is set.

  • Removed the invite-code section and the invite provisioning note (open registration since ADR 0029). Kept the legacy invite_codes update in the user-erasure SQL, since old rows may still name the user.

  • Dropped references to retired plan files, in the runbook and in comments in non-rendered files. No behaviour change, no apply needed.

  • Switchover status now says every tranche was applied 2026-08-09 to 2026-08-11, with the rest pinned (ADR 0039 Outcome). Tranche sections 3, 9 and 10 are marked historical. Added the never-blanket-replace gitborg_ warning (gitborg_web, gitborg_ephemeral). Conventions now names the real service user (gitborg, nologin shell) and the working sudo -u gitborg env ... recipe. Operational git.gitborg.se references changed to git.bitborg.se; the redirect measurements keep the old name.

Move durable operational knowledge into the runbook and fix stale statements. Runbook additions: - Kanidm delegation: how to prove one by hand, the 500 `ReferentialIntegrity` and read-only token (403) signatures (observed on 1.10.4). - Kanidm web UI: server-side rendered, templates compiled in. The Caddy `replace-response` route and its traps, and why it was rejected. - Account recovery paths, citation hygiene for the Kanidm book, and a link to the authentication-factors design doc in bitborg-docs. - The `bitborg-web` tile on the Kanidm dashboard cannot be hidden. Renaming a client display name is SSO-safe. - Self-hosted Renovate: compute guards (memory cap, window, sequential repos, metrics) and the escalation path with triggers. - Expected breakdown of a cold runner pickup. - New "Replace or shrink the services instance" subsection (state rm of the root, expected plan, abort gate, rollback). - New "DR key exercise" subsection (first run pending, infra#157). Fixes: - Renovate section: schedule 00:30, tenant mode, bot `bitborg-renovate` (created by the forgejo role), `bitborg_renovate_last_run_status`. - Stale "Render app.ini diff always appears" (gone since ADR 0031). - Backups are encrypted to the verify recipient only when it is set. - Removed the invite-code section and the invite provisioning note (open registration since ADR 0029). Kept the legacy `invite_codes` update in the user-erasure SQL, since old rows may still name the user. - Dropped references to retired plan files, in the runbook and in comments in non-rendered files. No behaviour change, no apply needed. - Switchover status now says every tranche was applied 2026-08-09 to 2026-08-11, with the rest pinned (ADR 0039 Outcome). Tranche sections 3, 9 and 10 are marked historical. Added the never-blanket-replace `gitborg_` warning (`gitborg_web`, `gitborg_ephemeral`). Conventions now names the real service user (`gitborg`, nologin shell) and the working `sudo -u gitborg env ...` recipe. Operational `git.gitborg.se` references changed to `git.bitborg.se`; the redirect measurements keep the old name.
supernaut lade till 4 incheckningar 2026-10-02 22:15:03 +00:00
Add Kanidm delegation probe notes, Kanidm UI and Caddy rewrite facts, recovery paths,
Renovate tenant mode and compute rationale, instance replace or shrink procedure and DR key
exercise. Drop the stale invite-code section and fix stale schedule, bot name and app.ini notes.
docs(runbook): close out the switchover status and fix the service user recipe
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m56s
3470a7a2ed
supernaut schemalade den här ändringsförfrågan för automatisk sammanfogning när alla kontroller lyckas 2026-10-02 22:16:56 +00:00
supernaut sammanfogade incheckning f2055ad70f till main 2026-10-02 22:17:30 +00:00
supernaut tog bort grenen docs/runbook-absorb-plans 2026-10-02 22:17:30 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!528
Ingen beskrivning angiven.