2.8 KiB
2.8 KiB
Exact staged installation and acceptance order
Every numbered boundary requires review and explicit approval. Nothing here authorizes execution.
- From this directory, run only
tests/00-root-preinstall-validate.shas root and require zero failures. It atomically checks both manifests, staged nftables/systemd/shell/JSON, exact Phase 1 ownership/modes, absent approval marker/installed payload/manager/process/socket/linger, and public/NAT address drift. Save output outside production. - Preserve the approved Quad9 DNS pair
9.9.9.9and149.112.112.112, observed public/NAT address denial74.67.173.56, and verified root inventory. Quad9 requires no LAN exception;192.168.10.1remains denied. Any different value or public/NAT drift requires artifact edits, a new manifest, and another review. - Copy only the manifest-listed launcher to
/usr/local/libexec, mode0755,root:root; rehash the installed file. - Copy only the slice and
user@1200.servicedrop-ins, resolver file, namespace helper/unit, and nftables fragment to their manifest paths withroot:root, directories/files0755/0644, helper0755. After exact-value approval, create root-owned mode0644/etc/le-app-codex-runtime/OPERATOR-INPUTS-APPROVEDcontaining the artifact-manifest checksum and approval timestamp. Do not start anything. Runsystemd-analyze verifyandnft --check -f; inspect the mergedsystemctl cat/properties. - Copy the Docker user unit/config/context and tests below
/srv/le-app-codex; set directories0750, config/unit/tests0640except tests0750, all owned1200:1200. Do not create credentials, checkout, or source copies. - Run
systemctl daemon-reload. Confirm the user manager remains inactive, lingering absent, and socket/process absent. - Start only
le-app-codex-netns.service. Inspect namespace identity, IPv4-only addresses/routes, nftables counters/rules, host routing, and production Docker health. Stop on any drift. - Run
tests/run-inert-without-user-manager.sh. This starts only a finite transient test process, neveruser@1200.service, Docker, or Codex. Require every filesystem/process/cgroup/device/socket/network assertion to pass. - Review the inert evidence. Only a later explicit runtime-acceptance approval may start
user@1200.service, enabledocker.servicewithin its controlled lifetime, or runtests/20-rootless-docker.shas UID 1200. - The later positive/negative Docker test uses only
unix:///run/user/1200/docker.sock, disposable pinned images, and teardown. It must prove rootless/data-root/context behavior and denial of rootful sockets, private/host/LAN/VPN/metadata/SMTP/IPv6, and published ports. - Stop the manager after testing. Codex authentication, Codex startup, repository/source/credential copying, application startup, and production changes remain out of scope.