docs: record that a rebuild is deferred and unproven #731
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/rebuild-is-deferred"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The north star said
make rebuildmust complete with zero manualintervention. That reads as an operative rule. It is an aspiration, and the
gap to it is large.
The cluster has run for months without a rebuild, and the probability that
it comes back up is very far from 100 percent. Changes are tested in
production -- the deliberate choice for now -- but rebuild safety drifted away
a long time ago.
Why this is worth a whole section
The old wording already misled a reader. In this session an agent read it as
a live constraint and proposed running
make rebuildas the verification gatefor retiring a component. The most dangerous operation available here was
offered as a safety step. The next reader makes the same inference, because the
text invites it.
So the file now says plainly: do not run it, do not propose it as a gate. It
lists the three conditions that must hold first -- stable operations, radical
simplification, and a rebuild proven in a separate environment -- and says
what to verify instead, since work still needs some way to be checked:
fidelity to live state, ordering written into Git rather than implied by a
controller, and live checks in production.
A node roll keeps its own section
Rolling nodes replaces them one at a time against a live cluster. It is a
different operation, the deferral does not apply to it, and the kernel-security
argument for it is unchanged. The two were adjacent in one block and easy to
conflate.
The LE-prod rule loses a stale reason
It was justified by "the dev cluster gets rebuilt often," which is no longer
true. The rule stands on the rate limit alone -- 5 certs per identifier per 168
hours does not care what causes the re-issues.
bash tests/check.shexits 0, including the four guards that assert onAGENTS.md content. The
CLAUDE.md -> AGENTS.mdsymlink is untouched.https://claude.ai/code/session_01GfkEuwuvGSqGyXVuxwT7PA
afe986a97639e3166b78