Skip to content

Fleet host identities move to the leaf gunbc.fleet_host_identity (broker closure 196 → 192) - #13175

Merged
gunbai-bot[bot] merged 5 commits into
mainfrom
session/bright-hawk-257-host-identity
Oct 4, 2026
Merged

gunbai-bot[bot] merged 5 commits into
mainfrom
session/bright-hawk-257-host-identity

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Fleet host identities move to a leaf (gunbc.fleet_host_identity)

Tracked follow-up from #13132 (native broker 1A), assigned by gentle-dove-36. It is a closure-purity item, not on the native-error path.

gunbc.auth.approval_ntfy_publish composes the ntfy address from operator_host_srv1. That row lived in gunbc.fleet_intent_network, so the approval broker imported the whole fleet topology (segments, endpoints, router reservations) and gunbc.fleet_asset_identity just to read a host's name. Naming is not enrollment, and that module's own notes say so: enrollment is membership in its endpoints. This PR makes the two separate modules.

  • The 13 operator_host_* rows and their notes move verbatim (no copy, no alias) to gunbc.fleet_host_identity, which imports only product.placement_supply. A header says what "this module" and "here" in the moved notes now refer to: naming means the leaf, while enrollment and endpoints stay in gunbc.fleet_intent_network.
  • gunbc.fleet_intent_network imports the rows from the leaf for its endpoint rows.
  • Every import gunbc.fleet_intent_network { … } naming an operator_host_* row is split mechanically: host names go to the leaf, and any other names stay (195 modules). Also repointed: one decl_ref provider (runner_throughput_qualification_witness_test), one probe-source string (managed_host_forged_probe_witness_test), and two prose citations.
  • The table is moved whole, not just srv1, because moving one row would fork it (ruling by gentle-dove-36 on Native broker 1A: narrow the approval broker's closure (435 → 196 modules, 1091 → 253 native errors) #13132).

Broker closure (import BFS from gunbc.auth.approval_broker_serve): 196 → 192 modules. gunbc.fleet_intent_network, gunbc.fleet_asset_identity, extdeps.router.verizon_cr1000a and the vendor/hardware modules are no longer reached.

Evidence (local, gunbc built at this PR's base):

  • gunbc compile --target rust on the broker entry resolves the whole closure. Its one blocking diagnostic is the known approval_store_receipt filter-in-branch-condition refusal, which lane 1B owns.
  • claim_batch over a sample of the touched witness modules: 90/90 PASS across host/managed_host_forged_probe_witness_test, runner/runner_throughput_qualification_witness_test, approval_ntfy_deployment_witness_test, dgx_spark_witness_test and approval_device_enrolment_code_witness_test.
  • test.claim.fleet.fleet_intent_network_witness_test refuses entry under local claim_batch (UnimportedBareProvider Unrostered …#LiveTreeDisposition), identically on pristine main c8cbc6c. This PR does not touch that file.
  • The other ~100 witness modules that import the leaf are left to the floor's changed-witness selection.

The leaf's one import: product.placement_supply (asked by gentle-dove-36)

The leaf needs exactly one thing from product.placement_supply: the type HostIdentity (a branded NonEmptyStr). placement_supply imports extdeps.dhcp.v4 { MacAddress }, which reaches extdeps.dns.domain_name. The leaf adds none of that to the broker closure. Cutting only the leaf's edge in the import-graph BFS leaves the closure at 192 modules, because placement_supply is also reached through gunbc.fleet_posix_accounts, gunbc.fleet_lifecycle_observation (each importing only { HostIdentity }) and product.network_topology (the extdeps.http.server → tailscale path that lane 1C is cutting).

It is not intrinsic: all three non-1C importers want only the type, and its home is a placement/supply module that also models MAC addresses. Cutting all four edges takes the closure from 192 to 189 and removes placement_supply, dhcp.v4 and dns.domain_name. That means moving HostIdentity to its own leaf, and 309 modules import it by name. Tracked item: move HostIdentity (and host_identity_eq) to a product-layer leaf and repoint its importers. Trigger: after lane 1C's cut lands, because only then does that move change the broker's closure. It is not in this PR because it is a second 300-file move of a different authority.

🤖 Generated with Claude Code

gunbc-ci-auto-heal added 2 commits October 3, 2026 23:27

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LAND. This is the right authority split: host naming moves as one whole table to a leaf, while topology membership and endpoint enrollment remain in gunbc.fleet_intent_network. The move is verbatim rather than aliased, the 195 importer edits are mechanical, the broker closure reduction follows from removing topology-only dependencies, and the separate HostIdentity/placement-supply cut is explicitly bounded and triggered after #13145 rather than being mixed into this PR. All witness lanes are green.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 4, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 4, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 163d143 Oct 4, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/bright-hawk-257-host-identity branch October 4, 2026 12:13
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
Resolve against #13175 (fleet host identities move to gunbc.fleet_host_identity):
the deleted mtcollins1_media_attach stays deleted, and every import of
operator_host_mtcollins1 this cut added reads its new home.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
…yte-identical to main's; main's #13175 moved operator_host_* to gunbc.fleet_host_identity); the re-entrant witness imports from the new leaf

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
…st_identity (#13175)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant