Operator decision (resolves grill C-04 + escalation E-03): keep 2 milestones (v0.9 + v0.10), keep all phases (40 total, exceeds 35 soft limit), v1.0 is UAT-gated and cut as a separate tag (v1.0.0) after v0.10 completion per operator sign-off — not a separate milestone. Relabels all v1.0 milestone references to v0.10 across ROADMAP, REQUIREMENTS, GRILL_v0.9, IDEATION_v0.9, PRD_v0.9, PROJECT. Phase content unchanged; only the milestone label moves. Historical grill narrative (the original PRD §23 counts and the E-03 auto-split reasoning) preserved verbatim for audit integrity. C-04 and E-03 marked RESOLVED in GRILL_v0.9.md. Milestone structure: - v0.9: Re-architecture Foundation & Workloads (13 phases P00..P0X) - v0.10: Production Hardening (19 phases P00..P16, milestone tag v0.10.0) - v1.0: UAT-gated production-ready cut (separate v1.0.0 tag, not a milestone) verify-reqs: 90 requirements consistent. ---ci--- project: orca phase: 0 milestone: v0.9 status: complete gate: C-04 resolved ---/ci---
25 KiB
Requirements: Orca
The canonical requirements table. Each row carries the REQ-ID, the milestone it belongs to, the requirement summary, priority, the phase that addresses it, and the current status. This single table is the source of truth — superseded any per-milestone status tables in earlier versions of this file.
| ID | Requirement | Priority | Phase | Status |
|---|---|---|---|---|
| REQ-001 | Go 1.25+ toolchain support | High | v0.1 P01 | Complete |
| REQ-002 | CLI-first interface for all operations (single binary) | High | v0.1 P01 | Complete |
| REQ-003 | Offline-first operational mode (no cloud deps) | High | v0.1 | Complete |
| REQ-004 | Basic task deployment (single-node process execution) | Medium | v0.1 P03 | Complete (single-node); multi-node dispatch in v0.2 P02 |
| REQ-005 | Local state storage via modernc/sqlite (CGO-free) | Medium | v0.1 P02 | Complete |
| REQ-006 | Security-first audit logging via log/slog |
High | v0.1 P04 | Complete |
| REQ-007 | CoreCI full release flow integration via .coreci.yml |
High | v0.1 P06 | Complete (per-phase releases) |
| REQ-008 | Structured JSON logging (slog) | High | v0.1 P05 | Complete |
| REQ-009 | HCL/YAML job spec parsing | Medium | v0.1 P03 | Complete |
| REQ-010 | --json output flag for machine consumption |
High | v0.1 P01 | Complete |
| REQ-011 | mTLS for inter-node communication | Medium | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-012 | ~/.orca/config.hcl and /etc/orca/orca.hcl config locations |
Low | v0.1 P01 | Complete (CLI uses ~/.orca/ + ORCA_DB env) |
| REQ-013 | Pre-push git hook triggers CoreCI on every push | High | v0.1 P01 | Complete |
| REQ-014 | gosec + govulncheck in CI pipeline |
High | v0.2 P03 | Complete (P10 shipped v0.2.3) |
| REQ-015 | MIT LICENSE | Low | v0.1 P01 | Complete |
| REQ-016 | README.md with quickstart | Medium | v0.1 P01 | Complete |
| REQ-017 | context.Context propagation in all I/O |
High | v0.1 | Complete |
| REQ-018 | Error wrapping with fmt.Errorf("...: %w", err) |
High | v0.1 | Complete |
| REQ-019 | Cobra CLI framework | High | v0.1 P01 | Complete |
| REQ-020 | HCL parser integration (hashicorp/hcl) |
Medium | v0.1 P03 | Complete |
| REQ-021 | os/exec with WaitDelay (Go 1.25+) |
Medium | v0.1 P03 | Complete |
| REQ-022 | iter.Seq for streaming job lists (Go 1.25+) |
Low | v0.3 P01 | Complete (v0.3 P01 shipped v0.3.1) |
| REQ-023 | Self-signed mTLS cert generation | Medium | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-024 | Makefile with standard targets |
High | v0.1 P01 | Complete |
| REQ-025 | Bounded cert rotation history: retain last N=3 server certs per node for rollback | Medium | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-026 | Trusted-CA fingerprint pinned in config; daemon refuses to start on mismatch | High | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-027 | govulncheck runs in offline mode in CI (no vuln.go.dev calls; pre-mirrored DB or -format json + jq gate) |
High | v0.2 P03 | Complete (P10 shipped v0.2.3) |
| REQ-028 | HCL/YAML schema for NodeCapacity declaration (orca node join flag and/or ~/.orca/node.hcl) |
High | v0.2 P02 | Complete (P09 shipped v0.2.2; orca node capacity CLI) |
| REQ-029 | gitleaks baseline file committed to repo to suppress pre-existing .env SHA-1 leak in git history |
Medium | v0.2 P03 | Complete (P10 shipped v0.2.3) |
| REQ-030 | --watch output format mode: table (default) vs streaming one-line JSON per event |
Low | v0.3 P01 | Complete (v0.3 P01 shipped v0.3.1) |
| REQ-031 | go test -race enabled in CI for all v0.2 packages |
High | v0.2 P01–P04 | Complete (P10; .coreci.yml test pipeline runs -race) |
| REQ-032 | orca doctor subcommand for diagnostics (CA/cert health, db integrity, peer reachability) |
Medium | v0.2 P01 / v0.3 P02 | Complete (cert checks P01 v0.2.1; network + db P02 v0.3.2) |
| REQ-033 | Cert file mode enforcement: 0600 for keys, 0644 for certs (refuses to start on violation) | High | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-034 | Cert proactive rotation alarm: structured slog WARN 30 days before not_after |
Medium | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-035 | orca cert show redacts private key material from default and --json output |
High | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-036 | Server cert SAN validation: SAN entries (DNS + IP) populated at sign-time; refuses to sign a CSR without them | High | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-037 | X-Orca-Idempotency-Key header on cross-node POST; dispatcher retries only when header is present |
Medium | v0.2 P02 | Complete (P09 shipped v0.2.2; internal/transport/idempotency.go) |
| REQ-038 | Structured slog fields for mTLS failures: event=mtls.handshake, peer, cert_fp, err |
Medium | v0.2 P01 | Complete (P01 shipped v0.2.1) |
| REQ-039 | .gitleaks.toml extended with stopwords for test data paths and CA cert PEM blocks |
Medium | v0.2 P03 | Complete (P10 shipped v0.2.3) |
| REQ-040 | .golangci.yml unified lint config superseding per-tool invocations |
Low | v0.2 P03 | Complete (P10 shipped v0.2.3) |
| REQ-041 | Unified namespace root via ORCA_HOME for all components (db, certs, init, daemon) |
High | v0.5 P1 | Complete (P1 shipped v0.4.2) |
| REQ-042 | --system flag selects system-level namespace root /root/.orca |
High | v0.5 P1 | Complete (P1 shipped v0.4.2) |
| REQ-043 | install.sh 1-liner pulling release binary from public Gitea URL; user-level default, --system for system-level |
High | v0.5 P2 | Complete (P2 shipped v0.4.3) |
| REQ-044 | install.sh in-place update preserves config/state; idempotent re-run |
High | v0.5 P2 | Complete (P2 shipped v0.4.3) |
| REQ-045 | Gitea repo + releases publicly accessible (unauthenticated download) | High | v0.5 P0 | Complete (P0 ship: repo + org visibility public) |
| REQ-046 | Docker image published to Gitea container registry per release | Medium | v0.5 P3 | Complete (P3 shipped v0.4.4) |
v0.1 Milestone Summary
Status: Complete — all 6 phases shipped (P00–P06) plus P07 backfill,
4-layer verification passed at every phase, tagged v0.2.0 per
run.md versioning logic (next-minor after all feature-patches
v0.1.1..v0.1.7 ship).
