fix: harden service provisioning and verify disposable Linux lifecycle - #23
Merged
Conversation
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fresh dedicated-account installs failed when rootless Podman inherited the operator's container-storage configuration or private working directory. Provision the service image from the service-owned checkout with the explicit environment used by the daemon.
Add disposable GitHub-hosted Linux acceptance workflows for the real systemd installer, full production image, restart, encrypted fixture backup/restore, uninstall preservation and an actual Ubuntu guest OS reboot under KVM. A local-upstream fixture invokes the unmodified CLI updater against test/readiness failures and checks real Git/service rollback; engine smoke and test/pretest commands are controlled fixture inputs.
Validation on merge SHA
547ae2454d96fc038e97ae111174cebfb3bcd998:All data and passwords were synthetic fixtures in disposable VMs. No production runtime or credentials were used. Reboot happened only inside the guest, while the GitHub runner stayed alive. Authenticated Claude/Codex conversation/session gates remain unexecuted; private Airtable QA remains deferred by operator instruction. Detailed reproduction and evidence are in TEST-PLAN.md.