Applies the document contract from
docs/plans/2026-08-20_stack-docs-flatten-and-alignment.md section 3, partially:
`kind` and `status` only. `parent` is deliberately held until the flatten in
section 4 lands, so that 127 documents do not have to be re-pointed by hand
when docs/fleet/NORTH_STAR.yaml moves to docs/NORTH_STAR.yaml.
Scope, measured on origin/next at 63069149:
127 live docs = all *.md under docs/ minus docs/archive/ minus docs/_old_structure/
104 stamped here
19 held operator judgement (plan section 9), worklist in the same PR
3 held the SUPERSEDED TASKS.md stamps, which cite the moving path
1 untouched docs/fleet/FLEET-DOCTRINE.md, already stamped in W1
Kinds applied: 54 guide, 34 record, 9 spec, 6 tracking, 1 projection.
Every row carries a confidence and a one-line rationale in the worklist.
Two collisions with the existing state, both flagged rather than resolved:
1. docs/README.md:150-160 already documents a front-matter convention
(title/type/audience/status/source_of_truth) with its own allowed values.
It is applied to 4 of 127 files. Its `status` vocabulary is
current|draft|deprecated|historical; the new contract's is active|superseded-by.
The key collides. This commit lets the new contract win and rewrites
`status: current` to `status: active` on those 4 files, keeping their other
legacy keys untouched. No code reads any of them: `git grep source_of_truth`
outside docs/ returns nothing. docs/README.md still prescribes the old
convention and is an operator row, so it is not edited here.
2. Two of the plan's 20 operator rows are YAML files, not markdown
(docs/fleet/examples/roster-v2.yaml, docs/openapi-tess.yaml), and the
contract's front-matter form has no defined meaning for a .yaml document.
That gap also applies to docs/fleet/NORTH_STAR.yaml, the source of truth
itself. Raised in the worklist.
A third row from the plan, docs/fleet/north-star.md, no longer exists: W1
renamed it to docs/fleet/FLEET-DOCTRINE.md.
Verification: 104/104 parse with the expected kind and status in front matter;
the check was shown to reject a wrong kind before it was trusted. The diff
removes 4 lines total, all of them `status: current`.
60 lines
3.3 KiB
Markdown
60 lines
3.3 KiB
Markdown
---
|
|
kind: record
|
|
status: active
|
|
---
|
|
|
|
# FCM-M5-001 Fleet Documentation Deferrals and Holds
|
|
|
|
**Issue:** #758 · **Branch:** `docs/758-fleet-config-operator-docs`
|
|
|
|
These are accepted existing DAG boundaries, not omissions silently claimed as delivered.
|
|
|
|
## FCM-M3-002 hold
|
|
|
|
- Boot/reboot preservation for roster members persisted stopped or disabled.
|
|
- Current installation may enable all agent units, while the launcher projection does not yet carry
|
|
`lifecycle.enabled` or `desired_state`; documentation therefore does not claim lifecycle-safe reboot.
|
|
- Heartbeat/liveness integration into roster-v2 `status`, `doctor`, and `verify`; current observations
|
|
cover systemd active state, tmux sessions, holder ownership, and unmanaged sessions only.
|
|
|
|
## FCM-M4-002 hold
|
|
|
|
- Executable v1-to-v2 cutover, reversible canary, and rollback.
|
|
- Stale-projection/orphan migration classification and current-host managed/unmanaged fixture coverage.
|
|
- Any live migration, lifecycle, systemd/tmux/session, or rollback action.
|
|
|
|
M5 docs describe prerequisites and the preview boundary only. A ready preview is not migration or rollback evidence.
|
|
|
|
## Explicit validate-operation gap
|
|
|
|
- `FCM-REQ-03` requires a documented programmatic `mosaic fleet validate` operation.
|
|
- The current CLI does not expose that operation. Existing mutation/reconcile validation and the
|
|
documentation example test are not a replacement for the missing command.
|
|
- FCM-M5-001 documents this implementation gap without inventing syntax, JSON, exit behavior, or an
|
|
owning implementation card. Parent #758 must remain open until the requirement is implemented and
|
|
evidenced or the PRD/DAG is explicitly revised through the authoritative process.
|
|
|
|
## FCM-M5-002 hold
|
|
|
|
- Deterministic source-versus-installed asset revision detection and safe refresh implementation.
|
|
- Rolling local canary, independent validator certificate, final release evidence, merge-gate approval, and parent #758 closure.
|
|
|
|
`operations/upgrade-assets.md` is therefore a fail-closed hold, not an invented procedure.
|
|
|
|
## Compatibility interpretation
|
|
|
|
The M0 cross-cutting row requiring every retained/migrated artifact to validate through the executable contract is satisfied by each artifact's declared executable disposition, not by forcing versioned v1 fixtures through the v2 parser:
|
|
|
|
- retained examples are explicit `version: 1` fixtures validated by the production v1 parser;
|
|
- canonical profiles validate through the shared baseline plus `roles.local` resolver;
|
|
- the service preset validates through its production service-policy reader;
|
|
- migration candidates validate through the production v2 compiler and shared semantic resolver.
|
|
|
|
The executable disposition inventory rejects undeclared additions/removals and prevents silent legacy drift.
|
|
|
|
## Repository-wide documentation structure
|
|
|
|
The accepted #758 IA is the domain book under `docs/fleet/`. Creating global `USER-GUIDE`, `ADMIN-GUIDE`, or `DEVELOPER-GUIDE` books and cleaning unrelated pre-existing `docs/` root files are outside this bounded card. The repository sitemap links the fleet book. No HTTP/API/auth contract changed, so OpenAPI and endpoint-index updates are not applicable.
|
|
|
|
Canonical documentation remains in-repository; no external publishing or generated publishing output is in scope. Parent issue #758 stays open through M5.
|