feat(wake): W6 — off-host dead-man beacon + pluggable alarm-sink adapter
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
A8 of the wake canon (EPIC #892, W6): the independent liveness leg. beacon.sh: - MONOTONIC EMITTER (emit): strictly-increasing seq + emit_ts each cycle, shipped off-host via a pluggable sink adapter. The primitive the detector run-loop calls each poll (§1.3). - DEAD-MAN / ABSENCE alarm (record + check): the off-host monitor's receiver and absence check. A missing/stale-past-SLO beacon FIRES the alarm and ROUTES it to a human/other-host, depending on nothing the dying host does (§1.3/§4-G1). - PLUGGABLE alarm-sink / beacon-sink ADAPTER INTERFACE: the framework ships the emitter + interface; the operator owns the target endpoint, resolved BY NAME (load_credentials), never inlined (§1.4). FAIL-CLOSED: unconfigured OR unreachable target FAILS LOUD — no silent no-alarm host (§4-G2a). - DEGRADED MODES (honest, not silent): a same-host sibling is REJECTED as non-independent (shares user-manager/host/sender/socket/session); an isolated host degrades to a FLAGGED different-supervision-root beacon; capture-pane is a liveness HINT only (§1.3). detector.sh: a single minimal, opt-in W6 emit seam in the run-loop (inert unless the operator wires WAKE_BEACON_SINK_CMD; a beacon emit failure never kills the loop but is loud). No store/ack/digest/sign code touched. test-wake-beacon.sh: RED-FIRST harness (10 invariant groups), wired into test:framework-shell. manifest.txt bumped 0.4.0 -> 0.5.0 + inventory. Part of #892 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0158NZqN2n2ymKFeJAZ4GUCb
This commit is contained in:
@@ -15,8 +15,10 @@
|
||||
# 0.2.0 W3 — cumulative-state digest renderer + non-circular HMAC signer.
|
||||
# 0.3.0 W4 — per-host single-instance delta-gated detector daemon.
|
||||
# 0.4.0 W5 — synthetic-canary FN-oracle + source-parity reconciler.
|
||||
# 0.5.0 W6 — off-host dead-man beacon emitter + pluggable alarm-sink adapter
|
||||
# + beacon-absence alarm (fail-loud on unconfigured/unreachable).
|
||||
component=wake
|
||||
version=0.4.0
|
||||
version=0.5.0
|
||||
|
||||
# Watch-list schema this component consumes, and the INCLUSIVE range of
|
||||
# schema_version values it supports. A wake-watch-list.json whose schema_version
|
||||
@@ -45,4 +47,16 @@ schema_max=1
|
||||
# inventory (an omitted source cannot pass the vector
|
||||
# vacuously) + (ii) periodic full reconcile to 0-unaccounted,
|
||||
# enumerating pre-existing/startup state into the store. (W5)
|
||||
# Out of scope (later waves): off-host beacon (W6), installer (W7).
|
||||
# beacon.sh A8 — off-host DEAD-MAN liveness beacon: a monotonic beacon
|
||||
# EMITTER (emit — the primitive the detector run-loop calls
|
||||
# each cycle), the off-host monitor's RECEIVER + beacon-ABSENCE
|
||||
# alarm (record, check), and a pluggable alarm-sink/beacon-sink
|
||||
# ADAPTER INTERFACE. Liveness is SPLIT from work-triggering;
|
||||
# the alarm fires on ABSENCE, routing to a human/other-host
|
||||
# within its SLO (§4/G1). FAIL-CLOSED: an unconfigured OR
|
||||
# unreachable target FAILS LOUD (no silent no-alarm host).
|
||||
# A same-host sibling is REJECTED as non-independent; an
|
||||
# isolated host degrades to a FLAGGED different-supervision-root
|
||||
# beacon; capture-pane is a liveness HINT only. (W6)
|
||||
# Out of scope (later waves): installer (W7 wires + install-validates the beacon
|
||||
# target that beacon.sh's fail-loud primitive is designed for).
|
||||
|
||||
Reference in New Issue
Block a user