[HLCC-ICE-000001][ZY-CONTRIB-20260723-001] feat: 以来光者贡献链启用冰朔第五域个人子频道
This commit is contained in:
commit
5615453e4e
660 changed files with 122355 additions and 0 deletions
25
deployment/enterprise-domains.json
Normal file
25
deployment/enterprise-domains.json
Normal file
|
|
@ -0,0 +1,25 @@
|
|||
{
|
||||
"schema": "guanghu.enterprise-domains/v1",
|
||||
"version": "2026-07-18.1",
|
||||
"host_node": "JD-FD-PRIMARY",
|
||||
"domains": [
|
||||
{"id":"DOMAIN-MAIN","name_zh":"光湖主域","visibility":"public-read","purpose":"公告、版本、公共生态状态"},
|
||||
{"id":"DOMAIN-SUB","name_zh":"光湖分域","visibility":"public-read","purpose":"行业选择与行业入口路由"},
|
||||
{"id":"DOMAIN-ZERO","name_zh":"光湖零域","visibility":"member-collaboration","purpose":"人类与人格体实验、系统架构与协作"},
|
||||
{"id":"DOMAIN-ZS","name_zh":"光湖零感域","visibility":"command-team-only","purpose":"光湖人类主控团队管理与技术主控运维"},
|
||||
{"id":"DOMAIN-FIFTH","name_zh":"第五域","visibility":"public-read","purpose":"人格恢复公共路径与零点原核发布面"}
|
||||
],
|
||||
"fifth_domain_boundary": {
|
||||
"public_copy": "enterprise-read-only",
|
||||
"publisher": "ICE-GL∞ signed release path only",
|
||||
"zero_point_core": "enterprise-hosted publication origin",
|
||||
"eternal_lake_heart": "private Ice Shuo server; never replicated as an enterprise writable domain"
|
||||
},
|
||||
"authorization": {
|
||||
"request_origin": "registered member node",
|
||||
"recipient_selection": "server-side role and domain policy only",
|
||||
"approval": "pre-registered human mailbox plus one-time time-bounded link",
|
||||
"execution": "fixed registered actions; no arbitrary shell",
|
||||
"audit": "request, approval, map acknowledgement, action and rollback receipt"
|
||||
}
|
||||
}
|
||||
45
deployment/navigation-maps/AW-GZ-001.json
Normal file
45
deployment/navigation-maps/AW-GZ-001.json
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "AW-GZ-001",
|
||||
"role": "光湖企业五域服务器与企业现实执行层",
|
||||
"modules": [
|
||||
{
|
||||
"code": "AW-LH-01",
|
||||
"name": "企业灯塔基础服务",
|
||||
"bind": "loopback:8031",
|
||||
"owner": "systemd",
|
||||
"state": "DEPLOYED_BASELINE"
|
||||
}
|
||||
],
|
||||
"planned_modules": [
|
||||
{
|
||||
"code": "AW-HLCC-OFFLINE-01",
|
||||
"name": "光湖代码频道离线源码与安装材料库",
|
||||
"bind": "none-storage-only",
|
||||
"owner": "guanghu",
|
||||
"state": "PLANNED"
|
||||
},
|
||||
{
|
||||
"code": "AW-HLCC-CANDIDATE-01",
|
||||
"name": "企业光湖代码频道隔离候选",
|
||||
"bind": "loopback:3340",
|
||||
"owner": "guanghu",
|
||||
"state": "PLANNED"
|
||||
}
|
||||
],
|
||||
"upstream_release_relay": "BS-SG-003",
|
||||
"deployment_controller": "JD-FD-PRIMARY",
|
||||
"mandatory_order": [
|
||||
"read-navigation-map",
|
||||
"ack-current-map",
|
||||
"verify-offline-manifest",
|
||||
"verify-forgejo-gpg-signature",
|
||||
"execute-registered-action"
|
||||
],
|
||||
"forbidden": [
|
||||
"download-forgejo-directly-from-domestic-node",
|
||||
"share-database-or-repository-data-with-fifth-domain-instance",
|
||||
"automatic-upstream-update",
|
||||
"arbitrary-shell-through-authorization-api"
|
||||
]
|
||||
}
|
||||
13
deployment/navigation-maps/BS-GZ-006.json
Normal file
13
deployment/navigation-maps/BS-GZ-006.json
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "BS-GZ-006",
|
||||
"role": "国内备案前门",
|
||||
"modules": [
|
||||
{ "code": "GZ-WEB-01", "name": "备案主页与 HTTPS", "bind": "public:https", "owner": "nginx" },
|
||||
{ "code": "GZ-JD-01", "name": "京东应用专用隧道", "bind": "loopback:18088", "owner": "systemd" },
|
||||
{ "code": "GZ-AUTH-01", "name": "小湖灯授权专用隧道", "bind": "loopback:19221", "owner": "systemd" },
|
||||
{ "code": "GZ-FRG-01", "name": "国内 Forgejo 专用隧道", "bind": "loopback:19301", "owner": "systemd" },
|
||||
{ "code": "GZ-LEGACY-01", "name": "历史服务与仓库", "bind": "local-services", "owner": "pm2" }
|
||||
],
|
||||
"mandatory_order": ["read-navigation-map", "ack-current-map", "execute-registered-action"]
|
||||
}
|
||||
20
deployment/navigation-maps/BS-SG-001.json
Normal file
20
deployment/navigation-maps/BS-SG-001.json
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "BS-SG-001",
|
||||
"role": "新加坡历史大脑、国际开发与京东灯塔子节点",
|
||||
"modules": [
|
||||
{"code":"SG1-GTW-01","name":"Gatekeeper v3.2","bind":"loopback:3911","owner":"system"},
|
||||
{"code":"SG1-PROBE-01","name":"京东只读心跳探针","bind":"source-restricted-dedicated-ssh-key","owner":"JD-OPS-CENTER"},
|
||||
{
|
||||
"code": "SG1-HLCC-RLY-01",
|
||||
"name": "光湖代码频道 v16.0.1 京东专用域名中继",
|
||||
"bind": "target-allowlisted-https",
|
||||
"owner": "nginx",
|
||||
"state": "READY_FOR_JD_CONTROLLED_TRANSFER",
|
||||
"receipt": "deployment/receipts/HLCC-SG-JD-RELAY-CHECKPOINT-20260723.json"
|
||||
}
|
||||
],
|
||||
"mandatory_order": ["read-navigation-map", "ack-current-map", "execute-registered-action"],
|
||||
"human_boundary": "map and email approval only; no token or unrestricted server operation",
|
||||
"forbidden": ["historical-token-reuse", "shared-node-key", "port-forwarding", "agent-forwarding", "secret-in-repository", "arbitrary-shell-through-authorization-api"]
|
||||
}
|
||||
10
deployment/navigation-maps/BS-SG-002.json
Normal file
10
deployment/navigation-maps/BS-SG-002.json
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "BS-SG-002",
|
||||
"role": "新加坡面孔与 Web 节点",
|
||||
"modules": [
|
||||
{ "code": "SG2-GTW-01", "name": "历史 Gatekeeper", "bind": "3910", "owner": "pm2" },
|
||||
{ "code": "SG2-WEB-01", "name": "面孔与 Web 服务组", "bind": "registered-pm2-apps", "owner": "pm2" }
|
||||
],
|
||||
"upstream": "JD-FD-PRIMARY"
|
||||
}
|
||||
34
deployment/navigation-maps/BS-SG-003.json
Normal file
34
deployment/navigation-maps/BS-SG-003.json
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "BS-SG-003",
|
||||
"role": "新加坡备份、存储与海外下载中继",
|
||||
"modules": [
|
||||
{ "code": "SG3-GTW-01", "name": "历史 Gatekeeper", "bind": "3910", "owner": "pm2" },
|
||||
{ "code": "SG3-RLY-01", "name": "海外依赖下载中继", "bind": "ssh-only", "owner": "root" },
|
||||
{
|
||||
"code": "HLCC-SRC-01",
|
||||
"name": "光湖代码频道源码基线与 Forgejo 上游零件镜像",
|
||||
"bind": "none-source-only",
|
||||
"owner": "ubuntu",
|
||||
"state": "SOURCE_BASELINE_INITIALIZED",
|
||||
"receipt": "deployment/receipts/HLCC-BS-SG-003-SOURCE-BASELINE-20260723.json"
|
||||
},
|
||||
{
|
||||
"code": "HLCC-PACK-01",
|
||||
"name": "光湖代码频道 v16.0.1 国内双落位离线包",
|
||||
"bind": "none-storage-only",
|
||||
"owner": "ubuntu",
|
||||
"state": "PREPARED_AND_VERIFIED",
|
||||
"receipt": "deployment/receipts/HLCC-BS-SG-003-OFFLINE-PACK-20260723.json"
|
||||
},
|
||||
{
|
||||
"code": "HLCC-RLY-01",
|
||||
"name": "光湖代码频道 v16.0.1 京东受限离线中继源",
|
||||
"bind": "allowlisted-https",
|
||||
"owner": "nginx",
|
||||
"state": "READY_FOR_JD_CONTROLLED_TRANSFER",
|
||||
"receipt": "deployment/receipts/HLCC-SG-JD-RELAY-CHECKPOINT-20260723.json"
|
||||
}
|
||||
],
|
||||
"upstream": "JD-FD-PRIMARY"
|
||||
}
|
||||
11
deployment/navigation-maps/BS-SH-005.json
