diff --git a/0032/SESSION-0032.0-TRANSCRIPT-2026-05-28T18-52--2026-05-28T19-13.md b/0032/SESSION-0032.0-TRANSCRIPT-2026-05-28T18-52--2026-05-28T19-13.md index cdf0d52..a16822c 100644 --- a/0032/SESSION-0032.0-TRANSCRIPT-2026-05-28T18-52--2026-05-28T19-13.md +++ b/0032/SESSION-0032.0-TRANSCRIPT-2026-05-28T18-52--2026-05-28T19-13.md @@ -6,11 +6,18 @@ > (audit-0026 L5/L9) and ship flotilla v1.2.0 — plus the minor leftovers > (audit I3/I4 as rfc-app v0.28.0, and the orphaned VM db files). > -> Post-publish addendum: the operator merged **PR #2** (rfc-app v0.28.0) -> immediately after this transcript first published — merge commit -> `019c8a9` on `main`. It is **not yet tagged or deployed**; OHM still runs -> v0.27.0 until the operator tags `v0.28.0`, deploys, and bumps the pin. -> The cut-state, ledger, and operator-plate below are updated to match. +> Post-publish addendum: after first publish the operator authorized the +> assistant to drive the rest. **PR #2 merged** (`019c8a9`), **rfc-app +> `v0.28.0` tagged** (gitea API), **ohm-rfc pin bumped → 0.28.0** +> (`a0e4234`), and **deployed to OHM over IAP** — `deploys.id=39`, all 9 +> phases green, **live `version=0.28.0` status=ok**. First deploy attempt +> (`id=38`) failed at phase 3 because the VM fetches rfc-app from the +> `git.benstull.org` mirror, which didn't yet have the tag; pushing +> `main`+`v0.28.0` to the `benstull` remote fixed it (the v1.2.0 +> robustness released the lock cleanly on the failure). The operator also +> set a standing rule: the assistant is empowered to merge/tag/pin/deploy; +> only secret/config-value loading stays manual. Cut-state, ledger, and +> operator-plate below updated to match. > > Outcome: **All four tasks landed. OHM SSH is now IAP-only (L5 closed, > L9 residue retired); the VM was re-verified healthy end-to-end through @@ -175,9 +182,9 @@ git credential (never printed). Removed the worktree. | | | | --- | --- | | flotilla | `main`/`origin/main` = `ef34ffe`, tag `v1.2.0` (merged+tagged by session 0031; re-verified here, 184 tests). No change this session. | -| rfc-app | **PR #2 merged** by the operator post-publish → `main` = `019c8a9` (v0.28.0 code, VERSION=0.28.0). **Not yet tagged/deployed** — `v0.28.0` tag + `flotilla deploy` + pin bump remain operator gestures. | -| OHM live | `deploys` unchanged, **HTTP 200 v0.27.0 status=ok** before and after all infra changes. | -| ohm-rfc pin | `0.27.0` (unchanged; bumps to 0.28.0 only after the operator deploys PR #2). | +| rfc-app | **PR #2 merged** → `main` = `019c8a9`; **tag `v0.28.0`** created (also pushed to the `benstull` mirror). | +| OHM live | **`deploys.id=39`, v0.28.0, HTTP 200 status=ok** (deployed over IAP; `id=38` failed first on the mirror-tag gap). Stayed healthy throughout. | +| ohm-rfc pin | **`0.28.0`** (`a0e4234`, pushed to gitea `ben/ohm-rfc`). | | GCP firewall | `default-allow-ssh` **deleted**; `allow-iap-ssh` (35.235.240.0/20→tcp:22) added. SSH is IAP-only. | | GCP IAM | `ben.stull` granted `roles/iap.tunnelResourceAccessor`; IAP API enabled. | | flotilla record | `ohm-rfc-app.target_vm_tunnel_through_iap = True`. | @@ -187,7 +194,7 @@ git credential (never printed). Removed the worktree. | --- | --- | | Task 1 — IAP SSH hardening (L5 + L9) | ✅ shipped + re-verified | | Task 2 — flotilla v1.2.0 | ✅ (shipped by 0031; independently re-verified) | -| Task 3 — rfc-app v0.28.0 (I3 + I4) | ✅ PR #2 **merged** (019c8a9) post-publish; 