Jon Chery
ecdba833d9
feat(P7): doctor ingress + docs + integration tests (REQ-177,178,179)
...
New 'orca doctor ingress' command: verifies podman orca-traefik
container running, nft DNAT+SNAT, /etc/traefik/dynamic exists,
step-ca root CA present.
UAT signoff script: replaced assertion 36 (systemd → podman
container), added assertions 40-46 (nft table, DNAT, SNAT, dynamic
dir, step-ca CA, traefik.yml, doctor ingress pass).
docs/ingress.md: R-024 podman traefik section — three topologies,
container config, nft ruleset, doctor ingress, Dockerfile.traefik.
TLS model updated (drop certResolver, tls:{} for v0.14, mTLS v0.15).
ARCHITECTURE.md: v0.14 deltas section — R-024, three topologies,
nft emitter changes, TLS model, migration 0009, new CLI.
Integration tests (tests/ingress_bootstrap_test.go): nft postrouting
+ DNATTarget, priority -10, traefik TLS model (tls:{} no
certResolver), image ref resolution, floating-IP LXC provisioning
commands (pct create with hwaddr/ip/gw/features), MAC generation.
---ci---
project: orca
phase: 7
milestone: v0.14
status: execute
---/ci---
2026-08-10 20:24:13 +00:00
Jon Chery
0424f8ce02
feat(init): interactive remote pre-staging via ssh-copy-id
...
orca init now interactively prompts for remote host addresses and runs
ssh-copy-id automatically (password prompt passes through to the
operator). This makes orca init the single entry point — no manual
pre-staging of SSH keys required.
- Interactive: enter host addresses (one per line, empty line to finish)
- ssh-copy-id deploys the orca public key to each host
- Skipped in --json mode (non-interactive)
- Idempotent: re-running init can stage additional hosts
Also fixed: install.sh defaults to /usr/local/bin (on PATH for all users).
Non-root without sudo falls back to ~/.local/bin + auto-adds to .bashrc.
2026-08-10 17:37:42 +00:00
Jon Chery
d324939699
fix: PVE role/user idempotency + init pre-staging instructions
...
- createPVERole: use grep -qF + fallback to pveum role mod (was broken
by single-quote-in-grep pattern: grep -q '^'OrcaOperator'')
- createPVEUser: same idempotency fix (grep -qF + fallback to mod)
- orca init: prints ssh-copy-id instructions with the orca public key
path after generating the SSH keypair
- docs/uat.md: removed manual pre-staging (ssh-keygen, ssh-copy-id
with operator key, host-key fingerprint pinning). orca init handles
key generation; node join uses the orca key by default; TOFU is
automatic. Updated node join examples to not pass --ssh-key or
--host-key-fingerprint.
---ci---
project: orca
status: fix
---/ci---
2026-08-10 17:07:30 +00:00
Jon Chery
7dc7980d74
docs(E): UAT docs + signoff script fixes + pve-ct example (REQ-170)
...
- docs/uat.md: remove --rp-id from cluster seal (belongs to auth init-idp);
fix secrets set syntax (positional KEY=value, not --value flag); add
auth init-idp step; add troubleshooting section (ORCA_HOME, known_hosts,
Traefik, SSH, job list, Proxmox runtime)
- scripts/uat-signoff.sh: fix 6 assertions (#04 SKIP if no linux, #08
check node field in JSON, #14 verify file exists first, #27 fix pprof
grep, #34/35 already passing); add 3 new assertions (#36 traefik
installed, #37 known_hosts exists, #38 master_key exists); total 38
- examples/full-stack/web-app-lxc.md: pve-ct jobspec variant for Proxmox
LXC container deployment
---ci---
project: orca
milestone: v0.12.18
phase: E
status: complete
requirements:
covered: [170]
---/ci---
2026-08-10 16:37:57 +00:00
Jon Chery
52e17aefbf
feat(P12): --type linux SSH-join + UAT plan + signoff script (REQ-161..163)
...
--type linux (REQ-161):
- internal/linux/bootstrap.go: SSH bootstrap for generic Linux workers
(orcas pubkey, system user, drift-events dir; no PVE role/sudoers)
- internal/cli/node.go: joinLinux function + --type linux dispatch
- peer-setup kept as documented fallback
UAT plan (REQ-162):
- docs/uat.md: 3-host topology (lead Ubuntu + pve01 Proxmox + worker01
Ubuntu), 22 step-by-step commands, 35-claim matrix, Proxmox
prerequisite + alternative 3xUbuntu path (C-48), signoff procedure
UAT signoff script (REQ-163, C-47):
- scripts/uat-signoff.sh: 35 idempotent read-only assertions, exit 0
iff all pass. Includes 4 critical-path assertions: job deploys to
remote, ACL deny-by-default, seal/unseal round-trip, OIDC health
- scripts/uat-smoke.sh: 13 CI-tested pure-CLI assertions for .coreci.yml
Tests: node join --type linux test, fingerprint test updated, smoke
test all 13 pass.
---ci---
project: orca
phase: 12
milestone: v0.13
status: complete
requirements:
covered: [161, 162, 163]
---/ci---
2026-08-10 14:33:29 +00:00
Jon Chery
b6dd86fdf3
docs(P11): doc drift round 2 — README, cli.md, CHANGELOG, verify-reqs (REQ-160)
...
- README: status banner v0.12+v0.13, latest tag v0.12.10, subcommand
table expanded (auth/nft/peer-setup/secrets rotate-master), "mTLS by
default" corrected to "SSH-push canonical", docs table updated
- docs/cli.md: complete rewrite (521->1465 lines), all ~40 subcommands
- CHANGELOG: regenerated from git log (v0.11.29..HEAD)
- help text: job run HCL->markdown, job stop daemon->SSH-push
- docs/security-runbook.md: expanded to match P05 reality (seal/unseal,
doctor audit/modes/oidc, incident response)
- docs/webauthn.md: added auth register (P06)
- docs/namespace.md: added inherit + set-constraint
- internal/proxmox/bootstrap.go: comments password->key auth
- internal/cli/status.go: deprecation warning
- scripts/verify-docs.sh + make verify-docs: cli.md <-> orca --help
- cmd/verify-reqs/main.go: fix bold-format regex (was bypassing v0.12)
+ case-insensitive status matching
- .ciagent/REQUIREMENTS.md: v0.12 REQs marked complete
- .ciagent/ROADMAP.md: v0.12 bolded COMPLETE
---ci---
project: orca
phase: 11
milestone: v0.13
status: complete
requirements:
covered: [160]
---/ci---
2026-08-10 14:18:27 +00:00
Jon Chery
ed91d68fbf
feat(P10): observability expansion — metrics + security headers (REQ-159)
...
New metrics:
- orca_jobs_running / orca_jobs_failed / orca_jobs_complete (gauges)
- orca_audit_chain_head (gauge, chain integrity)
- orca_drift_events_total, orca_ssh_errors_total (counters)
- orca_txn_apply_total, orca_txn_rollback_total (counters)
- orca_acl_denials_total (counter)
Security headers on metrics + healthz endpoints:
- X-Content-Type-Options: nosniff
- X-Frame-Options: DENY
New file: docs/metrics.md (Prometheus reference + scrape config)
---ci---
project: orca
phase: 10
milestone: v0.13
status: complete
requirements:
covered: [159]
---/ci---
2026-08-10 13:44:04 +00:00
Jon Chery
0f7f9cf914
docs(P27): zero-trust + OIDC + WebAuthn + threat-model docs (REQ-142)
...
---ci---
project: orca
phase: 27
milestone: v0.12
status: execute
---/ci---
docs/threat-model.md (STRIDE + OS surface + residual risks),
docs/oidc.md (bundled Dex + BYO + claim mapping + offline),
docs/webauthn.md (passkeys + RP ID + bootstrap sequence),
docs/security-runbook.md (seal/unseal + rotation + incident response).
2026-08-07 11:33:58 +00:00
Jon Chery
e9686f4ab0
docs(P04): README refresh + namespace.md v0.9 layout update
...
P04 — README and namespace.md refresh (REQ-095, REQ-096).
README.md (REQ-095):
- Status line updated (v0.9 complete, v0.10 in progress).
- Install --version example updated to v0.9.1 (current).
- Added --check dry-run example.
- Update-in-place example updated to v0.8.15 -> v0.9.1.
- Subcommand table expanded to all 22 commands with Since column and
deprecation markers (daemon, cert, status marked deprecated).
- Development section complete (verify-reqs, security-scan, test-race,
changelog, release).
- New Documentation section linking all 7 docs/*.md.
- New Examples section linking examples/full-stack/.
docs/namespace.md (REQ-096):
- Replaced v0.8 flat path table with v0.9 multi-namespace layout
(cluster/, _defaults/, per-ns db/jobs/alloc/ns.md, orca_cache.db).
- Full path reference table from internal/paths/paths.go.
- Namespace root resolution (ORCA_HOME/--system/~/.orca).
- orca ns subcommand cross-link to docs/cli.md.
- Namespace inheritance (_defaults implicit root, D-159/D-185/D-187).
- v0.8 flat layout flagged deprecated with callout box.
All README links verified to resolve. make verify-reqs: 98 consistent.
---ci---
project: orca
phase: 4
milestone: v0.10
status: execute
---/ci---
2026-08-05 21:00:46 +00:00
Jon Chery
289e5cf6e1
docs(P02): CLI reference + jobspec reference + ingress guide
...
P02 — operator-facing documentation (REQ-091, REQ-092, REQ-093; gate C-22).
docs/cli.md (REQ-091):
- Full CLI command/flag reference: every command/subcommand with synopsis,
flag tables (name/type/default/description), one-line examples.
- Global flags (--json, --system, --config, --no-deprecation-warnings).
- Output modes (text/json/watch), env vars, exit codes.
