make snapshot / make state-backup: the pre-flight and post-flight gates (#32) #42
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!42
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/32-make-snapshot"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Two Targets package the gates the runbook carried in prose, so a service-touching
run is bracketed by commands rather than memory.
snapshotrefuses whentofu/.envis missing;state-backuprefuses whenansible/vault-passis missing — both before any command is composed.Closes #32
Evidence
Before: step 1 was a printed reminder ("No snapshot, no run") with no
command; step 6 said "copy an encrypted copy" with no recipe, and the existing
artifacts had no recorded producer.
After:
Merge Danger
Door: two-way
The Targets add commands; they change no existing behaviour.
make snapshotcreates one snapshot (and never prunes —
retention: 0);make state-backupwrites a new artifact. Either is deleted by hand.
Blast Radius: low
Prod Guest estate only, and only when a human or agent runs the Target. The
restore was proven once from a fresh backup; the recipe reuses the Vault password
as the state passphrase (recorded in the runbook as the trade-off) — a leaked
Vault password now also exposes the encrypted state.
0547fff87dto57872f919e