Files
orca/.ciagent/REQUIREMENTS.md
T
Jon Chery 40b5e781ce docs(P00): resolve C-04 — relabel v1.0→v0.10 milestone, keep all 40 phases, v1.0 UAT-gated
Operator decision (resolves grill C-04 + escalation E-03): keep 2 milestones
(v0.9 + v0.10), keep all phases (40 total, exceeds 35 soft limit), v1.0 is
UAT-gated and cut as a separate tag (v1.0.0) after v0.10 completion per
operator sign-off — not a separate milestone.

Relabels all v1.0 milestone references to v0.10 across ROADMAP, REQUIREMENTS,
GRILL_v0.9, IDEATION_v0.9, PRD_v0.9, PROJECT. Phase content unchanged; only
the milestone label moves. Historical grill narrative (the original PRD §23
counts and the E-03 auto-split reasoning) preserved verbatim for audit
integrity. C-04 and E-03 marked RESOLVED in GRILL_v0.9.md.

Milestone structure:
- v0.9: Re-architecture Foundation & Workloads (13 phases P00..P0X)
- v0.10: Production Hardening (19 phases P00..P16, milestone tag v0.10.0)
- v1.0: UAT-gated production-ready cut (separate v1.0.0 tag, not a milestone)

verify-reqs: 90 requirements consistent.

---ci---
project: orca
phase: 0
milestone: v0.9
status: complete
gate: C-04 resolved
---/ci---
2026-08-05 16:08:33 +00:00

25 KiB
Raw Blame History

Requirements: Orca

The canonical requirements table. Each row carries the REQ-ID, the milestone it belongs to, the requirement summary, priority, the phase that addresses it, and the current status. This single table is the source of truth — superseded any per-milestone status tables in earlier versions of this file.

ID Requirement Priority Phase Status
REQ-001 Go 1.25+ toolchain support High v0.1 P01 Complete
REQ-002 CLI-first interface for all operations (single binary) High v0.1 P01 Complete
REQ-003 Offline-first operational mode (no cloud deps) High v0.1 Complete
REQ-004 Basic task deployment (single-node process execution) Medium v0.1 P03 Complete (single-node); multi-node dispatch in v0.2 P02
REQ-005 Local state storage via modernc/sqlite (CGO-free) Medium v0.1 P02 Complete
REQ-006 Security-first audit logging via log/slog High v0.1 P04 Complete
REQ-007 CoreCI full release flow integration via .coreci.yml High v0.1 P06 Complete (per-phase releases)
REQ-008 Structured JSON logging (slog) High v0.1 P05 Complete
REQ-009 HCL/YAML job spec parsing Medium v0.1 P03 Complete
REQ-010 --json output flag for machine consumption High v0.1 P01 Complete
REQ-011 mTLS for inter-node communication Medium v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-012 ~/.orca/config.hcl and /etc/orca/orca.hcl config locations Low v0.1 P01 Complete (CLI uses ~/.orca/ + ORCA_DB env)
REQ-013 Pre-push git hook triggers CoreCI on every push High v0.1 P01 Complete
REQ-014 gosec + govulncheck in CI pipeline High v0.2 P03 Complete (P10 shipped v0.2.3)
REQ-015 MIT LICENSE Low v0.1 P01 Complete
REQ-016 README.md with quickstart Medium v0.1 P01 Complete
REQ-017 context.Context propagation in all I/O High v0.1 Complete
REQ-018 Error wrapping with fmt.Errorf("...: %w", err) High v0.1 Complete
REQ-019 Cobra CLI framework High v0.1 P01 Complete
REQ-020 HCL parser integration (hashicorp/hcl) Medium v0.1 P03 Complete
REQ-021 os/exec with WaitDelay (Go 1.25+) Medium v0.1 P03 Complete
REQ-022 iter.Seq for streaming job lists (Go 1.25+) Low v0.3 P01 Complete (v0.3 P01 shipped v0.3.1)
REQ-023 Self-signed mTLS cert generation Medium v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-024 Makefile with standard targets High v0.1 P01 Complete
REQ-025 Bounded cert rotation history: retain last N=3 server certs per node for rollback Medium v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-026 Trusted-CA fingerprint pinned in config; daemon refuses to start on mismatch High v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-027 govulncheck runs in offline mode in CI (no vuln.go.dev calls; pre-mirrored DB or -format json + jq gate) High v0.2 P03 Complete (P10 shipped v0.2.3)
REQ-028 HCL/YAML schema for NodeCapacity declaration (orca node join flag and/or ~/.orca/node.hcl) High v0.2 P02 Complete (P09 shipped v0.2.2; orca node capacity CLI)
REQ-029 gitleaks baseline file committed to repo to suppress pre-existing .env SHA-1 leak in git history Medium v0.2 P03 Complete (P10 shipped v0.2.3)
REQ-030 --watch output format mode: table (default) vs streaming one-line JSON per event Low v0.3 P01 Complete (v0.3 P01 shipped v0.3.1)
REQ-031 go test -race enabled in CI for all v0.2 packages High v0.2 P01P04 Complete (P10; .coreci.yml test pipeline runs -race)
REQ-032 orca doctor subcommand for diagnostics (CA/cert health, db integrity, peer reachability) Medium v0.2 P01 / v0.3 P02 Complete (cert checks P01 v0.2.1; network + db P02 v0.3.2)
REQ-033 Cert file mode enforcement: 0600 for keys, 0644 for certs (refuses to start on violation) High v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-034 Cert proactive rotation alarm: structured slog WARN 30 days before not_after Medium v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-035 orca cert show redacts private key material from default and --json output High v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-036 Server cert SAN validation: SAN entries (DNS + IP) populated at sign-time; refuses to sign a CSR without them High v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-037 X-Orca-Idempotency-Key header on cross-node POST; dispatcher retries only when header is present Medium v0.2 P02 Complete (P09 shipped v0.2.2; internal/transport/idempotency.go)
REQ-038 Structured slog fields for mTLS failures: event=mtls.handshake, peer, cert_fp, err Medium v0.2 P01 Complete (P01 shipped v0.2.1)
REQ-039 .gitleaks.toml extended with stopwords for test data paths and CA cert PEM blocks Medium v0.2 P03 Complete (P10 shipped v0.2.3)
REQ-040 .golangci.yml unified lint config superseding per-tool invocations Low v0.2 P03 Complete (P10 shipped v0.2.3)
REQ-041 Unified namespace root via ORCA_HOME for all components (db, certs, init, daemon) High v0.5 P1 Complete (P1 shipped v0.4.2)
REQ-042 --system flag selects system-level namespace root /root/.orca High v0.5 P1 Complete (P1 shipped v0.4.2)
REQ-043 install.sh 1-liner pulling release binary from public Gitea URL; user-level default, --system for system-level High v0.5 P2 Complete (P2 shipped v0.4.3)
REQ-044 install.sh in-place update preserves config/state; idempotent re-run High v0.5 P2 Complete (P2 shipped v0.4.3)
REQ-045 Gitea repo + releases publicly accessible (unauthenticated download) High v0.5 P0 Complete (P0 ship: repo + org visibility public)
REQ-046 Docker image published to Gitea container registry per release Medium v0.5 P3 Complete (P3 shipped v0.4.4)

v0.1 Milestone Summary

Status: Complete — all 6 phases shipped (P00P06) plus P07 backfill, 4-layer verification passed at every phase, tagged v0.2.0 per run.md versioning logic (next-minor after all feature-patches v0.1.1..v0.1.7 ship).

Coverage: 21/24 v0.1-declared requirements complete by v0.1 ship; the 3 deferred (REQ-011, REQ-014, REQ-022, REQ-023) all moved to v0.2. Plus REQ-025..REQ-040 (16 net-new) added by v0.2 IDEATE stage.

v0.2 Milestone Summary

Status: Functionally Complete (pending merge to main) — P08 (mTLS), P09 (scheduling), P10 (security scan) all shipped to the milestone/v0.2-networking-observability-security branch as v0.2.1, v0.2.2, v0.2.3. The milestone branch has NOT been merged to main yet. REQ-022/030 (iter.Seq streaming) and REQ-032 (doctor network/db) were deferred to v0.3.

v0.3 Milestone Summary

Status: Complete — P01 (iter.Seq streaming, v0.3.1) and P02 (doctor network+db, v0.3.2) both shipped. REQ-022, REQ-030, REQ-032 all complete. Re-init SPECIFY audit confirmed all other v0.2-deferred REQs (014, 027, 028, 029, 031, 037, 039, 040) already shipped in P08-P10.

Deferred to v0.4

  • pprof endpoint on orca daemon (idea I-308, 0.70 confidence): deferred to keep v0.2 lean; revisit in v0.3 once P02's dispatcher is stable.

v0.5 Milestone Summary

Status: Complete — all 3 execution phases + final review shipped. P0 (v0.4.1), P1 (v0.4.2), P2 (v0.4.3), P3 (v0.4.4), P4 final (v0.4.5). REQ-041..046 all complete. Repo + releases publicly accessible (REQ-045). Docker image published to Gitea container registry (REQ-046).

  • P0 (v0.4.1): pre-execution + repo visibility flipped to public (REQ-045).
  • P1 (v0.4.2): namespace unification — ORCA_HOME + --system (REQ-041/042).
  • P2 (v0.4.3): install.sh 1-liner + in-place update (REQ-043/044) + README quickstart (REQ-016).
  • P3 (v0.4.4): Docker release — distroless image + Gitea container registry (REQ-046).
  • P4 (v0.4.5): final review + audit + milestone release.

v0.6 Requirements — Node Bootstrap & Proxmox

ID Requirement Priority Phase Status
REQ-047 orca init auto-provisions CA + server cert + DB migrations + localhost node (idempotent; safe re-run) High v0.6 P1 Complete (P1 shipped v0.5.1)
REQ-048 orca init registers a default localhost node with auto-detected OS via /etc/os-release ID High v0.6 P1 Complete (P1 shipped v0.5.1)
REQ-049 Node schema extension: nodes.kind (localhost|linux|proxmox) + nodes.os columns (migration 0006, backward-compatible) High v0.6 P1 Complete (P1 shipped v0.5.1)
REQ-050 orca node join --type proxmox SSH bootstrap via golang.org/x/crypto/ssh (new direct dep); password auth, deploy orca pubkey, create orca user (config-overridable), assign PVE role, drop sudoers allowlist; idempotent High v0.6 P2 Complete (P2 shipped v0.5.2)
REQ-051 Proxmox least-privilege OrcaOperator PVE role (VM.Audit, Datastore.AllocateSpace, SDN.Use) + orca user + /etc/sudoers.d/orca allowlist (pct, qm, pvesh, apt-get, dpkg); config-overridable user/role names High v0.6 P2 Complete (P2 shipped v0.5.2; refined: pvesh excluded per AD-020, orca@pam per AD-019)
REQ-052 orca doctor extensions: doctor os (verify localhost OS detection matches stored node row) + doctor proxmox (SSH-probe each kind=proxmox node with pveversion/pvecmd status, 3s timeout, PASS/WARN/FAIL); audit log all bootstrap + join actions Medium v0.6 P3 Complete (P3 shipped v0.5.3)

v0.6 Milestone Summary

Status: Complete — all 3 execution phases + final review shipped. P0 (v0.5.0), P1 (v0.5.1), P2 (v0.5.2), P3 (v0.5.3), P4 final (v0.5.4). REQ-047..052 all complete.

  • P0 (v0.5.0): pre-execution (specify → clarify → research → plan). 8 decisions (D-030..D-037).
  • P1 (v0.5.1): orca init full bootstrap + schema 0006 (REQ-047/048/049).
  • P2 (v0.5.2): Proxmox SSH join + OrcaOperator role + sudoers (REQ-050/051).
  • P3 (v0.5.3): doctor os + doctor proxmox + audit logging (REQ-052).
  • P4 (v0.5.4): final review + audit + milestone release.

v0.7 Requirements — Hardening & Completion

ID Requirement Priority Phase Status
REQ-053 orca cert command tree registered on root command (cert ca-init, cert gen, cert show, cert renew, cert fingerprint) — code exists in internal/cli/cert.go but is never AddCommand'd; unreachable today High v0.7 P1 Complete (P1 shipped v0.6.1)
REQ-054 HCL config file parsing: internal/config package loads ~/.orca/config.hcl / /etc/orca/orca.hcl (keys: db_path, listen_addr, ca_path, server_cert_path, server_key_path, node_capacity); merge precedence flag > env > file > default; --config flag on root command High v0.7 P2 Complete (P2 shipped v0.6.2)
REQ-055 Test coverage uplift: every package ≥ 50% — adds tests for internal/engine (executor, dispatcher, peer), internal/transport (mtls, dispatch, handshake_log), internal/proxmox (bootstrap SSH path), internal/audit Medium v0.7 P3 Complete (P3 shipped v0.6.3)
REQ-056 --pprof <addr> opt-in flag on orca daemon (default disabled); net/http/pprof mounted on a separate mux, never on the mTLS daemon listener Low v0.7 P4 Complete (P4 shipped v0.6.4)

v0.8 Requirements — Coverage & Trust Hardening

ID Requirement Priority Phase Status
REQ-057 Test coverage uplift round 2: raise internal/engine (8.3%), internal/proxmox (5.1%), internal/cli (27.6%), internal/transport (26.3%), internal/store (46.7%), internal/jobspec (47.6%) to ≥ 70%; add first tests for internal/audit, internal/certpaths, cmd/orca (currently 0%) to ≥ 50% (D-047 tiered floor) High v0.8 P1 Complete (P1 shipped v0.7.1; all 9 packages exceeded floor)
REQ-058 --host-key-fingerprint <SHA256:base64> pre-pin flag on orca node join (validated when --type proxmox): when supplied, join fails fast if the SSH host key's OpenSSH SHA-256 fingerprint does not match; supersedes TOFU (D-035) for pre-pinned deployments (D-044, D-045) Medium v0.8 P2 Complete (P2 shipped v0.7.2)
REQ-059 orca node key-reset <node> command: clears the persisted SSH host key entry for the node from ~/.orca/known_hosts only (local, not remote authorized_keys — D-046); audit-logs event=node.key_reset; next doctor proxmox/dispatch re-pins via TOFU or --host-key-fingerprint Low v0.8 P2 Complete (P2 shipped v0.7.2)
REQ-060 Requirement-status hygiene sweep: REQUIREMENTS.md v0.7 rows were stale ("Pending" after ship); add a verify-stage assertion that every REQ listed as Complete in ROADMAP.md has a matching Complete row in REQUIREMENTS.md, enforced by make verify-reqs Medium v0.8 P3 Complete (P3 shipped v0.7.3)

v0.9/v0.10 Requirements — Re-architecture Foundation & Production Hardening

The v0.9/v0.10 milestones supersede the shipped v0.1v0.8 architecture per the adopted PRD (.ciagent/PRD_v0.9.md). The re-architecture is justified on six grounds recorded in the PROJECT.md Supersession Table. 30 net-new requirements (REQ-061..REQ-090) derive from the v0.9 IDEATION; their phase placement and binding grill conditions (C-01..C-19) are documented in IDEATION_v0.9.md and GRILL_v0.9.md.

ID Requirement Priority Phase Status
REQ-061 orca daemon deprecation command and build-tag removal path: v0.9 emits deprecation warning + still runs (dual-write window); v1.0 repurposes to orca daemon drain-and-stop (stops v0.8 daemons on peers via SSH, confirms workloads survive via systemd); post-v1.0 the command and internal/daemon/ are deleted. // Deprecated Go doc comments + slog.Warn on every run (I-M-001) High v0.10 P14 (warn v0.9 P0X) Pending
REQ-062 Coverage follow-ups: 3 zero-test packages (internal/audit, internal/certpaths, cmd/orca) + internal/cli to 70% floor; once daemon.go is deprecated/removed the exclusion reason disappears and the floor applies to the whole package; all net-new subsystems carry a 70% floor from their first phase (I-M-002) Medium v0.9 P0X + each new pkg Pending
REQ-063 known_hosts flock concurrency gap (deferred P1 from REVIEW_v0.8 A2): add flock-style advisory lock (stdlib syscall.Flock wrapper) around the read-modify-write in TOFUHostKeyCallback capture path (bootstrap.go:290-302) and ResetHostKey (bootstrap.go:479-523); lock file at cluster/known_hosts.lock (R-002) (I-M-003) Medium v0.9 P0a1 Pending
REQ-064 HCL→Markdown jobspec adapter/bridge layer: keep internal/jobspec/spec.go as legacy HCL path behind // Deprecated; add internal/jobspec/markdown.go (canonical) + internal/jobspec/dispatch.go (extension-based dispatcher: .md→Markdown, .hcl→legacy, .yaml→Markdown-with-empty-body); unified *WorkloadSpec populated via adapter; preserves orca job run old-spec.hcl during migration window (I-M-004) High v0.9 P0b Pending
REQ-065 orca doctor --legacy-paths detection: detects v0.8 residue (orca.db at ORCA_HOME root, ca.crt/ca.key, config.hcl, flat server.crt, namespace column in any *.db); outputs list of legacy artifacts with migration recommendations; the detection half of v0.10-P14 (I-M-005) Medium v0.10 P14c Pending
REQ-066 Legacy CA state migration to step-ca: orca upgrade --to-v1.0 --import-ca reads ~/.orca/ca.key, initializes step-ca with it, re-issues workload SVIDs; preserves audit history even if live trust root changes (I-M-006). Gated by C-07 High v0.10 P14a Pending
REQ-067 Fuzz test harness for Markdown frontmatter parser: testing.F fuzz target in internal/jobspec/markdown_test.go round-trips random frontmatter+body through ParseMarkdown asserting byte-exact body preservation; corpus of adversarial fixtures (CRLF, BOM, no-frontmatter, empty-frontmatter, frontmatter-with-only-separator) (I-M-007) Medium v0.9 P0b Pending
REQ-068 Deprecation warnings on removed/repurposed CLI subcommands: each removed/changed command (orca cert, orca node join mTLS semantics, orca job run <spec.hcl>) emits slog.Warn deprecation banner with v1.0 replacement except under orca upgrade; --no-deprecation-warnings global flag via root.go PersistentPreRunE (I-M-008) Low v0.9 P0X + v0.10 P13 Pending
REQ-069 internal/config/config.go HCL config demotion via adapter: keep internal/config/ as legacy_config.go with // Deprecated; add internal/config/markdown.go for new Markdown-frontmatter loader (R-014); root.go dispatches on file extension (.hcl→legacy, .md→new); --config semantics: .hcl read-only legacy, .md canonical (I-M-009) High v0.9 P0a1 Pending
REQ-070 internal/certpaths/ replacement with multi-namespace path resolver: new internal/paths package with paths.NamespaceDir(ns), paths.ClusterDir(), paths.CacheDB(), paths.MasterKey(), paths.NSDb(ns), paths.NSEnv(ns), paths.NSSecrets(ns); keep certpaths as thin shim for v0.8 compat then remove post-v1.0 (R-002) (I-M-010) — highest blast radius High v0.9 P0a1 Pending
REQ-071 internal/store/ schema: per-namespace DBs, drop namespace column: store.Open gains namespace parameter (or caller passes paths.NSDb(ns)); migrate.go runs migrations per namespace DB; cert_repo (0004) removed (step-ca handles certs); audit_log moves to CLI-side cache DB (R-008) (I-M-011) High v0.9 P0a1 + v0.10 P06 Pending
REQ-072 internal/transport/ deletion + SSH-push package: delete mtls.go, dispatch.go, handshake_log.go; extract retry/idempotency patterns into internal/sshpush/; existing transport.IdempotencyStore directly reusable (I-M-012). Deletion deferred to v0.10-P14 to keep dual-write window open High v0.9 P00 (delete v0.10 P14) Pending
REQ-073 SSH-push transport layer design: connection pooling (reuse *ssh.Client per peer), idempotency (content-addressed filenames), retry (exponential backoff 100ms×2 cap 5s max 5), timeout (30s SCP, 10s exec), fan-out (errgroup bounded concurrency default 8), known_hosts reuse proxmox.TOFUHostKeyCallback (I-B-001) High v0.9 P01 (design P0a1) Pending
REQ-074 Emitter template system (Layer 4): internal/emitter/ package with Emitter interface Render(spec *WorkloadSpec, node *Node) ([]File, error); implementations systemdEmitter/traefikEmitter/syncthingEmitter/socketEmitter; SSH-push SCPs []File atomically (write-to-tmp + rename); emitters registered per kind + runtime (I-B-002) High v0.9 P0c Pending
REQ-075 Lead applier execution model: CLI renders transaction bundle (tarball + apply.sh + verify.sh) on operator host, SCPs to lead's /run/orca/txns/<txn-id>/, lead's systemd timer runs apply.sh idempotently, CLI polls txn status via SSH; bash scripts generated by emitter not hand-written (I-B-003). Gated by C-09 High v0.10 P10 (design v0.9 P00) Pending
REQ-076 step-ca integration: orca init runs step ca init on lead; CLI SSHs to lead, installs step-ca via apt, stores step-ca.json; workload SVIDs via step ca token (JWE minted by CLI) → step ca certificate; SPIFFE ID as SAN; new internal/stepca/ package wraps step CLI via SSH (I-B-004). Reverses AD-010 per override justification ground 2 High v0.9 P07 + v0.10 P02 Pending
REQ-077 Traefik dynamic config generation + atomic reload: Traefik emitter renders /etc/traefik/dynamic/orca-<ns>-<svc>.yaml with backends (socket paths R-007), health checks, mTLS config pointing at step-ca root; atomic reload via tmpfile+fsync+rename triggering fsnotify; drain writes weight=0 or removes backend (I-B-005). Gated by C-10 High v0.9 P02 Pending
REQ-078 Runtime abstraction interface (5 backends): Runtime interface in internal/runtime/ with Prepare/Start/Stop/Status; processRuntime (wraps existing executor.go), wasmRuntime (wasmtime via SSH), podmanRuntime, pveVMRuntime (qm via proxmox SSH), pveCTRuntime (pct); runtimeRegistry keyed by runtime: frontmatter value; Alloc carries runtime field changeable on migration (I-B-006). Split P07a/b/c per PC-10. P07b gated by C-01 High v0.9 P07a/b/c Pending
REQ-079 Transaction bundle format + N-peer atomicity: bundle = tarball with desired-state.json + apply.sh + verify.sh + rollback.sh + manifest.sig (signed with master.key); content-addressed <txn-id>=sha256(desired-state.json) stored in cluster/txns/<txn-id>/; lead applies to self first then fans out; failure on any peer runs rollback.sh on applied peers (I-B-007). Gated by C-09 High v0.10 P10 (design v0.9 P00) Pending
REQ-080 Master key management + HKDF-SHA256 per-line .env.secrets encryption: cluster/master.key 32-byte random (generated at orca init using WriteAtomic pattern); each line `base64(nonce ciphertext
