Jon Chery
11da458883
test(cli): --host-key-fingerprint non-proxmox validation (T02.11, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 12:04:28 +00:00
Jon Chery
d66b3b9a0a
test(proxmox,cli): end-to-end trust-surface integration tests (T02.10, REQ-058, REQ-059)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 12:04:24 +00:00
Jon Chery
2dcb14377a
fix(doctor): TOFU capture-fix parity with bootstrap — v0.6 ship-defect (T02.9)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:56:45 +00:00
Jon Chery
13e6762f0f
feat(cli): orca node key-reset <node> — local known_hosts reset (T02.8, REQ-059)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:51:47 +00:00
Jon Chery
325a5662f4
feat(proxmox): populate Result.HostKeyFingerprint (T02.7, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:48:00 +00:00
Jon Chery
8b0cbe10ae
fix(proxmox): TOFU capture bug — v0.6 ship-defect first-connect join always failed (T02.6)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:46:38 +00:00
Jon Chery
bd17e6e114
feat(proxmox): pinnedHostKeyCallback for --host-key-fingerprint (T02.5, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:45:53 +00:00
Jon Chery
7cb12c52ce
feat(proxmox): HostKeyFingerprint field on Options (T02.4, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:38:39 +00:00
Jon Chery
08481d35ce
feat(cli): --host-key-fingerprint flag on node join (T02.3, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:37:01 +00:00
Jon Chery
00869c6f5b
refactor(security): export WriteAtomic (T02.2, REQ-059)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:36:42 +00:00
Jon Chery
aa3462826b
feat(security): SSHFingerprintSHA256 helper (T02.1, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:35:59 +00:00
Jon Chery
dea358d40b
verify(P01): 4-layer verification PASS — REQ-057 covered
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: verify
requirements:
covered: [REQ-057]
partial: []
---/ci---
v0.7.1
2026-08-04 01:51:26 +00:00
Jon Chery
367a338a72
test(P01): coverage-gate verification — all 9 packages hit tiered floor (T01.12, REQ-057)
...
>=70%: engine 88.9%, proxmox 87.1%, cli 76.2%, transport 93.0%,
store 84.7%, jobspec 90.5%
>=50%: audit 100.0%, certpaths 100.0%, cmd/orca 80.0%
go test -race ./... PASS. GRILL escape valve NOT needed.
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
requirements:
covered: [REQ-057]
partial: []
---/ci---
2026-08-04 01:49:15 +00:00
Jon Chery
2ce6622055
test(cmd/orca): smoke test ≥50% toe-hold, main→run refactor (T01.11, REQ-057)
...
Refactor main() into run() int (main calls os.Exit(run())) so the test
can exercise the CLI directly without os.Exit terminating the test
process. Add main_test.go with two cases: run() success path (version
command → exit 0) and run() error path (job run with missing spec →
exit 1, stderr contains "error:"). Low-effort toe-hold per RESEARCH
§1.1/§1.4 — do not over-invest in glue-code coverage.
Coverage: go test -cover ./cmd/orca → 80.0% (was 0%, target ≥50%).
go test -race PASS.
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:43:57 +00:00
Jon Chery
6408342a7f
test(cli): coverage uplift to ≥70% excl daemon.go (T01.6, REQ-057)
...
Add table-driven rootCmd.Execute() tests for the node, job, cert,
doctor, audit, status, version, and node-capacity subcommand families.
Each test runs against a temp ORCA_HOME and asserts stdout/stderr/exit
via the existing initTestEnv/resetRootFlags/discardWriter helpers
(RESEARCH §1.2). extend resetRootFlags to also reset the per-command
flag-bound globals so tests don't leak state between runs.
daemon.go is excluded from the ≥70% target (documented in node_test.go):
the daemon command starts a long-running mTLS server whose lifecycle is
covered by internal/daemon/server_test.go; only its --pprof flag
registration is verified here (daemon_test.go).
Coverage: go test -cover ./internal/cli → 76.2% overall (78.7% by
-func), which includes daemon.go's untested RunE; the non-daemon files
exceed 70% comfortably. go test -race PASS.
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:43:38 +00:00
Jon Chery
2d47cd9135
test(audit): first tests, ≥50% toe-hold (T01.9, REQ-057)
...
internal/audit/audit_test.go was added in d9d0bed (Wave 1 P03 uplift)
and already achieves 100.0% coverage — well above the ≥50% toe-hold
target. This empty commit records T01.9 acceptance for the Wave 2
task ledger; no code change was required.
