HWLAB M5 DEV Gate Aggregator v2
Status: blocked
Generated from: bf47a95a97a9
Scope: DEV only, report-only
Active frontend: http://74.48.78.17:16666/
Active API/live: http://74.48.78.17:16667/health/live
Deprecated public endpoints: http://74.48.78.17:6666, http://74.48.78.17:6667
Summary
Frontend revision 1e88056649 and EDGE/ROUTE DEV-LIVE evidence exist on :16666/:16667, but M5 remains blocked by artifact source drift, DB live degradation, missing M3 trusted loop operation evidence, and blocked M4 agent-loop preflight.
Frontend DEV Fact
The latest accepted #99/#108 frontend DEV fact is revision 1e8805664970839b72be40c34636b08f6d18b131 at http://74.48.78.17:16666/. This is DEV-LIVE browser/frontend evidence only and does not promote M3, M4, or M5.
Current DEV Layering
| Layer |
Status |
Evidence level |
Current conclusion |
Required next proof |
| Frontend DEV revision |
pass |
DEV-LIVE |
http://74.48.78.17:16666/ serves the accepted Cloud Workbench frontend revision 1e8805664970839b72be40c34636b08f6d18b131; this is browser/frontend evidence only. |
Keep frontend revision proof separate from DB live readiness, M3 hardware-loop evidence, M4 agent-loop evidence, and M5 acceptance. |
| EDGE/ROUTE live |
pass |
DEV-LIVE |
http://74.48.78.17:16666/, http://74.48.78.17:16667/health, and http://74.48.78.17:16667/health/live returned accepted HWLAB DEV responses in the active M2 read-only smoke. |
Keep this separated from DB readiness, M3/M4 loop evidence, and M5 acceptance. |
| DB live/degraded |
blocked |
BLOCKED |
cloud-api DB status=degraded; configReady=true; ready=false; connected=false; liveDbEvidence=false. |
Provide live DB connection evidence through redacted health output; route reachability alone is insufficient. |
| D601 runner observability |
blocked |
DEV-LIVE |
D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false. |
Treat #46 runner kubeconfig/readonly gaps separately from D601 service health; rerun read-only observability after the mount or permission path is repaired. |
| M3 hardware trusted loop |
blocked |
BLOCKED |
No live DEV operation has run yet. Blocker: DEV ingress is reachable on frozen :16667, but this runner cannot use /etc/rancher/k3s/k3s.yaml as readable kubeconfig to discover direct M3 service URLs (HWLAB_DEV_BOX_SIMU_1_URL, HWLAB_DEV_BOX_SIMU_2_URL, HWLAB_DEV_GATEWAY_SIMU_1_URL, HWLAB_DEV_GATEWAY_SIMU_2_URL, HWLAB_DEV_PATCH_PANEL_URL); this is a #46 runner permission/mount or read-only observability gap, not D601 global offline.. |
Only a real DEV res_boxsimu_1:DO1 -> hwlab-patch-panel -> res_boxsimu_2:DI1 observation with operation/trace/audit/evidence can clear M3. |
| M4 agent loop |
blocked |
BLOCKED |
Blocked at DB live readiness before scheduling a DEV agent task. |
Do not schedule or claim the agent loop as live until DB live and required runtime/evidence preconditions pass. |
| artifact/desired-state source |
blocked |
BLOCKED |
artifact targetCovered=false; artifactSource=7e29522b65c8; target=8e89409dda5d; desiredApplyMode=dry-run; mutationAttempted=false. |
Refresh artifact/source coverage for current origin/main and keep desired-state apply separate from read-only route proof. |
M0-M5 Level Classification
| Milestone |
Current classification |
Status |
Strongest evidence |
Live evidence |
Summary |
| M0 |
SOURCE |
pass |
SOURCE |
missing_or_blocked |
Source contract is green at source level only. |
| M1 |
LOCAL |
pass |
LOCAL |
missing_or_blocked |
Local smoke is green; it is not DEV-LIVE. |
| M2 |
DEV-LIVE |
blocked |
DEV-LIVE |
pass |
Current public frontend/API route evidence is DEV-LIVE for route/front-end reachability only. |
| M3 |
BLOCKED |
blocked |
LOCAL |
missing_or_blocked |
DEV-LIVE hardware trusted loop is blocked; local/source shape is not acceptance. |
| M4 |
BLOCKED |
blocked |
DRY-RUN |
missing_or_blocked |
DEV-LIVE agent loop is blocked at DB live readiness; local smoke is not acceptance. |
| M5 |
BLOCKED |
blocked |
DRY-RUN |
missing_or_blocked |
Dry-run is green, but bounded DEV-LIVE MVP e2e is blocked. |
Milestones
| Milestone |
Status |
Highest visible level |
Live evidence |
Summary |
| M0 |
pass |
SOURCE |
missing_or_blocked |
contract source is available; highest visible level is SOURCE; status is pass. |
| M1 |
pass |
LOCAL |
missing_or_blocked |
local smoke is available; highest visible level is LOCAL; status is pass. |
| M2 |
blocked |
DEV-LIVE |
pass |
deploy/runtime readiness is blocked before live DEV; highest visible level is DEV-LIVE; status is blocked. |
| M3 |
blocked |
LOCAL |
missing_or_blocked |
hardware loop has source/local shape but no live operation; highest visible level is LOCAL; status is blocked. |
| M4 |
blocked |
DRY-RUN |
missing_or_blocked |
agent loop has local smoke but live preflight is blocked; highest visible level is DRY-RUN; status is blocked. |
| M5 |
blocked |
DRY-RUN |
missing_or_blocked |
dry-run is green but live MVP gate is blocked; highest visible level is DRY-RUN; status is blocked. |
#9 DoD Checks
| Check |
Status |
Evidence level |
Summary |
| m0-source-contract |
pass |
SOURCE |
M0 contract checks are source-level evidence only. |
| m1-local-smoke |
pass |
LOCAL |
M1 local smoke is not a live DEV substitute. |
| artifact-publish-digests |
blocked |
BLOCKED |
artifactState=published, ciPublished=true, registryVerified=true, sha256=13, not_published=0, targetCovered=false |
| d601-k3s-observability |
blocked |
DEV-LIVE |
D601 public DEV endpoints are reachable, but the runner cannot read /etc/rancher/k3s/k3s.yaml; classify as #46 runner permission/mount or read-only observability gap, not D601 global offline. Alternate read-only cluster probes are readable. runnerKubeconfigReadable=false, runnerKubeconfigProbeExitCode=0, runnerKubeconfigProbeStderr=empty, d601PublicEndpointsReachable=true, d601K3sUnavailable=false. |
| dev-edge-frp-16667 |
pass |
DEV-LIVE |
Committed edge report proves read-only public HTTP on :16667 /health and /health/live; this is route evidence, not DB/M3/M4/M5 acceptance. |
| cloud-api-db-ready |
blocked |
BLOCKED |
cloud-api DB status=degraded; ready=false; connected=false; liveDbEvidence=false. |
| m3-hardware-trusted-loop |
blocked |
BLOCKED |
M3 trusted loop is blocked until res_boxsimu_1:DO1 -> patch-panel -> res_boxsimu_2:DI1 is proven with operation/trace/audit/evidence. |
| m4-agent-loop-live |
blocked |
BLOCKED |
M4 agent loop live path is blocked before accepted agent scheduling/evidence closure. |
| m5-mvp-dev-live |
blocked |
BLOCKED |
M5 dry-run passed; bounded DEV-LIVE MVP e2e has not passed. |
M3/M4/M5 Blocker Classification
| Milestone |
Status |
Current level |
Blocker class |
Dependency |
Required next proof |
| M3 |
blocked |
BLOCKED |
runner-readonly-observability-gap |
Runner read-only service discovery must be repaired before the real DEV trusted loop can be observed; this does not mean D601/k3s is globally unavailable. |
Repair the #46 runner readonly kubeconfig/service-discovery gap, then run the bounded DEV M3 live smoke only when direct simulator and patch-panel targets are discoverable. |
| M4 |
blocked |
BLOCKED |
db-live-readiness |
Cloud API /health/live must report DB ready=true, connected=true, and liveDbEvidence=true before live agent scheduling/evidence closure. |
Repair DB live readiness and rerun the M4 live preflight without scheduling a DEV agent task before preconditions pass. |
| M5 |
blocked |
BLOCKED |
composite-db-m3-m4-live |
M5 needs DB live readiness, M3 trusted-loop DEV evidence, M4 live preflight/evidence closure, and current source/artifact coverage. |
After DB/M3/M4 blockers are cleared, run only the bounded DEV MVP live gate command with explicit DEV/non-PROD confirmations. |
Blockers
| Priority |
Order |
Type |
Scope |
Summary |
| P1 |
3 |
contract_blocker |
artifact-source-commit |
