357a68bb95
Refs #49 Merged by commander after reviewing Code Queue task codex_1779422762669_1. Adds redacted DB readiness layering and refreshes DEV endpoint/report evidence. Follow-up: deploy/verify the new readiness probe in DEV via standard image CI/CD.
1263 lines
51 KiB
JSON
1263 lines
51 KiB
JSON
{
|
|
"$schema": "https://hwlab.pikastech.local/schemas/dev-m5-gate-aggregator-v2.schema.json",
|
|
"$id": "https://hwlab.pikastech.local/reports/dev-gate/dev-m5-gate-aggregator-v2.json",
|
|
"reportVersion": "v2",
|
|
"reportKind": "dev-m5-gate-aggregator",
|
|
"issue": "pikasTech/HWLAB#58",
|
|
"supports": [
|
|
"pikasTech/HWLAB#7",
|
|
"pikasTech/HWLAB#9",
|
|
"pikasTech/HWLAB#31",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#39",
|
|
"pikasTech/HWLAB#46"
|
|
],
|
|
"generatedAt": "2026-05-21T18:27:07.237Z",
|
|
"generatedFromCommit": "1e9591a6611e",
|
|
"environment": "dev",
|
|
"endpoint": "http://74.48.78.17:16667",
|
|
"devOnly": true,
|
|
"prodDisabled": true,
|
|
"safety": {
|
|
"reportOnly": true,
|
|
"noDeploy": true,
|
|
"noProd": true,
|
|
"noSecretRead": true,
|
|
"noRuntimeRestart": true,
|
|
"noLiveProbe": true,
|
|
"noHeavyE2E": true,
|
|
"noUniDeskRuntimeSubstitute": true
|
|
},
|
|
"sourceReports": {
|
|
"devPreflight": {
|
|
"path": "reports/dev-gate/dev-preflight-report.json",
|
|
"issue": "pikasTech/HWLAB#34",
|
|
"taskId": "dev-gate-preflight",
|
|
"status": "blocked",
|
|
"commitId": "1a2efd4915b2"
|
|
},
|
|
"devDeploy": {
|
|
"path": "reports/dev-gate/dev-deploy-report.json",
|
|
"issue": "pikasTech/HWLAB#33",
|
|
"taskId": "dev-deploy-apply",
|
|
"status": "blocked",
|
|
"commitId": "9b47ebe49f70"
|
|
},
|
|
"devArtifacts": {
|
|
"path": "reports/dev-gate/dev-artifacts.json",
|
|
"issue": "pikasTech/HWLAB#35",
|
|
"taskId": "dev-artifact-publish",
|
|
"status": "blocked",
|
|
"commitId": "7e0ccb0"
|
|
},
|
|
"devEdgeHealth": {
|
|
"path": "reports/dev-gate/dev-edge-health.json",
|
|
"issue": "pikasTech/HWLAB#36",
|
|
"taskId": "dev-edge-health",
|
|
"status": "not_run",
|
|
"commitId": "9b47ebe49f70"
|
|
},
|
|
"devM3Hardware": {
|
|
"path": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"issue": "pikasTech/HWLAB#38",
|
|
"taskId": "dev-m3-hardware-loop",
|
|
"status": "blocked",
|
|
"commitId": "70bb9168ead2"
|
|
},
|
|
"devM4Agent": {
|
|
"path": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"status": "blocked",
|
|
"commitId": "e9e71a7"
|
|
},
|
|
"devM5Gate": {
|
|
"path": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"status": "blocked",
|
|
"commitId": "6eb4c199b0c6"
|
|
},
|
|
"d601Observability": {
|
|
"path": "reports/d601-k3s-readonly-observability.json",
|
|
"issue": "pikasTech/HWLAB#46",
|
|
"taskId": "d601-k3s-readonly-observability",
|
|
"status": "blocked",
|
|
"commitId": "unknown"
|
|
}
|
|
},
|
|
"overall": {
|
|
"status": "blocked",
|
|
"green": false,
|
|
"reason": "SOURCE, LOCAL, and DRY-RUN evidence exists, but DEV-LIVE acceptance is blocked by artifact, observability, DB, edge/frp, and loop evidence gaps."
|
|
},
|
|
"dod": {
|
|
"status": "blocked",
|
|
"green": false,
|
|
"checks": [
|
|
{
|
|
"id": "m0-source-contract",
|
|
"status": "pass",
|
|
"evidenceLevel": "SOURCE",
|
|
"summary": "M0 contract checks are source-level evidence only."
|
|
},
|
|
{
|
|
"id": "m1-local-smoke",
|
|
"status": "pass",
|
|
"evidenceLevel": "LOCAL",
|
|
"summary": "M1 local smoke is not a live DEV substitute."
|
|
},
|
|
{
|
|
"id": "artifact-publish-digests",
|
|
"status": "blocked",
|
|
"evidenceLevel": "BLOCKED",
|
|
"summary": "artifactState=contract-skeleton, ciPublished=false, registryVerified=false, sha256=0, not_published=13"
|
|
},
|
|
{
|
|
"id": "d601-k3s-observability",
|
|
"status": "blocked",
|
|
"evidenceLevel": "BLOCKED",
|
|
"summary": "D601 runner lacks kubectl/k3s/kubeconfig observability for hwlab-dev."
|
|
},
|
|
{
|
|
"id": "dev-edge-frp-6667",
|
|
"status": "blocked",
|
|
"evidenceLevel": "BLOCKED",
|
|
"summary": "No committed report proves live HTTP 200/JSON on http://74.48.78.17:16667."
|
|
},
|
|
{
|
|
"id": "cloud-api-db-ready",
|
|
"status": "blocked",
|
|
"evidenceLevel": "BLOCKED",
|
|
"summary": "Manifest-level DB env exists, but live DB health readiness is still blocked/missing."
