Repository navigation
Fleet host identities move to the leaf gunbc.fleet_host_identity (broker closure 196 → 192) - #13175
Merged
Merged
Conversation
added 2 commits
October 3, 2026 23:27
… LiveTreeDisposition in the github app registry witness
briansrls
approved these changes
Oct 4, 2026
briansrls
left a comment
Contributor
There was a problem hiding this comment.
LAND. This is the right authority split: host naming moves as one whole table to a leaf, while topology membership and endpoint enrollment remain in gunbc.fleet_intent_network. The move is verbatim rather than aliased, the 195 importer edits are mechanical, the broker closure reduction follows from removing topology-only dependencies, and the separate HostIdentity/placement-supply cut is explicitly bounded and triggered after #13145 rather than being mixed into this PR. All witness lanes are green.
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Oct 4, 2026
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
…712dcc + sweep); old stacked history superseded
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
Resolve against #13175 (fleet host identities move to gunbc.fleet_host_identity): the deleted mtcollins1_media_attach stays deleted, and every import of operator_host_mtcollins1 this cut added reads its new home. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
…yte-identical to main's; main's #13175 moved operator_host_* to gunbc.fleet_host_identity); the re-entrant witness imports from the new leaf Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
…st_identity (#13175) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fleet host identities move to a leaf (
gunbc.fleet_host_identity)Tracked follow-up from #13132 (native broker 1A), assigned by gentle-dove-36. It is a closure-purity item, not on the native-error path.
gunbc.auth.approval_ntfy_publishcomposes the ntfy address fromoperator_host_srv1. That row lived ingunbc.fleet_intent_network, so the approval broker imported the whole fleet topology (segments, endpoints, router reservations) andgunbc.fleet_asset_identityjust to read a host's name. Naming is not enrollment, and that module's own notes say so: enrollment is membership in itsendpoints. This PR makes the two separate modules.operator_host_*rows and their notes move verbatim (no copy, no alias) togunbc.fleet_host_identity, which imports onlyproduct.placement_supply. A header says what "this module" and "here" in the moved notes now refer to: naming means the leaf, while enrollment andendpointsstay ingunbc.fleet_intent_network.gunbc.fleet_intent_networkimports the rows from the leaf for its endpoint rows.import gunbc.fleet_intent_network { … }naming anoperator_host_*row is split mechanically: host names go to the leaf, and any other names stay (195 modules). Also repointed: onedecl_refprovider (runner_throughput_qualification_witness_test), one probe-source string (managed_host_forged_probe_witness_test), and two prose citations.Broker closure (import BFS from
gunbc.auth.approval_broker_serve): 196 → 192 modules.gunbc.fleet_intent_network,gunbc.fleet_asset_identity,extdeps.router.verizon_cr1000aand the vendor/hardware modules are no longer reached.Evidence (local, gunbc built at this PR's base):
gunbc compile --target ruston the broker entry resolves the whole closure. Its one blocking diagnostic is the knownapproval_store_receiptfilter-in-branch-condition refusal, which lane 1B owns.claim_batchover a sample of the touched witness modules: 90/90 PASS acrosshost/managed_host_forged_probe_witness_test,runner/runner_throughput_qualification_witness_test,approval_ntfy_deployment_witness_test,dgx_spark_witness_testandapproval_device_enrolment_code_witness_test.test.claim.fleet.fleet_intent_network_witness_testrefuses entry under localclaim_batch(UnimportedBareProvider Unrostered …#LiveTreeDisposition), identically on pristine main c8cbc6c. This PR does not touch that file.The leaf's one import:
product.placement_supply(asked by gentle-dove-36)The leaf needs exactly one thing from
product.placement_supply: the typeHostIdentity(a brandedNonEmptyStr).placement_supplyimportsextdeps.dhcp.v4 { MacAddress }, which reachesextdeps.dns.domain_name. The leaf adds none of that to the broker closure. Cutting only the leaf's edge in the import-graph BFS leaves the closure at 192 modules, becauseplacement_supplyis also reached throughgunbc.fleet_posix_accounts,gunbc.fleet_lifecycle_observation(each importing only{ HostIdentity }) andproduct.network_topology(theextdeps.http.server→ tailscale path that lane 1C is cutting).It is not intrinsic: all three non-1C importers want only the type, and its home is a placement/supply module that also models MAC addresses. Cutting all four edges takes the closure from 192 to 189 and removes
placement_supply,dhcp.v4anddns.domain_name. That means movingHostIdentityto its own leaf, and 309 modules import it by name. Tracked item: moveHostIdentity(andhost_identity_eq) to a product-layer leaf and repoint its importers. Trigger: after lane 1C's cut lands, because only then does that move change the broker's closure. It is not in this PR because it is a second 300-file move of a different authority.🤖 Generated with Claude Code