Repository navigation
Conversation
Covers the spoke half of the air-gap transport (Basekick-Labs/arc PR 9b): the [edge_sync.spoke.bundle] block, writing and inspecting a bundle, the destination allow-list, the exported-vs-synced distinction, and reverting a drive that never arrived. Explains the two format decisions rather than just stating them: a directory over an archive because resume is free and the contents are auditable with ls and sha256sum, which matters when someone has to inspect what crosses an air gap. States what is NOT in the release: the hub-side import, the acknowledgment that advances exported to synced (so ledgers do not prune yet), and that bundles are signed but not encrypted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
7 tasks done
Covers the import half (Basekick-Labs/arc PR 9c): the [edge_sync.import] block, importing a drive, the three refusals an operator will actually meet, and the import history endpoint. Explains why a duplicate drive is refused by a dedup ledger rather than a timestamp window — the online freshness check works because a request is in flight, and a bundle is not. Notes the (spoke_id, bundle_id) key, so a compromised spoke cannot block another's future drives. Documents cluster-mode Raft batching, since a 2,500-file bundle costing 3 proposals instead of 2,500 is the kind of thing an operator sizing a cluster needs to know. Removes the "hub-side import is not in this release" limitation. The acknowledgment limitation stays. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Aug 7, 2026
docs(edge-sync): document hub-side air-gap import
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Documents the spoke half of the air-gap transport (Basekick-Labs/arc#581): the
[edge_sync.spoke.bundle]block, writing and inspecting a bundle, the destination allow-list, the exported-vs-synced distinction, and reverting a drive that never arrived.Explains the two format decisions rather than just stating them — a directory over an archive because resume is free and the contents are auditable with
lsandsha256sum, which is what matters when someone has to inspect what crosses an air gap.States what is NOT in the release
syncedand are not pruned. On a long-running air-gap spoke the ledger grows until that ships.Ships alongside Basekick-Labs/arc#581; every documented endpoint, config key, and status code was verified against the shipped code rather than the design doc.
🤖 Generated with Claude Code