Coverage: 21/24 v0.1-declared requirements complete by v0.1 ship; the 3 deferred (REQ-011, REQ-014, REQ-022, REQ-023) all moved to v0.2. Plus REQ-025..REQ-040 (16 net-new) added by v0.2 IDEATE stage.
v0.2 Milestone Summary
Status: Functionally Complete (pending merge to main) — P08 (mTLS),
P09 (scheduling), P10 (security scan) all shipped to the
milestone/v0.2-networking-observability-security branch as v0.2.1,
v0.2.2, v0.2.3. The milestone branch has NOT been merged to main yet.
REQ-022/030 (iter.Seq streaming) and REQ-032 (doctor network/db) were
deferred to v0.3.
v0.3 Milestone Summary
Status: Complete — P01 (iter.Seq streaming, v0.3.1) and P02 (doctor network+db, v0.3.2) both shipped. REQ-022, REQ-030, REQ-032 all complete. Re-init SPECIFY audit confirmed all other v0.2-deferred REQs (014, 027, 028, 029, 031, 037, 039, 040) already shipped in P08-P10.
Deferred to v0.4
- pprof endpoint on
orca daemon(idea I-308, 0.70 confidence): deferred to keep v0.2 lean; revisit in v0.3 once P02's dispatcher is stable.
v0.5 Milestone Summary
Status: Complete — all 3 execution phases + final review shipped. P0 (v0.4.1), P1 (v0.4.2), P2 (v0.4.3), P3 (v0.4.4), P4 final (v0.4.5). REQ-041..046 all complete. Repo + releases publicly accessible (REQ-045). Docker image published to Gitea container registry (REQ-046).
- P0 (v0.4.1): pre-execution + repo visibility flipped to public (REQ-045).
- P1 (v0.4.2): namespace unification —
ORCA_HOME+--system(REQ-041/042). - P2 (v0.4.3):
install.sh1-liner + in-place update (REQ-043/044) + README quickstart (REQ-016). - P3 (v0.4.4): Docker release — distroless image + Gitea container registry (REQ-046).
- P4 (v0.4.5): final review + audit + milestone release.
v0.6 Requirements — Node Bootstrap & Proxmox
| ID | Requirement | Priority | Phase | Status |
|---|---|---|---|---|
| REQ-047 | orca init auto-provisions CA + server cert + DB migrations + localhost node (idempotent; safe re-run) |
High | v0.6 P1 | Complete (P1 shipped v0.5.1) |
| REQ-048 | orca init registers a default localhost node with auto-detected OS via /etc/os-release ID |
High | v0.6 P1 | Complete (P1 shipped v0.5.1) |
| REQ-049 | Node schema extension: nodes.kind (localhost|linux|proxmox) + nodes.os columns (migration 0006, backward-compatible) |
High | v0.6 P1 | Complete (P1 shipped v0.5.1) |
| REQ-050 | orca node join --type proxmox SSH bootstrap via golang.org/x/crypto/ssh (new direct dep); password auth, deploy orca pubkey, create orca user (config-overridable), assign PVE role, drop sudoers allowlist; idempotent |
High | v0.6 P2 | Complete (P2 shipped v0.5.2) |
| REQ-051 | Proxmox least-privilege OrcaOperator PVE role (VM.Audit, Datastore.AllocateSpace, SDN.Use) + orca user + /etc/sudoers.d/orca allowlist (pct, qm, pvesh, apt-get, dpkg); config-overridable user/role names |
High | v0.6 P2 | Complete (P2 shipped v0.5.2; refined: pvesh excluded per AD-020, orca@pam per AD-019) |
| REQ-052 | orca doctor extensions: doctor os (verify localhost OS detection matches stored node row) + doctor proxmox (SSH-probe each kind=proxmox node with pveversion/pvecmd status, 3s timeout, PASS/WARN/FAIL); audit log all bootstrap + join actions |
Medium | v0.6 P3 | Complete (P3 shipped v0.5.3) |
v0.6 Milestone Summary
Status: Complete — all 3 execution phases + final review shipped. P0 (v0.5.0), P1 (v0.5.1), P2 (v0.5.2), P3 (v0.5.3), P4 final (v0.5.4). REQ-047..052 all complete.
- P0 (v0.5.0): pre-execution (specify → clarify → research → plan). 8 decisions (D-030..D-037).
- P1 (v0.5.1):
orca initfull bootstrap + schema 0006 (REQ-047/048/049). - P2 (v0.5.2): Proxmox SSH join + OrcaOperator role + sudoers (REQ-050/051).
- P3 (v0.5.3):
doctor os+doctor proxmox+ audit logging (REQ-052). - P4 (v0.5.4): final review + audit + milestone release.
v0.7 Requirements — Hardening & Completion
| ID | Requirement | Priority | Phase | Status |
|---|---|---|---|---|
| REQ-053 | orca cert command tree registered on root command (cert ca-init, cert gen, cert show, cert renew, cert fingerprint) — code exists in internal/cli/cert.go but is never AddCommand'd; unreachable today |
High | v0.7 P1 | Complete (P1 shipped v0.6.1) |
| REQ-054 | HCL config file parsing: internal/config package loads ~/.orca/config.hcl / /etc/orca/orca.hcl (keys: db_path, listen_addr, ca_path, server_cert_path, server_key_path, node_capacity); merge precedence flag > env > file > default; --config flag on root command |
High | v0.7 P2 | Complete (P2 shipped v0.6.2) |
| REQ-055 | Test coverage uplift: every package ≥ 50% — adds tests for internal/engine (executor, dispatcher, peer), internal/transport (mtls, dispatch, handshake_log), internal/proxmox (bootstrap SSH path), internal/audit |
Medium | v0.7 P3 | Complete (P3 shipped v0.6.3) |
| REQ-056 | --pprof <addr> opt-in flag on orca daemon (default disabled); net/http/pprof mounted on a separate mux, never on the mTLS daemon listener |
Low | v0.7 P4 | Complete (P4 shipped v0.6.4) |
v0.8 Requirements — Coverage & Trust Hardening
| ID | Requirement | Priority | Phase | Status |
|---|---|---|---|---|
| REQ-057 | Test coverage uplift round 2: raise internal/engine (8.3%), internal/proxmox (5.1%), internal/cli (27.6%), internal/transport (26.3%), internal/store (46.7%), internal/jobspec (47.6%) to ≥ 70%; add first tests for internal/audit, internal/certpaths, cmd/orca (currently 0%) to ≥ 50% (D-047 tiered floor) |
High | v0.8 P1 | Complete (P1 shipped v0.7.1; all 9 packages exceeded floor) |
| REQ-058 | --host-key-fingerprint <SHA256:base64> pre-pin flag on orca node join (validated when --type proxmox): when supplied, join fails fast if the SSH host key's OpenSSH SHA-256 fingerprint does not match; supersedes TOFU (D-035) for pre-pinned deployments (D-044, D-045) |
Medium | v0.8 P2 | Complete (P2 shipped v0.7.2) |
| REQ-059 | orca node key-reset <node> command: clears the persisted SSH host key entry for the node from ~/.orca/known_hosts only (local, not remote authorized_keys — D-046); audit-logs event=node.key_reset; next doctor proxmox/dispatch re-pins via TOFU or --host-key-fingerprint |
Low | v0.8 P2 | Complete (P2 shipped v0.7.2) |
| REQ-060 | Requirement-status hygiene sweep: REQUIREMENTS.md v0.7 rows were stale ("Pending" after ship); add a verify-stage assertion that every REQ listed as Complete in ROADMAP.md has a matching Complete row in REQUIREMENTS.md, enforced by make verify-reqs |
Medium | v0.8 P3 | Complete (P3 shipped v0.7.3) |
v0.9/v0.10 Requirements — Re-architecture Foundation & Production Hardening
The v0.9/v0.10 milestones supersede the shipped v0.1–v0.8 architecture per the
adopted PRD (.ciagent/PRD_v0.9.md). The re-architecture is justified on six
grounds recorded in the PROJECT.md Supersession Table. 30 net-new requirements
(REQ-061..REQ-090) derive from the v0.9 IDEATION; their phase placement and
binding grill conditions (C-01..C-19) are documented in IDEATION_v0.9.md
and GRILL_v0.9.md.
| ID | Requirement | Priority | Phase | Status |
|---|---|---|---|---|
| REQ-061 | orca daemon deprecation command and build-tag removal path: v0.9 emits deprecation warning + still runs (dual-write window); v1.0 repurposes to orca daemon drain-and-stop (stops v0.8 daemons on peers via SSH, confirms workloads survive via systemd); post-v1.0 the command and internal/daemon/ are deleted. // Deprecated Go doc comments + slog.Warn on every run (I-M-001) |
High | v0.10 P14 (warn v0.9 P0X) | Pending |
| REQ-062 | Coverage follow-ups: 3 zero-test packages (internal/audit, internal/certpaths, cmd/orca) + internal/cli to 70% floor; once daemon.go is deprecated/removed the exclusion reason disappears and the floor applies to the whole package; all net-new subsystems carry a 70% floor from their first phase (I-M-002) |
Medium | v0.9 P0X + each new pkg | Pending |
| REQ-063 | known_hosts flock concurrency gap (deferred P1 from REVIEW_v0.8 A2): add flock-style advisory lock (stdlib syscall.Flock wrapper) around the read-modify-write in TOFUHostKeyCallback capture path (bootstrap.go:290-302) and ResetHostKey (bootstrap.go:479-523); lock file at cluster/known_hosts.lock (R-002) (I-M-003) |
Medium | v0.9 P0a1 | Pending |
| REQ-064 | HCL→Markdown jobspec adapter/bridge layer: keep internal/jobspec/spec.go as legacy HCL path behind // Deprecated; add internal/jobspec/markdown.go (canonical) + internal/jobspec/dispatch.go (extension-based dispatcher: .md→Markdown, .hcl→legacy, .yaml→Markdown-with-empty-body); unified *WorkloadSpec populated via adapter; preserves orca job run old-spec.hcl during migration window (I-M-004) |
High | v0.9 P0b | Pending |
| REQ-065 | orca doctor --legacy-paths detection: detects v0.8 residue (orca.db at ORCA_HOME root, ca.crt/ca.key, config.hcl, flat server.crt, namespace column in any *.db); outputs list of legacy artifacts with migration recommendations; the detection half of v0.10-P14 (I-M-005) |
Medium | v0.10 P14c | Pending |
| REQ-066 | Legacy CA state migration to step-ca: orca upgrade --to-v1.0 --import-ca reads ~/.orca/ca.key, initializes step-ca with it, re-issues workload SVIDs; preserves audit history even if live trust root changes (I-M-006). Gated by C-07 |
High | v0.10 P14a | Pending |
| REQ-067 | Fuzz test harness for Markdown frontmatter parser: testing.F fuzz target in internal/jobspec/markdown_test.go round-trips random frontmatter+body through ParseMarkdown asserting byte-exact body preservation; corpus of adversarial fixtures (CRLF, BOM, no-frontmatter, empty-frontmatter, frontmatter-with-only-separator) (I-M-007) |
Medium | v0.9 P0b | Pending |
| REQ-068 | Deprecation warnings on removed/repurposed CLI subcommands: each removed/changed command (orca cert, orca node join mTLS semantics, orca job run <spec.hcl>) emits slog.Warn deprecation banner with v1.0 replacement except under orca upgrade; --no-deprecation-warnings global flag via root.go PersistentPreRunE (I-M-008) |
Low | v0.9 P0X + v0.10 P13 | Pending |
| REQ-069 | internal/config/config.go HCL config demotion via adapter: keep internal/config/ as legacy_config.go with // Deprecated; add internal/config/markdown.go for new Markdown-frontmatter loader (R-014); root.go dispatches on file extension (.hcl→legacy, .md→new); --config semantics: .hcl read-only legacy, .md canonical (I-M-009) |
High | v0.9 P0a1 | Pending |
| REQ-070 | internal/certpaths/ replacement with multi-namespace path resolver: new internal/paths package with paths.NamespaceDir(ns), paths.ClusterDir(), paths.CacheDB(), paths.MasterKey(), paths.NSDb(ns), paths.NSEnv(ns), paths.NSSecrets(ns); keep certpaths as thin shim for v0.8 compat then remove post-v1.0 (R-002) (I-M-010) — highest blast radius |
High | v0.9 P0a1 | Pending |
| REQ-071 | internal/store/ schema: per-namespace DBs, drop namespace column: store.Open gains namespace parameter (or caller passes paths.NSDb(ns)); migrate.go runs migrations per namespace DB; cert_repo (0004) removed (step-ca handles certs); audit_log moves to CLI-side cache DB (R-008) (I-M-011) |
High | v0.9 P0a1 + v0.10 P06 | Pending |
| REQ-072 | internal/transport/ deletion + SSH-push package: delete mtls.go, dispatch.go, handshake_log.go; extract retry/idempotency patterns into internal/sshpush/; existing transport.IdempotencyStore directly reusable (I-M-012). Deletion deferred to v0.10-P14 to keep dual-write window open |
High | v0.9 P00 (delete v0.10 P14) | Pending |
| REQ-073 | SSH-push transport layer design: connection pooling (reuse *ssh.Client per peer), idempotency (content-addressed filenames), retry (exponential backoff 100ms×2 cap 5s max 5), timeout (30s SCP, 10s exec), fan-out (errgroup bounded concurrency default 8), known_hosts reuse proxmox.TOFUHostKeyCallback (I-B-001) |
High | v0.9 P01 (design P0a1) | Pending |
| REQ-074 | Emitter template system (Layer 4): internal/emitter/ package with Emitter interface Render(spec *WorkloadSpec, node *Node) ([]File, error); implementations systemdEmitter/traefikEmitter/syncthingEmitter/socketEmitter; SSH-push SCPs []File atomically (write-to-tmp + rename); emitters registered per kind + runtime (I-B-002) |
High | v0.9 P0c | Pending |
| REQ-075 | Lead applier execution model: CLI renders transaction bundle (tarball + apply.sh + verify.sh) on operator host, SCPs to lead's /run/orca/txns/<txn-id>/, lead's systemd timer runs apply.sh idempotently, CLI polls txn status via SSH; bash scripts generated by emitter not hand-written (I-B-003). Gated by C-09 |
High | v0.10 P10 (design v0.9 P00) | Pending |
| REQ-076 | step-ca integration: orca init runs step ca init on lead; CLI SSHs to lead, installs step-ca via apt, stores step-ca.json; workload SVIDs via step ca token (JWE minted by CLI) → step ca certificate; SPIFFE ID as SAN; new internal/stepca/ package wraps step CLI via SSH (I-B-004). Reverses AD-010 per override justification ground 2 |
High | v0.9 P07 + v0.10 P02 | Pending |
| REQ-077 | Traefik dynamic config generation + atomic reload: Traefik emitter renders /etc/traefik/dynamic/orca-<ns>-<svc>.yaml with backends (socket paths R-007), health checks, mTLS config pointing at step-ca root; atomic reload via tmpfile+fsync+rename triggering fsnotify; drain writes weight=0 or removes backend (I-B-005). Gated by C-10 |
High | v0.9 P02 | Pending |
| REQ-078 | Runtime abstraction interface (5 backends): Runtime interface in internal/runtime/ with Prepare/Start/Stop/Status; processRuntime (wraps existing executor.go), wasmRuntime (wasmtime via SSH), podmanRuntime, pveVMRuntime (qm via proxmox SSH), pveCTRuntime (pct); runtimeRegistry keyed by runtime: frontmatter value; Alloc carries runtime field changeable on migration (I-B-006). Split P07a/b/c per PC-10. P07b gated by C-01 |
High | v0.9 P07a/b/c | Pending |
| REQ-079 | Transaction bundle format + N-peer atomicity: bundle = tarball with desired-state.json + apply.sh + verify.sh + rollback.sh + manifest.sig (signed with master.key); content-addressed <txn-id>=sha256(desired-state.json) stored in cluster/txns/<txn-id>/; lead applies to self first then fans out; failure on any peer runs rollback.sh on applied peers (I-B-007). Gated by C-09 |
High | v0.10 P10 (design v0.9 P00) | Pending |
| REQ-080 | Master key management + HKDF-SHA256 per-line .env.secrets encryption: cluster/master.key 32-byte random (generated at orca init using WriteAtomic pattern); each line `base64(nonce |
ciphertext | ||
| REQ-081 | Syncthing config rendering + folder-ID content-addressing: per-namespace Syncthing folder orca-<ns> with content-addressed folder ID sha256(ns + master-key-fingerprint); CLI renders config.xml per peer; Syncthing runs as systemd unit (emitted by systemd emitter); CLI discovers peers via cluster/peers/; migration works because new node joins folder and syncs before workload starts (I-B-009). Gated by C-02 + C-14 |
Medium | v0.9 P09 (spike v0.9 P00) | Pending |
| REQ-082 | Namespace inheritance resolver algorithm: DFS parent walker with visited set for cycle detection; _defaults/ implicit root (always exists, no parent); merge semantics: child overrides parent for scalars, arrays unioned (child adds to parent); pure function (no I/O) taking map[nsName→*NSConfig] returning map[nsName→*ResolvedNS] (I-B-010) |
High | v0.9 P0a2 | Pending |
| REQ-083 | CLI-side scheduler redesign: Score(node, workload) (score int, fits bool) where fits checks runtime compatibility + constraints, score is bin-packing (most free capacity = highest); Services pick count distinct nodes (anti-affinity default); DaemonSets pick all matching nodes; Job = one-shot; CLI-side not daemon-side (R-001) (I-B-011) |
High | v0.9 P05 (skeleton P0c) | Pending |
| REQ-084 | orca job lint category-driven lint engine: Linter runs Rule checks returning Finding{Category, Severity, Message, Explanation}; categories schema/runtime/security/migration/best-practice; --explain prints rationale; pure (no I/O) checks against static rules (I-B-012) |
Medium | v0.10 P11 | Pending |
| REQ-085 | v0.8→v1.0 migration ordering: v0.9 ships new parser + kinds + runtime + SSH-push alongside old daemon (dual-write window); orca job run dispatches on extension (.md→SSH-push, .hcl→old daemon); v0.10-P05 drains old daemons; v0.10-P14 converts remaining .hcl specs and removes daemon (I-C-001). Most important cross-cutting idea |
High | v0.9 P00 → v0.10 P14 | Pending |
| REQ-086 | "No orca on server" enforcement: orca doctor no-orca-on-server SSHs to each peer verifying no orca binary in PATH, no orca systemd service, no orca process, no /etc/orca/ directory; runs after v0.10-P05 before v0.10-P16; reuses v0.8 proxmox SSH session infrastructure (I-C-002). Implements grill C-13 |
High | v0.10 P14c | Pending |
| REQ-087 | Test infrastructure: hermetic 3-linux + 1-proxmox cluster pipeline: test/integration/ with docker-compose/vagrant creating 4 containers/VMs; Go test harness SSHes to each, runs CLI, asserts end-to-end workflows (ns create → workload submit → migrate → drain); proxmox simulated via mock pct/qm; v0.8 e2e tests (bootstrapE2ESetup) are foundation (I-C-003) |
Medium | v0.10 P08 (bootstrap v0.9 P00) | Pending |
| REQ-088 | Security-engineer + network-engineer persona reactivation: reactivate security-engineer (step-ca provisioner model, SSH-push blast radius, Traefik edge, .env.secrets crypto) and network-engineer (socket exposure R-007, Syncthing P2P ports, Traefik routing); cross-cutting review not single phase (I-C-004). Implements grill C-05 | High | v0.9 P00 → v0.10 P16 | Pending |
| REQ-089 | Documentation rewrite: ARCHITECTURE.md/PROJECT.md/README + AD-010 supersession: v0.9-P00 adds "v0.9 Architecture (Supersedes v0.8)" section + banners + Superseded Decisions table; v0.10-P15 rewrites README quickstart for new curl | sh + orca init + orca ns create flow (I-C-005) | Medium | v0.9 P00 + v0.10 P15/P16 |
| REQ-090 | Dual-write window: v0.9 orca job run dispatches on extension (.md→SSH-push new path, .hcl→old daemon path) via parser dispatcher (REQ-064); daemon not removed until v0.10-P05; SSH-push path writes to separate systemd unit namespace (orca-v1-<alloc>.service) while daemon uses orca-<job>.service — no unit name overlap = no conflict (I-C-006) |
High | v0.9 P00 | Pending |