Resetting the Secret-Projection Conformance No-Go
This procedure recovers the exact Linux server conformance attempt that stopped
at site.provision because /run/secrets/ahri-tre had the wrong owner and
mode. It preserves the sanitized no-go evidence and the complete checksummed
predecessor rollback unit, removes only the partial AHRI TRE attempt, activates
the corrected candidate, and then prepares entirely fresh external Secrets.
Neither wizard installs package files or invokes the conformance harness. Stop
after the preparation wizard declares HOST READY.
Use this procedure only for these immutable inputs:
- failed candidate SHA-256:
2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd; - corrected candidate SHA-256:
21a99920541e044000bba7134f685f8780ba1de44ab9637408d8ffd5c470b125; - fixed
0.3.12predecessor SHA-256:6f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed; - MinisForum
svrltreapcc02at192.168.31.75; - Deployment
f2ef37c5-7430-468a-a439-b3ba1b0527c1; and - Datastore
ahri-tre-test.
The failed and corrected archives deliberately have the same filename and kit version. Their SHA-256 values identify their different immutable contents.
What remains and what is reset
| Remains | Reset or replaced |
|---|---|
| hostname and reserved address | partial AHRI TRE server and site package files |
/data mount | captured Injected-secret authority and ephemeral projections |
| Docker installation and default bridge | generated configuration, Runtime state, and logs |
| runtime and PostgreSQL hosts mappings | failed Deployment root identity and WSL2 backup |
| intended UFW policy | remote public input and extraction workspace |
| declared service identities | active failed candidate pair |
| earlier protected failed-attempt records | nothing outside the named AHRI TRE attempt paths |
The complete /var/backups/ahri-tre/server-previous rollback unit is verified
with its own package-SHA256SUMS, then moved into this attempt’s protected
record. It is not reused for the next run.
1. Verify the corrected candidate in WSL2
Run from the ordinary WSL2 Ubuntu shell, not the development container:
cd /home/kobus/repos/ahri-tre-rs
cd dist/conformance-candidate-projection-retry-output-0.3.14
sha256sum --check --strict \
ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256
cd /home/kobus/repos/ahri-tre-rs
The check must print OK. The archive digest must be the corrected digest
shown above. Do not copy it over the active failed archive by hand.
The fixed predecessor archive and checksum must remain in:
/home/kobus/ahri-tre-conformance/input/
Do not regenerate or replace the predecessor.
2. Run the exact-state reset wizard
Keep the MinisForum running in its failed state. Do not reboot or manually
change /run/secrets first. Start:
cd /home/kobus/repos/ahri-tre-rs
./scripts/reset-failed-secret-projection-conformance-wizard.sh
The wizard performs seven guarded stages:
- It verifies WSL2, required tools, and the exact corrected archive pair.
- It verifies all internal checksums, committed-source server lifecycle, the corrected projector, and the corrected root-owned namespace declaration.
- It accepts only sanitized Linux evidence with
outcome=no-goandfailed_stage=site.provision, then preserves it locally. - It verifies the host, failed candidate digest, installed package and partial
site ownership, installed projector, observed
0700namespace, captured authority, and complete predecessor rollback unit. After confirmation, it verifies the installed uninstall plan, stops the units present at this partial-install boundary, removes only regular files declared by the server and site ownership manifests, and clears generated attempt state. - It retires the exact failed local pair, activates the corrected pair, and removes the failed root-identity backup.
- It proves the retained host foundation and displays UFW for human review.
- It stops at
RESET READYwithout installing packages or invoking conformance.
Approve the firewall prompt only when UFW remains active with default-deny incoming, default-allow outgoing, SSH allowed, LAN HTTPS on TCP 443 allowed, and PostgreSQL TCP 5432 denied.
The local failed record is retained under:
/home/kobus/ahri-tre-conformance/retired/no-go-2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd/
The protected server record is retained under:
/var/backups/ahri-tre/failed-installed-conformance/2caf994b9cf3d72d4eacd4a6fdeb859440481d2a6fb4cd3f02a3437a84e6a1cd/
If the wizard refuses, stop. Do not delete evidence, manufacture a checksum manifest, manually invoke an installer, or alter ownership to bypass a guard. An interrupted wizard can be run again; it recognizes its exact retired state.
3. Prepare fresh candidate-matching Secrets
After the reset wizard prints RESET READY, run:
cd /home/kobus/repos/ahri-tre-rs
./scripts/minisforum-conformance-preparation-wizard.sh
The preparation wizard re-verifies the corrected candidate and fixed predecessor, transfers those exact inputs, creates fresh PostgreSQL TLS and password projections, retrieves the ORCID Sandbox client Secret, projects the candidate Runtime key, creates and separately backs up a fresh Deployment root identity, and proves the shared namespace and leaf permissions.
The shared projection root must be root:root:0755. These traversal-only
namespaces must each be root:root:0711:
/run/secrets/ahri-tre
/run/secrets/oidc
/run/secrets/postgres
/run/secrets/postgres/tls
/run/secrets/runtime
The restricted leaf directories and files retain the owners and modes declared
by the candidate’s projection plan. Mode 0711 on a shared namespace does not
make Secret values readable.
Required stopping boundary
Stop when the preparation wizard prints:
HOST READY
The conformance harness has not been invoked.
Press Enter to finish at the host-ready boundary.
Do not reboot after HOST READY, because /run/secrets is intentionally
ephemeral. Do not install packages or invoke conformance in this reset and
preparation phase.