S15: Historical-Information, deploy-ns1, promote gate SHAs
Continue-until-done instructions live in Historical-Information.MD. run-review.sh now covers signed-config HTTP and catalog subjects. deploy-ns1.sh never skips tests and does not set PFC_REQUIRE_NPE.
This commit is contained in:
parent
c71dce2187
commit
c570dc10fb
10 changed files with 288 additions and 8 deletions
|
|
@ -3,7 +3,7 @@
|
|||
Decisions to confirm later. Work continued with guesses in `TODO-With-User.MD`.
|
||||
|
||||
1. **System public key custody** — lab Ed25519/X25519 generated into `keys/system/` (gitignored private). Production should be customer HSM. Rotate via signed config + admin-history cube.
|
||||
2. **Cut over `PFC_REQUIRE_NPE=1` on ns1** — not in this round (would fail-close the live console).
|
||||
2. **Cut over `PFC_REQUIRE_NPE=1` on ns1** — still not this round. `/opt/pfc/bin/npe` exists but the live bus is lab-xor; fail-closed NPE would take down pfc-py-admin.
|
||||
3. **Caddy hostname** for this hub (`sync.pfc.georgelambert.org` vs a path under `docs.pfc`). Guess: path `/sync/` under existing docs host after CI.
|
||||
4. **verae org** is empty — leave empty unless you want it as the canonical NATS catalog owner instead of `marchon`.
|
||||
5. **Website org** — no NATS changes. Confirm if any site should deep-link the endpoint catalog.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue