add Phase 2A host maintenance procedure
This commit is contained in:
parent
13ec935e87
commit
2cf249d6f2
9 changed files with 1119 additions and 3 deletions
|
|
@ -10,7 +10,7 @@ Status: revised pre-implementation plan. Work stops at the Milestone 0 host-runt
|
|||
|
||||
2. **Host runtime gate — requires human approval/provisioning**
|
||||
- Preserve the completed inert `le_app_codex` Phase 1 identity/workspace; do not rerun bootstrap artifacts.
|
||||
- Select the Phase 2 package path separately; never perform a partial Arch upgrade or install the unmodified AUR extras package.
|
||||
- Preserve the provisional Path A selection: prepare a scheduled complete Arch host upgrade, but require separate approval for the final transaction and reboot; never perform a partial Arch upgrade or install the unmodified AUR extras package.
|
||||
- Use a version-matched, checksum-pinned Moby launcher and a genuine per-user Docker service managed through root-controlled `user@1200.service`; never enable lingering or run `dockerd` from a system service with `User=le_app_codex`.
|
||||
- Apply containment and the proposed `user-1200.slice` limits to the complete user manager; accept only `unix:///run/user/1200/docker.sock`.
|
||||
- Create an IPv4-only root-owned namespace with default-deny egress and explicit host/LAN/WireGuard/metadata/private/loopback/bridge/SMTP/IPv6 denial after DNS and complete address inventories are approved.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue