{ "$schema": "https://hwlab.pikastech.local/schemas/dev-m5-gate-aggregator-v2.schema.json", "$id": "https://hwlab.pikastech.local/reports/dev-gate/dev-m5-gate-aggregator-v2.json", "reportVersion": "v2", "reportKind": "dev-m5-gate-aggregator", "issue": "pikasTech/HWLAB#58", "supports": [ "pikasTech/HWLAB#7", "pikasTech/HWLAB#9", "pikasTech/HWLAB#23", "pikasTech/HWLAB#26", "pikasTech/HWLAB#31", "pikasTech/HWLAB#33", "pikasTech/HWLAB#34", "pikasTech/HWLAB#35", "pikasTech/HWLAB#36", "pikasTech/HWLAB#37", "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#46", "pikasTech/HWLAB#64" ], "generatedAt": "2026-05-22T16:59:52.864Z", "generatedFromCommit": "f64182b54fe6", "environment": "dev", "endpoint": "http://74.48.78.17:16667", "frontendEndpoint": "http://74.48.78.17:16666", "activeEndpoints": { "frontend": "http://74.48.78.17:16666/", "apiLive": "http://74.48.78.17:16667/health/live" }, "deprecatedEndpoints": [ { "endpoint": "http://74.48.78.17:6666", "status": "historical/deprecated", "activeGreenEligible": false }, { "endpoint": "http://74.48.78.17:6667", "status": "historical/deprecated", "activeGreenEligible": false } ], "devOnly": true, "prodDisabled": true, "reportLifecycle": { "version": "v1", "state": "active", "activeEndpoint": "http://74.48.78.17:16667", "activeBrowserEndpoint": "http://74.48.78.17:16666", "deprecatedEndpoint": null, "summary": "Current M5 evidence aggregator report; source, local, and dry-run evidence are not DEV-LIVE acceptance." }, "safety": { "reportOnly": true, "noDeploy": true, "noProd": true, "noSecretRead": true, "noRuntimeRestart": true, "noLiveProbe": true, "noHeavyE2E": true, "noUniDeskRuntimeSubstitute": true }, "sourceReports": { "devPreflight": { "path": "reports/dev-gate/dev-preflight-report.json", "issue": "pikasTech/HWLAB#34", "taskId": "dev-gate-preflight", "lifecycleState": "active", "status": "blocked", "commitId": "f64182b54fe6" }, "devDeploy": { "path": "reports/dev-gate/dev-deploy-report.json", "issue": "pikasTech/HWLAB#33", "taskId": "dev-deploy-apply", "lifecycleState": "active", "status": "pass", "commitId": "7e29522" }, "devArtifacts": { "path": "reports/dev-gate/dev-artifacts.json", "issue": "pikasTech/HWLAB#35", "taskId": "dev-artifact-publish", "lifecycleState": "active", "status": "published", "commitId": "7e29522" }, "devEdgeHealth": { "path": "reports/dev-gate/dev-edge-health.json", "issue": "pikasTech/HWLAB#36", "taskId": "dev-edge-health", "lifecycleState": "active", "status": "blocked", "commitId": "c7de4745f491" }, "devM2Smoke": { "path": "reports/dev-gate/dev-m2-deploy-smoke-active.json", "issue": "pikasTech/HWLAB#23", "taskId": "m2-dev-deploy-smoke", "lifecycleState": "active", "status": "pass", "commitId": "8e89409dda5d" }, "devM3Hardware": { "path": "reports/dev-gate/dev-m3-hardware-loop.json", "issue": "pikasTech/HWLAB#38", "taskId": "dev-m3-hardware-loop", "lifecycleState": "active", "status": "blocked", "commitId": "c7de4745f491" }, "devM4Agent": { "path": "reports/dev-gate/dev-m4-agent-loop.json", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "lifecycleState": "active", "status": "blocked", "commitId": "0614202" }, "devM5Gate": { "path": "reports/dev-gate/dev-mvp-gate-report.json", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "lifecycleState": "active", "status": "blocked", "commitId": "86d769525caf" }, "d601Observability": { "path": "reports/d601-k3s-readonly-observability.json", "issue": "pikasTech/HWLAB#46", "taskId": "d601-k3s-readonly-observability", "lifecycleState": "active", "status": "blocked", "commitId": "unknown" } }, "overall": { "status": "blocked", "green": false, "reason": "Frontend revision 1e8805664970839b72be40c34636b08f6d18b131 and EDGE/ROUTE DEV-LIVE evidence exist on :16666/:16667, but M5 remains blocked by artifact source drift, DB live degradation, missing M3 trusted loop operation evidence, and blocked M4 agent-loop preflight." }, "latestFrontendDevFact": { "revision": "1e8805664970839b72be40c34636b08f6d18b131", "sources": [ "docs/dev-deploy-apply.md", "docs/cloud-web-workbench.md", "web/hwlab-cloud-web/index.html", "web/hwlab-cloud-web/styles.css" ], "evidence": [ "Cloud Web /health/live accepted revision 1e8805664970839b72be40c34636b08f6d18b131", "Cloud Workbench public browser endpoint is the active frontend route only", "Frontend load/revision evidence cannot satisfy DB, M3 hardware-loop, M4 agent-loop, or M5 MVP e2e acceptance" ], "commands": [ "node web/hwlab-cloud-web/scripts/check.mjs", "node scripts/dev-cloud-workbench-smoke.mjs --static" ], "summary": "#99/#108 Cloud Workbench revision 1e8805664970839b72be40c34636b08f6d18b131 is the latest accepted DEV frontend fact, but it is frontend-only evidence.", "issue": "pikasTech/HWLAB#99", "supports": [ "pikasTech/HWLAB#99", "pikasTech/HWLAB#108", "pikasTech/HWLAB#78" ], "endpoint": "http://74.48.78.17:16666/", "evidenceLevel": "DEV-LIVE", "promotesM3M4M5": false }, "dod": { "status": "blocked", "green": false, "checks": [ { "id": "m0-source-contract", "status": "pass", "evidenceLevel": "SOURCE", "summary": "M0 contract checks are source-level evidence only." }, { "id": "m1-local-smoke", "status": "pass", "evidenceLevel": "LOCAL", "summary": "M1 local smoke is not a live DEV substitute." }, { "id": "artifact-publish-digests", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "artifactState=contract-skeleton, ciPublished=false, registryVerified=false, sha256=0, not_published=13, targetCovered=false" }, { "id": "d601-k3s-observability", "status": "blocked", "evidenceLevel": "DEV-LIVE", "summary": "D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false." }, { "id": "dev-edge-frp-16667", "status": "pass", "evidenceLevel": "DEV-LIVE", "summary": "Committed edge report proves read-only public HTTP on :16667 /health and /health/live; this is route evidence, not DB/M3/M4/M5 acceptance." }, { "id": "cloud-api-db-ready", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "cloud-api DB status=degraded; ready=false; connected=false; liveDbEvidence=false." }, { "id": "m3-hardware-trusted-loop", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "M3 trusted loop is blocked until res_boxsimu_1:DO1 -> patch-panel -> res_boxsimu_2:DI1 is proven with operation/trace/audit/evidence." }, { "id": "m4-agent-loop-live", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "M4 agent loop live path is blocked before accepted agent scheduling/evidence closure." }, { "id": "m5-mvp-dev-live", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "M5 dry-run passed; bounded DEV-LIVE MVP e2e has not passed." } ] }, "currentDevLayering": { "frontendRevision": { "label": "Frontend DEV revision", "status": "pass", "evidenceLevel": "DEV-LIVE", "summary": "http://74.48.78.17:16666/ serves the accepted Cloud Workbench frontend revision 1e8805664970839b72be40c34636b08f6d18b131; this is browser/frontend evidence only.", "evidence": [ "Cloud Web /health/live accepted revision 1e8805664970839b72be40c34636b08f6d18b131", "Cloud Workbench public browser endpoint is the active frontend route only", "Frontend load/revision evidence cannot satisfy DB, M3 hardware-loop, M4 agent-loop, or M5 MVP e2e acceptance" ], "nextRequired": "Keep frontend revision proof separate from DB live readiness, M3 hardware-loop evidence, M4 agent-loop evidence, and M5 acceptance." }, "edgeRoute": { "label": "EDGE/ROUTE live", "status": "pass", "evidenceLevel": "DEV-LIVE", "summary": "http://74.48.78.17:16666/, http://74.48.78.17:16667/health, and http://74.48.78.17:16667/health/live returned accepted HWLAB DEV responses in the active M2 read-only smoke.", "evidence": [ "http://74.48.78.17:16667/health -> HTTP 200 identity=hwlab-edge-proxy status=ok", "http://74.48.78.17:16667/health/live -> HTTP 200 identity=hwlab-cloud-api status=degraded", "http://74.48.78.17:16666/ -> HTTP 200 identity=HWLAB DEV MVP Gate status=ok" ], "nextRequired": "Keep this separated from DB readiness, M3/M4 loop evidence, and M5 acceptance." }, "dbLive": { "label": "DB live/degraded", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "cloud-api DB status=degraded; configReady=true; ready=false; connected=false; liveDbEvidence=false.", "evidence": [ "http://74.48.78.17:16667/health/live -> HTTP 200 serviceId=hwlab-cloud-api status=degraded db.ready=false db.connected=false db.connectionChecked=false", "dev-edge-health active report -> blocked by DB live readiness, while public 16667 TCP/HTTP and frp control/tunnel health are reachable", "dev-m4-agent-loop active report -> blocked, classification=DB live, summary=cloud-api /health/live reports DB degraded; connected=false; ready=false" ], "nextRequired": "Provide live DB connection evidence through redacted health output; route reachability alone is insufficient." }, "d601RunnerObservability": { "label": "D601 runner observability", "status": "blocked", "evidenceLevel": "DEV-LIVE", "summary": "D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false.", "evidence": [ "runnerKubeconfigReadable=false", "runnerKubeconfigProbeExitCode=0", "runnerKubeconfigProbeStderr=empty", "d601PublicEndpointsReachable=true", "d601K3sUnavailable=false" ], "nextRequired": "Treat #46 runner kubeconfig/readonly gaps separately from D601 service health; rerun read-only observability after the mount or permission path is repaired." }, "m3HardwareTrustedLoop": { "label": "M3 hardware trusted loop", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "No live DEV operation was attempted because read-only direct target checks did not prove the required patch-panel-owned M3 route. Blocker: DEV exposes two box-simu endpoints, but live identities are not the required distinct resources res_boxsimu_1 and res_boxsimu_2; observed resources=res_boxsimu_1.", "evidence": [ "operationId=not_observed", "traceId=not_observed", "auditId=not_observed", "evidenceId=not_observed" ], "nextRequired": "Only a real DEV res_boxsimu_1:DO1 -> hwlab-patch-panel -> res_boxsimu_2:DI1 observation with operation/trace/audit/evidence can clear M3." }, "m4AgentLoop": { "label": "M4 agent loop", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "Blocked at DB live readiness before scheduling a DEV agent task.", "evidence": [ "k3s:namespace=hwlab-dev:read=true", "k3s:deploy/hwlab-agent-mgr:ready=1/1:available=True", "k3s:deploy/hwlab-agent-skills:ready=1/1:available=True", "k3s:svc/hwlab-agent-mgr:endpoints=1", "k3s:svc/hwlab-agent-skills:endpoints=1", "agent-mgr:/health/live:degraded", "agent-skills:/health/live:ok:cb35ada6860653b27269b0a57991184118cbf4b1", "worker-template:suspend=true:image=127.0.0.1:5000/hwlab/hwlab-agent-worker:cb35ada", "worker-job:server-dry-run=true:persisted=false", "skills-injection:commit=cb35ada:version=missing", "secret-rbac:get=yes:secretResourcesRead=false", "Public DEV API http://74.48.78.17:16667 health=200 live=200; frontend http://74.48.78.17:16666/=200.", "health:hwlab-edge-proxy:dev:ok", "live:hwlab-cloud-api:degraded:db-blocked" ], "nextRequired": "Do not schedule or claim the agent loop as live until DB live and required runtime/evidence preconditions pass." }, "artifactDesiredStateSource": { "label": "artifact/desired-state source", "status": "blocked", "evidenceLevel": "BLOCKED", "summary": "artifact targetCovered=false; artifactSource=7e29522b65c8; target=f64182b54fe6; desiredApplyMode=dry-run; mutationAttempted=false.", "evidence": [ "artifactState=contract-skeleton", "sourceStates=13 source-present, 0 intentionally-disabled", "desiredState=ready dry-run-only" ], "nextRequired": "Refresh artifact/source coverage for current origin/main and keep desired-state apply separate from read-only route proof." } }, "milestoneLevelClassification": [ { "milestone": "M0", "currentLevel": "SOURCE", "status": "pass", "strongestEvidenceLevel": "SOURCE", "liveEvidence": "missing_or_blocked", "summary": "Source contract is green at source level only." }, { "milestone": "M1", "currentLevel": "LOCAL", "status": "pass", "strongestEvidenceLevel": "LOCAL", "liveEvidence": "missing_or_blocked", "summary": "Local smoke is green; it is not DEV-LIVE." }, { "milestone": "M2", "currentLevel": "DEV-LIVE", "status": "blocked", "strongestEvidenceLevel": "DEV-LIVE", "liveEvidence": "pass", "summary": "Current public frontend/API route evidence is DEV-LIVE for route/front-end reachability only." }, { "milestone": "M3", "currentLevel": "BLOCKED", "status": "blocked", "strongestEvidenceLevel": "LOCAL", "liveEvidence": "missing_or_blocked", "summary": "DEV-LIVE hardware trusted loop is blocked; local/source shape is not acceptance." }, { "milestone": "M4", "currentLevel": "BLOCKED", "status": "blocked", "strongestEvidenceLevel": "DRY-RUN", "liveEvidence": "missing_or_blocked", "summary": "DEV-LIVE agent loop is blocked at DB live readiness; local smoke is not acceptance." }, { "milestone": "M5", "currentLevel": "BLOCKED", "status": "blocked", "strongestEvidenceLevel": "DRY-RUN", "liveEvidence": "missing_or_blocked", "summary": "Dry-run is green, but bounded DEV-LIVE MVP e2e is blocked." } ], "milestoneBlockerClassification": [ { "milestone": "M3", "status": "blocked", "currentLevel": "BLOCKED", "blockerClass": "direct-target-identity-gap", "dependency": "Two distinct live box-simu resources and two distinct gateway-simu identities are required before M3 can run.", "evidence": [ "operationId=not_observed", "traceId=not_observed", "auditId=not_observed", "evidenceId=not_observed", "runnerKubeconfigReadable=false", "d601PublicEndpointsReachable=true", "d601K3sUnavailable=false", "directTargetSource=kubernetes-endpointslices", "directTargetCounts={\"boxSimu\":2,\"gatewaySimu\":2,\"patchPanel\":1,\"distinctBoxResources\":1,\"distinctGatewayIdentities\":1}", "patchPanelM3Wiring=false" ], "nextRequired": "Fix DEV simulator instance identity so two box-simu pods report res_boxsimu_1/res_boxsimu_2 and two gateway-simu pods report distinct gateway identities.", "nonPromotionReason": "Public frontend, route, and artifact evidence do not prove the required hardware loop." }, { "milestone": "M4", "status": "blocked", "currentLevel": "BLOCKED", "blockerClass": "db-live-readiness", "dependency": "Cloud API /health/live must report DB ready=true, connected=true, and liveDbEvidence=true before live agent scheduling/evidence closure.", "evidence": [ "db.status=degraded", "db.ready=false", "db.connected=false", "db.liveDbEvidence=false" ], "nextRequired": "Repair DB live readiness and rerun the M4 live preflight without scheduling a DEV agent task before preconditions pass.", "nonPromotionReason": "Frontend revision and read-only route reachability do not prove DB-backed agent runtime readiness." }, { "milestone": "M5", "status": "blocked", "currentLevel": "BLOCKED", "blockerClass": "composite-db-m3-m4-live", "dependency": "M5 needs DB live readiness, M3 trusted-loop DEV evidence, M4 live preflight/evidence closure, and current source/artifact coverage.", "evidence": [ "M5 dry-run is green", "db.ready=false", "m3.live=false", "m4.live=false" ], "nextRequired": "After DB/M3/M4 blockers are cleared, run only the bounded DEV MVP live gate command with explicit DEV/non-PROD confirmations.", "nonPromotionReason": "No frontend, route-only, local, or dry-run evidence is allowed to stand in for bounded DEV-LIVE MVP e2e acceptance." } ], "milestones": [ { "id": "M0", "status": "pass", "highestVisibleLevel": "SOURCE", "liveEvidence": "missing_or_blocked", "evidenceCount": 1, "blockerCount": 0, "summary": "contract source is available; highest visible level is SOURCE; status is pass." }, { "id": "M1", "status": "pass", "highestVisibleLevel": "LOCAL", "liveEvidence": "missing_or_blocked", "evidenceCount": 1, "blockerCount": 0, "summary": "local smoke is available; highest visible level is LOCAL; status is pass." }, { "id": "M2", "status": "blocked", "highestVisibleLevel": "DEV-LIVE", "liveEvidence": "pass", "evidenceCount": 7, "blockerCount": 7, "summary": "deploy/runtime readiness is blocked before live DEV; highest visible level is DEV-LIVE; status is blocked." }, { "id": "M3", "status": "blocked", "highestVisibleLevel": "LOCAL", "liveEvidence": "missing_or_blocked", "evidenceCount": 3, "blockerCount": 5, "summary": "hardware loop has source/local shape but no live operation; highest visible level is LOCAL; status is blocked." }, { "id": "M4", "status": "blocked", "highestVisibleLevel": "DRY-RUN", "liveEvidence": "missing_or_blocked", "evidenceCount": 3, "blockerCount": 2, "summary": "agent loop has local smoke but live preflight is blocked; highest visible level is DRY-RUN; status is blocked." }, { "id": "M5", "status": "blocked", "highestVisibleLevel": "DRY-RUN", "liveEvidence": "missing_or_blocked", "evidenceCount": 2, "blockerCount": 15, "summary": "dry-run is green but live MVP gate is blocked; highest visible level is DRY-RUN; status is blocked." } ], "evidence": [ { "milestone": "M0", "issue": "pikasTech/HWLAB#31", "level": "SOURCE", "status": "pass", "category": "contract", "lifecycleState": "active", "sources": [ "docs/m0-contract-audit.md", "protocol/README.md", "protocol/evidence-chain.md", "protocol/schemas/evidence-record.schema.json", "protocol/examples/m0-contract/service-ids.json" ], "commands": [ "node scripts/validate-contract.mjs", "node scripts/validate-m0-contract.mjs", "node scripts/validate-evidence-chain.mjs" ], "summary": "Frozen service IDs, JSON-RPC, audit, topology, evidence, and DEV-only deploy contracts are source-ready." }, { "milestone": "M1", "issue": "pikasTech/HWLAB#7", "level": "LOCAL", "status": "pass", "category": "local-smoke", "lifecycleState": "active", "sources": [ "docs/m1-local-smoke.md", "fixtures/mvp/runtime.json", "scripts/m1-contract-smoke.mjs" ], "commands": [ "node scripts/m1-contract-smoke.mjs" ], "summary": "Local skeleton smoke covers cloud API, simulators, patch-panel routing, CLI dry-run boundary, and no DEV/PROD mutation." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#99", "taskId": "cloud-web-workbench-frontend", "lifecycleState": "active", "level": "DEV-LIVE", "status": "pass", "category": "frontend-dev-revision", "sources": [ "docs/dev-deploy-apply.md", "docs/cloud-web-workbench.md", "web/hwlab-cloud-web/index.html", "web/hwlab-cloud-web/styles.css" ], "commands": [ "node web/hwlab-cloud-web/scripts/check.mjs", "node scripts/dev-cloud-workbench-smoke.mjs --static" ], "evidence": [ "Cloud Web /health/live accepted revision 1e8805664970839b72be40c34636b08f6d18b131", "Cloud Workbench public browser endpoint is the active frontend route only", "Frontend load/revision evidence cannot satisfy DB, M3 hardware-loop, M4 agent-loop, or M5 MVP e2e acceptance" ], "summary": "#99/#108 Cloud Workbench revision 1e8805664970839b72be40c34636b08f6d18b131 is the latest accepted DEV frontend fact, but it is frontend-only evidence." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#34", "taskId": "dev-gate-preflight", "reportPath": "reports/dev-gate/dev-preflight-report.json", "commitId": "f64182b54fe6", "lifecycleState": "active", "level": "SOURCE", "status": "pass", "category": "deploy-manifest", "commands": [ "node --check scripts/dev-gate-preflight.mjs", "node --check scripts/src/dev-gate-preflight.mjs", "node --check scripts/src/registry-capabilities.mjs", "node --check scripts/refresh-artifact-catalog.mjs", "node scripts/dev-gate-preflight.mjs", "node --check scripts/validate-dev-gate-report.mjs", "node scripts/validate-dev-gate-report.mjs" ], "evidence": [ "source-contract-static=pass", "artifact catalog state=contract-skeleton", "catalog commit=c7de474" ], "summary": "Deploy manifests, FRP/master-edge contracts, and safety boundary are source-readable and scoped to hwlab-dev." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#33", "taskId": "dev-deploy-apply", "reportPath": "reports/dev-gate/dev-deploy-report.json", "commitId": "7e29522", "lifecycleState": "active", "level": "DRY-RUN", "status": "pass", "category": "deploy-apply", "commands": [ "node tools/hwlab-cli/bin/hwlab-cli.mjs test e2e --env dev --mvp --dry-run", "node scripts/dev-deploy-apply.mjs --dry-run --expect-blocked" ], "evidence": [ "artifact services checked: 13", "expected artifact commit: 7e29522", "namespace: hwlab-dev", "workloads planned: 13", "kubectl executor: /usr/local/bin/kubectl", "live health: pass", "template job replacements: 2" ], "summary": "DEV dry-run preflight passed." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#35", "taskId": "dev-artifact-publish", "reportPath": "reports/dev-gate/dev-artifacts.json", "commitId": "7e29522", "lifecycleState": "active", "level": "DRY-RUN", "status": "published", "category": "artifact-publish", "commands": [ "node --check scripts/dev-artifact-publish.mjs", "node --check scripts/src/dev-artifact-services.mjs", "node --check scripts/src/registry-capabilities.mjs", "node --check scripts/preflight-dev-base-image.mjs", "node --check scripts/src/dev-base-image-preflight.mjs", "node scripts/preflight-dev-base-image.mjs", "node scripts/dev-artifact-publish.mjs --preflight --no-report", "node --check scripts/validate-dev-gate-report.mjs", "node scripts/validate-dev-gate-report.mjs" ], "evidence": [ "services=13", "baseImagePreflight=ready", "published=13/13" ], "summary": "Artifact publish preflight exists but is blocked before any real image publish." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#23", "taskId": "m2-dev-deploy-smoke", "reportPath": "reports/dev-gate/dev-m2-deploy-smoke-active.json", "commitId": "8e89409dda5d", "lifecycleState": "active", "level": "DEV-LIVE", "status": "pass", "category": "public-entrypoints-read-only", "commands": [ "curl -fsS --max-time 10 http://74.48.78.17:16667/health", "curl -fsS --max-time 10 http://74.48.78.17:16667/health/live", "curl -fsS --max-time 10 http://74.48.78.17:16666/" ], "evidence": [ "http://74.48.78.17:16667/health -> HTTP 200 identity=hwlab-edge-proxy status=ok", "http://74.48.78.17:16667/health/live -> HTTP 200 identity=hwlab-cloud-api status=degraded", "http://74.48.78.17:16666/ -> HTTP 200 identity=HWLAB DEV MVP Gate status=ok" ], "summary": "Read-only probes prove the frozen public DEV entrypoints on :16666/:16667 are reachable; this is EDGE/ROUTE evidence only." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#36", "taskId": "dev-edge-health", "reportPath": "reports/dev-gate/dev-edge-health.json", "commitId": "c7de4745f491", "lifecycleState": "active", "level": "DEV-LIVE", "status": "blocker", "category": "edge-frp-contract", "commands": [ "node --check scripts/validate-dev-gate-report.mjs", "node scripts/validate-dev-gate-report.mjs", "node --check scripts/dev-edge-health-smoke.mjs", "node --check scripts/src/dev-edge-health-smoke-lib.mjs", "node --test scripts/src/dev-edge-health-smoke-lib.test.mjs", "node scripts/dev-edge-health-smoke.mjs --live --write-report" ], "evidence": [ "mode=live-read-only", "classification=app_health_blocker", "cloudApiDb=degraded" ], "summary": "Committed edge report proves read-only public HTTP on :16667 /health and /health/live; remaining edge report blocker is DB readiness, not route/frp reachability." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#46", "taskId": "d601-k3s-readonly-observability", "reportPath": "reports/d601-k3s-readonly-observability.json", "commitId": "unknown", "lifecycleState": "active", "level": "DEV-LIVE", "status": "blocked", "category": "d601-observability", "commands": [ "node --check scripts/d601-k3s-readonly-observability.mjs", "node --check scripts/src/d601-k3s-readonly-observability.mjs", "node scripts/d601-k3s-readonly-observability.mjs" ], "evidence": [ "runnerKubeconfigReadable=false", "runnerKubeconfigProbeExitCode=0", "runnerKubeconfigProbeStderr=empty", "d601PublicEndpointsReachable=true", "d601K3sUnavailable=false" ], "summary": "D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false." }, { "milestone": "M3", "issue": "pikasTech/HWLAB#38", "taskId": "dev-m3-hardware-loop", "reportPath": "reports/dev-gate/dev-m3-hardware-loop.json", "commitId": "c7de4745f491", "lifecycleState": "active", "level": "SOURCE", "status": "manifest-ready", "category": "hardware-loop-cardinality", "commands": [ "node scripts/validate-dev-m3-cardinality.mjs" ], "evidence": [ "deploy-skeleton-m3-cardinality=manifest-ready" ], "summary": "Static DEV manifest cardinality declares two box simulators, two gateway simulators, and one patch panel." }, { "milestone": "M3", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "commitId": "86d769525caf", "lifecycleState": "active", "level": "LOCAL", "status": "blocked", "category": "hardware-loop-local", "commands": [ "node scripts/m3-hardware-loop-smoke.mjs", "node scripts/dev-m3-hardware-loop-smoke.mjs --live --confirm-dev --confirmed-non-production" ], "evidence": [ "Local M3 hardware loop smoke passed", "Live DEV M3 smoke reached 16667 ingress and direct simulator/patch-panel Pod URLs", "Live DEV M3 blocked: patch-panel active DO1 -> DI1 connection missing" ], "summary": "Local M3 remains green, but active DEV-LIVE M3 is blocked by hardware loop topology." }, { "milestone": "M3", "issue": "pikasTech/HWLAB#38", "taskId": "dev-m3-hardware-loop", "reportPath": "reports/dev-gate/dev-m3-hardware-loop.json", "commitId": "c7de4745f491", "lifecycleState": "active", "level": "BLOCKED", "status": "not_run", "category": "hardware-loop-live", "commands": [ "node scripts/dev-m3-hardware-loop-smoke.mjs --live --confirm-dev --confirmed-non-production" ], "evidence": [ "operationId=not_observed", "traceId=not_observed", "auditId=not_observed", "evidenceId=not_observed" ], "summary": "No live DEV operation was attempted because read-only direct target checks did not prove the required patch-panel-owned M3 route. Blocker: DEV exposes two box-simu endpoints, but live identities are not the required distinct resources res_boxsimu_1 and res_boxsimu_2; observed resources=res_boxsimu_1." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "commitId": "0614202", "lifecycleState": "active", "level": "LOCAL", "status": "pass", "category": "agent-loop-local", "commands": [ "node scripts/m4-agent-loop-smoke.mjs" ], "evidence": [ "Local runtime skeleton smoke confirms create/start/trace/finish/cleanup coverage.", "Workspace isolation and explicit skills commit wiring are covered by fixture assertions." ], "summary": "Local contract smoke passes on the repo fixture." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "commitId": "0614202", "lifecycleState": "active", "level": "DRY-RUN", "status": "pass", "category": "agent-loop-dry-run", "commands": [ "node scripts/dev-m4-agent-loop-smoke.mjs --dry-run" ], "evidence": [ "hwlab-agent-mgr:session=agt_m4_agent_loop_01:created=queued:final=cleanup", "hwlab-agent-worker:session=wkr_agt_m4_agent_loop_01:status=cleanup", "workspace:vol_agt_m4_agent_loop_01:cleaned=true:existsAfterCleanup=false", "hwlab-agent-skills:commit=6509a35:version=v1", "trace:trc_agt_m4_agent_loop_01:events=5", "evidence:evi_agt_m4_agent_loop_01:kind=report", "cleanup:cln_agt_m4_agent_loop_01:removed=true" ], "summary": "Local dry-run covered agent manager, worker, workspace isolation, skills commit, trace, evidence, and cleanup without live DEV mutation." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "commitId": "0614202", "lifecycleState": "active", "level": "BLOCKED", "status": "blocked", "category": "agent-loop-live-preflight", "commands": [ "node scripts/dev-m4-agent-loop-smoke.mjs --live --confirm-dev --confirmed-non-production" ], "evidence": [ "k3s:namespace=hwlab-dev:read=true", "k3s:deploy/hwlab-agent-mgr:ready=1/1:available=True", "k3s:deploy/hwlab-agent-skills:ready=1/1:available=True", "k3s:svc/hwlab-agent-mgr:endpoints=1", "k3s:svc/hwlab-agent-skills:endpoints=1", "agent-mgr:/health/live:degraded", "agent-skills:/health/live:ok:cb35ada6860653b27269b0a57991184118cbf4b1", "worker-template:suspend=true:image=127.0.0.1:5000/hwlab/hwlab-agent-worker:cb35ada", "worker-job:server-dry-run=true:persisted=false", "skills-injection:commit=cb35ada:version=missing", "secret-rbac:get=yes:secretResourcesRead=false", "Public DEV API http://74.48.78.17:16667 health=200 live=200; frontend http://74.48.78.17:16666/=200.", "health:hwlab-edge-proxy:dev:ok", "live:hwlab-cloud-api:degraded:db-blocked" ], "summary": "Blocked at DB live readiness before scheduling a DEV agent task." }, { "milestone": "M5", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "commitId": "86d769525caf", "lifecycleState": "active", "level": "DRY-RUN", "status": "pass", "category": "mvp-e2e-dry-run", "commands": [ "node tools/hwlab-cli/bin/hwlab-cli.mjs health", "node tools/hwlab-cli/bin/hwlab-cli.mjs test e2e --env dev --mvp --dry-run", "node scripts/m5-mvp-e2e-dry-run.mjs" ], "evidence": [ "hwlab-cli health -> status: ok, environment: dev, endpoint: http://74.48.78.17:16667, projects: 2", "hwlab-cli dry-run -> 9 steps, 13 artifacts, 14 health contracts, 2 hardware operations, 2 evidence records, 0 network calls", "M5 MVP E2E dry-run passed: 9 steps, 13 artifacts, 14 health contracts, 2 hardware operations, 2 evidence records, 0 network calls" ], "summary": "The M5 orchestration dry-run is green, but it remains fixture-only and does not establish a live DEV gate." }, { "milestone": "M5", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "commitId": "86d769525caf", "lifecycleState": "active", "level": "BLOCKED", "status": "blocked", "category": "mvp-e2e-live", "commands": [ "curl -fsS --max-time 8 http://74.48.78.17:16666/", "curl -fsS --max-time 8 http://74.48.78.17:16667/health/live", "curl -fsS --max-time 8 http://74.48.78.17:16667/health", "HWLAB_DEV_BOX_SIMU_1_URL=http://10.42.0.200:7201 HWLAB_DEV_BOX_SIMU_2_URL=http://10.42.0.208:7201 HWLAB_DEV_GATEWAY_SIMU_1_URL=http://10.42.0.209:7101 HWLAB_DEV_GATEWAY_SIMU_2_URL=http://10.42.0.204:7101 HWLAB_DEV_PATCH_PANEL_URL=http://10.42.0.205:7301 node scripts/dev-m3-hardware-loop-smoke.mjs --live --confirm-dev --confirmed-non-production", "node scripts/dev-m4-agent-loop-smoke.mjs --live --confirm-dev --confirmed-non-production" ], "evidence": [ "http://74.48.78.17:16666/ -> HTTP 200 text/html, title=HWLAB DEV MVP Gate", "http://74.48.78.17:16667/health -> HTTP 200 serviceId=hwlab-edge-proxy status=ok commit=cb35ada6860653b27269b0a57991184118cbf4b1", "http://74.48.78.17:16667/health/live -> HTTP 200 serviceId=hwlab-cloud-api status=degraded db.ready=false db.connected=false db.connectionChecked=false", "dev-edge-health active report -> blocked by DB live readiness, while public 16667 TCP/HTTP and frp control/tunnel health are reachable", "dev-m3-hardware-loop active report -> blocked, classification=hardware loop, summary=patch-panel active DO1 -> DI1 connection missing", "dev-m4-agent-loop active report -> blocked, classification=DB live, summary=cloud-api /health/live reports DB degraded; connected=false; ready=false" ], "summary": "Public DEV route/frp is reachable on 16666/16667, but live MVP remains blocked by DB live readiness and the M3 hardware loop topology; no historical 6667 failure is counted as active evidence." } ], "levels": { "SOURCE": [ { "milestone": "M0", "issue": "pikasTech/HWLAB#31", "lifecycleState": "active", "status": "pass", "category": "contract", "summary": "Frozen service IDs, JSON-RPC, audit, topology, evidence, and DEV-only deploy contracts are source-ready." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#34", "taskId": "dev-gate-preflight", "lifecycleState": "active", "status": "pass", "category": "deploy-manifest", "reportPath": "reports/dev-gate/dev-preflight-report.json", "summary": "Deploy manifests, FRP/master-edge contracts, and safety boundary are source-readable and scoped to hwlab-dev." }, { "milestone": "M3", "issue": "pikasTech/HWLAB#38", "taskId": "dev-m3-hardware-loop", "lifecycleState": "active", "status": "manifest-ready", "category": "hardware-loop-cardinality", "reportPath": "reports/dev-gate/dev-m3-hardware-loop.json", "summary": "Static DEV manifest cardinality declares two box simulators, two gateway simulators, and one patch panel." } ], "LOCAL": [ { "milestone": "M1", "issue": "pikasTech/HWLAB#7", "lifecycleState": "active", "status": "pass", "category": "local-smoke", "summary": "Local skeleton smoke covers cloud API, simulators, patch-panel routing, CLI dry-run boundary, and no DEV/PROD mutation." }, { "milestone": "M3", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "lifecycleState": "active", "status": "blocked", "category": "hardware-loop-local", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "summary": "Local M3 remains green, but active DEV-LIVE M3 is blocked by hardware loop topology." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "lifecycleState": "active", "status": "pass", "category": "agent-loop-local", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "Local contract smoke passes on the repo fixture." } ], "DRY-RUN": [ { "milestone": "M2", "issue": "pikasTech/HWLAB#33", "taskId": "dev-deploy-apply", "lifecycleState": "active", "status": "pass", "category": "deploy-apply", "reportPath": "reports/dev-gate/dev-deploy-report.json", "summary": "DEV dry-run preflight passed." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#35", "taskId": "dev-artifact-publish", "lifecycleState": "active", "status": "published", "category": "artifact-publish", "reportPath": "reports/dev-gate/dev-artifacts.json", "summary": "Artifact publish preflight exists but is blocked before any real image publish." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "lifecycleState": "active", "status": "pass", "category": "agent-loop-dry-run", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "Local dry-run covered agent manager, worker, workspace isolation, skills commit, trace, evidence, and cleanup without live DEV mutation." }, { "milestone": "M5", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "lifecycleState": "active", "status": "pass", "category": "mvp-e2e-dry-run", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "summary": "The M5 orchestration dry-run is green, but it remains fixture-only and does not establish a live DEV gate." } ], "DEV-LIVE": [ { "milestone": "M2", "issue": "pikasTech/HWLAB#99", "taskId": "cloud-web-workbench-frontend", "lifecycleState": "active", "status": "pass", "category": "frontend-dev-revision", "summary": "#99/#108 Cloud Workbench revision 1e8805664970839b72be40c34636b08f6d18b131 is the latest accepted DEV frontend fact, but it is frontend-only evidence." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#23", "taskId": "m2-dev-deploy-smoke", "lifecycleState": "active", "status": "pass", "category": "public-entrypoints-read-only", "reportPath": "reports/dev-gate/dev-m2-deploy-smoke-active.json", "summary": "Read-only probes prove the frozen public DEV entrypoints on :16666/:16667 are reachable; this is EDGE/ROUTE evidence only." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#36", "taskId": "dev-edge-health", "lifecycleState": "active", "status": "blocker", "category": "edge-frp-contract", "reportPath": "reports/dev-gate/dev-edge-health.json", "summary": "Committed edge report proves read-only public HTTP on :16667 /health and /health/live; remaining edge report blocker is DB readiness, not route/frp reachability." }, { "milestone": "M2", "issue": "pikasTech/HWLAB#46", "taskId": "d601-k3s-readonly-observability", "lifecycleState": "active", "status": "blocked", "category": "d601-observability", "reportPath": "reports/d601-k3s-readonly-observability.json", "summary": "D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false." } ], "BLOCKED": [ { "milestone": "M3", "issue": "pikasTech/HWLAB#38", "taskId": "dev-m3-hardware-loop", "lifecycleState": "active", "status": "not_run", "category": "hardware-loop-live", "reportPath": "reports/dev-gate/dev-m3-hardware-loop.json", "summary": "No live DEV operation was attempted because read-only direct target checks did not prove the required patch-panel-owned M3 route. Blocker: DEV exposes two box-simu endpoints, but live identities are not the required distinct resources res_boxsimu_1 and res_boxsimu_2; observed