|
|
},
|
|
{
|
|
"id": "m5-mvp-dev-live",
|
|
"status": "blocked",
|
|
"evidenceLevel": "BLOCKED",
|
|
"summary": "M5 dry-run passed; bounded DEV-LIVE MVP e2e has not passed."
|
|
}
|
|
]
|
|
},
|
|
"milestones": [
|
|
{
|
|
"id": "M0",
|
|
"status": "pass",
|
|
"highestVisibleLevel": "SOURCE",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 1,
|
|
"blockerCount": 0,
|
|
"summary": "contract source is available; highest visible level is SOURCE; status is pass."
|
|
},
|
|
{
|
|
"id": "M1",
|
|
"status": "pass",
|
|
"highestVisibleLevel": "LOCAL",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 1,
|
|
"blockerCount": 0,
|
|
"summary": "local smoke is available; highest visible level is LOCAL; status is pass."
|
|
},
|
|
{
|
|
"id": "M2",
|
|
"status": "blocked",
|
|
"highestVisibleLevel": "DRY-RUN",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 5,
|
|
"blockerCount": 18,
|
|
"summary": "deploy/runtime readiness is blocked before live DEV; highest visible level is DRY-RUN; status is blocked."
|
|
},
|
|
{
|
|
"id": "M3",
|
|
"status": "blocked",
|
|
"highestVisibleLevel": "LOCAL",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 3,
|
|
"blockerCount": 10,
|
|
"summary": "hardware loop has source/local shape but no live operation; highest visible level is LOCAL; status is blocked."
|
|
},
|
|
{
|
|
"id": "M4",
|
|
"status": "blocked",
|
|
"highestVisibleLevel": "LOCAL",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 3,
|
|
"blockerCount": 5,
|
|
"summary": "agent loop has local smoke but live preflight is blocked; highest visible level is LOCAL; status is blocked."
|
|
},
|
|
{
|
|
"id": "M5",
|
|
"status": "blocked",
|
|
"highestVisibleLevel": "DRY-RUN",
|
|
"liveEvidence": "missing_or_blocked",
|
|
"evidenceCount": 2,
|
|
"blockerCount": 12,
|
|
"summary": "dry-run is green but live MVP gate is blocked; highest visible level is DRY-RUN; status is blocked."
|
|
}
|
|
],
|
|
"evidence": [
|
|
{
|
|
"milestone": "M0",
|
|
"issue": "pikasTech/HWLAB#31",
|
|
"level": "SOURCE",
|
|
"status": "pass",
|
|
"category": "contract",
|
|
"sources": [
|
|
"docs/m0-contract-audit.md",
|
|
"protocol/README.md",
|
|
"protocol/evidence-chain.md",
|
|
"protocol/schemas/evidence-record.schema.json",
|
|
"protocol/examples/m0-contract/service-ids.json"
|
|
],
|
|
"commands": [
|
|
"node scripts/validate-contract.mjs",
|
|
"node scripts/validate-m0-contract.mjs",
|
|
"node scripts/validate-evidence-chain.mjs"
|
|
],
|
|
"summary": "Frozen service IDs, JSON-RPC, audit, topology, evidence, and DEV-only deploy contracts are source-ready."
|
|
},
|
|
{
|
|
"milestone": "M1",
|
|
"issue": "pikasTech/HWLAB#7",
|
|
"level": "LOCAL",
|
|
"status": "pass",
|
|
"category": "local-smoke",
|
|
"sources": [
|
|
"docs/m1-local-smoke.md",
|
|
"fixtures/mvp/runtime.json",
|
|
"scripts/m1-contract-smoke.mjs"
|
|
],
|
|
"commands": [
|
|
"node scripts/m1-contract-smoke.mjs"
|
|
],
|
|
"summary": "Local skeleton smoke covers cloud API, simulators, patch-panel routing, CLI dry-run boundary, and no DEV/PROD mutation."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#34",
|
|
"taskId": "dev-gate-preflight",
|
|
"reportPath": "reports/dev-gate/dev-preflight-report.json",
|
|
"commitId": "1a2efd4915b2",
|
|
"level": "SOURCE",
|
|
"status": "pass",
|
|
"category": "deploy-manifest",
|
|
"commands": [
|
|
"node --check scripts/dev-gate-preflight.mjs",
|
|
"node --check scripts/src/dev-gate-preflight.mjs",
|
|
"node --check scripts/refresh-artifact-catalog.mjs",
|
|
"node scripts/dev-gate-preflight.mjs",
|
|
"node --check scripts/validate-dev-gate-report.mjs",
|
|
"node scripts/validate-dev-gate-report.mjs"
|
|
],
|
|
"evidence": [
|
|
"source-contract-static=pass",
|
|
"artifact catalog state=contract-skeleton",
|
|
"catalog commit=1a2efd4"
|
|
],
|
|
"summary": "Deploy manifests, FRP/master-edge contracts, and safety boundary are source-readable and scoped to hwlab-dev."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#33",
|
|
"taskId": "dev-deploy-apply",
|
|
"reportPath": "reports/dev-gate/dev-deploy-report.json",
|
|
"commitId": "9b47ebe49f70",
|
|
"level": "DRY-RUN",
|
|
"status": "blocked",
|
|
"category": "deploy-apply",
|
|
"commands": [
|
|
"node tools/hwlab-cli/bin/hwlab-cli.mjs test e2e --env dev --mvp --dry-run",
|
|
"node scripts/dev-deploy-apply.mjs --dry-run --expect-blocked"
|
|
],
|
|
"evidence": [
|
|
"artifact services checked: 13",
|
|
"expected artifact commit: 24eb3bf",
|
|
"namespace: hwlab-dev",
|
|
"workloads planned: 13",
|
|
"kubectl executor: missing",
|
|
"live health: not_run"
|
|
],
|
|
"summary": "DEV apply is blocked before mutation."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#35",
|
|
"taskId": "dev-artifact-publish",
|
|
"reportPath": "reports/dev-gate/dev-artifacts.json",
|
|
"commitId": "7e0ccb0",
|
|
"level": "DRY-RUN",
|
|
"status": "blocked",
|
|
"category": "artifact-publish",
|
|
"commands": [
|
|
"node --check scripts/dev-artifact-publish.mjs",
|
|
"node --check scripts/preflight-dev-base-image.mjs",
|
|
"node --check scripts/src/dev-base-image-preflight.mjs",
|
|
"node scripts/preflight-dev-base-image.mjs",
|
|
"node scripts/dev-artifact-publish.mjs --preflight --no-report",
|
|
"node --check scripts/validate-dev-gate-report.mjs",
|
|
"node scripts/validate-dev-gate-report.mjs"
|
|
],
|
|
"evidence": [
|
|
"services=13",
|
|
"baseImagePreflight=blocked",
|
|
"published=0/13"
|
|
],
|
|
"summary": "Artifact publish preflight exists but is blocked before any real image publish."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#36",
|
|
"taskId": "dev-edge-health",
|
|
"reportPath": "reports/dev-gate/dev-edge-health.json",
|
|
"commitId": "9b47ebe49f70",
|
|
"level": "SOURCE",
|
|
"status": "not_run",
|
|
"category": "edge-frp-contract",
|
|
"commands": [
|
|
"node --check scripts/validate-dev-gate-report.mjs",
|
|
"node scripts/validate-dev-gate-report.mjs",
|
|
"node --check scripts/dev-edge-health-smoke.mjs",
|
|
"node --check scripts/src/dev-edge-health-smoke-lib.mjs",
|
|
"node scripts/dev-edge-health-smoke.mjs --live --write-report"
|
|
],
|
|
"evidence": [
|
|
"mode=contract-only",
|
|
"classification=not_run",
|
|
"cloudApiDb=ready"
|
|
],
|
|
"summary": "Committed edge report is contract-only/not-run; it must not be counted as DEV-LIVE."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#46",
|
|
"taskId": "d601-k3s-readonly-observability",
|
|
"reportPath": "reports/d601-k3s-readonly-observability.json",
|
|
"commitId": "unknown",
|
|
"level": "BLOCKED",
|
|
"status": "blocked",
|
|
"category": "d601-observability",
|
|
"commands": [
|
|
"node --check scripts/d601-k3s-readonly-observability.mjs",
|
|
"node --check scripts/src/d601-k3s-readonly-observability.mjs",
|
|
"node scripts/d601-k3s-readonly-observability.mjs"
|
|
],
|
|
"evidence": [
|
|
"kubectl=missing",
|
|
"k3s=missing",
|
|
"clusterReadable=no"
|
|
],
|
|
"summary": "D601 k3s observability is blocked; cluster state has not been read."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#38",
|
|
"taskId": "dev-m3-hardware-loop",
|
|
"reportPath": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"commitId": "70bb9168ead2",
|
|
"level": "SOURCE",
|
|
"status": "manifest-ready",
|
|
"category": "hardware-loop-cardinality",
|
|
"commands": [
|
|
"node scripts/validate-dev-m3-cardinality.mjs"
|
|
],
|
|
"evidence": [
|
|
"deploy-skeleton-m3-cardinality=manifest-ready"
|
|
],
|
|
"summary": "Static DEV manifest cardinality declares two box simulators, two gateway simulators, and one patch panel."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"commitId": "6eb4c199b0c6",
|
|
"level": "LOCAL",
|
|
"status": "pass",
|
|
"category": "hardware-loop-local",
|
|
"commands": [
|
|
"node scripts/m3-hardware-loop-smoke.mjs"
|
|
],
|
|
"evidence": [
|
|
"M3 hardware loop smoke passed",
|
|
"topology: 2 box simulators, 2 gateway simulators, 1 patch panel",
|
|
"wiring: box-simu-1 DO1 -> box-simu-2 DI1 via hwlab-patch-panel"
|
|
],
|
|
"summary": "The local hardware trusted loop smoke passes."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#38",
|
|
"taskId": "dev-m3-hardware-loop",
|
|
"reportPath": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"commitId": "70bb9168ead2",
|
|
"level": "BLOCKED",
|
|
"status": "not_run",
|
|
"category": "hardware-loop-live",
|
|
"commands": [
|
|
"node scripts/dev-m3-hardware-loop-smoke.mjs --live --confirm-dev --confirmed-non-production"
|
|
],
|
|
"evidence": [
|
|
"operationId=not_observed",
|
|
"traceId=not_observed",
|
|
"auditId=not_observed",
|
|
"evidenceId=not_observed"
|
|
],
|
|
"summary": "No live do.write -> di.read operation was attempted because DEV ingress is blocked."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"commitId": "e9e71a7",
|
|
"level": "LOCAL",
|
|
"status": "pass",
|
|
"category": "agent-loop-local",
|
|
"commands": [
|
|
"node scripts/m4-agent-loop-smoke.mjs"
|
|
],
|
|
"evidence": [
|
|
"Local runtime skeleton smoke confirms create/start/trace/finish/cleanup coverage.",
|
|
"Workspace isolation and explicit skills commit wiring are covered by fixture assertions."
|
|
],
|
|
"summary": "Local contract smoke passes on the repo fixture."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"commitId": "e9e71a7",
|
|
"level": "DRY-RUN",
|
|
"status": "not_run",
|
|
"category": "agent-loop-dry-run",
|
|
"commands": [
|
|
"node scripts/dev-m4-agent-loop-smoke.mjs --dry-run"
|
|
],
|
|
"evidence": [
|
|
"No dry-run output is attached to the live preflight report."
|
|
],
|
|
"summary": "The live preflight report does not attempt a dry-run agent run."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"commitId": "e9e71a7",
|
|
"level": "BLOCKED",
|
|
"status": "blocked",
|
|
"category": "agent-loop-live-preflight",
|
|
"commands": [
|
|
"node scripts/dev-m4-agent-loop-smoke.mjs --live --confirm-dev --confirmed-non-production"
|
|
],
|
|
"evidence": [
|
|
"No live DEV observation was recorded."
|
|
],
|
|
"summary": "Blocked before agent scheduling because http://74.48.78.17:16667 is unreachable from this runner."
|
|
},
|
|
{
|
|
"milestone": "M5",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"commitId": "6eb4c199b0c6",
|
|
"level": "DRY-RUN",
|
|
"status": "pass",
|
|
"category": "mvp-e2e-dry-run",
|
|
"commands": [
|
|
"node tools/hwlab-cli/bin/hwlab-cli.mjs health",
|
|
"node tools/hwlab-cli/bin/hwlab-cli.mjs test e2e --env dev --mvp --dry-run",
|
|
"node scripts/m5-mvp-e2e-dry-run.mjs"
|
|
],
|
|
"evidence": [
|
|
"hwlab-cli health -> status: ok, environment: dev, endpoint: http://74.48.78.17:16667, projects: 2",
|
|
"hwlab-cli dry-run -> 9 steps, 13 artifacts, 14 health contracts, 2 hardware operations, 2 evidence records, 0 network calls",
|
|
"M5 MVP E2E dry-run passed: 9 steps, 13 artifacts, 14 health contracts, 2 hardware operations, 2 evidence records, 0 network calls"
|
|
],
|
|
"summary": "The M5 orchestration dry-run is green, but it remains fixture-only and does not establish a live DEV gate."
|
|
},
|
|
{
|
|
"milestone": "M5",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"commitId": "6eb4c199b0c6",
|
|
"level": "BLOCKED",
|
|
"status": "blocked",
|
|
"category": "mvp-e2e-live",
|
|
"commands": [
|
|
"curl -fsS --max-time 5 http://74.48.78.17:16667/health",
|
|
"curl -fsS --max-time 5 http://74.48.78.17:16667/live"
|
|
],
|
|
"evidence": [
|
|
"curl exit 7 for /health: could not connect to 74.48.78.17 port 6667",
|
|
"curl exit 7 for /live: could not connect to 74.48.78.17 port 6667"
|
|
],
|
|
"summary": "The frozen DEV endpoint is not reachable from this runner, so no live DEV gate can be claimed yet."
|
|
}
|
|
],
|
|
"levels": {
|
|
"SOURCE": [
|
|
{
|
|
"milestone": "M0",
|
|
"issue": "pikasTech/HWLAB#31",
|
|
"status": "pass",
|
|
"category": "contract",
|
|
"summary": "Frozen service IDs, JSON-RPC, audit, topology, evidence, and DEV-only deploy contracts are source-ready."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#34",
|
|
"taskId": "dev-gate-preflight",
|
|
"status": "pass",
|
|
"category": "deploy-manifest",
|
|
"reportPath": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "Deploy manifests, FRP/master-edge contracts, and safety boundary are source-readable and scoped to hwlab-dev."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#36",
|
|
"taskId": "dev-edge-health",
|
|
"status": "not_run",
|
|
"category": "edge-frp-contract",
|
|
"reportPath": "reports/dev-gate/dev-edge-health.json",
|
|
"summary": "Committed edge report is contract-only/not-run; it must not be counted as DEV-LIVE."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#38",
|
|
"taskId": "dev-m3-hardware-loop",
|
|
"status": "manifest-ready",
|
|
"category": "hardware-loop-cardinality",
|
|
"reportPath": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"summary": "Static DEV manifest cardinality declares two box simulators, two gateway simulators, and one patch panel."
|
|
}
|
|
],
|
|
"LOCAL": [
|
|
{
|
|
"milestone": "M1",
|
|
"issue": "pikasTech/HWLAB#7",
|
|
"status": "pass",
|
|
"category": "local-smoke",
|
|
"summary": "Local skeleton smoke covers cloud API, simulators, patch-panel routing, CLI dry-run boundary, and no DEV/PROD mutation."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"status": "pass",
|
|
"category": "hardware-loop-local",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"summary": "The local hardware trusted loop smoke passes."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"status": "pass",
|
|
"category": "agent-loop-local",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"summary": "Local contract smoke passes on the repo fixture."
|
|
}
|
|
],
|
|
"DRY-RUN": [
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#33",
|
|
"taskId": "dev-deploy-apply",
|
|
"status": "blocked",
|
|
"category": "deploy-apply",
|
|
"reportPath": "reports/dev-gate/dev-deploy-report.json",
|
|
"summary": "DEV apply is blocked before mutation."
|
|
},
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#35",
|
|
"taskId": "dev-artifact-publish",
|
|
"status": "blocked",
|
|
"category": "artifact-publish",
|
|
"reportPath": "reports/dev-gate/dev-artifacts.json",
|
|
"summary": "Artifact publish preflight exists but is blocked before any real image publish."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"status": "not_run",
|
|
"category": "agent-loop-dry-run",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"summary": "The live preflight report does not attempt a dry-run agent run."
|
|
},
|
|
{
|
|
"milestone": "M5",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"status": "pass",
|
|
"category": "mvp-e2e-dry-run",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"summary": "The M5 orchestration dry-run is green, but it remains fixture-only and does not establish a live DEV gate."