- Deprecated surface callout boxes (daemon, cert, node-join-mTLS, HCL
jobspec) pointing to v0.11 removal.
docs/jobspec.md (REQ-092):
- Markdown frontmatter schema reference: all top-level keys, block
reference (runtime/ports/env-secrets/volumes/restart/update/service/
health/lifecycle/constraints/affinity/tasks), kinds matrix
(Job/Service/DaemonSet required vs allowed), CEL subset grammar, body
byte-exact preservation (R-015), deprecated HCL callout.
docs/ingress.md (REQ-093):
- Traefik ingress reference: service->Traefik mapping (D-175), R-007
socket-vs-TCP-bind semantics, generated YAML shape (routers/services/
healthCheck), atomic reload (C-10), drain (weight:0), TLS (certResolver,
trust domain, step-ca), worked-example pointer to examples/full-stack/,
v0.11 forward limitations.
All factual claims grounded in live codebase (gate C-22). Cross-links
verified to resolve.
---ci---
project: orca
phase: 2
milestone: v0.10
status: execute
---/ci---
2026-08-05 20:57:05 +00:00
Jon Chery
de8fdc0fe4
feat(P03): docker release — multi-stage Dockerfile + Gitea container registry publish
...
REQ-046: Docker image published to Gitea container registry per release.
Dockerfile: multi-stage (golang:1.25 -> distroless/static-debian12:nonroot).
CGO_ENABLED=0, ORCA_HOME=/var/lib/orca, ENTRYPOINT [/orca].
Image size: ~28MB. Runs as nonroot.
.coreci.yml: new container-publish step in release pipeline (docker:24-cli,
builds + tags + login + push + logout).
scripts/release.sh: docker build + push after Gitea release. Graceful
skip if docker absent or GITEA_TOKEN unset. Env-overridable registry.
.dockerignore: excludes .git, bin/, .env, .ciagent/, testdata/, *.tar.gz.
docs/docker.md: pull, run, state persistence (volume mount), local build,
manual publish guide.
Verified: docker build + run version/init with volume persistence.
---ci---
project: orca
phase: 3
milestone: v0.5
status: verify
---/ci---
2026-08-03 18:52:36 +00:00
Jon Chery
85963dc320
feat(P02): install.sh 1-liner + in-place update + README quickstart
...
REQ-043: install.sh pulls release binary from public Gitea URL.
User-level default (~/.local/bin/orca), --system for system-level
(/usr/local/bin/orca). Defaults to latest release; --version pins.
Env-overridable GITEA_URL/OWNER/REPO for testability.
REQ-044: in-place update detects existing binary, reads version via
'orca version --json', prints update message, overwrites binary,
preserves namespace dir (config/db/certs). Idempotent re-install.
REQ-016 (completion): README quickstart now documents the 1-liner
install + --system variant + update-in-place pattern.
Tests: 8/8 pass in scripts/install_test.sh (real public Gitea releases,
no mock server; timeout-guarded to prevent hangs).
Docs: docs/install.md covers user/system install, version pinning,
in-place update, uninstall, troubleshooting.
---ci---
project: orca
phase: 2
milestone: v0.5
status: verify
---/ci---
2026-08-03 18:49:50 +00:00
Jon Chery
4bfc246be4
feat(P01): unified namespace root via ORCA_HOME + --system flag
...
REQ-041: ORCA_HOME is now the single namespace root for all components
(db, certs, init, daemon). store.Open("") and init command both
route through certpaths.Dir()/DBPath() instead of hardcoding ~/.orca.
Backward compatible: empty ORCA_HOME -> ~/.orca.
REQ-042: --system persistent flag on rootCmd sets ORCA_HOME=/root/.orca
via PersistentPreRunE. Errors on conflict with pre-set ORCA_HOME.
Tests: 7 new tests in namespace_test.go (default, ORCA_HOME override,
--system sets root, conflict detection, init --json, flag registered).
Full suite passes (no regressions).
Docs: docs/namespace.md covers default, ORCA_HOME, --system, ORCA_DB,
resolution order, and path layout tables.
---ci---
project: orca
phase: 1
milestone: v0.5
status: verify
---/ci---
2026-08-03 18:05:01 +00:00
Jon Chery
df58bc25a3
docs(milestone): complete scheduling-streaming (v0.3)
...
---ci---
project: orca
phase: 3
milestone: v0.3
status: complete
requirements:
covered: [REQ-022, REQ-030, REQ-032]
partial: []
---/ci---
v0.3 milestone merged to main. Includes all v0.2 work (P08-P10) that
was previously on the milestone branch but not yet merged to main, plus
the v0.3 completion work (iter.Seq streaming + doctor network/db).
v0.2 phases included: P08 (mTLS), P09 (scheduling), P10 (security scan).
v0.3 phases: P0 (pre-execution), P1 (iter.Seq streaming), P2 (doctor),
P3 (final review+ship).
Total: 40 requirements, all complete. No new go.mod dependencies.
Full test suite passes under -race. gofmt + go vet clean.
2026-08-01 20:06:47 +00:00