mirror of
https://scm.tikali.ai/tikali/applications/monky/monky-deployd.git
synced 2026-09-18 05:36:15 +00:00
837a7e5bb1
The first real kit run (env-qa-02) downloaded monky-deployd_26.04 LTS (Resolute Raccoon)_amd64.deb: sourcing /etc/os-release inline overwrote VERSION. Script vars are now DEPLOYD_VERSION and os-release is read in a subshell. Per the operator's rule (end users run ONE script), install.sh now installs Docker Engine when absent — Docker's apt suite for the host codename, falling back to Ubuntu's docker.io — with --docker-data-root <dir> to place the data-root before first start. Existing Docker is left untouched. bash -n + shellcheck -S warning clean. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
57 lines
3.9 KiB
Markdown
57 lines
3.9 KiB
Markdown
<!-- xlate:verbatim-fences -->
|
||
# Changelog
|
||
|
||
## 0.1.3 — 2026-09-06
|
||
|
||
- **install.sh: `--version` was clobbered by `/etc/os-release`** (it defines `VERSION`), so the kit tried to download
|
||
`monky-deployd_26.04 LTS (Resolute Raccoon)_amd64.deb` (env-qa-02 pilot, first real kit run). Script variables are now
|
||
`DEPLOYD_VERSION`; os-release is read in a subshell.
|
||
- **install.sh installs Docker Engine when absent** (Docker's apt suite for the codename → fallback `docker.io`), with
|
||
`--docker-data-root <dir>` to place the data-root before first start. One script for the end user, per the operator's rule.
|
||
|
||
## v0.1.2 — 2026-09-05
|
||
|
||
- **The GitLab project is private** (its parent groups are private, so it cannot be made public;
|
||
found when the v0.1.1 one-liner returned 401 anonymously). `install.sh` gains `--token <deploy-token>`
|
||
/ `MONKY_DEPLOYD_TOKEN`: every download from the generic package registry — the script itself
|
||
included — sends `DEPLOY-TOKEN: <token>`, a read-only GitLab **deploy token** (scope
|
||
`read_package_registry` only, revocable), seeded in OpenBao at `monky/monky-tenancy/deployd-download`
|
||
(key `token`) and handed to the box by the monky-tenancy install kit. The token never reaches the
|
||
command line, the log or an xtrace (curl `-K` config file, 0600, deleted after the download;
|
||
`set +x` forced). The one-liner now fetches `install.sh` from the registry
|
||
(`…/monky-deployd/<ver>/install.sh`) instead of `-/raw/main`, and takes the bootstrap grant via
|
||
`--bootstrap-file` — with `curl … | bash -s --` stdin IS the script, so it is no longer read for
|
||
the grant in that mode. `--source gitea` (no token) stays the off-estate alternative.
|
||
- Ansible role: `monky_deployd_download_token` (vaulted) → `DEPLOY-TOKEN` header on both fetches,
|
||
`no_log: true`.
|
||
- README / OPERATIONS: why (private project; split-horizon Gitea, cbs/iac#102), token scope, revocation.
|
||
No agent behaviour change.
|
||
|
||
## v0.1.1 — 2026-09-05
|
||
|
||
- `install.sh` / ansible role / README: the **primary download is the public GitLab project's generic
|
||
package registry on scm.tikali.ai** (`/api/v4/projects/69/packages/generic/monky-deployd/<ver>/…`);
|
||
the one-liner fetches the script from `scm.tikali.ai/…/-/raw/main/packaging/install.sh`. Inside the
|
||
estate `gitea.cbs.tikali.net` is split-horizon to jump1's RED EIP (no HTTP ingress), so backend
|
||
boxes could not fetch the artefacts (cbs/iac#102). The Gitea release stays the off-estate
|
||
alternative (`--source gitea` / `MONKY_DEPLOYD_SOURCE=gitea`). No agent behaviour change.
|
||
|
||
## v0.1.0 — 2026-09-05
|
||
|
||
First release (MONKY-ADR-0028 §D, Reconciliation v2, Gate 1 v2).
|
||
|
||
- Stdlib-only Python 3.12 agent: `run --once|loop`, `status`, `bootstrap`, `--prune`.
|
||
- Protocol: `POST /v1/agent/checkin` (`action apply|none|down`), `GET /v1/agent/bundle/{env}/{sha}`
|
||
(sha256 verified), `POST /v1/agent/lease` → **deploy grant** (`login_jwt`), `POST /v1/agent/report`
|
||
(`result applied|failed|down`, redacted `log_tail`). An AppRole-shaped lease is refused (`LEASE_SHAPE`).
|
||
- OpenBao: `POST /v1/auth/jwt-tenancy/login {"role":"see-env","jwt":…}`; KV-v2 reads pinned to the
|
||
manifest's versions, paths pinned to `monky/data/<env>/see/`; renew-self / re-lease before max TTL.
|
||
- Refusals: `ENV_INCOMPLETE` (names only), `PRIVILEGED_REFUSED`, `ROLLBACK_REFUSED`, `DISK_INSUFFICIENT`
|
||
(`need × 1.5 + 2 GiB` vs docker data-root), `BUNDLE_SHA_MISMATCH`, `BUNDLE_ENV_MISMATCH`.
|
||
- Transports `sdk` (openziti SDK), `proxy` (`ziti tunnel proxy` 18443/18200), `system`.
|
||
- Exit codes 0 / 75 / 78 (`AGENT_ENV_MISMATCH`, no retry storm) / 1; laptop mode (offline exits 0).
|
||
- Packaging: hardened `monky-deployd.service` oneshot + 60 s timer, `monky-deployd-proxy.service`,
|
||
`nfpm` `.deb` with `/opt/monky-deployd/venv`, `packaging/install.sh` (Ubuntu 26.04), ansible role skeleton.
|
||
- Known divergence: monky-tenancy `main` (MR !15) still ships the AppRole lease/kit; the JWT-grant
|
||
follow-up is the tenancy side of this release (docs/PROTOCOL.md "Divergences").
|