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:13:46 +00:00
Jon Chery
9727edf4df
test(certpaths): first tests, ≥50% toe-hold (T01.10, REQ-057)
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:13:43 +00:00
Jon Chery
e45232f395
test(jobspec): coverage uplift to ≥70% + golden HCL fixtures (T01.8, REQ-057)
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:12:59 +00:00
Jon Chery
82f3bcacfd
test(store): coverage uplift to ≥70% + missing cert_repo_test.go (T01.7, REQ-057)
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:12:12 +00:00
Jon Chery
7a834357ec
test(proxmox): coverage uplift to ≥70% (T01.5, REQ-057)
...
Extend bootstrap_test.go with FullFlow_IdempotentReRun (two
sequential bootstraps on the same fake SSH server — verifies the
idempotent no-op path end-to-end), FullFlow_NoPasswordInLogs
(asserts the SSH password never appears in slog output, D-031),
FullFlow_ValidateSudoersFails (forceSudoersInvalid flag →
wrapped 'validate sudoers' error), FullFlow_CreateLinuxUserFails
(ProxmoxUser=root exercises the /root home branch in deployPubKey),
DefaultSSHDialer_DialContext_ConnectionRefused (covers the real
defaultSSHDialer.DialContext concrete path), and
SSHSessionRunner_CombinedOutput_NewSessionError (closed-client →
'new session' error branch). Add forceSudoersInvalid knob +
funcDialer helper to ssh_session_test.go.
Coverage: 83.2% → 87.1%. go test -race PASS. No production code
changed (T01.1 sessionRunner seam already in place).
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:05:12 +00:00
Jon Chery
40906a0697
test(engine): coverage uplift to ≥70% (T01.4, REQ-057)
...
Add registry_test.go (NEW) covering NodeRegistry Join/Leave/Forget/
List/Get (success + not-found + duplicate), NewNodeRegistry nil-
logger, Audit Record success/error (sqlite-backed via openTestDB
pattern) + NewAudit nil-logger. Extend scheduler_test.go with
MemLocalNode/Capacity (happy + nil), JobSpecScore nil/over-capacity/
fits, JobSpecFits nil, PickNode empty. Extend dispatcher_test.go
with Submit error paths: bad spec, explicit target no-registry,
target peer-not-found, peer-pick missing CA, no peer registry, nil
capacity fallthrough, all-peers-fail PickNode.
Coverage: 65.1% → 88.9%. go test -race PASS. No production code
changed; T01.2 peerDispatcher seam NOT needed (error-path tests
via stubbed LocalExecutor + PeerRegistry reached 89% without it;
httptest.NewTLSServer was not required either since dispatchToPeer
CA-missing and PickNode-fail branches cover the remote path).
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:05:09 +00:00
Jon Chery
16e4f8a1f2
test(transport): coverage uplift to ≥70% (T01.3, REQ-057)
...
Add retry_test.go (NEW) covering DefaultRetryPolicy, first-attempt
success, idempotent-verb retry, idempotency-key retry, MaxAttempts
exhaustion, zero-MaxAttempts defaulting, transient+non-idempotent+
no-key bail, ctx-cancel mid-backoff, exponential backoff growth +
cap, and contains() substring helper. Extend idempotency_test.go
with Sweep, empty-key Put/Get, and empty-key WithIdempotencyKey.
Extend handshake_log_test.go with LogHandshakeFromCert happy path
(real x509 cert → fingerprint) and FingerprintOfCert round-trip.
Coverage: 84.6% → 93.0%. go test -race PASS. No production code
changed; no new seams (httptest already covered DispatchClient).
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 01:05:03 +00:00
Jon Chery
2786de166d
refactor(proxmox): extract sessionRunner seam for testability (T01.1, REQ-057)
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 00:51:15 +00:00
Jon Chery
97a10353da
docs(P00): grill v0.8 plan — PROCEED-WITH-CONDITION (4 binding fixes applied)
...
GRILL_v0.8.md (30KB): 9-axis adversarial review, overall verdict
PROCEED-WITH-CONDITION (confidence 0.78). 7 PROCEED + 4
PROCEED-WITH-CONDITION + 0 REPLAN findings.
4 binding plan changes applied to PLAN_v0.8.md:
#1 T02.6 relabeled as v0.6 ship-defect bugfix (not v0.8 feature);
P04 audit must record ship-defect closure
#2 T02.9 doctor proxmox parity — P02 not complete until both
bootstrap + doctor callbacks use capture-fix wrapper
#3 T01.6 cli coverage escape valve — ship at 65% if 70% not reached
after Wave 2 (RESEARCH §1.4 flags 55-65% realistic); do not block
P02/P03 on the last 5%
#4 T03.1 verify-reqs regex substring-tolerant (matches v0.2 header
variant) + reverse-direction assertion (REQUIREMENTS Complete ↔
ROADMAP COMPLETE); scope note: doc-vs-doc drift only
T02.10 case 7 added (known_hosts pre-populated v0.6→v0.8 migration
path). No escalations; all axes resolved at confidence ≥ 0.60.
---ci---
project: orca
phase: 0
milestone: v0.8
status: grill
---/ci---
v0.7.0
2026-08-04 00:49:07 +00:00
Jon Chery
a288eb93ea
docs(P00): create v0.8 phase plans — 4 exec phases + final review
...
PLAN_v0.8.md (33KB): 4 execution phases, 37 tasks (36 must-haves),
3-wave ordering per phase, persona-assigned (lead/backend/data),
REQ-057..060 mapped.
P01 coverage round 2 (12 tasks): proxmox sessionRunner seam + 9 pkg
tests, tiered floor ≥70%/≥50% per D-047.
P02 SSH trust (11 tasks): --host-key-fingerprint pre-pin + key-reset +
TOFU capture bugfix + HostKeyFingerprint population.
P03 verify-reqs gate (5 tasks): cmd/verify-reqs Go program + make
target + .coreci.yml hook.
P04 final review + ship + audit (9 tasks).
Zero new direct deps. ROADMAP reconciled to 4-phase structure (P04 =
final review, no separate P05).
---ci---
project: orca
phase: 0
milestone: v0.8
status: plan
---/ci---
2026-08-04 00:49:07 +00:00
Jon Chery
285ffee863
docs(P00): v0.8 research findings + persona assessment
...
RESEARCH_v0.8.md (35KB): per-package coverage strategy for 9 pkgs,
SSH trust research (uncovered latent TOFU capture bug + unpopulated
HostKeyFingerprint field), verify-reqs Go program approach, 4 ADs,
10 pitfalls. PERSONAS.md updated for v0.8 (3-persona roster retained,
connectrpc removed from backend frameworks per AD-014, territory globs
aligned to actual file structure).
Key findings flagged for PLAN:
- proxmox needs sessionRunner seam (~10 LOC) or stalls at ~55%
- cert_repo_test.go missing (v0.7 P01 leftover) blocks store 70%
- TOFU known_hosts capture broken + HostKeyFingerprint never populated
(bootstrap.go:195-198) — P02 fixes both
- verify-reqs = Go program at cmd/verify-reqs (~80 LOC, stdlib only)
---ci---
project: orca
phase: 0
milestone: v0.8
status: research
---/ci---
2026-08-04 00:49:07 +00:00
Jon Chery
a0b3b7439d
docs(P00): clarify v0.8 ambiguities (5 decisions, full autonomy)
...
D-043 P02 chore vs feat (chore — trust-surface hardening, no new capability)
D-044 --host-key-fingerprint placement (node join root, validated on --type proxmox)
D-045 fingerprint format (OpenSSH SHA256:base64)
D-046 key-reset scope (local known_hosts only, not remote authorized_keys)
D-047 coverage tiered floor (70% for retested, 50% for zero-test packages)
---ci---
project: orca
phase: 0
milestone: v0.8
status: clarify
---/ci---
2026-08-04 00:49:05 +00:00
Jon Chery
a052bf20f1
docs(init): validate v0.8 specification — coverage & trust hardening
...
---ci---
project: orca
phase: 0
milestone: v0.8
status: specify
---/ci---
2026-08-04 00:49:05 +00:00
Jon Chery
7bb533c2fb
docs(milestone): complete hardening-completion
...
v0.7 milestone complete. All 4 execution phases + final review shipped.
REQ-053..056 all complete. Tags v0.6.0..v0.6.5 on v0.6.x patch line.
Merged milestone/v0.7-hardening-completion → main.
---ci---
project: orca
phase: 5
milestone: v0.7
status: complete
requirements:
covered: [REQ-053, REQ-054, REQ-055, REQ-056]
partial: []
---/ci---
2026-08-04 00:29:51 +00:00
Jon Chery
d7d6961261
fix(P05): final review fixes — PERSONAS.md body, config --addr precedence, migration 0007 dedup
...
Audit fix: PERSONAS.md body roster updated for v0.7 (was stale v0.6
content). Review P1-004: daemon --addr now uses cmd.Flags().Changed()
to detect explicit flag, so config listen_addr only applies when --addr
was not explicitly passed (correct flag>env>file>default precedence).
Review P1-001: migration 0007 now dedups existing duplicate serial_hex
rows before creating the UNIQUE index (backward-compat with v0.6 DBs
that accumulated duplicates before the constraint existed).
---ci---
project: orca
phase: 5
milestone: v0.7
status: execute
requirements:
covered: [REQ-053, REQ-054, REQ-055, REQ-056]
partial: []
---/ci---
v0.6.5
2026-08-04 00:28:48 +00:00
Jon Chery
afcd15cde4
docs(P04): complete pprof-daemon phase — shipped v0.6.4
...
REQ-056 complete. I-308 (deferred since v0.2) implemented. Tag + merge +
Gitea release succeeded.
---ci---
project: orca
phase: 4
milestone: v0.7
status: complete
requirements:
covered: [REQ-056]
partial: []
---/ci---
2026-08-04 00:22:39 +00:00
Jon Chery
0b58286ca2
feat(P04): --pprof opt-in on orca daemon (REQ-056, I-308)
...
Separate *http.Server + *http.ServeMux (AD-024), default disabled.
Operator opts in via --pprof <addr>. WARN logged on startup. All pprof
handlers explicitly registered on dedicated mux (no DefaultServeMux
side-effect). I-308 deferred since v0.2 now implemented. 6 new tests.
---ci---
project: orca
phase: 4
milestone: v0.7
status: verify
requirements:
covered: [REQ-056]
partial: []
---/ci---
v0.6.4
2026-08-04 00:22:17 +00:00
Jon Chery
f8b135e7a8
docs(P03): complete coverage-uplift phase — shipped v0.6.3
...
REQ-055 complete. All 4 target packages ≥ 50% (engine 65.1%, transport
84.6%, proxmox 82.7%, audit 100%). Latent dispatch.go EOF bug fixed.
---ci---
project: orca
phase: 3
milestone: v0.7
status: complete
requirements:
covered: [REQ-055]
partial: []
---/ci---
2026-08-04 00:19:20 +00:00
Jon Chery
d9d0beda3b
test(P03): coverage uplift — engine/transport/proxmox/audit ≥50% + dispatch.go EOF fix (REQ-055)
...
94 new tests across 4 packages. Coverage: engine 8.3%→65.1%, transport
26.3%→84.6%, proxmox 5.1%→82.7%, audit 0%→100%. Bug fix: dispatch.go
bytesReadCloser.Read returned fmt.Errorf("EOF") instead of io.EOF —
broke HTTP request body transmission (latent since v0.2 P02).
---ci---
project: orca
phase: 3
milestone: v0.7
status: verify
requirements:
covered: [REQ-055]
partial: []
---/ci---
v0.6.3
2026-08-04 00:18:58 +00:00
Jon Chery
007d3a12e8
docs(P02): complete config-parser phase — shipped v0.6.2
...
REQ-054 complete. Tag + merge + Gitea release succeeded.
---ci---
project: orca
phase: 2
milestone: v0.7
status: complete
requirements:
covered: [REQ-054]
partial: []
---/ci---
2026-08-04 00:09:56 +00:00
Jon Chery
cd07e435d9
feat(P02): HCL config file parsing — internal/config package (REQ-054)
...
New internal/config package: Config struct (HCL tags), Load(paths...),
MergeOverrides(flags, env) with flag>env>file>default precedence (D-039).
No package-level state (AD-023). --config persistent flag on root command;
daemon uses cfg.ListenAddr when flag at default. 11 config tests + 2 cli tests.
---ci---
project: orca
phase: 2
milestone: v0.7
status: verify
requirements:
covered: [REQ-054]
partial: []
---/ci---
v0.6.2
2026-08-04 00:09:33 +00:00
Jon Chery
27f2abf8fb
docs(P01): complete cert-register phase — shipped v0.6.1
...
REQ-053 complete. Tag + merge + Gitea release succeeded.
---ci---
project: orca
phase: 1
milestone: v0.7
status: complete
requirements:
covered: [REQ-053]
partial: []
---/ci---
2026-08-04 00:05:45 +00:00
Jon Chery
04d9dccd41
fix(P01): register orca cert command tree + cert_repo tests (REQ-053)
...
The `orca cert` command (ca-init, gen, show, renew, fingerprint) was
fully implemented in internal/cli/cert.go but never registered on
rootCmd — unreachable from the CLI. Added init() registration (AD-022).
Added cert_test.go (regression) + cert_smoke_test.go (e2e). Added
cert_repo_test.go (11 tests) + migration 0007 (UNIQUE serial_hex, I-107).
---ci---
project: orca
phase: 1
milestone: v0.7
status: verify
requirements:
covered: [REQ-053]
partial: []
---/ci---
v0.6.1
2026-08-04 00:05:10 +00:00
Jon Chery
c100892ad9
docs(P00): complete v0.7 pre-execution phase — shipped v0.6.0
...
Tag + merge + Gitea release #399 all succeeded. Phase 0 complete.
---ci---
project: orca
phase: 0
milestone: v0.7
status: complete
---/ci---
2026-08-03 23:54:37 +00:00
Jon Chery
561bf61317
docs(P00): correct v0.7 tag line to v0.6.x per branch-strategy.md
...
Tags run on the previous minor's patch line. v0.7 milestone → v0.6.x
tags (v0.6.0 P0 … v0.6.5 P05 milestone release). Prior commits
incorrectly referenced v0.5.x (the v0.6 milestone's line).
---ci---
project: orca
phase: 0
milestone: v0.7
status: plan
---/ci---
v0.6.0
2026-08-03 23:52:19 +00:00
Jon Chery
f7902dddda
docs(P00): create v0.7 phase plans — 4 exec phases + final review
...
Vertical-slice plans: P01 cert registration + cert_repo tests (REQ-053),
P02 HCL config parser (REQ-054), P03 coverage uplift engine/transport/
proxmox/audit ≥50% (REQ-055), P04 pprof opt-in (REQ-056), P05 final.
NFR milestone, tags v0.5.5..v0.5.10.
---ci---
project: orca
phase: 0
milestone: v0.7
status: plan
---/ci---
2026-08-03 20:30:23 +00:00
Jon Chery
f022ef5395
docs(P00): v0.7 ideation results — 13 accepted, 0 skipped
...
3-tier ideation: 5 mechanical (cert unreachable, cert_repo no test,
engine/transport/audit low coverage) + 5 backend (config parser, pprof,
precedence test, separate mux, CI gate) + 3 cross-project (version --json
verify, init() registration, zero new deps). All >=0.60, auto-accepted.
---ci---
project: orca
phase: 0
milestone: v0.7
status: ideate
decisions:
- id: D-043
decision: "Accepted 13 ideation recommendations (REQ-053..056 + 9 refinements)"
rationale: "All >=0.60 confidence; full autonomy auto-accept. Scope confirmed: cert registration, config parser, coverage uplift, pprof."
confidence: 0.92
requirements:
covered: [REQ-053, REQ-054, REQ-055, REQ-056]
---/ci---
2026-08-03 20:29:37 +00:00
Jon Chery
7c4b603811
docs(P00): v0.7 research findings + persona assessment
...
Codebase audit: cert command unreachable, no config parser, low coverage
(engine 8.3%, transport 26.3%, proxmox 5.1%, audit 0%), pprof deferred.
5 architectural decisions (AD-022..AD-026). Zero new deps.
---ci---
project: orca
phase: 0
milestone: v0.7
status: research
---/ci---
2026-08-03 20:29:07 +00:00
Jon Chery
fc034218e3
docs(P00): clarify v0.7 ambiguities (5 decisions, full autonomy)
...
D-038 HCL config (reuse jobspec dep) | D-039 flag>env>file>default
D-040 pprof opt-in operator addr | D-041 cert registration order
D-042 50% coverage floor, 70% new-code floor
---ci---
project: orca
phase: 0
milestone: v0.7
status: clarify
---/ci---
2026-08-03 20:28:21 +00:00
Jon Chery
bd4a34daa2
docs(init): validate v0.7 specification — hardening & completion
...
---ci---
project: orca
phase: 0
milestone: v0.7
status: specify
---/ci---
2026-08-03 20:28:05 +00:00
Jon Chery
55d4d699a3
docs(milestone): complete node-bootstrap-proxmox
...
Milestone v0.6 complete. All 6 requirements (REQ-047..052) shipped
across 3 execution phases + final review. Tags v0.5.0..v0.5.4.
---ci---
project: orca
phase: 4
milestone: v0.6
status: complete
requirements:
covered: [REQ-047, REQ-048, REQ-049, REQ-050, REQ-051, REQ-052]
partial: []
---/ci---
v0.5.4
2026-08-03 20:02:44 +00:00
Jon Chery
7cfc4b7027
docs(P03): verification report — all 4 layers PASS
...
---ci---
project: orca
phase: 3
milestone: v0.6
status: verify
---/ci---
v0.5.3
2026-08-03 20:00:12 +00:00
Jon Chery
f66472fd37
feat(P03): doctor os + doctor proxmox + audit logging
...
Extends orca doctor with two new checks (REQ-052):
- doctor os: re-runs OS detection from /etc/os-release, compares to
stored localhost node's os field. Drift = WARN (re-run orca init);
match = PASS; missing localhost node = FAIL.
- doctor proxmox: iterates kind=proxmox nodes, SSH-probes each with
`pveversion` (3s timeout per node, clones Network() pattern).
Zero proxmox nodes = WARN; reachable = PASS; unreachable = FAIL.
Changes:
- internal/osdetect: new shared package (Detect + ParseID) extracted
from internal/cli to avoid import cycle (cli + doctor both need it)
- internal/cli/osdetect.go: thin wrapper delegating to osdetect package
- internal/doctor/doctor.go: OS() and Proxmox() checks; All() extended;
probeProxmoxPVEVersion uses orca SSH key + knownhosts TOFU
- internal/cli/doctor.go: doctor os + doctor proxmox subcommands (--json)
- internal/doctor/doctor_test.go: 5 new tests (OS match/drift/missing,
proxmox no-nodes/unreachable)
E2E: orca init -> orca doctor shows 6 PASS / 1 WARN (proxmox=none) /
1 FAIL (network=daemon not running). doctor os --json valid.
---ci---
project: orca
phase: 3
milestone: v0.6
status: execute
---/ci---
2026-08-03 19:59:51 +00:00
Jon Chery
82dd01f620
docs(P02): verification report — all 4 layers PASS
...
---ci---
project: orca
phase: 2
milestone: v0.6
status: verify
---/ci---
v0.5.2
2026-08-03 19:56:05 +00:00
Jon Chery
797bc2f412
feat(P02): Proxmox SSH join + OrcaOperator role + sudoers
...
orca node join --type proxmox bootstraps a remote Proxmox VE 8/9 host
via SSH (REQ-050, REQ-051). The password is used only for initial auth;
subsequent access uses the deployed orca SSH key (D-031).
Changes:
- go.mod: add golang.org/x/crypto v0.54.0 (ssh + ssh/knownhosts + ed25519)
bump x/sys to v0.47.0, add x/term (indirect)
- internal/certpaths: SSHKeyPath, SSHPubPath, KnownHostsPath (D-037)
- internal/security/sshkey.go: GenerateOrLoadSSHKey (Ed25519, PKCS8 PEM,
0600/0644 modes, idempotent load per D-036)
- internal/proxmox/bootstrap.go: BootstrapProxmox SSH dance:
1. Generate/load SSH key
2. SSH dial (password + knownhosts.New TOFU per D-035)
3. Deploy pubkey to ~orca/.ssh/authorized_keys (idempotent)
4. useradd -m orca (idempotent)
5. pveum role add OrcaOperator --privs 'VM.Audit Datastore.AllocateSpace SDN.Use'
6. pveum user add orca@pam (AD-019: PAM realm, not @pve)
7. pveum acl modify / -user orca@pam -role OrcaOperator
8. Write /etc/sudoers.d/orca (AD-020: NOEXEC on pct/qm, no NOEXEC on
apt-get/dpkg, pvesh EXCLUDED — API execute bypasses NOEXEC)
9. visudo -cf validation (abort on failure)
All steps idempotent; audit-logged.
- internal/cli/node.go: --type/--host/--ssh-user/--password/--ssh-port/
--proxmox-user/--proxmox-role flags; joinProxmox() wires to
proxmox.BootstrapProxmox + registers node with kind=proxmox, os=pve.
Password zeroed after use (D-031).
- tests: sshkey generate/load round-trip, idempotency, file modes;
proxmox sudoers content (NOEXEC/NOPASSWD/pvesh-excluded),
privilege set, validation; node join flag wiring
---ci---
project: orca
phase: 2
milestone: v0.6
status: execute
---/ci---
2026-08-03 19:55:14 +00:00