REQ-081 Syncthing config rendering + folder-ID content-addressing: per-namespace Syncthing folder orca-<ns> with content-addressed folder ID sha256(ns + master-key-fingerprint); CLI renders config.xml per peer; Syncthing runs as systemd unit (emitted by systemd emitter); CLI discovers peers via cluster/peers/; migration works because new node joins folder and syncs before workload starts (I-B-009). Gated by C-02 + C-14 Medium v0.9 P09 (spike v0.9 P00) Pending
REQ-082 Namespace inheritance resolver algorithm: DFS parent walker with visited set for cycle detection; _defaults/ implicit root (always exists, no parent); merge semantics: child overrides parent for scalars, arrays unioned (child adds to parent); pure function (no I/O) taking map[nsName→*NSConfig] returning map[nsName→*ResolvedNS] (I-B-010) High v0.9 P0a2 Pending
REQ-083 CLI-side scheduler redesign: Score(node, workload) (score int, fits bool) where fits checks runtime compatibility + constraints, score is bin-packing (most free capacity = highest); Services pick count distinct nodes (anti-affinity default); DaemonSets pick all matching nodes; Job = one-shot; CLI-side not daemon-side (R-001) (I-B-011) High v0.9 P05 (skeleton P0c) Pending
REQ-084 orca job lint category-driven lint engine: Linter runs Rule checks returning Finding{Category, Severity, Message, Explanation}; categories schema/runtime/security/migration/best-practice; --explain prints rationale; pure (no I/O) checks against static rules (I-B-012) Medium v0.10 P11 Pending
REQ-085 v0.8→v1.0 migration ordering: v0.9 ships new parser + kinds + runtime + SSH-push alongside old daemon (dual-write window); orca job run dispatches on extension (.md→SSH-push, .hcl→old daemon); v0.10-P05 drains old daemons; v0.10-P14 converts remaining .hcl specs and removes daemon (I-C-001). Most important cross-cutting idea High v0.9 P00 → v0.10 P14 Pending
REQ-086 "No orca on server" enforcement: orca doctor no-orca-on-server SSHs to each peer verifying no orca binary in PATH, no orca systemd service, no orca process, no /etc/orca/ directory; runs after v0.10-P05 before v0.10-P16; reuses v0.8 proxmox SSH session infrastructure (I-C-002). Implements grill C-13 High v0.10 P14c Pending
REQ-087 Test infrastructure: hermetic 3-linux + 1-proxmox cluster pipeline: test/integration/ with docker-compose/vagrant creating 4 containers/VMs; Go test harness SSHes to each, runs CLI, asserts end-to-end workflows (ns create → workload submit → migrate → drain); proxmox simulated via mock pct/qm; v0.8 e2e tests (bootstrapE2ESetup) are foundation (I-C-003) Medium v0.10 P08 (bootstrap v0.9 P00) Pending
REQ-088 Security-engineer + network-engineer persona reactivation: reactivate security-engineer (step-ca provisioner model, SSH-push blast radius, Traefik edge, .env.secrets crypto) and network-engineer (socket exposure R-007, Syncthing P2P ports, Traefik routing); cross-cutting review not single phase (I-C-004). Implements grill C-05 High v0.9 P00 → v0.10 P16 Pending
REQ-089 Documentation rewrite: ARCHITECTURE.md/PROJECT.md/README + AD-010 supersession: v0.9-P00 adds "v0.9 Architecture (Supersedes v0.8)" section + banners + Superseded Decisions table; v0.10-P15 rewrites README quickstart for new curl sh + orca init + orca ns create flow (I-C-005) Medium v0.9 P00 + v0.10 P15/P16
REQ-090 Dual-write window: v0.9 orca job run dispatches on extension (.md→SSH-push new path, .hcl→old daemon path) via parser dispatcher (REQ-064); daemon not removed until v0.10-P05; SSH-push path writes to separate systemd unit namespace (orca-v1-<alloc>.service) while daemon uses orca-<job>.service — no unit name overlap = no conflict (I-C-006) High v0.9 P00 Pending