|
|
}
|
|
],
|
|
"DEV-LIVE": [],
|
|
"BLOCKED": [
|
|
{
|
|
"milestone": "M2",
|
|
"issue": "pikasTech/HWLAB#46",
|
|
"taskId": "d601-k3s-readonly-observability",
|
|
"status": "blocked",
|
|
"category": "d601-observability",
|
|
"reportPath": "reports/d601-k3s-readonly-observability.json",
|
|
"summary": "D601 k3s observability is blocked; cluster state has not been read."
|
|
},
|
|
{
|
|
"milestone": "M3",
|
|
"issue": "pikasTech/HWLAB#38",
|
|
"taskId": "dev-m3-hardware-loop",
|
|
"status": "not_run",
|
|
"category": "hardware-loop-live",
|
|
"reportPath": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"summary": "No live do.write -> di.read operation was attempted because DEV ingress is blocked."
|
|
},
|
|
{
|
|
"milestone": "M4",
|
|
"issue": "pikasTech/HWLAB#37",
|
|
"taskId": "dev-m4-agent-loop",
|
|
"status": "blocked",
|
|
"category": "agent-loop-live-preflight",
|
|
"reportPath": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"summary": "Blocked before agent scheduling because http://74.48.78.17:16667 is unreachable from this runner."
|
|
},
|
|
{
|
|
"milestone": "M5",
|
|
"issue": "pikasTech/HWLAB#39",
|
|
"taskId": "dev-mvp-gate-report",
|
|
"status": "blocked",
|
|
"category": "mvp-e2e-live",
|
|
"reportPath": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"summary": "The frozen DEV endpoint is not reachable from this runner, so no live DEV gate can be claimed yet."
|
|
},
|
|
{
|
|
"priority": "P0",
|
|
"order": 1,
|
|
"type": "environment_blocker",
|
|
"scope": "base-image",
|
|
"sourceIssue": "pikasTech/HWLAB#35",
|
|
"source": "reports/dev-gate/dev-artifacts.json",
|
|
"summary": "HWLAB_DEV_BASE_IMAGE is not set and no approved local DEV builder base image was found in the Docker image cache; expected node:20-bookworm-slim or 127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim.",
|
|
"nextTask": "Preload node:20-bookworm-slim into the D601 Docker cache, or tag it as 127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim. Set HWLAB_DEV_BASE_IMAGE=node:20-bookworm-slim or HWLAB_DEV_BASE_IMAGE=127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim when invoking artifact publish. Rerun this preflight and require status=ready before #35 artifact publish. Do not use UniDesk runtime, Code Queue runner, backend-core, provider-gateway, or microservice-proxy images as substitutes."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 3,
|
|
"type": "observability_blocker",
|
|
"scope": "artifact-publish",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"summary": "DEV artifact catalog has no CI publish, registry verification, or registry digests",
|
|
"nextTask": "Publish DEV images from the intended commit and update the catalog with registry digests and verification evidence."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 3,
|
|
"type": "observability_blocker",
|
|
"scope": "artifact-source-commit",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"summary": "deploy/catalog artifact commit 24eb3bf/24eb3bf does not match source 9b47ebe49f70",
|
|
"nextTask": "Regenerate deploy/deploy.json and deploy/artifact-catalog.dev.json for the source commit that will be promoted."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 3,
|
|
"type": "runtime_blocker",
|
|
"scope": "artifact-catalog",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "deploy/artifact-catalog.dev.json does not prove published artifacts for origin/main 1a2efd4; ciPublished=false, registryVerified=false, not_published=13.",
|
|
"nextTask": "Run the DEV artifact publish workflow, then record only real sha256 digests with `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`; if publish is still blocked, keep not_published via `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 3,
|
|
"type": "runtime_blocker",
|
|
"scope": "dev-artifact-publish",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "reports/dev-gate/dev-artifacts.json does not prove all HWLAB service artifacts for origin/main 1a2efd4; current status is blocked with 0/13 published.",
|
|
"nextTask": "Complete DEV artifact publishing for every frozen HWLAB service at the current origin/main commit and record immutable registry digests."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 3,
|
|
"type": "runtime_blocker",
|
|
"scope": "ghcr",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "This preflight could not verify GHCR manifests for the DEV catalog images without reading credentials.",
|
|
"nextTask": "Publish public DEV images or provide a non-secret registry evidence artifact with immutable digests for each HWLAB service."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 4,
|
|
"type": "environment_blocker",
|
|
"scope": "d601-k3s-client-binary",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"summary": "Neither kubectl nor k3s is installed in this runner PATH.",
|
|
"nextTask": "Install kubectl in the D601 Code Queue runner image, or mount an approved k3s kubectl client path for read-only hwlab-dev observation."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 4,
|
|
"type": "environment_blocker",
|
|
"scope": "d601-kubeconfig-path",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"summary": "No readable KUBECONFIG/default k3s kubeconfig path was found by metadata checks.",
|
|
"nextTask": "Mount a read-only kubeconfig for hwlab-dev, or document the approved k3s local kubeconfig path without exposing token material."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 4,
|
|
"type": "environment_blocker",
|
|
"scope": "d601-maintenance-ssh-bridge",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"summary": "No SSH maintenance bridge was detected from ssh binary plus known environment variables or ~/.ssh/config metadata.",
|
|
"nextTask": "Provide a documented read-only maintenance bridge variable or config path if kubectl cannot be mounted directly in the runner."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 4,
|
|
"type": "environment_blocker",
|
|
"scope": "kubectl",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"summary": "kubectl is not installed in the runner",
|
|
"nextTask": "Provide a kubectl client configured for the D601 DEV k3s context without exposing token or secret values."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 4,
|
|
"type": "environment_blocker",
|
|
"scope": "d601-k3s",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "D601 runner lacks kubectl and no default kubeconfig was used by this preflight.",
|
|
"nextTask": "Provide a read-only kubectl/kubeconfig path for the real D601 hwlab-dev k3s cluster, then rerun this preflight."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 5,
|
|
"type": "runtime_blocker",
|
|
"scope": "cloud-api-db",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"summary": "cloud-api health reports DB config blocked; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE",
|
|
"nextTask": "Configure and verify the DEV cloud-api DB env readiness through health output, without reading secret values."
|
|
},
|
|
{
|
|
"priority": "P1",
|
|
"order": 5,
|
|
"type": "runtime_blocker",
|
|
"scope": "cloud-api-db-health-gate",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "cloud-api DB runtime env is not ready; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE.",
|
|
"nextTask": "Configure DEV hwlab-cloud-api with Secret hwlab-cloud-api-dev-db/database-url and HWLAB_CLOUD_DB_SSL_MODE=require, then rerun health/preflight without printing the secret value."
|
|
},
|
|
{
|
|
"priority": "P2",
|
|
"order": 6,
|
|
"type": "network_blocker",
|
|
"scope": "dev-edge",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "http://74.48.78.17:16667/health/live is not reachable from this runner.",
|
|
"nextTask": "Bring up or repair the D601-to-master frp route and hwlab-edge-proxy, then rerun the health probe."
|
|
},
|
|
{
|
|
"priority": "P2",
|
|
"order": 6,
|
|
"type": "network_blocker",
|
|
"scope": "dev-edge-health",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"summary": "live network probes require --live",
|
|
"nextTask": "Repair the master frps/public DEV edge route and rerun the read-only DEV edge health smoke before real deployment."
|
|
},
|
|
{
|
|
"priority": "P2",
|
|
"order": 6,
|
|
"type": "network_blocker",
|
|
"scope": "dev-ingress-health",
|
|
"sourceIssue": "pikasTech/HWLAB#38",
|
|
"source": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"summary": "Blocked at the #33 DEV runtime readiness condition: public DEV ingress does not accept HWLAB health requests, so #36/M3 hardware-loop checks were not reached."
|
|
},
|
|
{
|
|
"priority": "P2",
|
|
"order": 6,
|
|
"type": "network_blocker",
|
|
"scope": "devPreconditions",
|
|
"sourceIssue": "pikasTech/HWLAB#37",
|
|
"source": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"summary": "connect ECONNREFUSED 74.48.78.17:16667"
|
|
},
|
|
{
|
|
"priority": "P2",
|
|
"order": 6,
|
|
"type": "network_blocker",
|
|
"scope": "devPreconditions",
|
|
"sourceIssue": "pikasTech/HWLAB#39",
|
|
"source": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"summary": "http://74.48.78.17:16667/health and /live both fail with curl exit 7; live DEV ingress evidence is missing."
|
|
}
|
|
]
|
|
},
|
|
"blockers": [
|
|
{
|
|
"id": "dev-artifact-publish:base-image",
|
|
"priority": "P0",
|
|
"type": "environment_blocker",
|
|
"scope": "base-image",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-artifacts.json",
|
|
"sourceIssue": "pikasTech/HWLAB#35",
|
|
"summary": "HWLAB_DEV_BASE_IMAGE is not set and no approved local DEV builder base image was found in the Docker image cache; expected node:20-bookworm-slim or 127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim.",
|
|
"nextTask": "Preload node:20-bookworm-slim into the D601 Docker cache, or tag it as 127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim. Set HWLAB_DEV_BASE_IMAGE=node:20-bookworm-slim or HWLAB_DEV_BASE_IMAGE=127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim when invoking artifact publish. Rerun this preflight and require status=ready before #35 artifact publish. Do not use UniDesk runtime, Code Queue runner, backend-core, provider-gateway, or microservice-proxy images as substitutes.",
|
|
"unblockOrder": 1,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33"
|
|
],
|
|
"rationale": "Artifact publishing cannot start until an approved Node 20 DEV builder base image is available."
|
|
},
|
|
{
|
|
"id": "dev-deploy-apply:artifact-publish",
|
|
"priority": "P1",
|
|
"type": "observability_blocker",
|
|
"scope": "artifact-publish",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"summary": "DEV artifact catalog has no CI publish, registry verification, or registry digests",
|
|
"nextTask": "Publish DEV images from the intended commit and update the catalog with registry digests and verification evidence.",
|
|
"unblockOrder": 3,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests."
|
|
},
|
|
{
|
|
"id": "dev-deploy-apply:artifact-source-commit",
|
|
"priority": "P1",
|
|
"type": "observability_blocker",
|
|
"scope": "artifact-source-commit",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"summary": "deploy/catalog artifact commit 24eb3bf/24eb3bf does not match source 9b47ebe49f70",
|
|
"nextTask": "Regenerate deploy/deploy.json and deploy/artifact-catalog.dev.json for the source commit that will be promoted.",
|
|
"unblockOrder": 3,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:artifact-catalog",
|
|
"priority": "P1",
|
|
"type": "runtime_blocker",
|
|
"scope": "artifact-catalog",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "deploy/artifact-catalog.dev.json does not prove published artifacts for origin/main 1a2efd4; ciPublished=false, registryVerified=false, not_published=13.",
|
|
"nextTask": "Run the DEV artifact publish workflow, then record only real sha256 digests with `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json`; if publish is still blocked, keep not_published via `node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked`.",
|
|
"unblockOrder": 3,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:dev-artifact-publish",
|
|
"priority": "P1",
|
|
"type": "runtime_blocker",
|
|
"scope": "dev-artifact-publish",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "reports/dev-gate/dev-artifacts.json does not prove all HWLAB service artifacts for origin/main 1a2efd4; current status is blocked with 0/13 published.",
|
|
"nextTask": "Complete DEV artifact publishing for every frozen HWLAB service at the current origin/main commit and record immutable registry digests.",
|
|
"unblockOrder": 3,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:ghcr",
|
|
"priority": "P1",
|
|
"type": "runtime_blocker",
|
|
"scope": "ghcr",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "This preflight could not verify GHCR manifests for the DEV catalog images without reading credentials.",
|
|
"nextTask": "Publish public DEV images or provide a non-secret registry evidence artifact with immutable digests for each HWLAB service.",
|
|
"unblockOrder": 3,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests."
|
|
},
|
|
{
|
|
"id": "d601-k3s-readonly-observability:d601-k3s-client-binary",
|
|
"priority": "P1",
|
|
"type": "environment_blocker",
|
|
"scope": "d601-k3s-client-binary",
|
|
"status": "open",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"summary": "Neither kubectl nor k3s is installed in this runner PATH.",
|
|
"nextTask": "Install kubectl in the D601 Code Queue runner image, or mount an approved k3s kubectl client path for read-only hwlab-dev observation.",
|
|
"unblockOrder": 4,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance."
|
|
},
|
|
{
|
|
"id": "d601-k3s-readonly-observability:d601-kubeconfig-path",
|
|
"priority": "P1",
|
|
"type": "environment_blocker",
|
|
"scope": "d601-kubeconfig-path",
|
|
"status": "open",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"summary": "No readable KUBECONFIG/default k3s kubeconfig path was found by metadata checks.",
|
|
"nextTask": "Mount a read-only kubeconfig for hwlab-dev, or document the approved k3s local kubeconfig path without exposing token material.",
|
|
"unblockOrder": 4,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance."
|
|
},
|
|
{
|
|
"id": "d601-k3s-readonly-observability:d601-maintenance-ssh-bridge",
|
|
"priority": "P1",
|
|
"type": "environment_blocker",
|
|
"scope": "d601-maintenance-ssh-bridge",
|
|
"status": "open",
|
|
"source": "reports/d601-k3s-readonly-observability.json",
|
|
"sourceIssue": "pikasTech/HWLAB#46",
|
|
"summary": "No SSH maintenance bridge was detected from ssh binary plus known environment variables or ~/.ssh/config metadata.",
|
|
"nextTask": "Provide a documented read-only maintenance bridge variable or config path if kubectl cannot be mounted directly in the runner.",
|
|
"unblockOrder": 4,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance."
|
|
},
|
|
{
|
|
"id": "dev-deploy-apply:kubectl",
|
|
"priority": "P1",
|
|
"type": "environment_blocker",
|
|
"scope": "kubectl",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"summary": "kubectl is not installed in the runner",
|
|
"nextTask": "Provide a kubectl client configured for the D601 DEV k3s context without exposing token or secret values.",
|
|
"unblockOrder": 4,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:d601-k3s",
|
|
"priority": "P1",
|
|
"type": "environment_blocker",
|
|
"scope": "d601-k3s",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "D601 runner lacks kubectl and no default kubeconfig was used by this preflight.",
|
|
"nextTask": "Provide a read-only kubectl/kubeconfig path for the real D601 hwlab-dev k3s cluster, then rerun this preflight.",
|
|
"unblockOrder": 4,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance."
|
|
},
|
|
{
|
|
"id": "dev-deploy-apply:cloud-api-db",
|
|
"priority": "P1",
|
|
"type": "runtime_blocker",
|
|
"scope": "cloud-api-db",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-deploy-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#33",
|
|
"summary": "cloud-api health reports DB config blocked; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE",
|
|
"nextTask": "Configure and verify the DEV cloud-api DB env readiness through health output, without reading secret values.",
|
|
"unblockOrder": 5,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:cloud-api-db-health-gate",
|
|
"priority": "P1",
|
|
"type": "runtime_blocker",
|
|
"scope": "cloud-api-db-health-gate",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "cloud-api DB runtime env is not ready; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE.",
|
|
"nextTask": "Configure DEV hwlab-cloud-api with Secret hwlab-cloud-api-dev-db/database-url and HWLAB_CLOUD_DB_SSL_MODE=require, then rerun health/preflight without printing the secret value.",
|
|
"unblockOrder": 5,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:dev-edge",
|
|
"priority": "P2",
|
|
"type": "network_blocker",
|
|
"scope": "dev-edge",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "http://74.48.78.17:16667/health/live is not reachable from this runner.",
|
|
"nextTask": "Bring up or repair the D601-to-master frp route and hwlab-edge-proxy, then rerun the health probe.",
|
|
"unblockOrder": 6,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected."
|
|
},
|
|
{
|
|
"id": "dev-gate-preflight:dev-edge-health",
|
|
"priority": "P2",
|
|
"type": "network_blocker",
|
|
"scope": "dev-edge-health",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-preflight-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#34",
|
|
"summary": "live network probes require --live",
|
|
"nextTask": "Repair the master frps/public DEV edge route and rerun the read-only DEV edge health smoke before real deployment.",
|
|
"unblockOrder": 6,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected."
|
|
},
|
|
{
|
|
"id": "dev-m3-hardware-loop:dev-ingress-health",
|
|
"priority": "P2",
|
|
"type": "network_blocker",
|
|
"scope": "dev-ingress-health",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-m3-hardware-loop.json",
|
|
"sourceIssue": "pikasTech/HWLAB#38",
|
|
"summary": "Blocked at the #33 DEV runtime readiness condition: public DEV ingress does not accept HWLAB health requests, so #36/M3 hardware-loop checks were not reached.",
|
|
"unblockOrder": 6,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected."
|
|
},
|
|
{
|
|
"id": "dev-m4-agent-loop:devPreconditions",
|
|
"priority": "P2",
|
|
"type": "network_blocker",
|
|
"scope": "devPreconditions",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-m4-agent-loop.json",
|
|
"sourceIssue": "pikasTech/HWLAB#37",
|
|
"summary": "connect ECONNREFUSED 74.48.78.17:16667",
|
|
"unblockOrder": 6,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected."
|
|
},
|
|
{
|
|
"id": "dev-mvp-gate-report:devPreconditions",
|
|
"priority": "P2",
|
|
"type": "network_blocker",
|
|
"scope": "devPreconditions",
|
|
"status": "open",
|
|
"source": "reports/dev-gate/dev-mvp-gate-report.json",
|
|
"sourceIssue": "pikasTech/HWLAB#39",
|
|
"summary": "http://74.48.78.17:16667/health and /live both fail with curl exit 7; live DEV ingress evidence is missing.",
|
|
"unblockOrder": 6,
|
|
"unblocks": [
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected."
|
|
}
|
|
],
|
|
"nextSteps": [
|
|
{
|
|
"order": 1,
|
|
"blockerOrder": 1,
|
|
"priority": "P0",
|
|
"scopes": [
|
|
"base-image"
|
|
],
|
|
"sourceIssues": [
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#35"
|
|
],
|
|
"rationale": "Artifact publishing cannot start until an approved Node 20 DEV builder base image is available.",
|
|
"action": "Preload node:20-bookworm-slim into the D601 Docker cache, or tag it as 127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim. Set HWLAB_DEV_BASE_IMAGE=node:20-bookworm-slim or HWLAB_DEV_BASE_IMAGE=127.0.0.1:5000/hwlab/hwlab-dev-base:node20-bookworm-slim when invoking artifact publish. Rerun this preflight and require status=ready before #35 artifact publish. Do not use UniDesk runtime, Code Queue runner, backend-core, provider-gateway, or microservice-proxy images as substitutes.",
|
|
"evidenceRequired": "Base-image preflight status=ready with approved Node 20 builder base and no UniDesk/runtime substitute."
|
|
},
|
|
{
|
|
"order": 2,
|
|
"blockerOrder": 3,
|
|
"priority": "P1",
|
|
"scopes": [
|
|
"artifact-publish",
|
|
"artifact-source-commit",
|
|
"artifact-catalog",
|
|
"dev-artifact-publish",
|
|
"ghcr"
|
|
],
|
|
"sourceIssues": [
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#35",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The gate cannot promote deploy or runtime observations without immutable image provenance and digests.",
|
|
"action": "Publish DEV images from the intended commit and update the catalog with registry digests and verification evidence.",
|
|
"evidenceRequired": "Artifact publish report with ciPublished=true, registryVerified=true, and sha256 digest for each frozen service ID."
|
|
},
|
|
{
|
|
"order": 3,
|
|
"blockerOrder": 4,
|
|
"priority": "P1",
|
|
"scopes": [
|
|
"d601-k3s-client-binary",
|
|
"d601-kubeconfig-path",
|
|
"d601-maintenance-ssh-bridge",
|
|
"kubectl",
|
|
"d601-k3s"
|
|
],
|
|
"sourceIssues": [
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#46"
|
|
],
|
|
"rationale": "D601 hwlab-dev cluster state must be observable read-only before any live apply or M3/M4/M5 acceptance.",
|
|
"action": "Install kubectl in the D601 Code Queue runner image, or mount an approved k3s kubectl client path for read-only hwlab-dev observation.",
|
|
"evidenceRequired": "Read-only kubectl/k3s report proving pods/services/configmaps are observable in hwlab-dev without reading Secrets."
|
|
},
|
|
{
|
|
"order": 4,
|
|
"blockerOrder": 5,
|
|
"priority": "P1",
|
|
"scopes": [
|
|
"cloud-api-db",
|
|
"cloud-api-db-health-gate"
|
|
],
|
|
"sourceIssues": [
|
|
"pikasTech/HWLAB#33",
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "Cloud API DB env and health readiness block runtime health and MVP evidence even if ingress starts responding.",
|
|
"action": "Configure and verify the DEV cloud-api DB env readiness through health output, without reading secret values.",
|
|
"evidenceRequired": "Cloud API health/live output showing DB env ready and redacted secret references, without secret material."
|
|
},
|
|
{
|
|
"order": 5,
|
|
"blockerOrder": 6,
|
|
"priority": "P2",
|
|
"scopes": [
|
|
"dev-edge",
|
|
"dev-edge-health",
|
|
"dev-ingress-health",
|
|
"devPreconditions"
|
|
],
|
|
"sourceIssues": [
|
|
"pikasTech/HWLAB#34",
|
|
"pikasTech/HWLAB#36",
|
|
"pikasTech/HWLAB#37",
|
|
"pikasTech/HWLAB#38",
|
|
"pikasTech/HWLAB#39"
|
|
],
|
|
"rationale": "The :6667/frp path must be reachable before any DEV-LIVE M3, M4, or M5 evidence can be collected.",
|
|
"action": "Bring up or repair the D601-to-master frp route and hwlab-edge-proxy, then rerun the health probe.",
|
|
"evidenceRequired": "Read-only DEV route observation for :6667/frp/edge/router with HWLAB service identity and artifact identity."
|
|
}
|
|
],
|
|
"validationCommands": [
|
|
"node --check scripts/dev-evidence-blocker-aggregator.mjs",
|
|
"node --check scripts/src/dev-evidence-blocker-aggregator.mjs",
|
|
"node scripts/dev-evidence-blocker-aggregator.mjs --check",
|
|
"node scripts/dev-evidence-blocker-aggregator.mjs --markdown",
|
|
"node --check scripts/validate-dev-gate-report.mjs",
|
|
"node scripts/validate-dev-gate-report.mjs"
|
|
]
|
|
}
|