Skip to content

docs(superpowers): GCP parity design and plan - #2120

Merged
Smana merged 8 commits into
mainfrom
docs/gcp-parity
Oct 7, 2026
Merged

Smana merged 8 commits into
mainfrom
docs/gcp-parity

Conversation

@Smana

@Smana Smana commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

🔍 docs

📝 Summary

The next rebuild runs on GCP (owner, 2026-09-29): gcp-0 becomes a GCP-only platform that runs the agent factory, and AWS keeps only Route53, the AWS↔GCP federation, the S3 state bucket and the OpenBao lineage. Text only.

  • Salvage: the OpenBao Stage 2 port to GCP, verified live on 2026-09-11 but never merged (worktree-openbao-stage2-gcp ac62abf2), aligned with main.
  • PRs:
    • G-0 (octo-sts GKE issuer): merges first, because octo-sts reads trust policies from main.
    • G-1…G-3 (Stage 2 on GCP, GKE rebuild hygiene, GCP-hosted IdP): platform fixes that can merge on their own.
    • G-4: flips primary_cloud to gcp (the owner decides when).
    • G-5: the gcp-0 agent platform, stacked on H-1.
  • Real risks found: AWS-shaped issuers in agent-router and octo-sts; gcp-0's package lacks the AgentRun XRD; no Kyverno on gcp-0; teardown misses target pools and firewall rules. Each is a task.
  • Owner steps after tonight's 21:00 reset are listed in order in the plan.

An independent review is running; its fixes will land on this PR.

2026-09-29 execution rulings

Each plan now ends with a Rulings applied during execution (2026-09-29) table, and the task text carries each ruling in place.

  • GCP plan and spec: PR status (G-0 chore(agents): octo-sts trust policies accept gcp-0's issuer #2122, G-1 fix(openbao): Stage 2 on GCP's OpenBao #2123, G-2 fix(gcp): GKE rebuilds that can repeat #2125 and G-3 fix(gcp): a GCP-hosted ZITADEL keeps its consumers in step #2126 merged; G-4 a draft on main; G-5 in progress). W1–W5 are in tasks 6.1–6.7, and the runbook retarget moves to Phase 7 (new Task 7.2). Also:
    • Z1: a Kyverno toleration lets the gVisor pool scale from zero.
    • Z2: socketLB.hostNamespaceOnly is kept as a guard, plus a negative Gateway check from two nodes.
    • Z3: the metadata server is reached by CIDR on gcp-0.
    • R, U and AB, and Phase 8's open live items.
  • SP2 plan and spec:
    • P33 is lifted for agent-platform only, and AP-0 is merged.
    • Ruling Y: the database enforces append-only. Tasks 1.3/1.4 carry the store as landed, and Appendix C is rewritten.
    • Rulings AC/AD: the engineering standard is applied across Tasks 1.6, 1.9, 1.11, 1.12 and phases 2–6.
    • GP-18 is applied in the task bodies.
    • The CRD bounds, atlasSchema.ref after AP-1, the /api/rooms json tags, and the Phase 7 release gaps.
  • SP3 plan: the merge gate lands on GCP's management stack too.

The next rebuild runs on GCP (owner, 2026-09-29): gcp-0 becomes a
GCP-only platform that runs the agent factory, and AWS keeps only
Route53, the AWS-GCP federation, the S3 state bucket and the OpenBao
lineage.

The plan salvages the OpenBao Stage 2 port to GCP verified live on
2026-09-11 (never merged), moves ZITADEL's primary to GCP, adds a GKE
Sandbox pool, per-cloud issuers for agent-router and octo-sts, gcp-0
agent umbrellas and a cloud-shape render gate. Platform fixes (G-0..G-3)
can merge on their own; G-4 flips the primary; G-5 stacks on H-1.
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Rendered manifest diff — this PR vs main (desired state)

No changes to the rendered desired state. ✅

The independent review found 4 Critical and 11 Important issues; all are
fixed in the plan and spec, with the owner's decisions of 2026-09-29:
the freshly generated ZITADEL PAT always wins over a stored one, the old
GCP OpenBao lineage is restored, G-0..G-3 merge ahead when green while
G-4 (primary cloud) stays on integration, and a guarded GCP teardown
sweep deletes leftover load-balancer resources.

Also carries H-1's final-review amendments to the SP2 plan: Task 0.5.14
moves integration's package pin to an artifact-publishing pre-release
and checks run logs for GitHub tokens, Task 3.8 lists the MCP allowlist
test, P39 names its residual reads, and Phase 7 re-points runbook URLs.
Applies the GCP parity plan's cross-plan edits: SP2 retargets its live
gates to gcp-0, adds TLS on the room broker's bridge listener (GP-18, no
WireGuard on gcp-0) and the gcp-0 hairpin ruling; the observability plan
stacks O-1 on GCP parity G-5 and runs its live gates on gcp-0.
…, SP2 and SP3 plans

GCP parity plan and spec:
- PR map status (G-0..G-3 merged, G-4 draft on main, G-5 in progress) and
  the H' rebase-onto-main base for G-2/G-3
- W1-W5 in tasks 6.1-6.7; the runbook retarget moves to Phase 7 (Task 7.2)
- Z1 gVisor toleration policy, Z2 socketLB as a guard, Z3 metadata server
  by CIDR; task 6.3's code as committed
- Rulings R, U and AB; Phase 8 open live items and new checks
- A "Rulings applied during execution" index

SP2 plan and spec:
- P33 lifted for agent-platform; AP-0 merged; no package-visibility step
- Ruling Y: tasks 1.3/1.4 carry the landed schema and store; Appendix C
- Rulings AC/AD: internal/app, OTel metrics, httpx, injected clock, server
  timeouts, TLS reload across tasks 1.6, 1.9, 1.11, 1.12 and phases 2-6
- GP-18 applied in tasks 1.9, 1.11, 1.14 and the live curls; CRD bounds;
  atlasSchema.ref after AP-1; /api/rooms json tags; Phase 7 gaps

SP3 plan: the merge gate lands on GCP's management stack too.
The rooms plan's three conflicts are unions: main's R04 internal-egress gate, its
internal-run OWNER row and the 7.0 UX-fixes node, beside this branch's 2026-09-29
rulings and OWNER rows. Task 7.2 gains a status note: the agent-platform P33 lift
was not used past AP-0, so AP-1…AP-6 still merge in the wave.
@Smana
Smana merged commit 7c2f6d6 into main Oct 7, 2026
22 of 23 checks passed
@Smana
Smana deleted the docs/gcp-parity branch October 8, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant