09 – Document Build, Deployment and Recovery Workflows #240

Open
opened 2026-09-19 20:34:37 +01:00 by nimmo · 0 comments
Owner

Goal

Document the implemented build, deployment, security, and recovery workflows as durable repository operational knowledge.

Dependencies

Start architecture notes after #232; complete operational procedures after #237 and #238.

Documentation ownership

Put durable fleet architecture and runbooks in the repository wiki, following its source/provenance process. Keep concise, implementation-adjacent commands or links in version-controlled repository documentation where that is the established owner; avoid duplicate competing runbooks.

Required content

  • Fedora-managed Nova builder role and its later NixOS migration contract.
  • Controller source-snapshot/evaluation, Nova build, closure transfer, target test/boot/switch, and dirty/untracked-source handling.
  • How to observe that a real build ran remotely rather than being substituted.
  • Credential rotation/revocation, local-build fallback, Nova failure, controller failure, target SSH failure, activation failure, and rollback.
  • Which hosts are opted in or deliberately excluded, with concrete commands and links to relevant modules/scripts.

Validation

Exercise the documented normal and recovery commands on the implemented workflow, then have the documentation independently reviewed against live/declarative configuration.

## Goal Document the implemented build, deployment, security, and recovery workflows as durable repository operational knowledge. ## Dependencies Start architecture notes after #232; complete operational procedures after #237 and #238. ## Documentation ownership Put durable fleet architecture and runbooks in the repository wiki, following its source/provenance process. Keep concise, implementation-adjacent commands or links in version-controlled repository documentation where that is the established owner; avoid duplicate competing runbooks. ## Required content - Fedora-managed Nova builder role and its later NixOS migration contract. - Controller source-snapshot/evaluation, Nova build, closure transfer, target `test`/`boot`/`switch`, and dirty/untracked-source handling. - How to observe that a real build ran remotely rather than being substituted. - Credential rotation/revocation, local-build fallback, Nova failure, controller failure, target SSH failure, activation failure, and rollback. - Which hosts are opted in or deliberately excluded, with concrete commands and links to relevant modules/scripts. ## Validation Exercise the documented normal and recovery commands on the implemented workflow, then have the documentation independently reviewed against live/declarative configuration.
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#240
No description provided.