Skip to content

task: rebuild a destroyed host from the repository and prove convergence #36

Description

@tucktuck101

Parent PRD

#5

Objective

Record evidence on this issue that a destroyed host can be rebuilt to an equivalent functional and security state from the repository alone, and that rerunning the automation against the rebuilt host converges.

Definition of done

  • A host is destroyed outright and replaced with a bare Ubuntu host — not reset, reverted or partially reused
  • The replacement is rebuilt using only the repository's automation, the documented bootstrap credentials and the secrets the automation declares
  • Nothing is done by hand during the rebuild; anything that had to be is recorded as a defect in the automation and filed
  • The verification suite passes against the rebuilt host
  • A second full run of the automation against the rebuilt host reports zero changes, evidencing Ruling 11's convergence requirement
  • Whatever the backup-scope ADR declared must survive destruction is shown to have survived and been restored
  • The elapsed time and the number of manual interventions are recorded, so the cohort knows what a real recovery would cost
  • The drill is run on the destroyable VM, since the cohort's VPS cannot be destroyed to prove this

Impacted components

launchpad/deploy/     exercised end to end; defects found are filed against it

No repository files change from the drill itself — it produces evidence, and any fix is filed separately.

Out of scope


Filed by an AI agent (Claude Opus 5) on behalf of @tucktuck101 as part of a decomposition of #5. Drafted, not executed. This is the task the destroyable local VM exists for: Rulings 11 and 14 require proving that a rebuild restores the security baseline and that repeated runs converge, and neither can be honestly tested on a single production VPS. Ruling 11 is folded in here as a definition-of-done line rather than filed separately, because convergence is a property of the automation rather than a work item of its own.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:deployVPS, Ansible, host configuration, hardeningby:agentFiled or authored by an AI agent, not a humantype:taskBounded work with no children of its own. The default type.wontfixThis will not be worked on

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions