diff --git a/.github/workflows/fleet-converge.yml b/.github/workflows/fleet-converge.yml index 3cdf0ff870a..d33f725dfd1 100644 --- a/.github/workflows/fleet-converge.yml +++ b/.github/workflows/fleet-converge.yml @@ -227,7 +227,7 @@ jobs: echo "fleet-key: agent loaded (identity fleet-automation@gunbc; secret versions/1 pinned; fingerprint verified against modeled authority; key file wiped)" env: WIF_ACCESS_TOKEN: ${{ steps.wif_auth.outputs.access_token }} - if: github.event.inputs.mode == 'plan' || github.event.inputs.mode == 'launch_environment_plan' || github.event.inputs.mode == 'allocation_store_plan' || github.event.inputs.mode == 'apply' || github.event.inputs.mode == 'app_control_plane_observe' || github.event.inputs.mode == 'microvm_host_converge' || github.event.inputs.mode == 'guest_image_observe' || github.event.inputs.mode == 'guest_image_converge' || github.event.inputs.mode == 'microvm_boot_probe' || github.event.inputs.mode == 'spark_grants' || github.event.inputs.mode == 'spark_bootstrap' || github.event.inputs.mode == 'spark_serving_apply' || github.event.inputs.mode == 'spark_runtime_image_probe' || github.event.inputs.mode == 'dashboard_deploy' || github.event.inputs.mode == 'rlm_launch_deployment_receipt' || github.event.inputs.mode == 'host_reset_return' || github.event.inputs.mode == 'runner_host_file_observe' || github.event.inputs.mode == 'runner_host_file_converge' || github.event.inputs.mode == 'runner_password_session_tool_converge' || github.event.inputs.mode == 'r2_mint_preflight' || github.event.inputs.mode == 'r2_object_write_mint' || github.event.inputs.mode == 'approval_keyring_converge' || github.event.inputs.mode == 'mtcollins1_boot' + if: github.event.inputs.mode == 'plan' || github.event.inputs.mode == 'launch_environment_plan' || github.event.inputs.mode == 'allocation_store_plan' || github.event.inputs.mode == 'apply' || github.event.inputs.mode == 'app_control_plane_observe' || github.event.inputs.mode == 'microvm_host_converge' || github.event.inputs.mode == 'guest_image_observe' || github.event.inputs.mode == 'guest_image_converge' || github.event.inputs.mode == 'microvm_boot_probe' || github.event.inputs.mode == 'spark_grants' || github.event.inputs.mode == 'spark_bootstrap' || github.event.inputs.mode == 'spark_serving_apply' || github.event.inputs.mode == 'spark_runtime_image_probe' || github.event.inputs.mode == 'dashboard_deploy' || github.event.inputs.mode == 'rlm_launch_deployment_receipt' || github.event.inputs.mode == 'host_reset_return' || github.event.inputs.mode == 'runner_host_file_observe' || github.event.inputs.mode == 'runner_host_file_converge' || github.event.inputs.mode == 'runner_password_session_tool_converge' || github.event.inputs.mode == 'r2_mint_preflight' || github.event.inputs.mode == 'r2_object_write_mint' || github.event.inputs.mode == 'approval_keyring_converge' timeout-minutes: 5 - name: Fleet converge plan (membership_reconcile → artifact) id: plan diff --git a/dag/gunbc/fleet/fleet_converge_workflow.dag b/dag/gunbc/fleet/fleet_converge_workflow.dag index 2f36bc83a5b..9b25df48112 100644 --- a/dag/gunbc/fleet/fleet_converge_workflow.dag +++ b/dag/gunbc/fleet/fleet_converge_workflow.dag @@ -312,9 +312,12 @@ fn fleet_converge_any_mode_step_if(modes: List) -> St // inherit the fleet key by omission. The fleet-converge job materializes the fleet key only for a // dispatch whose mode consumes it: an API-only read (the org credential observe and the org runner // roster read, both of which reach GitHub over gh and open no host session) must not hold host SSH -// authority it never uses. Only those two modes are established API-only by this declaration; -// every other mode keeps the key it held before, which is the status quo rather than a finding -// that it needs it. +// authority it never uses. Three modes are established as not consuming it: the two API-only reads, +// and the Mt. Collins boot, whose route is BMC/IPMI, SOL and HTTP approval submission with no fleet +// SSH operation. Every mode that predates this declaration keeps the key it held before, which is +// the status quo rather than a finding that it needs it; a mode added AFTER it has no prior standing +// to keep, so its arm is derived from its operation route (the approval keyring converge executes +// over fleet SSH to srv1 and consumes it). type FleetSshKeyDemand = FleetSshKeyConsumed | FleetSshKeyNotConsumed fn fleet_converge_mode_fleet_ssh_key_demand(mode: FleetConvergeWorkflowMode) -> FleetSshKeyDemand { @@ -343,7 +346,7 @@ fn fleet_converge_mode_fleet_ssh_key_demand(mode: FleetConvergeWorkflowMode) -> R2MintPreflight => FleetSshKeyConsumed R2ObjectWriteMint => FleetSshKeyConsumed ApprovalKeyringConverge => FleetSshKeyConsumed - MtCollins1Boot => FleetSshKeyConsumed + MtCollins1Boot => FleetSshKeyNotConsumed } }