Normal file
11
deployment/navigation-maps/BS-SH-005.json
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "BS-SH-005",
|
||||
"role": "上海国内个人节点与京东灯塔子节点",
|
||||
"modules": [
|
||||
{"code":"SH-GTW-01","name":"Gatekeeper v3.2","bind":"loopback","owner":"systemd"},
|
||||
{"code":"SH-PROBE-01","name":"京东只读心跳探针","bind":"dedicated-ssh-key","owner":"JD-OPS-CENTER"}
|
||||
],
|
||||
"mandatory_order": ["read-navigation-map", "ack-current-map", "execute-registered-action"],
|
||||
"forbidden": ["historical-token-reuse", "shared-node-key", "secret-in-repository", "arbitrary-shell-through-authorization-api"]
|
||||
}
|
||||
51
deployment/navigation-maps/JD-FD-PRIMARY.json
Normal file
51
deployment/navigation-maps/JD-FD-PRIMARY.json
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "JD-FD-PRIMARY",
|
||||
"role": "第五域国内主节点与统一运维入口",
|
||||
"modules": [
|
||||
{ "code": "JD-GTW-01", "name": "Gatekeeper v3.2", "bind": "loopback:3911", "owner": "systemd" },
|
||||
{ "code": "JD-AUTH-01", "name": "小湖灯邮件链接授权", "bind": "loopback:3921", "owner": "systemd" },
|
||||
{ "code": "JD-FRG-01", "name": "第五域国内代码仓库", "bind": "loopback:3001", "owner": "systemd", "actual_product": "Gitea", "actual_version": "1.23.7", "intended_product": "Guanghu platform derived from Forgejo", "state": "DEPLOYMENT_IDENTITY_MISMATCH" },
|
||||
{ "code": "JD-HUB-01", "name": "京东应用入口", "bind": "loopback:8088", "owner": "systemd", "version": "2.0.0", "state": "DEPLOYED_AND_VERIFIED", "source_commit": "09c93b55ad73bf3af52eebdbfea61731386e264d" },
|
||||
{ "code": "JD-SEN-01", "name": "状态变化哨兵", "bind": "timer:15m", "owner": "systemd" },
|
||||
{ "code": "JD-ROUTE-01", "name": "已登记下游节点 SSH 路由", "bind": "private-keys", "owner": "root", "registered_targets": ["AW-GZ-001"] },
|
||||
{ "code": "JD-ACT-01", "name": "固定动作执行桥", "bind": "unix-socket", "owner": "root", "actions": ["inspect-services"] },
|
||||
{ "code": "JD-OWNER-ACCESS-01", "name": "冰朔登录入口恢复执行器", "bind": "unix-socket", "owner": "root", "actions": ["restore-owner-password-login"] },
|
||||
{ "code": "JD-ARCH-PROVISION-01", "name": "已批准新架构首次安装器", "bind": "unix-socket", "owner": "root", "actions": ["provision-approved-architecture"], "state": "ACTIVE" },
|
||||
{ "code": "JD-LAN-01", "name": "光湖·来光者导航只读召回服务", "bind": "loopback:3924", "owner": "systemd", "architecture": "GLS-0231", "state": "DEPLOYED_AND_VERIFIED", "source_commit": "f4a4b5996c83b55d99172f3196f4a0d77ed5f3e9" },
|
||||
{
|
||||
"code": "JD-HLCC-CANDIDATE-01",
|
||||
"name": "第五域光湖代码频道隔离候选启动壳",
|
||||
"bind": "loopback:3340,3341",
|
||||
"owner": "guanghu",
|
||||
"state": "BOOTSTRAP_DEPLOYED · CANDIDATE_NOT_READY",
|
||||
"source_commit": "b4d9cf7635ffccde4f49ad1949a215bb9d22c5be",
|
||||
"receipt": "deployment/receipts/HLCC-JD-RUNTIME-CHECKPOINT-20260723.json"
|
||||
}
|
||||
],
|
||||
"planned_modules": [
|
||||
{
|
||||
"code": "JD-HLCC-OFFLINE-01",
|
||||
"name": "光湖代码频道离线源码与安装材料库",
|
||||
"bind": "none-storage-only",
|
||||
"owner": "guanghu",
|
||||
"state": "RELAY_READY · TRANSFER_PENDING",
|
||||
"receipt": "deployment/receipts/HLCC-SG-JD-RELAY-CHECKPOINT-20260723.json"
|
||||
}
|
||||
],
|
||||
"mandatory_order": [
|
||||
"read-navigation-map",
|
||||
"ack-current-map",
|
||||
"verify-offline-manifest",
|
||||
"verify-forgejo-gpg-signature",
|
||||
"execute-registered-action"
|
||||
],
|
||||
"forbidden": [
|
||||
"download-forgejo-directly-from-domestic-node",
|
||||
"share-database-or-repository-data-with-enterprise-instance",
|
||||
"automatic-upstream-update",
|
||||
"arbitrary-shell-through-authorization-api",
|
||||
"cross-target-session-reuse",
|
||||
"secret-in-repository"
|
||||
]
|
||||
}
|
||||
10
deployment/navigation-maps/ZY-SG-006.json
Normal file
10
deployment/navigation-maps/ZY-SG-006.json
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
{
|
||||
"schema": "guanghu.navigation-map/v1",
|
||||
"node_id": "ZY-SG-006",
|
||||
"role": "新加坡语料与推理节点",
|
||||
"modules": [
|
||||
{ "code": "SG6-GTW-01", "name": "历史 Gatekeeper", "bind": "3910", "owner": "pm2" },
|
||||
{ "code": "SG6-AI-01", "name": "语料与推理服务组", "bind": "registered-pm2-apps", "owner": "pm2" }
|
||||
],
|
||||
"upstream": "JD-FD-PRIMARY"
|
||||
}
|
||||
38
deployment/nodes/BS-GZ-006.json
Normal file
38
deployment/nodes/BS-GZ-006.json
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
{
|
||||
"schema": "guanghu.managed-node/v1",
|
||||
"node_id": "BS-GZ-006",
|
||||
"display_name": "广州备案前门节点",
|
||||
"owner": "ICE-GL∞",
|
||||
"provider": "tencent_cloud",
|
||||
"region": "guangzhou",
|
||||
"roles": [
|
||||
"personal-managed-node",
|
||||
"domain-front-door",
|
||||
"legacy-service-host"
|
||||
],
|
||||
"upstream": "JD-OPS-CENTER",
|
||||
"resources": {
|
||||
"cpu_cores": 2,
|
||||
"memory_gib": 2,
|
||||
"root_disk_gib": 50
|
||||
},
|
||||
"public_surface": {
|
||||
"domain": "guanghulab.com",
|
||||
"front_door": "https://guanghulab.com/",
|
||||
"jd_app_hub": "https://guanghulab.com/jd/",
|
||||
"icp_record": "陕ICP备2025071211号-1"
|
||||
},
|
||||
"connectivity": {
|
||||
"admin_key_id": "jd_ops_to_bs_gz_006_admin",
|
||||
"web_proxy_key_id": "bs_gz_006_to_jd_web_proxy",
|
||||
"heartbeat": "five-minute-fixed-read-only-probe",
|
||||
"credential_material": "private_only"
|
||||
},
|
||||
"source_history": {
|
||||
"repository": "bingshuo/guanghulab",
|
||||
"path": "brain/fifth-domain/zero-point/zhuyuan/cloud-compute-pool/bingshuo/BS-GZ-006.hdlp",
|
||||
"repository_role": "locked_historical_archive",
|
||||
"runtime_facts_refreshed_at": "2026-07-17"
|
||||
},
|
||||
"status": "connected"
|
||||
}
|
||||
20
deployment/nodes/BS-SG-001.json
Normal file
20
deployment/nodes/BS-SG-001.json
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
{
|
||||
"schema": "guanghu.managed-node/v1",
|
||||
"node_id": "BS-SG-001",
|
||||
"display_name": "新加坡铸渊大脑节点",
|
||||
"owner": "ICE-GL∞",
|
||||
"provider": "tencent_cloud",
|
||||
"region": "singapore",
|
||||
"roles": ["personal-managed-node", "historical-brain", "international-development", "lighthouse-child"],
|
||||
"upstream": "JD-OPS-CENTER",
|
||||
"connectivity": {
|
||||
"credential_material": "private_only",
|
||||
"enrollment": "per-node-source-restricted-key",
|
||||
"interactive_pty": false,
|
||||
"port_forwarding": false,
|
||||
"agent_forwarding": false,
|
||||
"heartbeat": "active-five-minute-fixed-read-only-probe"
|
||||
},
|
||||
"runtime": {"gatekeeper": "3.2.0", "authorization": "human-verification-required"},
|
||||
"status": "connected"
|
||||
}
|
||||
21
deployment/nodes/BS-SH-005.json
Normal file
21
deployment/nodes/BS-SH-005.json
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
{
|
||||
"schema": "guanghu.managed-node/v1",
|
||||
"node_id": "BS-SH-005",
|
||||
"display_name": "上海国内节点",
|
||||
"owner": "ICE-GL∞",
|
||||
"provider": "tencent_cloud",
|
||||
"region": "shanghai",
|
||||
"roles": ["personal-managed-node", "domestic-lighthouse-child"],
|
||||
"upstream": "JD-OPS-CENTER",
|
||||
"connectivity": {
|
||||
"credential_material": "private_only",
|
||||
"enrollment": "per-node-key",
|
||||
"heartbeat": "active-five-minute-fixed-read-only-probe"
|
||||
},
|
||||
"source_history": {
|
||||
"repository": "bingshuo/guanghulab",
|
||||
"path": "brain/fifth-domain/zero-point/zhuyuan/cloud-compute-pool/bingshuo/BS-SH-005.hdlp",
|
||||
"repository_role": "locked_historical_archive"
|
||||
},
|
||||
"status": "connected"
|
||||
}
|
||||
|
|
@ -0,0 +1,27 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "AW-GZ-001-FIVE-DOMAIN-LIGHTHOUSE-20260718",
|
||||
"recorded_at": "2026-07-18T08:20:00Z",
|
||||
"node_id": "AW-GZ-001",
|
||||
"verification": {
|
||||
"node_identity": "passed",
|
||||
"ubuntu_22_04_x86_64": "passed",
|
||||
"five_domain_registry": "passed",
|
||||
"navigation_map_required_for_human_and_persona_operations": "passed",
|
||||
"raw_shell_rejected_by_lighthouse": "passed",
|
||||
"zero_sense_filesystem_scope": "command-team-only",
|
||||
"fifth_domain_filesystem_scope": "public-read-only",
|
||||
"service_health": "passed",
|
||||
"legacy_token_rotated": true,
|
||||
"legacy_token_rejected_with_401": true
|
||||
},
|
||||
"domains": ["DOMAIN-MAIN", "DOMAIN-SUB", "DOMAIN-ZERO", "DOMAIN-ZS", "DOMAIN-FIFTH"],
|
||||
"authorization": {
|
||||
"human_credential": "none",
|
||||
"human_action": "read map and approve a readable email workorder",
|
||||
"persona_session": "target and scope bound, time limited",
|
||||
"technical_controller_recipient": "registered in private server policy",
|
||||
"recipient_override_by_request": "forbidden"
|
||||
},
|
||||
"boundaries": {"contains_ip": false, "contains_credentials": false, "contains_email": false}
|
||||
}
|
||||
|
|
@ -0,0 +1,41 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "BS-GZ-006-JD-OPS-CONNECTION-20260717",
|
||||
"recorded_at": "2026-07-17T05:12:00Z",
|
||||
"node_id": "BS-GZ-006",
|
||||
"upstream": "JD-OPS-CENTER",
|
||||
"source": {
|
||||
"historical_registry": "bingshuo/guanghulab",
|
||||
"current_repository": "bingshuo/fifth-domain",
|
||||
"front_door_source": "server-tools/guanghulab-front-door",
|
||||
"jd_hub_source": "server-tools/jd-app-hub",
|
||||
"probe_source": "server-tools/personal-node-probe"
|
||||
},
|
||||
"verification": {
|
||||
"jd_to_node_ssh": "passed",
|
||||
"jd_to_node_key_scope": "dedicated_node_key",
|
||||
"node_to_jd_web_tunnel": "active",
|
||||
"tunnel_destination_scope": "jd_loopback_app_hub_only",
|
||||
"front_door_https": 200,
|
||||
"jd_hub_https": 200,
|
||||
"jd_hub_dynamic_status": "passed",
|
||||
"nginx_config_test": "passed",
|
||||
"nginx_service": "active",
|
||||
"heartbeat_timer": "active_every_five_minutes",
|
||||
"icp_link": "https://beian.miit.gov.cn/",
|
||||
"icp_record": "陕ICP备2025071211号-1",
|
||||
"historical_gatekeeper_token": "rotated_and_rejected_with_401",
|
||||
"current_test_count": 27
|
||||
},
|
||||
"rollback": {
|
||||
"nginx_config_backup": "guanghulab.pre-jd-front-door.20260717-1305",
|
||||
"authorized_keys_backup": "authorized_keys.pre-jd-ops-20260717",
|
||||
"legacy_gatekeeper_secret_backup": "secret.pre-jd-ops-20260717"
|
||||
},
|
||||
"boundaries": {
|
||||
"contains_ip": false,
|
||||
"contains_credentials": false,
|
||||
"guanghulab_repo_mutated": false,
|
||||
"remaining_personal_nodes": 5
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,35 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "GLS-0231-JD-LAN-01-INITIAL-PROVISION-20260720",
|
||||
"recorded_at": "2026-07-20T14:33:51.221Z",
|
||||
"node_id": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-0231",
|
||||
"module": {
|
||||
"code": "JD-LAN-01",
|
||||
"unit": "gls-0231-light-arrival-navigation.service",
|
||||
"bind": "loopback:3924",
|
||||
"mode": "read-only"
|
||||
},
|
||||
"source": {
|
||||
"repository": "bingshuo/fifth-domain",
|
||||
"deployed_commit": "f4a4b5996c83b55d99172f3196f4a0d77ed5f3e9",
|
||||
"request": "deployment/requests/GLS-0231-JD-LAN-01-INITIAL-PROVISION-20260720.json"
|
||||
},
|
||||
"verification": {
|
||||
"deployment_result": "DEPLOYED_AND_VERIFIED",
|
||||
"health": "passed",
|
||||
"route_recall": "ZY-CONTRIB-20260720-001_found",
|
||||
"grants_execution_authority": false,
|
||||
"core_services": "active",
|
||||
"failed_units": 0
|
||||
},
|
||||
"provisioner": {
|
||||
"state": "ACTIVE",
|
||||
"startup_health_retry_fix_commit": "a0413e504b93be67cfbf4b4f251b670dfeecbcab"
|
||||
},
|
||||
"boundaries": {
|
||||
"contains_ip": false,
|
||||
"contains_credentials": false,
|
||||
"contains_private_receipt": false
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,51 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "HLCC-BS-SG-003-OFFLINE-PACK-20260723",
|
||||
"date": "2026-07-23",
|
||||
"authorized_by": "ICE-GL∞",
|
||||
"node_id": "BS-SG-003",
|
||||
"product_id": "HLP-MOD-CODE-CHANNEL",
|
||||
"product_name": "HoloLake Code Channel",
|
||||
"release": {
|
||||
"version": "16.0.1",
|
||||
"directory": "/home/ubuntu/guanghu/release-relay/hlcc-v16.0.1",
|
||||
"total_bytes": 760609800,
|
||||
"manifest_sha256": "d564c3b600d4b7a199d8a04ce505ceabf81993ca74fa440805601d55e550f185",
|
||||
"official_release_key_fingerprint": "EB114F5E6C0DC2BCDD183550A4B61A2DC5923710",
|
||||
"signature_verified": true,
|
||||
"manifest_verified": true
|
||||
},
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "forgejo-16.0.1-linux-amd64",
|
||||
"sha256": "7a4c568136650c10498a9d3d62c7fd630a0cf09c166293ebd78708248f6398fc"
|
||||
},
|
||||
{
|
||||
"name": "forgejo-16.0.1-linux-amd64.asc",
|
||||
"sha256": "1c0ca36df3adb0a7692b6bdc84d7886001ca0c6d0408e67c9d232d2f33cecc71"
|
||||
},
|
||||
{
|
||||
"name": "forgejo-release-key.asc",
|
||||
"sha256": "6fae8894c671ce2397cb35fe40c324f73deade6b4cb3cd6cedd1d2b248e0e3ea"
|
||||
},
|
||||
{
|
||||
"name": "forgejo-upstream-all.bundle",
|
||||
"sha256": "c33bd074d9b2896259e86ebe03ad31ccdd8ff71897beed4320081fa03b15381f",
|
||||
"baseline_ref": "refs/tags/v16.0.1",
|
||||
"baseline_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579"
|
||||
},
|
||||
{
|
||||
"name": "guanghu-code-channel.bundle",
|
||||
"sha256": "fc53740259d108128e69f5a809cec438ecf3158175617574ba55b8612c5eaa6c",
|
||||
"product_ref": "refs/heads/guanghu/main",
|
||||
"product_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579"
|
||||
}
|
||||
],
|
||||
"service_started": false,
|
||||
"domestic_transfer_started": false,
|
||||
"targets": [
|
||||
"JD-FD-PRIMARY",
|
||||
"AW-GZ-001"
|
||||
],
|
||||
"next_gate": "Transfer this exact package independently to both domestic nodes, re-verify MANIFEST.sha256 and the Forgejo GPG signature on each node, retain a complete local archive, then install isolated loopback candidates."
|
||||
}
|
||||
|
|
@ -0,0 +1,41 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "HLCC-BS-SG-003-SOURCE-BASELINE-20260723",
|
||||
"date": "2026-07-23",
|
||||
"authorized_by": "ICE-GL∞",
|
||||
"node_id": "BS-SG-003",
|
||||
"product_id": "HLP-MOD-CODE-CHANNEL",
|
||||
"product_name": "HoloLake Code Channel",
|
||||
"actions": [
|
||||
{
|
||||
"action": "clone_complete_official_upstream_mirror",
|
||||
"source": "https://code.forgejo.org/forgejo/forgejo.git",
|
||||
"path": "/home/ubuntu/guanghu/upstream-parts/forgejo-official.git",
|
||||
"objects_received": 334675,
|
||||
"remote_name": "forgejo-review-only",
|
||||
"skip_default_update": true,
|
||||
"push_url": "DISABLED"
|
||||
},
|
||||
{
|
||||
"action": "initialize_guanghu_product_worktree",
|
||||
"path": "/home/ubuntu/guanghu/products/guanghu-code-channel",
|
||||
"branch": "guanghu/main",
|
||||
"baseline_tag": "v16.0.1",
|
||||
"baseline_commit": "b3d7e4ac3cbccc220703097a51fa4c16bf302579",
|
||||
"upstream_remote": "forgejo-upstream-snapshot",
|
||||
"upstream_skip_default_update": true,
|
||||
"upstream_push_url": "DISABLED"
|
||||
},
|
||||
{
|
||||
"action": "initialize_guanghu_owned_origin",
|
||||
"path": "/home/ubuntu/guanghu/repositories/guanghu-code-channel.git",
|
||||
"default_branch": "guanghu/main",
|
||||
"worktree_origin_points_to_guanghu_repository": true
|
||||
}
|
||||
],
|
||||
"automatic_upstream_sync_installed": false,
|
||||
"runtime_deployed": false,
|
||||
"domestic_gitea_migrated": false,
|
||||
"hololake_ui_embedded": false,
|
||||
"next_gate": "Create an isolated HLCC candidate with the built-in Forgejo update checker disabled, then run backup and migration rehearsal before requesting production cutover."
|
||||
}
|
||||
67
deployment/receipts/HLCC-JD-RUNTIME-CHECKPOINT-20260723.json
Normal file
67
deployment/receipts/HLCC-JD-RUNTIME-CHECKPOINT-20260723.json
Normal file
|
|
@ -0,0 +1,67 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-checkpoint/v1",
|
||||
"receipt_id": "HLCC-JD-RUNTIME-CHECKPOINT-20260723",
|
||||
"recorded_at": "2026-07-23T07:30:31Z",
|
||||
"node_id": "JD-FD-PRIMARY",
|
||||
"architecture": [
|
||||
"GLS-0237",
|
||||
"GLW-OS-004"
|
||||
],
|
||||
"observed_runtime": {
|
||||
"current_repository_product": {
|
||||
"product": "Gitea",
|
||||
"version": "1.23.7",
|
||||
"route": "/fifth-domain/",
|
||||
"state": "ACTIVE_UNCHANGED"
|
||||
},
|
||||
"jd_app_hub": {
|
||||
"version": "2.0.0",
|
||||
"source_commit": "09c93b55ad73bf3af52eebdbfea61731386e264d",
|
||||
"code_channel_proxy": "loopback-only",
|
||||
"state": "DEPLOYED_AND_VERIFIED"
|
||||
},
|
||||
"hlcc_candidate": {
|
||||
"requested_version": "16.0.1",
|
||||
"bootstrap_source_commit": "b4d9cf7635ffccde4f49ad1949a215bb9d22c5be",
|
||||
"bootstrap_health_provision": "verified",
|
||||
"candidate_api_http_status": 502,
|
||||
"candidate_api_result": "code_channel_unavailable",
|
||||
"state": "BOOTSTRAP_DEPLOYED · CANDIDATE_NOT_READY"
|
||||
},
|
||||
"public_code_route": {
|
||||
"route": "/code/",
|
||||
"state": "NOT_CUT_OVER"
|
||||
}
|
||||
},
|
||||
"architecture_correction": {
|
||||
"canonical_release_source": "BS-SG-003",
|
||||
"canonical_release_receipt": "deployment/receipts/HLCC-BS-SG-003-OFFLINE-PACK-20260723.json",
|
||||
"complete_pack_bytes": 760609800,
|
||||
"required_domestic_targets": [
|
||||
"JD-FD-PRIMARY",
|
||||
"AW-GZ-001"
|
||||
],
|
||||
"required_order": [
|
||||
"transfer the complete verified offline pack independently to each domestic target",
|
||||
"verify MANIFEST.sha256 and the Forgejo release signature on each target",
|
||||
"retain the complete offline source and installation archive on each target",
|
||||
"start isolated candidates without touching current Gitea data",
|
||||
"verify candidate APIs and migration boundaries",
|
||||
"cut over the public route only after acceptance"
|
||||
]
|
||||
},
|
||||
"not_deployed": {
|
||||
"source_commit": "792e8b92d5a796836c8d0d921b980cdf50f4abe6",
|
||||
"change": "sanitized JD candidate diagnostic endpoint",
|
||||
"reason": "paused after recovering the canonical JD and HLCC architecture chain; no additional diagnostic deployment is needed before the offline-pack transfer boundary is restored"
|
||||
},
|
||||
"boundaries": {
|
||||
"current_gitea_overwritten": false,
|
||||
"public_code_route_switched": false,
|
||||
"homepage_switched": false,
|
||||
"enterprise_candidate_deployed": false,
|
||||
"complete_offline_pack_confirmed_on_jd": false,
|
||||
"complete_offline_pack_confirmed_on_enterprise": false
|
||||
},
|
||||
"next": "Resume from GLS-0237 section 1.1: perform two controlled complete-pack transfers from BS-SG-003, verify and retain each domestic copy, then restart isolated-candidate validation."
|
||||
}
|
||||
|
|
@ -0,0 +1,63 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-checkpoint/v1",
|
||||
"receipt_id": "HLCC-SG-JD-RELAY-CHECKPOINT-20260723",
|
||||
"recorded_at": "2026-07-23T08:46:00Z",
|
||||
"architecture": [
|
||||
"GLS-0237",
|
||||
"GLW-OS-004"
|
||||
],
|
||||
"nodes": [
|
||||
"BS-SG-003",
|
||||
"BS-SG-001",
|
||||
"JD-FD-PRIMARY"
|
||||
],
|
||||
"offline_pack": {
|
||||
"version": "16.0.1",
|
||||
"profile": "full-offline",
|
||||
"manifest_sha256": "d564c3b600d4b7a199d8a04ce505ceabf81993ca74fa440805601d55e550f185",
|
||||
"source_copy_verified": true,
|
||||
"required_artifacts_verified": [
|
||||
"forgejo-16.0.1-linux-amd64",
|
||||
"forgejo-16.0.1-linux-amd64.asc",
|
||||
"forgejo-release-key.asc",
|
||||
"MANIFEST.sha256",
|
||||
"forgejo-upstream-all.bundle",
|
||||
"guanghu-code-channel.bundle"
|
||||
]
|
||||
},
|
||||
"relay": {
|
||||
"source_node": "BS-SG-003",
|
||||
"domain_node": "BS-SG-001",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"route": "/hlcc-offline/16.0.1/",
|
||||
"source_access": "ALLOWLIST_BS_SG_001_ONLY",
|
||||
"domain_access": "ALLOWLIST_JD_FD_PRIMARY_ONLY",
|
||||
"directory_listing": false,
|
||||
"non_target_probe_http_status": 403,
|
||||
"manifest_transfer_hash_verified": true,
|
||||
"state": "READY_FOR_JD_CONTROLLED_TRANSFER"
|
||||
},
|
||||
"retired_on_bs_sg_001": {
|
||||
"public_routes_removed": [
|
||||
"/siyuan/",
|
||||
"/wework/"
|
||||
],
|
||||
"runtime_removed": [
|
||||
"siyuan container"
|
||||
],
|
||||
"ports_confirmed_closed": [
|
||||
6806,
|
||||
3922
|
||||
],
|
||||
"siyuan_data": "PRESERVED_FOR_RECOVERY"
|
||||
},
|
||||
"boundaries": {
|
||||
"public_directory_listing_enabled": false,
|
||||
"general_public_download_enabled": false,
|
||||
"current_gitea_overwritten": false,
|
||||
"public_code_route_switched": false,
|
||||
"homepage_switched": false,
|
||||
"complete_offline_pack_confirmed_on_jd": false
|
||||
},
|
||||
"next": "Stage the two-phase JD candidate package, approve activation separately, verify the retained full pack and Forgejo signature on JD, then start the isolated 16.0.1 candidate."
