docs(runbook): fix the mail tranche's section number and refresh what remains #397

Sammanfogat
supernaut sammanfogade 1 incheckning från docs/rename-register-numbering in i main 2026-08-06 08:09:43 +00:00
Ägare

Documentation only.

1. §5 mail was the wrong number

The mail move landed on 2026-08-05 logged as "§5 mail". It is §4 — the register's §4 is
"Hostnames, TLS and mail", and §5 is "Data-carrying objects — migrate, never rename".

I introduced this on 08-05, carrying the label in from a session plan without checking it against the
register. It matters more than a wrong cross-reference usually would: read literally, the register
announced that §5 was complete, when §5 has not been started and is the riskiest tranche left —
the one where editing a declaration creates a second empty volume rather than renaming the full
one. Every other §5 reference in the runbook (lines ~4415, ~4422, ~4481, ~4837) correctly means
data-carrying objects, so the register contradicted the rest of the document.

Corrected in both places, keeping a note of the old label so this can be reconciled against the
session plans in the private repo, which still say "§5".

2. "What remains" was stale

It still named §1 (Kanidm domain) and §4 (hostnames/TLS/mail) as outstanding. Both are done — §1 on
08-04, §4 across 08-04 and 08-05.

Replaced with a table of the six tranches actually remaining, each carrying the reason it is not
merely an edit, since that is the part that gets lost between sessions:

  • §1b — a Kanidm client id is not renamable; delete + recreate + fresh secret, SSO down by design
  • §3 — re-push or retag before repointing; never re-cut an existing release tag
  • §7 — renaming the ntfy topic silently stops notifications until every device resubscribes
  • §5 — editing a declaration creates a second empty object; migrate, never rename
  • §8b — connection.local.yml is gitignored; rename the directory and Ansible loses the host
  • §8c — instance_name feeds two ForceNew attributes and replaces both VMs

Plus §9/§10 close-out, and the seven service-account addresses (#390) noted as separately tracked.

Documentation only. ## 1. `§5 mail` was the wrong number The mail move landed on 2026-08-05 logged as **"§5 mail"**. It is **§4** — the register's §4 is "Hostnames, TLS and mail", and **§5 is "Data-carrying objects — migrate, never rename"**. I introduced this on 08-05, carrying the label in from a session plan without checking it against the register. It matters more than a wrong cross-reference usually would: read literally, the register announced that §5 was complete, when §5 has not been started and is the **riskiest tranche left** — the one where editing a declaration creates a second **empty** volume rather than renaming the full one. Every other `§5` reference in the runbook (lines ~4415, ~4422, ~4481, ~4837) correctly means data-carrying objects, so the register contradicted the rest of the document. Corrected in both places, keeping a note of the old label so this can be reconciled against the session plans in the private repo, which still say "§5". ## 2. "What remains" was stale It still named §1 (Kanidm domain) and §4 (hostnames/TLS/mail) as outstanding. Both are done — §1 on 08-04, §4 across 08-04 and 08-05. Replaced with a table of the six tranches actually remaining, each carrying the reason it is not merely an edit, since that is the part that gets lost between sessions: - **§1b** — a Kanidm client id is not renamable; delete + recreate + fresh secret, SSO down by design - **§3** — re-push or retag before repointing; never re-cut an existing release tag - **§7** — renaming the ntfy topic silently stops notifications until every device resubscribes - **§5** — editing a declaration creates a second **empty** object; migrate, never rename - **§8b** — `connection.local.yml` is gitignored; rename the directory and Ansible loses the host - **§8c** — `instance_name` feeds two ForceNew attributes and **replaces both VMs** Plus §9/§10 close-out, and the seven service-account addresses (#390) noted as separately tracked.
supernaut lade till 1 incheckning 2026-08-06 08:08:42 +00:00
docs(runbook): fix the mail tranche's section number and refresh what remains
Alla kontroller lyckades
ci / ci (pull_request) Successful in 16s
2766067dcd
Two corrections to the switchover register.

The mail move was logged as "§5 mail". §5 is data-carrying objects —
volumes, the unix user, /home/gitborg, Postgres, the podman secrets. Mail
belongs to §4, "Hostnames, TLS and mail". The mislabel came in from a
session plan and I carried it into the register on 08-05. Read literally
it claimed the riskiest outstanding tranche was finished, when §5 has not
been started and is the one where editing a declaration creates a second
EMPTY object. Corrected in both places, with the old label noted so the
next reader can reconcile it against the plan docs.

The "what remains" paragraph still listed §1 and §4 as outstanding; both
have been done since 08-04/08-05. Replaced with a table of the six
tranches actually left, each with the reason it is not just an edit —
the client id that cannot be renamed, the ntfy topic that silently stops
notifying, the declaration that creates an empty volume, the gitignored
inventory file, and instance_name replacing both VMs. Adds the
service-account addresses (#390) as separately tracked.
supernaut sammanfogade incheckning 240093fc14 till main 2026-08-06 08:09:43 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!397
Ingen beskrivning angiven.