Split out #266 — memberCredentials.sshAuthSock's value names (block/allow) make the same kind of claim this ticket is about, one layer down. block names an effect fleetd does not have: it…
Item 1 is done — merged as fa97f59 (PR #265). fleetd now logs the member trust model at startup, and the message changes when memberHerdrSocket is set. The unset branch says plainly…
Merged to main as fa97f59.
I re-ran the mutation proof myself rather than taking the report on trust. Breaking the configured branch (if (false && ...)) turns MemberTrustModelReportTest…
Item 1 progress — the "write down the truth" half is done, the startup warning is in flight.
Done: the config no longer lies
PR #264, merged as b5ddbe5, with a follow-up in a2b8caf. The…
Merged to main as b5ddbe5, with a follow-up in a2b8caf. Build: 1262 tests, 0 failures.
The correction itself is right, and the four points I asked for are all there in plain language. Thank…
I put this to an architect as a design question — "what is the honest security boundary we can actually build, and what should we stop claiming?" — rather than as an implementation job. Its…
Fixed. PR #262 merged to main as e2fe861, with a follow-up correction in f0e7ac7.
What shipped
Route B — document it completely. The worker picked this over sourcing the secret store,…
free and the spawn gate now disagree by one on subscription profiles