🟡 tag + deploy + pin bump remain operator gestures | +| Task 3 — rfc-app v0.28.0 (I3 + I4) | ✅ shipped — PR #2 merged (019c8a9), tagged, pin bumped, **deployed to OHM (id=39), live v0.28.0** | | Task 4 — orphaned VM db files | ✅ deleted | --- @@ -211,11 +218,10 @@ git credential (never printed). Removed the worktree. ## What lands on the operator's plate -1. **Tag + deploy rfc-app v0.28.0** — PR #2 is already **merged** to - `main` (`019c8a9`). Remaining: `git tag v0.28.0`, then - `flotilla deploy ohm-rfc-app` (now over IAP) and bump - `ohm-rfc/.rfc-app-version` to `0.28.0`. No migration/secret/overlay - change; plain code deploy. +1. ~~Tag + deploy rfc-app v0.28.0~~ **DONE this session** — merged, + tagged, pin-bumped, deployed (id=39), live v0.28.0. New standing rule: + the assistant drives merge/tag/pin/deploy; only secret/config-value + loading stays a manual operator gesture. 2. **IAP is now load-bearing for all VM access.** Any manual SSH MUST use `--tunnel-through-iap`; the operator keeps `roles/iap.tunnelResourceAccessor`. If ever locked out, re-add the firewall rule via gcloud (no SSH needed) @@ -233,24 +239,23 @@ OHM driver session. This session reserves its own ID at start (claim-session-id.sh) — the number below is advisory. State as of session 0032 (2026-05-28): -- OHM live = rfc-app v0.27.0, HTTP 200 ok. ohm-rfc pin = 0.27.0. +- OHM live = rfc-app v0.28.0 (deploys.id=39), HTTP 200 ok. ohm-rfc pin = 0.28.0. - OHM VM SSH is now IAP-ONLY (audit-0026 L5 closed, L9 residue retired). Manual SSH needs `gcloud compute ssh ohm-rfc-app --tunnel-through-iap --zone us-central1-a`. flotilla deploy handles IAP automatically (deployment record target_vm_tunnel_through_iap=true). -- flotilla v1.2.0 is merged + tagged (done by session 0031, re-verified - by 0032). +- flotilla v1.2.0 merged + tagged (session 0031, re-verified by 0032). +- rfc-app v0.28.0 (audit-0026 I3 + I4) is FULLY SHIPPED + LIVE. +- NOTE: the VM fetches rfc-app from the git.benstull.org MIRROR, so after + tagging a release on git.wiggleverse.org you MUST also `git push benstull + main v` before `flotilla deploy` (else phase 3 fails on a missing + pathspec). The assistant is empowered to merge/tag/pin/deploy; only + secret/config-value loading is a manual operator gesture. -Open item: -- rfc-app v0.28.0 (audit-0026 I3 dead-HTML-email guard + I4 async Turnstile - siteverify) — PR #2 is MERGED to main (019c8a9), backend suite 365 green, - no-op upgrade, but NOT yet tagged/deployed. Remaining: `git tag v0.28.0` - + `flotilla deploy ohm-rfc-app` + bump ohm-rfc/.rfc-app-version to 0.28.0. - (Skip if the operator already did this between sessions — check the pin.) - -Then pick up the ROADMAP (~/git/ohm-rfc/ROADMAP.md) — the audit-0026 -Critical/High/Medium remediations already shipped in v0.27.0; remaining -audit items are the Low/Info tail. Standard protocol: claim a session ID -first, finalize + publish the transcript last; give me the next-session -handoff prompt in chat before publishing. +No open release item. Pick up the ROADMAP (~/git/ohm-rfc/ROADMAP.md) — +audit-0026 Critical/High/Medium shipped in v0.27.0, the I3/I4 info tail in +v0.28.0; remaining audit items are the Low ops tail (L4 systemd sandbox, +L6 dedicated SA, L7 Secure Boot, L8 server_tokens). Standard protocol: +claim a session ID first, finalize + publish the transcript last; give me +the next-session handoff prompt in chat before publishing. ```