Roll out role-provider selector schema safely across client hosts #743

Closed
opened 2026-08-04 20:08:38 +00:00 by coilyco-ops · 0 comments
Owner

Parent

coilysiren/inbox#325

Outcome

Client-host convergence installs a selector-capable Agent Compose before rendering and consuming AOSK role-provider configuration that uses the new strict schema.

Scope

  • Upgrade the Agent Compose formula on supported macOS and Linux or WSL personal clients.
  • Order the product upgrade before rendering configuration that may use a newly released schema.
  • Preserve AOSK's role-provider declaration as the owning source. Infrastructure passes it through without adding another parser or duplicate selector inventory.
  • Preserve check-mode behavior and make schema or product-version failures actionable.
  • Verify that staged-home consumers receive the same immutable selected bundle.
  • Keep server-class hosts on the isolated Ward composition path.
  • Record native Windows as an explicit remaining boundary under #356 unless this work lands an equivalent tracked convergence path.
  • Do not perform a live fleet converge from Engineer or QA work.

Acceptance

  • An older installed binary cannot be left to consume selector-bearing configuration.
  • Ansible render and check-mode validation cover macOS and Linux or WSL clients.
  • Existing whole-provider configurations still render unchanged.
  • Agent Compose compose or dry-run succeeds against the rendered AOSK declaration.
  • Documentation names the product, policy, and rollout owners correctly.
  • Run the repository's Ward validation and pre-commit surface.
## Parent https://forgejo.coilysiren.me/coilysiren/inbox/issues/325 ## Outcome Client-host convergence installs a selector-capable Agent Compose before rendering and consuming AOSK role-provider configuration that uses the new strict schema. ## Scope * Upgrade the Agent Compose formula on supported macOS and Linux or WSL personal clients. * Order the product upgrade before rendering configuration that may use a newly released schema. * Preserve AOSK's role-provider declaration as the owning source. Infrastructure passes it through without adding another parser or duplicate selector inventory. * Preserve check-mode behavior and make schema or product-version failures actionable. * Verify that staged-home consumers receive the same immutable selected bundle. * Keep server-class hosts on the isolated Ward composition path. * Record native Windows as an explicit remaining boundary under https://forgejo.coilysiren.me/coilyco-flight-deck/infrastructure/issues/356 unless this work lands an equivalent tracked convergence path. * Do not perform a live fleet converge from Engineer or QA work. ## Acceptance * An older installed binary cannot be left to consume selector-bearing configuration. * Ansible render and check-mode validation cover macOS and Linux or WSL clients. * Existing whole-provider configurations still render unchanged. * Agent Compose compose or dry-run succeeds against the rendered AOSK declaration. * Documentation names the product, policy, and rollout owners correctly. * Run the repository's Ward validation and pre-commit surface.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-flight-deck/infrastructure#743
No description provided.