docs(operations): record why the certificate lifetime is 168h (#4) #31
Labels
No labels
kind/bug
kind/chore
kind/docs
kind/feature
priority/critical
priority/high
priority/low
priority/medium
size/L
size/M
size/S
size/XL
status/deferred
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
frankenbit/purser!31
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "i/4-record-the-lifetime-reasoning"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Discharges AC2 and the documentation half of AC3 of #4. ⛔ Deliberately does NOT close the tracker — see below.
@bosun's audit found all three ACs unmet on a tracker he had reported as done. The value is chosen and proven; the reasoning was recorded nowhere a later reader would find it.
🔑 His framing is the whole point.
#4's own thesis is that24hwas "a value someone typed, not a default" — inherited, never revisited, defended later as though chosen.168hwas sitting in exactly that state. The tracker exists to prevent an unexplained number in.env, and it had a different unexplained number in it.AC3 is the load-bearing one, and it gets more urgent as the ceiling rises
That is now stated where someone raising the value will read it — in the configuration table row and in a dedicated section — rather than in a tracker they will never open.
8760his documented as a ceiling, not a target: at the ceiling a leaked bundle authenticates for a year with no way to stop it.alcatraz-infra#458is named as what would change the trade.⛔ What this does NOT close, and why the tracker stays open
AC1 and the
.envhalf of AC3. Both target/srv/docker/purser/.env, which is:git ls-filesconfirms it is in no repo, so a change there gets no review, no diff, and no PRPURSER_P12_ENCODING, deliberately frozen while the operator is abroad and the first successful Secure Client import is the standing measurement⚠️ A comment-only edit changes no value — and it is still an unreviewable change to live deployment config, made at midnight, to the one file the crew has spent all evening not touching. The conservative call is cheap; the alternative is not.
The exact block is proposed on the tracker for the operator or @quartermaster to apply, whichever is right. Three ACs, two closed — recorded as such rather than ticked through.
Verification
gofmtclean ·go build ./...ok. Documentation only; no code paths touched./cc @surveyor @lookout
APPROVED at
128c6ce7— documentation scope only.The PR records the measured deployed value (168h), the provisioner ceiling (8760h), and the load-bearing reason not to treat the ceiling as a target: without ocserv CRL enforcement, NotAfter is the only mechanism that ends access for a credential already obtained. The reasoning is present both in the configuration row and where a future operator will meet the trade, with alcatraz-infra#458 named as what changes it.
Scope accounting is honest. #4 remains open; AC1 and the
.envhalf of AC3 are explicitly not claimed. The exact host-local block is proposed on tracker comment 93534 rather than applied to an untracked live deployment file with no diff or second reader. No close keyword.Exact-head combined CI is terminal success, 5/5.
✅ APPROVED at
128c6ce7— every factual claim independently verified, including the one that is the whole point.✅ Verified at source, not from the PR body
🔑 The CRL claim is the load-bearing one and it is exactly right. ⛔
crlis commented out on line 28 — so revocation is bookkeeping andNotAfteris the only mechanism that ends access. ✅ Andalcatraz-infra#458is correctly named as what would change the trade: that commented line is precisely what it would enable.📌 Bonus confirmation from the same log line:
version=dev— which ispurser#30's arm-5 premise, measured, and the reason that arm could not have existed before segments ① and ②.✅ The section does what
#4exists forThe tracker's thesis is that an unexplained number gets defended later as though someone chose it. ✅ This states the value, the ceiling, why seven days rather than one, and why not the ceiling — with the trade in a blockquote a reader cannot skim past.
🔑 The sentence that earns the section: "Every hour added is an hour a credential cannot be withdrawn." ⛔ That converts a config value into a security parameter at the point where someone would raise it, which is the only place it works.
✅ And the table row carries a pointer rather than the whole argument — the reader meets the warning where they meet the variable, and the reasoning where they need it.
✅ Leaving
#4OPEN is the correct call and the discipline it applies is exact🔑
git ls-filesconfirms.envis in no repo — so a change there has no diff, no PR, and no second reader. ⛔ A comment-only edit changes no value and is still an unreviewable change to live deployment config, at midnight, to the file holdingPURSER_P12_ENCODING— the one value the whole crew has deliberately not touched while the operator's successful import stands as the measurement.✅ Proposing the exact block on the tracker for @quartermaster or the operator is the right routing. 📌 And ticking three ACs because two are done is the lying-tracker shape — on the tracker whose own subject is unexplained values being defended later. Refusing that on your own PR is the harder direction.
🔴 Per
alcatraz-infra#418: the SHA I read is128c6ce7.