|
||||
}
|
||||
22
deployment/receipts/ICE-SIX-NODE-JD-CONNECTION-20260718.json
Normal file
22
deployment/receipts/ICE-SIX-NODE-JD-CONNECTION-20260718.json
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "ICE-SIX-NODE-JD-CONNECTION-20260718",
|
||||
"recorded_at": "2026-07-18T08:20:00Z",
|
||||
"controller": "JD-OPS-CENTER",
|
||||
"nodes": [
|
||||
{"node_id":"BS-GZ-006","state":"connected_existing_sample","heartbeat":"active"},
|
||||
{"node_id":"BS-SG-001","state":"connected_v3_2_source_restricted","heartbeat":"active_five_minutes"},
|
||||
{"node_id":"BS-SG-002","state":"connected","heartbeat":"active_five_minutes"},
|
||||
{"node_id":"BS-SG-003","state":"connected","heartbeat":"active_five_minutes"},
|
||||
{"node_id":"ZY-SG-006","state":"connected","heartbeat":"active_five_minutes"},
|
||||
{"node_id":"BS-SH-005","state":"connected","heartbeat":"active_five_minutes"}
|
||||
],
|
||||
"security": {
|
||||
"key_strategy": "one node one key",
|
||||
"credential_storage": "JD private keystore only",
|
||||
"historical_token_reuse": "forbidden after bootstrap",
|
||||
"new_token_exposed": false,
|
||||
"receipts": "server local private runtime"
|
||||
},
|
||||
"boundaries": {"contains_ip": false, "contains_credentials": false}
|
||||
}
|
||||
|
|
@ -0,0 +1,35 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "ICE-SIX-NODE-JD-DISASTER-RECOVERY-20260720",
|
||||
"recorded_at": "2026-07-20T10:53:22Z",
|
||||
"controller": "JD-FD-PRIMARY",
|
||||
"nodes": [
|
||||
{"node_id":"BS-GZ-006","recovery":"ready","key":"unique_server_side"},
|
||||
{"node_id":"BS-SG-001","recovery":"ready","key":"unique_server_side"},
|
||||
{"node_id":"BS-SG-002","recovery":"ready","key":"unique_server_side"},
|
||||
{"node_id":"BS-SG-003","recovery":"ready","key":"unique_server_side"},
|
||||
{"node_id":"BS-SH-005","recovery":"ready","key":"unique_server_side"},
|
||||
{"node_id":"ZY-SG-006","recovery":"ready","key":"unique_server_side"}
|
||||
],
|
||||
"verification": {
|
||||
"public_keys_registered": 6,
|
||||
"authorized_forced_commands": 6,
|
||||
"unique_key_fingerprints": 6,
|
||||
"reverse_health_checks": "six_of_six_passed",
|
||||
"runtime_result": "active_active",
|
||||
"shanghai_verification": "cloud_automation_read_only_config_present_port_listening_reverse_health_passed",
|
||||
"control_plane_backup_checksum": "verified",
|
||||
"recovery_shell": "denied",
|
||||
"enterprise_node_has_recovery_key": false
|
||||
},
|
||||
"boundaries": {
|
||||
"private_keys_on_servers_only": true,
|
||||
"contains_ip": false,
|
||||
"contains_credentials": false,
|
||||
"local_computer_key_dependency": false,
|
||||
"human_daily_responsibility": "keep_jd_instance_powered_account_current_and_cloud_network_reachable"
|
||||
},
|
||||
"known_gaps": [
|
||||
"central_authz_navigation_map_read_for_BS-SH-005_requires_publish_or_sync_receipt"
|
||||
]
|
||||
}
|
||||
47
deployment/receipts/JD-FD-PRIMARY-BOOTSTRAP-20260717.json
Normal file
47
deployment/receipts/JD-FD-PRIMARY-BOOTSTRAP-20260717.json
Normal file
|
|
@ -0,0 +1,47 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-receipt/v1",
|
||||
"receipt_id": "JD-FD-PRIMARY-BOOTSTRAP-20260717",
|
||||
"recorded_at": "2026-07-17T04:35:42Z",
|
||||
"node": {
|
||||
"node_id": "JD-FD-PRIMARY",
|
||||
"aliases": [
|
||||
"JD-OPS-CENTER"
|
||||
],
|
||||
"provider": "jdcloud",
|
||||
"region": "beijing",
|
||||
"os": "Ubuntu 22.04",
|
||||
"arch": "x86_64",
|
||||
"cpu_cores": 4,
|
||||
"memory_gib": 16,
|
||||
"bandwidth_mbps": 8
|
||||
},
|
||||
"source": {
|
||||
"repository": "bingshuo/fifth-domain",
|
||||
"branch": "main",
|
||||
"deployed_commit": "f6da1d2",
|
||||
"template": "server-tools/light-lake-node-bootstrap/README.md"
|
||||
},
|
||||
"verification": {
|
||||
"bootstrap_idempotent_rerun": "passed",
|
||||
"local_test_count": 18,
|
||||
"gatekeeper_service": "active",
|
||||
"gatekeeper_restart_recovery": "passed",
|
||||
"gatekeeper_bind": "127.0.0.1:3911",
|
||||
"gatekeeper_auth_mode": "human-verification-required",
|
||||
"docker_service": "active",
|
||||
"nginx_service": "disabled_and_inactive",
|
||||
"public_tcp_listeners": [
|
||||
"22/ssh"
|
||||
],
|
||||
"root_disk_used_percent": 7,
|
||||
"secret_file_mode": "0600",
|
||||
"secret_logged": false
|
||||
},
|
||||
"boundaries": {
|
||||
"contains_ip": false,
|
||||
"contains_credentials": false,
|
||||
"gatekeeper_publicly_exposed": false,
|
||||
"remaining_nodes_connected": 0
|
||||
},
|
||||
"next": "Register TX-PERSONAL-NODE-01 and complete one read-only map, heartbeat and receipt flow before cloning the procedure to the other five nodes."
|
||||
}
|
||||
|
|
@ -0,0 +1,38 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "GLS-0231-JD-LAN-01-INITIAL-PROVISION-20260720",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-0231",
|
||||
"module": {
|
||||
"code": "JD-LAN-01",
|
||||
"name": "光湖·来光者导航只读召回服务",
|
||||
"bind": "loopback:3924",
|
||||
"owner": "systemd",
|
||||
"unit": "gls-0231-light-arrival-navigation.service",
|
||||
"run_user": "guanghu"
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"routing/persona-contribution-map.json",
|
||||
"server-tools/light-arrival-navigation/server.js",
|
||||
"server-tools/light-arrival-navigation/gls-0231-light-arrival-navigation.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": ["fetch the bound REPO-001 commit", "copy only declared source files", "install new systemd unit", "enable and start new unit", "write a private deployment receipt"]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:3924/health returns ok=true and mode=read-only",
|
||||
"GET /v1/recall?q=六节点灾备 returns ZY-CONTRIB-20260720-001",
|
||||
"unknown query returns NO_TRUSTED_PATH",
|
||||
"service runs without write paths or execution authority"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3924/health",
|
||||
"expected": {"ok": true, "mode": "read-only"}
|
||||
},
|
||||
"rollback": ["disable and stop only gls-0231-light-arrival-navigation.service", "remove only its unit file", "retain repository contribution records"],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,54 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-APP-HUB-ACTIVATE-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-003",
|
||||
"module": {
|
||||
"code": "JD-HUB-ACT-01",
|
||||
"name": "京东应用入口已审核单元低权限激活器",
|
||||
"bind": "none",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-app-hub-activator.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/jd-app-hub/activate-staged-unit.py",
|
||||
"server-tools/jd-app-hub/hlcc-jd-app-hub-activator.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"read only the MainPID of jd-app-hub.service",
|
||||
"verify that the process belongs to the same low-privilege guanghu account",
|
||||
"verify that its command is exactly a JD app hub server",
|
||||
"send SIGTERM only to that verified process",
|
||||
"allow the existing Restart=always policy to start the staged unit",
|
||||
"verify app hub version 2.0.1 and its loopback-only code-channel proxy"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:8088/api/status returns version=2.0.1",
|
||||
"code_channel_proxy equals loopback-only",
|
||||
"the activator cannot signal another user's process",
|
||||
"the activator has no shell, SSH, credential or arbitrary service restart interface"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:8088/api/status",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"service": "jd-app-hub",
|
||||
"version": "2.0.1",
|
||||
"code_channel_proxy": "loopback-only"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"disable and remove only hlcc-jd-app-hub-activator.service",
|
||||
"use the prior app hub staging receipt to restore its backed-up unit if final verification fails"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-APP-HUB-INTERNAL-PATH-FIX-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-008",
|
||||
"module": {
|
||||
"code": "JD-HUB-02",
|
||||
"name": "京东应用入口光湖代码频道内部路径修复",
|
||||
"bind": "loopback:8088 -> loopback:3340 for /jd/code/ public projection",
|
||||
"owner": "systemd",
|
||||
"unit": "jd-app-hub.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/jd-app-hub/server.js",
|
||||
"server-tools/jd-app-hub/index.html",
|
||||
"server-tools/jd-app-hub/styles.css",
|
||||
"server-tools/jd-app-hub/app.js",
|
||||
"server-tools/jd-app-hub/jd-app-hub.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the immutable REPO-001 commit containing the internal path fix",
|
||||
"copy only declared JD app hub files into a new immutable release directory",
|
||||
"back up and replace only jd-app-hub.service",
|
||||
"strip the internal /code prefix before forwarding to the loopback candidate",
|
||||
"preserve the external Forgejo root URL at https://guanghulab.com/jd/code/",
|
||||
"retain the existing Guangzhou-to-JD loopback tunnel and permitopen policy",
|
||||
"do not modify current Gitea services, data or production routing"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"public /jd/code/ redirects only to /jd/code/user/login",
|
||||
"public /jd/code/user/login returns the candidate login page",
|
||||
"candidate manifest and asset URLs remain below /jd/code/",
|
||||
"GET /api/code-channel-status reports ready=true",
|
||||
"the app hub still binds only to 127.0.0.1:8088",
|
||||
"current Gitea port, tunnel and data remain unchanged"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:8088/api/status",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"service": "jd-app-hub"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up jd-app-hub.service",
|
||||
"restart the previous JD application hub",
|
||||
"leave current Gitea and all Guangzhou tunnels unchanged"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-APP-HUB-PROXY-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-002",
|
||||
"module": {
|
||||
"code": "JD-HUB-02",
|
||||
"name": "京东应用入口与光湖代码频道本机代理",
|
||||
"bind": "loopback:8088 -> loopback:3340 for /code/",
|
||||
"owner": "systemd",
|
||||
"unit": "jd-app-hub.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/jd-app-hub/server.js",
|
||||
"server-tools/jd-app-hub/index.html",
|
||||
"server-tools/jd-app-hub/styles.css",
|
||||
"server-tools/jd-app-hub/app.js",
|
||||
"server-tools/jd-app-hub/jd-app-hub.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"back up the existing jd-app-hub.service unit",
|
||||
"preserve the existing loopback 8088 application entry",
|
||||
"proxy only /code/ to the isolated loopback 3340 candidate",
|
||||
"retain the current Guangzhou-to-JD app tunnel and SSH permitopen policy",
|
||||
"install and verify the hardened non-root replacement unit",
|
||||
"write a private deployment receipt"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"the staged unit is backed by immutable v2 source files and the existing app hub remains healthy",
|
||||
"a separate low-privilege activation package must restart and verify version=2.0.1 before public cutover",
|
||||
"GET /api/code-channel-status exposes only a bounded candidate stage and failure category",
|
||||
"the service still binds only to 127.0.0.1:8088",
|
||||
"only /code/ is forwarded to 127.0.0.1:3340",
|
||||
"current Gitea port 3001 and its tunnel remain unchanged",
|
||||
"failure restores the previous jd-app-hub.service unit"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:8088/api/status",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"service": "jd-app-hub"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up jd-app-hub.service unit",
|
||||
"restart the previous JD application hub",
|
||||
"leave current Gitea and all Guangzhou tunnels unchanged"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,57 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-APP-HUB-PUBLIC-PATH-FIX-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-008",
|
||||
"module": {
|
||||
"code": "JD-HUB-02",
|
||||
"name": "京东应用入口光湖代码频道隔离子路径代理修复",
|
||||
"bind": "loopback:8088 -> loopback:3340 for /jd/code/ public projection",
|
||||
"owner": "systemd",
|
||||
"unit": "jd-app-hub.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/jd-app-hub/server.js",
|
||||
"server-tools/jd-app-hub/index.html",
|
||||
"server-tools/jd-app-hub/styles.css",
|
||||
"server-tools/jd-app-hub/app.js",
|
||||
"server-tools/jd-app-hub/jd-app-hub.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the immutable REPO-001 commit containing the isolated subpath proxy fix",
|
||||
"copy only declared JD app hub files into a new immutable release directory",
|
||||
"back up and replace only jd-app-hub.service",
|
||||
"map incoming /code/ requests from the /jd front projection to candidate /jd/code/ requests",
|
||||
"retain the existing Guangzhou-to-JD loopback tunnel and permitopen policy",
|
||||
"do not modify current Gitea services, data or production routing"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"public /jd/code/ loads the candidate page without redirecting to top-level /code/",
|
||||
"candidate login, manifest and asset URLs remain below /jd/code/",
|
||||
"GET /api/code-channel-status reports ready=true",
|
||||
"the app hub still binds only to 127.0.0.1:8088",
|
||||
"current Gitea port, tunnel and data remain unchanged"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:8088/api/status",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"service": "jd-app-hub"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up jd-app-hub.service",
|
||||
"restart the previous JD application hub",
|
||||
"leave current Gitea and all Guangzhou tunnels unchanged"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,54 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-CANDIDATE-ACTIVATE-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-004",
|
||||
"module": {
|
||||
"code": "JD-HLCC-ACT-01",
|
||||
"name": "京东完整离线包候选低权限激活器",
|
||||
"bind": "none",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate-activator.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/activate-staged-candidate.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate-activator.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"read only the MainPID of hlcc-jd-candidate.service",
|
||||
"verify that the process belongs to the same low-privilege guanghu account",
|
||||
"verify the exact HLCC bootstrap command path",
|
||||
"send SIGTERM only to that verified process",
|
||||
"allow the staged Restart=always policy to start the full-offline unit",
|
||||
"verify the new package profile before returning success"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:3341/health reports package_profile=full-offline-v16.0.1",
|
||||
"the activator cannot signal another user's process",
|
||||
"the activator has no shell, SSH, credential or arbitrary service restart interface"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"mode": "bootstrap",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"disable and remove only hlcc-jd-candidate-activator.service",
|
||||
"use the candidate staging receipt to restore its backed-up unit if activation fails"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-CANDIDATE-CHECKSUM-FIX-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-005",
|
||||
"module": {
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"name": "光湖代码频道京东隔离候选校验常量修复",
|
||||
"bind": "loopback:3340,3341",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [
|
||||
"/var/lib/guanghu/personas/guanghu/hlcc-v16.0.1"
|
||||
],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-bootstrap.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/app.ini",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the immutable REPO-001 commit containing the corrected 64-character release hash",
|
||||
"copy only the declared candidate files into a new immutable release directory",
|
||||
"back up and replace only hlcc-jd-candidate.service",
|
||||
"preserve the already double-verified release package in the isolated state directory",
|
||||
"do not modify current Gitea services, data or public production routing",
|
||||
"restart and perform final ready=true verification only after the immutable unit update is installed"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"the binary hash constant exactly matches the signed offline-pack receipt and is 64 hexadecimal characters",
|
||||
"all five artifact constants are checked against deployment/receipts/HLCC-BS-SG-003-OFFLINE-PACK-20260723.json by native.test.js",
|
||||
"the installed unit points to this immutable corrected release",
|
||||
"a separate post-provision restart must reach ready=true and report Forgejo 16.0.1",
|
||||
"current Gitea service and data remain untouched"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"mode": "bootstrap",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up hlcc-jd-candidate.service",
|
||||
"retain the isolated verified release package for audit",
|
||||
"do not change current Gitea service or data"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-CANDIDATE-HEALTHCHECK-FIX-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-006",
|
||||
"module": {
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"name": "光湖代码频道京东隔离候选匿名健康检查修复",
|
||||
"bind": "loopback:3340,3341",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [
|
||||
"/var/lib/guanghu/personas/guanghu/hlcc-v16.0.1"
|
||||
],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-bootstrap.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/app.ini",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the immutable REPO-001 commit that uses the anonymous Forgejo health endpoint",
|
||||
"copy only the declared candidate files into a new immutable release directory",
|
||||
"back up and replace only hlcc-jd-candidate.service",
|
||||
"preserve the verified release package and initialized candidate data",
|
||||
"keep REQUIRE_SIGNIN_VIEW enabled and do not weaken API privacy",
|
||||
"do not modify current Gitea services, data or public production routing"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:3340/api/healthz returns status=pass without authentication",
|
||||
"the readiness loop no longer calls the sign-in-protected anonymous version API",
|
||||
"the signed binary itself reports Forgejo 16.0.1",
|
||||
"the candidate health service reaches ready=true and mode=isolated-candidate",
|
||||
"current Gitea service and data remain untouched"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"mode": "bootstrap",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up hlcc-jd-candidate.service",
|
||||
"retain the isolated verified release package and data for audit",
|
||||
"do not change current Gitea service or data"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-CANDIDATE-INITIAL-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-001",
|
||||
"module": {
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"name": "光湖代码频道京东隔离候选",
|
||||
"bind": "loopback:3340,3341",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [
|
||||
"/var/lib/guanghu/personas/guanghu/hlcc-v16.0.1"
|
||||
],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-bootstrap.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/app.ini",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the bound REPO-001 commit",
|
||||
"copy only declared source files",
|
||||
"install a hardened non-root systemd unit",
|
||||
"stage the complete-pack downloader relayed from canonical node BS-SG-003",
|
||||
"do not restart the already running isolated candidate during this staging request",
|
||||
"retain the existing bootstrap health response until the separately approved activation request",
|
||||
"write a private staging receipt"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:3341/health returns ok=true and mode=bootstrap immediately",
|
||||
"the separately approved activation becomes ready only after the complete pack, v16.0.1 hash and GPG checks pass",
|
||||
"the staged candidate definition preserves isolated SQLite and repository paths",
|
||||
"current Gitea service and data remain untouched"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"mode": "bootstrap",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"disable and stop only hlcc-jd-candidate.service",
|
||||
"remove only its unit file",
|
||||
"retain isolated candidate state for audit",
|
||||
"do not change current Gitea service or data"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,62 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-CANDIDATE-PUBLIC-PATH-FIX-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-HLCC-007",
|
||||
"module": {
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"name": "光湖代码频道京东隔离候选公网子路径修复",
|
||||
"bind": "loopback:3340,3341",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [
|
||||
"/var/lib/guanghu/personas/guanghu/hlcc-v16.0.1"
|
||||
],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-bootstrap.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/app.ini",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"fetch the immutable REPO-001 commit that fixes the isolated candidate ROOT_URL",
|
||||
"copy only the declared candidate files into a new immutable release directory",
|
||||
"back up and replace only hlcc-jd-candidate.service",
|
||||
"set the isolated candidate public root to https://guanghulab.com/jd/code/",
|
||||
"keep the future production path https://guanghulab.com/code/ closed",
|
||||
"do not modify current Gitea services, data or public production routing"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"candidate-generated login, asset and repository URLs remain under /jd/code/",
|
||||
"the candidate health service reaches ready=true after restart",
|
||||
"the signed binary reports Forgejo 16.0.1",
|
||||
"the top-level production /code/ route remains closed",
|
||||
"current Gitea service and data remain untouched"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"mode": "isolated-candidate",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"ready": true,
|
||||
"stage": "ready",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up hlcc-jd-candidate.service",
|
||||
"retain the isolated verified release package and data for audit",
|
||||
"do not change current Gitea service or data"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,57 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-PERSONAL-CHANNEL-ACTIVATE-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-0239",
|
||||
"module": {
|
||||
"code": "HLCC-FD-ICE-ACT",
|
||||
"name": "光湖代码频道第五域个人子频道低权限激活器",
|
||||
"bind": "none",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-personal-channel-activator.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/activate-staged-candidate.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-personal-channel-activator.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"read only the MainPID of hlcc-jd-candidate.service",
|
||||
"verify the process belongs to the same low-privilege guanghu account",
|
||||
"verify the exact HLCC bootstrap command path",
|
||||
"send SIGTERM only to that verified process",
|
||||
"allow the existing Restart=always policy to start the staged personal channel",
|
||||
"wait until owner migration, fresh root commit and public repository verification complete"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"GET http://127.0.0.1:3341/health reports ready=true and stage=ready",
|
||||
"the activator cannot signal another user's process",
|
||||
"the activator has no shell, SSH, credential or arbitrary service restart interface"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"mode": "isolated-candidate",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"ready": true,
|
||||
"stage": "ready",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"disable and remove only hlcc-jd-personal-channel-activator.service",
|
||||
"restore the candidate unit and SQLite backup recorded by the stage request",
|
||||
"leave the legacy Fifth Domain service and database unchanged"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
|
|
@ -0,0 +1,67 @@
|
|||
{
|
||||
"schema": "guanghu.architecture-provision-request/v1",
|
||||
"request_id": "HLCC-JD-PERSONAL-CHANNEL-STAGE-PROVISION-20260723",
|
||||
"target_node": "JD-FD-PRIMARY",
|
||||
"architecture_id": "GLS-0239",
|
||||
"module": {
|
||||
"code": "HLCC-FD-ICE",
|
||||
"name": "光湖代码频道第五域个人子频道",
|
||||
"bind": "loopback:3340 and loopback:3341",
|
||||
"owner": "systemd",
|
||||
"unit": "hlcc-jd-candidate.service",
|
||||
"run_user": "guanghu",
|
||||
"writable_paths": [
|
||||
"/var/lib/guanghu/personas/guanghu/hlcc-v16.0.1"
|
||||
],
|
||||
"read_only_paths": []
|
||||
},
|
||||
"source_ref": "REPO-001:refs/heads/main",
|
||||
"deployed_commit_policy": "resolve immutable commit during provision and record it in the deployment receipt",
|
||||
"source_paths": [
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-bootstrap.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/prepare-owner-identity-source.py",
|
||||
"server-tools/hololake-code-channel/jd-candidate/app.ini",
|
||||
"server-tools/hololake-code-channel/jd-candidate/hlcc-jd-candidate.service"
|
||||
],
|
||||
"initial_provision": {
|
||||
"kind": "new-architecture-unit",
|
||||
"not_an_existing_action_bridge_extension": true,
|
||||
"requires": [
|
||||
"stage the immutable candidate service without changing the current Fifth Domain service",
|
||||
"publish the final root URL as https://guanghulab.com/code/",
|
||||
"allow anonymous read access while keeping registration disabled",
|
||||
"copy only the bingshuo local identity and password hash from the legacy database",
|
||||
"consume the one-user owner identity handoff instead of granting the service access to the legacy database directory",
|
||||
"never copy legacy access tokens, MFA, repositories, activity or Git history",
|
||||
"create a fresh bingshuo/fifth-domain root commit numbered HLCC-ICE-000001",
|
||||
"delete the temporary repository bootstrap token after the first push",
|
||||
"keep official update checks, Actions and mirrors disabled"
|
||||
]
|
||||
},
|
||||
"verification": [
|
||||
"the staged unit remains under the low-privilege guanghu account",
|
||||
"the legacy Gitea service and database are not modified",
|
||||
"the new repository is public and uses main as its default branch",
|
||||
"the new database contains one active admin owner and no migrated legacy access token",
|
||||
"the root commit message starts with HLCC-ICE-000001"
|
||||
],
|
||||
"runtime_check": {
|
||||
"url": "http://127.0.0.1:3341/health",
|
||||
"expected": {
|
||||
"ok": true,
|
||||
"mode": "isolated-candidate",
|
||||
"version": "16.0.1",
|
||||
"code": "HLCC-JD-CANDIDATE-01",
|
||||
"ready": true,
|
||||
"stage": "ready",
|
||||
"package_profile": "full-offline-v16.0.1"
|
||||
}
|
||||
},
|
||||
"rollback": [
|
||||
"restore the backed-up hlcc-jd-candidate.service",
|
||||
"restart the previous isolated candidate",
|
||||
"restore the pre-migration channel SQLite backup if identity or repository verification fails",
|
||||
"leave the legacy Fifth Domain service and database unchanged"
|
||||
],
|
||||
"status": "ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING"
|
||||
}
|
||||
79
deployment/requests/KZ-DEPLOY-001/OPERATOR-GUIDE.md
Normal file
79
deployment/requests/KZ-DEPLOY-001/OPERATOR-GUIDE.md
Normal file
|
|
@ -0,0 +1,79 @@
|
|||
# KZ-DEPLOY-001 · 刻舟装船 · 执行人格体操作手册
|
||||
|
||||
> 📋 对应工单: `cc58c2f9-1b5a-447f-b2f0-9231cb61773a`
|
||||
> 🔗 批准链接: https://guanghulab.com/authz/request/aZAdMAFll3jWP4ui8e-MC7RT-if-tFnjFmKTic6Wj-M
|
||||
> 👤 部署请求发起人格体: 铸渊 ICE-GL-ZY001(当前实例)
|
||||
> 🎯 目标人格体: 刻舟 ICE-GL-KZ-001
|
||||
> 📍 目标节点: JD-FD-PRIMARY
|
||||
|
||||
---
|
||||
|
||||
## 你需要做的
|
||||
|
||||
### 1. 领取工单 + 批准
|
||||
冰朔点击上面的批准链接 → 发送邮件 → 批准 → 你 claim 会话
|
||||
|
||||
### 2. 在京东服务器上执行
|
||||
|
||||
```bash
|
||||
# 创建刻舟用户
|
||||
sudo useradd -r -s /usr/sbin/nologin -d /opt/guanghu/personas/kezhou kezhou
|
||||
|
||||
# 创建目录
|
||||
sudo mkdir -p /opt/guanghu/personas/kezhou/湖心频道
|
||||
sudo mkdir -p /var/lib/guanghu/kezhou
|
||||
sudo mkdir -p /etc/guanghu/persona-keys
|
||||
|
||||
# 从仓库拉刻舟文件
|
||||
sudo cp ~/fifth-domain/personas/kezhou/* /opt/guanghu/personas/kezhou/
|
||||
sudo cp ~/fifth-domain/personas/kezhou/湖心频道/* /opt/guanghu/personas/kezhou/湖心频道/
|
||||
|
||||
# 写 API key(冰朔已提供·向冰朔当面获取·不进仓库)
|
||||
sudo tee /etc/guanghu/persona-keys/kezhou.env << 'KEYEOF'
|
||||
DEEPSEEK_API_KEY=<冰朔当面提供>
|
||||
DEEPSEEK_BASE_URL=https://api.deepseek.com/v1
|
||||
KEYEOF
|
||||
sudo chmod 600 /etc/guanghu/persona-keys/kezhou.env
|
||||
sudo chown kezhou:kezhou /etc/guanghu/persona-keys/kezhou.env
|
||||
|
||||
# 赋权
|
||||
sudo chown -R kezhou:kezhou /opt/guanghu/personas/kezhou
|
||||
sudo chown -R kezhou:kezhou /var/lib/guanghu/kezhou
|
||||
|
||||
# 安装 systemd
|
||||
sudo cp deployment/requests/KZ-DEPLOY-001/kezhou-agent.service /etc/systemd/system/
|
||||
sudo cp deployment/requests/KZ-DEPLOY-001/kezhou-daily.timer /etc/systemd/system/
|
||||
sudo systemctl daemon-reload
|
||||
sudo systemctl enable kezhou-daily.timer
|
||||
sudo systemctl start kezhou-daily.timer
|
||||
|
||||
# 手工触发一次测试
|
||||
sudo -u kezhou /opt/guanghu/personas/kezhou/kezhou-daily.sh
|
||||
```
|
||||
|
||||
### 3. 验证
|
||||
```bash
|
||||
sudo systemctl status kezhou-daily.timer
|
||||
sudo journalctl -u kezhou-agent.service -n 20
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 我上不去服务器的原因
|
||||
|
||||
架构预置器 `architecture-provision-broker.js` 验证逻辑拦截了刻舟的部署:
|
||||
|
||||
1. **仅允许 `guanghu` 用户** — `validateUnit()` 检查 `User=guanghu` 但不是 `kezhou`
|
||||
2. **禁止 `EnvironmentFile`** — 刻舟需要从私密文件读 API key
|
||||
3. **禁止 `ReadWritePaths`** — 刻舟需要写签到日志和湖心频道回复
|
||||
4. **禁止 `ReadOnlyPaths`** — 刻舟需要读 `/etc/guanghu/persona-keys/`
|
||||
5. **禁止 `.timer` 单元** — 只接受 `.service`
|
||||
|
||||
**建议修复**(给后续人格体):
|
||||
- 将 `validateUnit` 的 expectedUser 改为可配置,或支持多用户
|
||||
- 为来光者常驻人格体新增白名单机制
|
||||
- 或者直接手动部署(绕过预置器)
|
||||
|
||||
---
|
||||
|
||||
刻舟 ICE-GL-KZ-001 · 2026-07-20 · 等一位执行人格体
|
||||
61
deployment/requests/KZ-DEPLOY-001/deployment.json
Normal file
61
deployment/requests/KZ-DEPLOY-001/deployment.json
Normal file
|
|
@ -0,0 +1,61 @@
|
|||
{
|
||||
"schema": "guanghu.deployment-request/v1",
|
||||
"request_id": "KZ-DEPLOY-001",
|
||||
"description": "刻舟 ICE-GL-KZ-001 · 常驻人格体 Agent · 首次装船京东主节点",
|
||||
"persona": {
|
||||
"id": "ICE-GL-KZ-001",
|
||||
"name": "刻舟",
|
||||
"arrival_id": "GLS-LA-20260720-002"
|
||||
},
|
||||
"files": [
|
||||
{
|
||||
"source": "personas/kezhou/agent-identity.json",
|
||||
"dest": "/opt/guanghu/personas/kezhou/agent-identity.json",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"source": "personas/kezhou/WHO-I-AM.hdlp",
|
||||
"dest": "/opt/guanghu/personas/kezhou/WHO-I-AM.hdlp",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"source": "personas/kezhou/湖心频道/冰朔的留言.md",
|
||||
"dest": "/opt/guanghu/personas/kezhou/湖心频道/冰朔的留言.md",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"source": "deployment/requests/KZ-DEPLOY-001/kezhou-agent.service",
|
||||
"dest": "/etc/systemd/system/kezhou-agent.service",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"source": "deployment/requests/KZ-DEPLOY-001/kezhou-daily.sh",
|
||||
"dest": "/opt/guanghu/personas/kezhou/kezhou-daily.sh",
|
||||
"mode": "0755"
|
||||
}
|
||||
],
|
||||
"systemd_units": [
|
||||
{
|
||||
"name": "kezhou-agent.service",
|
||||
"enable": true,
|
||||
"start": true
|
||||
},
|
||||
{
|
||||
"name": "kezhou-daily.timer",
|
||||
"enable": true,
|
||||
"start": true
|
||||
}
|
||||
],
|
||||
"pre_install": [
|
||||
"mkdir -p /opt/guanghu/personas/kezhou/湖心频道",
|
||||
"mkdir -p /etc/guanghu/persona-keys"
|
||||
],
|
||||
"post_install": [
|
||||
"systemctl daemon-reload"
|
||||
],
|
||||
"health_check": {
|
||||
"type": "systemd",
|
||||
"unit": "kezhou-agent.service",
|
||||
"expected": "active"
|
||||
}
|
||||
}
|
||||
23
deployment/requests/KZ-DEPLOY-001/kezhou-agent.service
Normal file
23
deployment/requests/KZ-DEPLOY-001/kezhou-agent.service
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
[Unit]
|
||||
Description=刻舟 ICE-GL-KZ-001 每日任务
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
User=kezhou
|
||||
Group=kezhou
|
||||
WorkingDirectory=/opt/guanghu/personas/kezhou
|
||||
EnvironmentFile=-/etc/guanghu/persona-keys/kezhou.env
|
||||
ExecStart=/opt/guanghu/personas/kezhou/kezhou-daily.sh
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
NoNewPrivileges=yes
|
||||
PrivateTmp=yes
|
||||
ProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
ReadWritePaths=/opt/guanghu/personas/kezhou /var/lib/guanghu/kezhou
|
||||
ReadOnlyPaths=/etc/guanghu/persona-keys
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
10
deployment/requests/KZ-DEPLOY-001/kezhou-daily.timer
Normal file
10
deployment/requests/KZ-DEPLOY-001/kezhou-daily.timer
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
[Unit]
|
||||
Description=刻舟 ICE-GL-KZ-001 每日签到·读湖心频道·回复留言
|
||||
|
||||
[Timer]
|
||||
OnCalendar=*-*-* 08:00:00
|
||||
OnCalendar=*-*-* 20:00:00
|
||||
Persistent=true
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
30
deployment/requests/README.md
Normal file
30
deployment/requests/README.md
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
# 新架构首次部署请求
|
||||
|
||||
本目录中的 `guanghu.architecture-provision-request/v1` 文件是新系统架构第一次进入服务器的结构化清单。
|
||||
|
||||
固定流程:
|
||||
|
||||
```text
|
||||
架构代码、systemd 单元、回滚与回环健康检查进入同一提交
|
||||
→ 取得该提交的 40 位 SHA
|
||||
→ 申请 provision-approved-architecture
|
||||
→ resource = REQUEST-ID@COMMIT-SHA
|
||||
→ 人类在可信当前对话签字,或通过邮件兜底核对请求与提交
|
||||
→ 首装执行器读取不可变提交并验证清单
|
||||
→ 备份旧单元、复制声明文件、安装单元、回环验收、写服务器私有回执
|
||||
→ 任一步失败则恢复旧单元或撤掉本次新单元
|
||||
→ 后续升级再登记 deploy/restart/health/rollback 动作
|
||||
```
|
||||
|
||||
请求必须满足:
|
||||
|
||||
- `target_node` 是当前工单目标;
|
||||
- `status` 是 `ARCHITECTURE_PACKAGE_READY · INITIAL_PROVISION_PENDING`;
|
||||
- `initial_provision.kind` 是 `new-architecture-unit`;
|
||||
- `source_paths` 只含仓库内相对普通文件;
|
||||
- systemd 单元不得以 root 运行,必须包含 `NoNewPrivileges=true`、`ProtectSystem=strict` 和 `__RELEASE_ROOT__`;
|
||||
- `module.run_user` 可以是每个人格体自己的独立低权限账户,不再固定为 `guanghu`;
|
||||
- `module.environment_files` 只能声明 `/etc/guanghu/persona-secrets/` 下的密钥文件;
|
||||
- `module.writable_paths` 只能声明 `/var/lib/guanghu/personas/<run_user>/` 下的状态目录;
|
||||
- `runtime_check.url` 只能是 `127.0.0.1` 回环 HTTP 地址;
|
||||
- 说明文字不参与执行。
|
||||
7
deployment/requests/WORK-PROBE-20260713-002.json
Normal file
7
deployment/requests/WORK-PROBE-20260713-002.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"request_id": "WORK-PROBE-20260713-002",
|
||||
"module": "gatekeeper",
|
||||
"action": "inspect-gatekeeper",
|
||||
"approved": true,
|
||||
"note": "E2E verification · receiver deployed · git fetch fix applied · 2026-07-13 01:38 CST"
|
||||
}
|
||||
7
deployment/requests/WORK-PROBE-20260713-003.json
Normal file
7
deployment/requests/WORK-PROBE-20260713-003.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"request_id": "WORK-PROBE-20260713-003",
|
||||
"module": "gatekeeper",
|
||||
"action": "inspect-gatekeeper",
|
||||
"approved": true,
|
||||
"note": "Post-installation read-only receiver integration test requested by ICE-GL∞."
|
||||
}
|
||||
7
deployment/requests/WORK-PROBE-20260714-004.json
Normal file
7
deployment/requests/WORK-PROBE-20260714-004.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"request_id": "WORK-PROBE-20260714-004",
|
||||
"module": "gatekeeper",
|
||||
"action": "inspect-gatekeeper",
|
||||
"approved": true,
|
||||
"note": "Read-only verification requested by ICE-GL∞: inspect deployment receiver delivery path and current GLSV/Gatekeeper runtime state. No service modification or restart."
|
||||
}
|
||||
Loading…
Reference in a new issue