Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Resetting the Secret-Projection Conformance No-Go

This procedure recovers the exact Linux server conformance attempt that stopped at site.provision because /run/secrets/ahri-tre had the wrong owner and mode. It preserves the sanitized no-go evidence and the complete checksummed predecessor rollback unit, removes only the partial AHRI TRE attempt, activates the corrected candidate, and then prepares entirely fresh external Secrets.

Neither wizard installs package files or invokes the conformance harness. Stop after the preparation wizard declares HOST READY.

Use this procedure only for these immutable inputs:

  • failed candidate SHA-256: 2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd;
  • corrected candidate SHA-256: 21a99920541e044000bba7134f685f8780ba1de44ab9637408d8ffd5c470b125;
  • fixed 0.3.12 predecessor SHA-256: 6f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed;
  • MinisForum svrltreapcc02 at 192.168.31.75;
  • Deployment f2ef37c5-7430-468a-a439-b3ba1b0527c1; and
  • Datastore ahri-tre-test.

The failed and corrected archives deliberately have the same filename and kit version. Their SHA-256 values identify their different immutable contents.

What remains and what is reset

RemainsReset or replaced
hostname and reserved addresspartial AHRI TRE server and site package files
/data mountcaptured Injected-secret authority and ephemeral projections
Docker installation and default bridgegenerated configuration, Runtime state, and logs
runtime and PostgreSQL hosts mappingsfailed Deployment root identity and WSL2 backup
intended UFW policyremote public input and extraction workspace
declared service identitiesactive failed candidate pair
earlier protected failed-attempt recordsnothing outside the named AHRI TRE attempt paths

The complete /var/backups/ahri-tre/server-previous rollback unit is verified with its own package-SHA256SUMS, then moved into this attempt’s protected record. It is not reused for the next run.

1. Verify the corrected candidate in WSL2

Run from the ordinary WSL2 Ubuntu shell, not the development container:

cd /home/kobus/repos/ahri-tre-rs
cd dist/conformance-candidate-projection-retry-output-0.3.14
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256
cd /home/kobus/repos/ahri-tre-rs

The check must print OK. The archive digest must be the corrected digest shown above. Do not copy it over the active failed archive by hand.

The fixed predecessor archive and checksum must remain in:

/home/kobus/ahri-tre-conformance/input/

Do not regenerate or replace the predecessor.

2. Run the exact-state reset wizard

Keep the MinisForum running in its failed state. Do not reboot or manually change /run/secrets first. Start:

cd /home/kobus/repos/ahri-tre-rs
./scripts/reset-failed-secret-projection-conformance-wizard.sh

The wizard performs seven guarded stages:

  1. It verifies WSL2, required tools, and the exact corrected archive pair.
  2. It verifies all internal checksums, committed-source server lifecycle, the corrected projector, and the corrected root-owned namespace declaration.
  3. It accepts only sanitized Linux evidence with outcome=no-go and failed_stage=site.provision, then preserves it locally.
  4. It verifies the host, failed candidate digest, installed package and partial site ownership, installed projector, observed 0700 namespace, captured authority, and complete predecessor rollback unit. After confirmation, it verifies the installed uninstall plan, stops the units present at this partial-install boundary, removes only regular files declared by the server and site ownership manifests, and clears generated attempt state.
  5. It retires the exact failed local pair, activates the corrected pair, and removes the failed root-identity backup.
  6. It proves the retained host foundation and displays UFW for human review.
  7. It stops at RESET READY without installing packages or invoking conformance.

Approve the firewall prompt only when UFW remains active with default-deny incoming, default-allow outgoing, SSH allowed, LAN HTTPS on TCP 443 allowed, and PostgreSQL TCP 5432 denied.

The local failed record is retained under:

/home/kobus/ahri-tre-conformance/retired/no-go-2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd/

The protected server record is retained under:

/var/backups/ahri-tre/failed-installed-conformance/2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd/

If the wizard refuses, stop. Do not delete evidence, manufacture a checksum manifest, manually invoke an installer, or alter ownership to bypass a guard. An interrupted wizard can be run again; it recognizes its exact retired state.

3. Prepare fresh candidate-matching Secrets

After the reset wizard prints RESET READY, run:

cd /home/kobus/repos/ahri-tre-rs
./scripts/minisforum-conformance-preparation-wizard.sh

The preparation wizard re-verifies the corrected candidate and fixed predecessor, transfers those exact inputs, creates fresh PostgreSQL TLS and password projections, retrieves the ORCID Sandbox client Secret, projects the candidate Runtime key, creates and separately backs up a fresh Deployment root identity, and proves the shared namespace and leaf permissions.

The shared projection root must be root:root:0755. These traversal-only namespaces must each be root:root:0711:

/run/secrets/ahri-tre
/run/secrets/oidc
/run/secrets/postgres
/run/secrets/postgres/tls
/run/secrets/runtime

The restricted leaf directories and files retain the owners and modes declared by the candidate’s projection plan. Mode 0711 on a shared namespace does not make Secret values readable.

Required stopping boundary

Stop when the preparation wizard prints:

HOST READY
The conformance harness has not been invoked.
Press Enter to finish at the host-ready boundary.

Do not reboot after HOST READY, because /run/secrets is intentionally ephemeral. Do not install packages or invoke conformance in this reset and preparation phase.