source commit origin/main 8e89409 is not covered by artifact source 7e29522; target changes since the artifact source touch artifact build inputs. |
| P1 |
3 |
runtime_blocker |
dev-artifact-publish |
reports/dev-gate/dev-artifacts.json does not prove all required HWLAB service artifacts for origin/main 8e89409; current status is published with 13/13 required services published and source states resolved: 13 source-present, 0 intentionally-disabled. |
| P1 |
4 |
observability_blocker |
runner-kubeconfig-readonly-gap |
The runner cannot read /etc/rancher/k3s/k3s.yaml; classify this as a runner permission/mount gap, not a D601 global outage. Alternate read-only cluster probes and public DEV endpoint probes are reported separately. |
| P1 |
4 |
observability_blocker |
m3-service-discovery |
DEV ingress is reachable on frozen :16667, but this runner cannot use /etc/rancher/k3s/k3s.yaml as readable kubeconfig to discover direct M3 service URLs (HWLAB_DEV_BOX_SIMU_1_URL, HWLAB_DEV_BOX_SIMU_2_URL, HWLAB_DEV_GATEWAY_SIMU_1_URL, HWLAB_DEV_GATEWAY_SIMU_2_URL, HWLAB_DEV_PATCH_PANEL_URL); this is a #46 runner permission/mount or read-only observability gap, not D601 global offline. |
| P1 |
5 |
runtime_blocker |
cloud-api-db |
cloud-api DB env is injected, but runtime health has not attempted a live DB connection |
| P1 |
5 |
network_blocker |
cloud-api-db |
cloud-api DB env is injected, but runtime health has not attempted a live DB connection |
| P1 |
5 |
runtime_blocker |
cloud-api-db-health-gate |
cloud-api DB runtime env is not ready; missing HWLAB_CLOUD_DB_URL, HWLAB_CLOUD_DB_SSL_MODE. |
| P1 |
5 |
runtime_blocker |
db-live |
cloud-api /health/live reports DB degraded; connected=false; ready=false. |
| P1 |
5 |
runtime_blocker |
db-live |
cloud-api /health/live reports DB degraded; db.ready=false, db.connected=false, and live DB evidence is not established. |
| P0 |
6 |
runtime_blocker |
m3-hardware-loop-runtime |
Live M3 smoke reached DEV simulators, but patch-panel active DO1 -> DI1 connection is missing. |
Next Unblock Order
- Refresh without fake digests using
node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --blocked, or after a successful publish run node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report reports/dev-gate/dev-artifacts.json.
Evidence required: Artifact publish report with ciPublished=true, registryVerified=true, and sha256 digest for each frozen service ID.
- Provide the approved read-only runner kubeconfig mount or document the intended alternate KUBECONFIG path, then rerun the read-only report.
Evidence required: Read-only report with runnerKubeconfigReadable, runnerKubeconfigProbeExitCode/stderr, d601PublicEndpointsReachable, and d601K3sUnavailable recorded separately, plus direct M3 service target discovery before any DO write.
- Deploy cloud-api DB runtime readiness probe and/or repair DEV DB connectivity, then rerun the read-only health smoke without reading or printing the DB secret value.
Evidence required: Cloud API health/live output showing DB env ready and redacted secret references, without secret material.
- Prove the real DEV M3 trusted loop res_boxsimu_1:DO1 -> hwlab-patch-panel -> res_boxsimu_2:DI1 with operation, trace, audit, and evidence identifiers.
Evidence required: Operation, trace, audit, and evidence IDs from the real DEV DO1 -> patch-panel -> DI1 trusted loop.
Validation
node --check scripts/dev-evidence-blocker-aggregator.mjs
node --check scripts/src/dev-evidence-blocker-aggregator.mjs
node scripts/dev-evidence-blocker-aggregator.mjs --check
node scripts/dev-evidence-blocker-aggregator.mjs --markdown
node --check scripts/validate-dev-gate-report.mjs
node scripts/validate-dev-gate-report.mjs
Boundary
This report reads committed reports and fixtures only. It does not deploy, call DEV, call PROD, read secrets, restart runtime, run heavy e2e, or substitute UniDesk runtime for HWLAB runtime.