resources=res_boxsimu_1." }, { "milestone": "M4", "issue": "pikasTech/HWLAB#37", "taskId": "dev-m4-agent-loop", "lifecycleState": "active", "status": "blocked", "category": "agent-loop-live-preflight", "reportPath": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "Blocked at DB live readiness before scheduling a DEV agent task." }, { "milestone": "M5", "issue": "pikasTech/HWLAB#39", "taskId": "dev-mvp-gate-report", "lifecycleState": "active", "status": "blocked", "category": "mvp-e2e-live", "reportPath": "reports/dev-gate/dev-mvp-gate-report.json", "summary": "Public DEV route/frp is reachable on 16666/16667, but live MVP remains blocked by DB live readiness and the M3 hardware loop topology; no historical 6667 failure is counted as active evidence." }, { "priority": "P1", "order": 3, "type": "runtime_blocker", "scope": "artifact-catalog", "sourceIssue": "pikasTech/HWLAB#34", "source": "reports/dev-gate/dev-preflight-report.json", "summary": "deploy/artifact-catalog.dev.json does not prove published artifacts for origin/main f64182b; ciPublished=false, registryVerified=false, not_published=13.", "nextTask": "Run the DEV artifact publish workflow, then record only real sha256 digests with `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`; if publish is still blocked, keep not_published via `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`." }, { "priority": "P1", "order": 3, "type": "contract_blocker", "scope": "artifact-source-commit", "sourceIssue": "pikasTech/HWLAB#34", "source": "reports/dev-gate/dev-preflight-report.json", "summary": "source commit origin/main f64182b is not covered by artifact source 7e29522; target changes since the artifact source touch artifact build inputs.", "nextTask": "Refresh without fake digests using `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`, or after a successful publish run `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`." }, { "priority": "P1", "order": 3, "type": "runtime_blocker", "scope": "dev-artifact-publish", "sourceIssue": "pikasTech/HWLAB#34", "source": "reports/dev-gate/dev-preflight-report.json", "summary": "reports/dev-gate/dev-artifacts.json does not prove all required HWLAB service artifacts for origin/main f64182b; current status is published with 13/13 required services published and source states resolved: 13 source-present, 0 intentionally-disabled.", "nextTask": "Complete DEV artifact publishing for every enabled required HWLAB service at the artifact source commit, or prove the target commit has no artifact build input changes; keep disabled services marked not_published with reasons." }, { "priority": "P1", "order": 4, "type": "observability_blocker", "scope": "runner-kubeconfig-readonly-gap", "sourceIssue": "pikasTech/HWLAB#46", "source": "reports/d601-k3s-readonly-observability.json", "summary": "The runner cannot read /etc/rancher/k3s/k3s.yaml; classify this as a runner permission/mount gap, not a D601 global outage. Alternate read-only cluster probes and public DEV endpoint probes are reported separately.", "nextTask": "Provide the approved read-only runner kubeconfig mount or document the intended alternate KUBECONFIG path, then rerun the read-only report." }, { "priority": "P1", "order": 5, "type": "runtime_blocker", "scope": "cloud-api-db", "sourceIssue": "pikasTech/HWLAB#36", "source": "reports/dev-gate/dev-edge-health.json", "summary": "DB endpoint DNS resolution failed from the cloud-api runtime" }, { "priority": "P1", "order": 5, "type": "network_blocker", "scope": "cloud-api-db", "sourceIssue": "pikasTech/HWLAB#34", "source": "reports/dev-gate/dev-preflight-report.json", "summary": "DB endpoint DNS resolution failed from the cloud-api runtime", "nextTask": "Deploy cloud-api DB runtime readiness probe and/or repair DEV DB connectivity, then rerun the read-only health smoke without reading or printing the DB secret value." }, { "priority": "P1", "order": 5, "type": "runtime_blocker", "scope": "cloud-api-db-health-gate", "sourceIssue": "pikasTech/HWLAB#34", "source": "reports/dev-gate/dev-preflight-report.json", "summary": "cloud-api DB runtime env is not ready; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE.", "nextTask": "Configure DEV hwlab-cloud-api with Secret hwlab-cloud-api-dev-db/database-url and HWLAB_CLOUD_DB_SSL_MODE=require, then rerun health/preflight without printing the secret value." }, { "priority": "P1", "order": 5, "type": "runtime_blocker", "scope": "db-live", "sourceIssue": "pikasTech/HWLAB#37", "source": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "cloud-api /health/live reports DB degraded; connected=false; ready=false." }, { "priority": "P1", "order": 5, "type": "runtime_blocker", "scope": "db-live", "sourceIssue": "pikasTech/HWLAB#39", "source": "reports/dev-gate/dev-mvp-gate-report.json", "summary": "cloud-api /health/live reports DB degraded; db.ready=false, db.connected=false, and live DB evidence is not established." }, { "priority": "P0", "order": 6, "type": "runtime_blocker", "scope": "m3-box-simu-identity", "sourceIssue": "pikasTech/HWLAB#38", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "summary": "DEV exposes two box-simu endpoints, but live identities are not the required distinct resources res_boxsimu_1 and res_boxsimu_2; observed resources=res_boxsimu_1." }, { "priority": "P0", "order": 6, "type": "runtime_blocker", "scope": "m3-gateway-simu-identity", "sourceIssue": "pikasTech/HWLAB#38", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "summary": "DEV exposes two gateway-simu endpoints, but live gateway identities are not distinct; observed identities=gateway-a:gws_gateway-a." }, { "priority": "P0", "order": 6, "type": "runtime_blocker", "scope": "m3-patch-panel-wiring", "sourceIssue": "pikasTech/HWLAB#38", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "summary": "DEV patch-panel is callable, but live wiring does not contain res_boxsimu_1:DO1 -> res_boxsimu_2:DI1; active=res_boxsim_alpha:uart0->res_boxsim_beta:uart0, res_boxsim_alpha:gpio0->res_boxsim_beta:gpio0; configured=res_boxsim_alpha:uart0->res_boxsim_beta:uart0, res_boxsim_alpha:gpio0->res_boxsim_beta:gpio0." }, { "priority": "P0", "order": 6, "type": "runtime_blocker", "scope": "m3-hardware-loop-runtime", "sourceIssue": "pikasTech/HWLAB#39", "source": "reports/dev-gate/dev-mvp-gate-report.json", "summary": "Live M3 smoke reached DEV simulators, but patch-panel active DO1 -> DI1 connection is missing." }, { "priority": "P3", "order": 99, "type": "agent_blocker", "scope": "code-agent-provider-secret", "sourceIssue": "pikasTech/HWLAB#36", "source": "reports/dev-gate/dev-edge-health.json", "summary": "Code Agent provider Secret hwlab-code-agent-provider/openai-api-key is not present as key-presence evidence; #143 real provider-backed chat remains blocked" }, { "priority": "P3", "order": 99, "type": "agent_blocker", "scope": "agent-mgr-health", "sourceIssue": "pikasTech/HWLAB#37", "source": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "hwlab-agent-mgr /health/live is degraded." }, { "priority": "P3", "order": 99, "type": "agent_blocker", "scope": "skills-commit-version-injection", "sourceIssue": "pikasTech/HWLAB#37", "source": "reports/dev-gate/dev-m4-agent-loop.json", "summary": "DEV skills injection is incomplete: missing hwlab-agent-skills.HWLAB_SKILLS_VERSION, worker-dry-run.HWLAB_SKILL_VERSION_FROM_DEV." } ] }, "blockers": [ { "id": "dev-gate-preflight:artifact-catalog", "priority": "P1", "type": "runtime_blocker", "scope": "artifact-catalog", "status": "open", "source": "reports/dev-gate/dev-preflight-report.json", "sourceIssue": "pikasTech/HWLAB#34", "summary": "deploy/artifact-catalog.dev.json does not prove published artifacts for origin/main f64182b; ciPublished=false, registryVerified=false, not_published=13.", "nextTask": "Run the DEV artifact publish workflow, then record only real sha256 digests with `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`; if publish is still blocked, keep not_published via `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`.", "unblockOrder": 3, "unblocks": [ "pikasTech/HWLAB#35", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests." }, { "id": "dev-gate-preflight:artifact-source-commit", "priority": "P1", "type": "contract_blocker", "scope": "artifact-source-commit", "status": "open", "source": "reports/dev-gate/dev-preflight-report.json", "sourceIssue": "pikasTech/HWLAB#34", "summary": "source commit origin/main f64182b is not covered by artifact source 7e29522; target changes since the artifact source touch artifact build inputs.", "nextTask": "Refresh without fake digests using `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`, or after a successful publish run `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`.", "unblockOrder": 3, "unblocks": [ "pikasTech/HWLAB#35", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests." }, { "id": "dev-gate-preflight:dev-artifact-publish", "priority": "P1", "type": "runtime_blocker", "scope": "dev-artifact-publish", "status": "open", "source": "reports/dev-gate/dev-preflight-report.json", "sourceIssue": "pikasTech/HWLAB#34", "summary": "reports/dev-gate/dev-artifacts.json does not prove all required HWLAB service artifacts for origin/main f64182b; current status is published with 13/13 required services published and source states resolved: 13 source-present, 0 intentionally-disabled.", "nextTask": "Complete DEV artifact publishing for every enabled required HWLAB service at the artifact source commit, or prove the target commit has no artifact build input changes; keep disabled services marked not_published with reasons.", "unblockOrder": 3, "unblocks": [ "pikasTech/HWLAB#35", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests." }, { "id": "d601-k3s-readonly-observability:runner-kubeconfig-readonly-gap", "priority": "P1", "type": "observability_blocker", "scope": "runner-kubeconfig-readonly-gap", "status": "open", "source": "reports/d601-k3s-readonly-observability.json", "sourceIssue": "pikasTech/HWLAB#46", "summary": "The runner cannot read /etc/rancher/k3s/k3s.yaml; classify this as a runner permission/mount gap, not a D601 global outage. Alternate read-only cluster probes and public DEV endpoint probes are reported separately.", "nextTask": "Provide the approved read-only runner kubeconfig mount or document the intended alternate KUBECONFIG path, then rerun the read-only report.", "unblockOrder": 4, "unblocks": [ "pikasTech/HWLAB#34", "pikasTech/HWLAB#33", "pikasTech/HWLAB#36", "pikasTech/HWLAB#38", "pikasTech/HWLAB#46", "pikasTech/HWLAB#64" ], "rationale": "Runner read-only observability must be repaired without treating the runner gap as proof that D601 k3s or public DEV endpoints are unavailable." }, { "id": "dev-edge-health:cloud-api-db", "priority": "P1", "type": "runtime_blocker", "scope": "cloud-api-db", "status": "open", "source": "reports/dev-gate/dev-edge-health.json", "sourceIssue": "pikasTech/HWLAB#36", "summary": "DB endpoint DNS resolution failed from the cloud-api runtime", "unblockOrder": 5, "unblocks": [ "pikasTech/HWLAB#34", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding." }, { "id": "dev-gate-preflight:cloud-api-db", "priority": "P1", "type": "network_blocker", "scope": "cloud-api-db", "status": "open", "source": "reports/dev-gate/dev-preflight-report.json", "sourceIssue": "pikasTech/HWLAB#34", "summary": "DB endpoint DNS resolution failed from the cloud-api runtime", "nextTask": "Deploy cloud-api DB runtime readiness probe and/or repair DEV DB connectivity, then rerun the read-only health smoke without reading or printing the DB secret value.", "unblockOrder": 5, "unblocks": [ "pikasTech/HWLAB#34", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding." }, { "id": "dev-gate-preflight:cloud-api-db-health-gate", "priority": "P1", "type": "runtime_blocker", "scope": "cloud-api-db-health-gate", "status": "open", "source": "reports/dev-gate/dev-preflight-report.json", "sourceIssue": "pikasTech/HWLAB#34", "summary": "cloud-api DB runtime env is not ready; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE.", "nextTask": "Configure DEV hwlab-cloud-api with Secret hwlab-cloud-api-dev-db/database-url and HWLAB_CLOUD_DB_SSL_MODE=require, then rerun health/preflight without printing the secret value.", "unblockOrder": 5, "unblocks": [ "pikasTech/HWLAB#34", "pikasTech/HWLAB#33", "pikasTech/HWLAB#39" ], "rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding." }, { "id": "dev-m4-agent-loop:db-live", "priority": "P1", "type": "runtime_blocker", "scope": "db-live", "status": "open", "source": "reports/dev-gate/dev-m4-agent-loop.json", "sourceIssue": "pikasTech/HWLAB#37", "summary": "cloud-api /health/live reports DB degraded; connected=false; ready=false.", "unblockOrder": 5, "unblocks": [ "pikasTech/HWLAB#37", "pikasTech/HWLAB#39" ], "rationale": "M4 and M5 cannot claim live agent or MVP evidence until cloud-api /health/live proves DB readiness with redacted live evidence." }, { "id": "dev-mvp-gate-report:db-live", "priority": "P1", "type": "runtime_blocker", "scope": "db-live", "status": "open", "source": "reports/dev-gate/dev-mvp-gate-report.json", "sourceIssue": "pikasTech/HWLAB#39", "summary": "cloud-api /health/live reports DB degraded; db.ready=false, db.connected=false, and live DB evidence is not established.", "unblockOrder": 5, "unblocks": [ "pikasTech/HWLAB#37", "pikasTech/HWLAB#39" ], "rationale": "M4 and M5 cannot claim live agent or MVP evidence until cloud-api /health/live proves DB readiness with redacted live evidence." }, { "id": "dev-m3-hardware-loop:m3-box-simu-identity", "priority": "P0", "type": "runtime_blocker", "scope": "m3-box-simu-identity", "status": "open", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "sourceIssue": "pikasTech/HWLAB#38", "summary": "DEV exposes two box-simu endpoints, but live identities are not the required distinct resources res_boxsimu_1 and res_boxsimu_2; observed resources=res_boxsimu_1.", "unblockOrder": 6, "unblocks": [ "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#64" ], "rationale": "M3 remains blocked until the real DEV hardware trusted loop proves DO1 -> patch-panel -> DI1 with operation, trace, audit, and evidence identifiers." }, { "id": "dev-m3-hardware-loop:m3-gateway-simu-identity", "priority": "P0", "type": "runtime_blocker", "scope": "m3-gateway-simu-identity", "status": "open", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "sourceIssue": "pikasTech/HWLAB#38", "summary": "DEV exposes two gateway-simu endpoints, but live gateway identities are not distinct; observed identities=gateway-a:gws_gateway-a.", "unblockOrder": 6, "unblocks": [ "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#64" ], "rationale": "M3 remains blocked until the real DEV hardware trusted loop proves DO1 -> patch-panel -> DI1 with operation, trace, audit, and evidence identifiers." }, { "id": "dev-m3-hardware-loop:m3-patch-panel-wiring", "priority": "P0", "type": "runtime_blocker", "scope": "m3-patch-panel-wiring", "status": "open", "source": "reports/dev-gate/dev-m3-hardware-loop.json", "sourceIssue": "pikasTech/HWLAB#38", "summary": "DEV patch-panel is callable, but live wiring does not contain res_boxsimu_1:DO1 -> res_boxsimu_2:DI1; active=res_boxsim_alpha:uart0->res_boxsim_beta:uart0, res_boxsim_alpha:gpio0->res_boxsim_beta:gpio0; configured=res_boxsim_alpha:uart0->res_boxsim_beta:uart0, res_boxsim_alpha:gpio0->res_boxsim_beta:gpio0.", "unblockOrder": 6, "unblocks": [ "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#64" ], "rationale": "M3 remains blocked until the real DEV hardware trusted loop proves DO1 -> patch-panel -> DI1 with operation, trace, audit, and evidence identifiers." }, { "id": "dev-mvp-gate-report:m3-hardware-loop-runtime", "priority": "P0", "type": "runtime_blocker", "scope": "m3-hardware-loop-runtime", "status": "open", "source": "reports/dev-gate/dev-mvp-gate-report.json", "sourceIssue": "pikasTech/HWLAB#39", "summary": "Live M3 smoke reached DEV simulators, but patch-panel active DO1 -> DI1 connection is missing.", "unblockOrder": 6, "unblocks": [ "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#64" ], "rationale": "M3 remains blocked until the real DEV hardware trusted loop proves DO1 -> patch-panel -> DI1 with operation, trace, audit, and evidence identifiers." }, { "id": "dev-edge-health:code-agent-provider-secret", "priority": "P3", "type": "agent_blocker", "scope": "code-agent-provider-secret", "status": "open", "source": "reports/dev-gate/dev-edge-health.json", "sourceIssue": "pikasTech/HWLAB#36", "summary": "Code Agent provider Secret hwlab-code-agent-provider/openai-api-key is not present as key-presence evidence; #143 real provider-backed chat remains blocked", "unblockOrder": 99, "unblocks": [ "pikasTech/HWLAB#39" ], "rationale": "Residual blocker that must be classified before claiming a green DEV gate." }, { "id": "dev-m4-agent-loop:agent-mgr-health", "priority": "P3", "type": "agent_blocker", "scope": "agent-mgr-health", "status": "open", "source": "reports/dev-gate/dev-m4-agent-loop.json", "sourceIssue": "pikasTech/HWLAB#37", "summary": "hwlab-agent-mgr /health/live is degraded.", "unblockOrder": 99, "unblocks": [ "pikasTech/HWLAB#39" ], "rationale": "Residual blocker that must be classified before claiming a green DEV gate." }, { "id": "dev-m4-agent-loop:skills-commit-version-injection", "priority": "P3", "type": "agent_blocker", "scope": "skills-commit-version-injection", "status": "open", "source": "reports/dev-gate/dev-m4-agent-loop.json", "sourceIssue": "pikasTech/HWLAB#37", "summary": "DEV skills injection is incomplete: missing hwlab-agent-skills.HWLAB_SKILLS_VERSION, worker-dry-run.HWLAB_SKILL_VERSION_FROM_DEV.", "unblockOrder": 99, "unblocks": [ "pikasTech/HWLAB#39" ], "rationale": "Residual blocker that must be classified before claiming a green DEV gate." } ], "nextSteps": [ { "order": 1, "blockerOrder": 3, "priority": "P1", "scopes": [ "artifact-catalog", "artifact-source-commit", "dev-artifact-publish" ], "sourceIssues": [ "pikasTech/HWLAB#33", "pikasTech/HWLAB#34", "pikasTech/HWLAB#35", "pikasTech/HWLAB#39" ], "rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests.", "action": "Run the DEV artifact publish workflow, then record only real sha256 digests with `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`; if publish is still blocked, keep not_published via `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`.", "evidenceRequired": "Artifact publish report with ciPublished=true, registryVerified=true, and sha256 digest for each frozen service ID." }, { "order": 2, "blockerOrder": 4, "priority": "P1", "scopes": [ "runner-kubeconfig-readonly-gap" ], "sourceIssues": [ "pikasTech/HWLAB#33", "pikasTech/HWLAB#34", "pikasTech/HWLAB#36", "pikasTech/HWLAB#38", "pikasTech/HWLAB#46", "pikasTech/HWLAB#64" ], "rationale": "Runner read-only observability must be repaired without treating the runner gap as proof that D601 k3s or public DEV endpoints are unavailable.", "action": "Provide the approved read-only runner kubeconfig mount or document the intended alternate KUBECONFIG path, then rerun the read-only report.", "evidenceRequired": "Read-only report with runnerKubeconfigReadable, runnerKubeconfigProbeExitCode/stderr, d601PublicEndpointsReachable, and d601K3sUnavailable recorded separately, plus direct M3 service target discovery before any DO write." }, { "order": 3, "blockerOrder": 5, "priority": "P1", "scopes": [ "cloud-api-db", "cloud-api-db-health-gate", "db-live" ], "sourceIssues": [ "pikasTech/HWLAB#33", "pikasTech/HWLAB#34", "pikasTech/HWLAB#36", "pikasTech/HWLAB#37", "pikasTech/HWLAB#39" ], "rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding.", "action": "Deploy cloud-api DB runtime readiness probe and/or repair DEV DB connectivity, then rerun the read-only health smoke without reading or printing the DB secret value.", "evidenceRequired": "Cloud API health/live output showing DB env ready and redacted secret references, without secret material." }, { "order": 4, "blockerOrder": 6, "priority": "P0", "scopes": [ "m3-box-simu-identity", "m3-gateway-simu-identity", "m3-patch-panel-wiring", "m3-hardware-loop-runtime" ], "sourceIssues": [ "pikasTech/HWLAB#38", "pikasTech/HWLAB#39", "pikasTech/HWLAB#64" ], "rationale": "M3 remains blocked until the real DEV hardware trusted loop proves DO1 -> patch-panel -> DI1 with operation, trace, audit, and evidence identifiers.", "action": "Fix DEV box-simu instance identity so direct endpoints expose distinct res_boxsimu_1 and res_boxsimu_2 resources.", "evidenceRequired": "Read-only direct box-simu /health/live and /status output showing distinct res_boxsimu_1 and res_boxsimu_2 resources." }, { "order": 5, "blockerOrder": 99, "priority": "P3", "scopes": [ "code-agent-provider-secret", "agent-mgr-health", "skills-commit-version-injection" ], "sourceIssues": [ "pikasTech/HWLAB#36", "pikasTech/HWLAB#37", "pikasTech/HWLAB#39" ], "rationale": "Residual blocker that must be classified before claiming a green DEV gate.", "action": "Resolve the blocker and attach source/local/dry-run/DEV-live evidence at the correct level.", "evidenceRequired": "A committed report with the exact evidence level and command used." } ], "validationCommands": [ "node --check scripts/dev-evidence-blocker-aggregator.mjs", "node --check scripts/src/dev-evidence-blocker-aggregator.mjs", "node scripts/dev-evidence-blocker-aggregator.mjs --check", "node scripts/dev-evidence-blocker-aggregator.mjs --markdown", "node --check scripts/validate-dev-gate-report.mjs", "node scripts/validate-dev-gate-report.mjs" ] }