Files
stack/docs/fleet/reference/lifecycle-transitions.md
T
veronica f0d2dd9920 docs(W4): stamp kind and status front matter on 104 live documents
Applies the document contract from
docs/plans/2026-08-20_stack-docs-flatten-and-alignment.md section 3, partially:
`kind` and `status` only. `parent` is deliberately held until the flatten in
section 4 lands, so that 127 documents do not have to be re-pointed by hand
when docs/fleet/NORTH_STAR.yaml moves to docs/NORTH_STAR.yaml.

Scope, measured on origin/next at 63069149:

  127 live docs   = all *.md under docs/ minus docs/archive/ minus docs/_old_structure/
  104 stamped     here
   19 held        operator judgement (plan section 9), worklist in the same PR
    3 held        the SUPERSEDED TASKS.md stamps, which cite the moving path
    1 untouched   docs/fleet/FLEET-DOCTRINE.md, already stamped in W1

Kinds applied: 54 guide, 34 record, 9 spec, 6 tracking, 1 projection.
Every row carries a confidence and a one-line rationale in the worklist.

Two collisions with the existing state, both flagged rather than resolved:

1. docs/README.md:150-160 already documents a front-matter convention
   (title/type/audience/status/source_of_truth) with its own allowed values.
   It is applied to 4 of 127 files. Its `status` vocabulary is
   current|draft|deprecated|historical; the new contract's is active|superseded-by.
   The key collides. This commit lets the new contract win and rewrites
   `status: current` to `status: active` on those 4 files, keeping their other
   legacy keys untouched. No code reads any of them: `git grep source_of_truth`
   outside docs/ returns nothing. docs/README.md still prescribes the old
   convention and is an operator row, so it is not edited here.

2. Two of the plan's 20 operator rows are YAML files, not markdown
   (docs/fleet/examples/roster-v2.yaml, docs/openapi-tess.yaml), and the
   contract's front-matter form has no defined meaning for a .yaml document.
   That gap also applies to docs/fleet/NORTH_STAR.yaml, the source of truth
   itself. Raised in the worklist.

A third row from the plan, docs/fleet/north-star.md, no longer exists: W1
renamed it to docs/fleet/FLEET-DOCTRINE.md.

Verification: 104/104 parse with the expected kind and status in front matter;
the check was shown to reject a wrong kind before it was trusted. The diff
removes 4 lines total, all of them `status: current`.
2026-08-20 19:30:25 -05:00

5.7 KiB

kind, status
kind status
guide active

Local Fleet Lifecycle Transitions

Roster-v2 lifecycle.enabled and lifecycle.desired_state are the only persisted lifecycle authority. Systemd, tmux, generated environment, and heartbeat state are derived or observed.

Event Desired-state write Runtime effect Safety boundary
fleet create Adds enabled/stopped by default; --persisted-start records running None Generation-guarded; validates full roster/projections.
fleet update Preserves the existing enabled/desired state; updates other mutable fields None Generation-guarded; stable name and lifecycle are immutable on this path.
fleet delete Removes exact roster member None Removes only generated projection; retains local/quarantine evidence.
fleet apply / reconcile Never Rebuilds projections; starts only enabled/running; stops disabled or stopped roster members Current generation, private lock/paths, semantic validity, holder ownership, no unmanaged named-socket sessions.
fleet start Never One-shot exact service start Exact enabled roster name and proven ownership.
fleet stop Never One-shot exact service stop Exact roster name and proven ownership.
fleet restart Never One-shot exact service restart Exact enabled roster name and proven ownership.
Reboot/service activation Never Current installation may activate enabled units without honoring roster lifecycle Held for FCM-M3-002: boot preservation for stopped/disabled agents is not yet proven; inspect/disable units rather than assuming lifecycle-safe reboot.
v1 migration preview Never None Observed active+present maps running; inactive+missing maps stopped; ambiguity blocks.
Cutover/canary Held for FCM-M4-002 Not implemented by preview Must preserve every observed stopped state.
Rollback Held for FCM-M4-002 Not implemented Must restore selected authority/projections without surprise starts or unmanaged targeting.

Explicit apply/reconcile never starts a stopped roster agent. Direct lifecycle commands are explicit one-shot actions and do not persist intent. The current update operation preserves existing.lifecycle; there is no delivered generation-guarded CRUD operation for changing durable lifecycle after creation. Reboot preservation for stopped/disabled agents is not yet guaranteed because current enabled units and launcher projections do not carry the persisted lifecycle fence; that acceptance evidence remains FCM-M3-002.

Missing/stale generation, concurrent writer, unsafe path, ownership mismatch, unmanaged session, unsupported runtime, invalid projection, and lifecycle precondition failures return stable redacted JSON and non-zero status. No command targets fuzzy names, arbitrary sockets/commands/channels/secrets, or generated files as authority. Legacy sensitive values are never printed.