Repository navigation
Phase 3: deploy one isolated live runner and prove one-job destruction #7
Copy link
Copy link
Closed
Description
Activity
Phase 3 live-pilot preflight update (
rd-ci-fleet-live-pilot-v1):ci-fleetis clean currentmainatc5a6bd4cdb3add2bc7ae9a0fcea27c9cf11814b1.- A dedicated private pilot repository now contains exactly one active, manual-only workflow. It uses only
contents: read, requests onlydocker-ci-experimental, and pinsactions/checkoutto an immutable commit. Dispatch count remains zero. - The existing organization-owned
rd-ci-fleet-01GitHub App installation has Metadata read-only, organization Self-hosted runners read/write, and repository Administration no access. - Stopped at two hard gates: the authenticated GitHub CLI OAuth token lacks the
admin:orgscope required to inspect/create/restrict the organization runner group, and the designated pilot host is ICMP-reachable but refuses SSH on port 22. Host isolation, services, containers, mounts, configuration, PEM ownership/mode, preflight, and image state therefore cannot yet be verified.
No controller was started, no workflow was dispatched, no runner or scale set was created by this session, and no cleanup apply was run. Existing downstream-consumer runners, development, and production were not modified. Issue #7 remains open.
Resume only after an operator approves
admin:orgfor the existing GitHub CLI session and restores an authorized secure management path to the designated isolated host. Do not use the Default runner group or broaden repository access.Phase 3 live lifecycle proof passed with one permitted root-cause retry.
- GitHub authorization includes
admin:org;trusted-private-ci-experimentalis selected-repositories-only, allows no public repositories, and authorizes only the private pilot repository. Default and downstream consumers are excluded. - Existing isolated controller was reconciled without duplication:
docker-ci-rd-ci-fleet-01, labeldocker-ci-experimental, MIN=0, MAX=1. Committed preflight ended exactlyPREFLIGHT_OK warnings=0. - Initial run 29451460747 exposed a root-owned volume/non-root proof-writer defect; its runner and resources were destroyed. The one-line root-cause fix merged in fix: allow live pilot to write Docker volume #29 and was copied to the pilot.
- The single permitted retry succeeded; its evidence remains in the private pilot record: one queued job, one JIT-backed ephemeral runner, one accepted job,
contents: read, Docker capability pass, scoped container/network/volume proof pass, then runner destruction. - Final state: zero runner/job containers, pilot networks, pilot volumes, workspaces, persisted JIT/token artifacts, or expired cleanup candidates. Scoped cleanup dry-run listed nothing; apply was unnecessary. Healthcheck passed with the controller running and disk at 5%.
- Rollback is documented. Existing downstream-consumer runners remained unchanged; neither workflow was dispatched by this task.
Current ci-fleet main:
674fe318f851e750dcc31f538ac927331b8e4df4.- GitHub authorization includes
Metadata
Metadata
Assignees
Labels
No labels
Outcome
Deploy one controller on one isolated Docker host, register one organization-level experimental scale set, run one manually dispatched read-only job, and prove that the runner and job resources disappear afterward.
Prerequisites
/etc/ci-fleet/secrets/github-app.pemPilot
MIN=0,MAX=1contents: readRollback
Hard gates
Repository preparation evidence
ci-fleetrepository excluded from live runner accessEvidence: commit 8447ef8, validation run 29287297659.
The issue remains open at the host, private pilot repository, runner-group, and GitHub App authorization gate.