Skip to content

Commit 7abd237

Browse files
JamesReateclaude
andcommitted
docs: plan 06 step 1 done — differ=0 across all 11 signer pairs
Run in prod 2026-08-21 02:33 UTC. Every signer exists on both sides and derives one address; stored addresses match; nothing undecryptable. The 0x-prefix parse hazard in sharing.go is recorded as found-but-untripped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WSYDqdJ1fWmYJAXNgAJzTr
1 parent 8f01846 commit 7abd237

3 files changed

Lines changed: 15 additions & 3 deletions

File tree

‎docs/plans/06-signer-key-consolidation.md‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -188,7 +188,7 @@ with the same meaning.
188188

189189
## Steps
190190

191-
### 1. Prove the two copies are the same key
191+
### 1. Prove the two copies are the same key — DONE 2026-08-21, differ=0
192192

193193
A `signer-diff` subcommand in this service, shaped like fleet-lite's
194194
`tenancy-diff` and `groups-diff`. For every tenant present in both databases:
@@ -200,6 +200,18 @@ rows.
200200

201201
Nothing else starts until this reports `differ=0` and no unexplained missing.
202202

203+
**Run in production, 2026-08-21 02:33 UTC** (`signer-diff`, released `v0.20.0`
204+
as image `33e9e11`, via `docs/signer-diff-job.yaml`):
205+
`agree=11 differ=0 missing_local=0 missing_remote=0 no_signer=8
206+
stored_address_drift=0 decrypt_failed=0`. Every signer exists on both sides and
207+
derives one address; the eight no-signer tenants are self-serve, which is the
208+
designed state. The gate is met and step 2 may start.
209+
210+
One hazard found while building it, real but untripped: `sharing.go` parses the
211+
decrypted key without trimming a `0x` prefix, where `credentials.go` trims it —
212+
a prefixed key would sign attestations fine and fail its first share. No stored
213+
key is prefixed today; the diff warns if one ever appears.
214+
203215
**Cost if wrong:** everything downstream assumes one logical key with two
204216
wrappers. If a tenant's copies have drifted — a signer regenerated on one side,
205217
a partial backfill, a master key changed — then consolidating picks a winner

‎docs/plans/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ the row in the same PR that ships the step**, not later.
2121
| [02-vehicle-memberships.md](02-vehicle-memberships.md) | **Done** — steps 1–6 shipped; enforced in prod |
2222
| [03-fleet-lite-operator-tenants.md](03-fleet-lite-operator-tenants.md) | Planned 2026-08-15, nothing shipped |
2323
| [04-invitations-into-tenancy.md](04-invitations-into-tenancy.md) | P1 deployed, P2 backfilled 2026-08-16; **flag flip outstanding** (`INVITES_FROM_TENANCY` unset in prod) |
24-
| [06-signer-key-consolidation.md](06-signer-key-consolidation.md) | Written 2026-08-19, not started; step 1 is read-only and cheap |
24+
| [06-signer-key-consolidation.md](06-signer-key-consolidation.md) | **Step 1 done 2026-08-21** — `signer-diff` reports `differ=0`, all 11 signer pairs agree, stored addresses match; steps 2–6 unblocked |
2525
| [07-vehicle-roster.md](07-vehicle-roster.md) | Steps 1–3 done and live; **step 4 done** — both readers cut over and ON in prod (fleet-lite 2026-08-20 14:17, kaufmann `v1.53.0` + flip 20:20 UTC); neither path exercised by real traffic yet; step 5 not started |
2626

2727
## Writing one

‎docs/signer-diff-job.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ spec:
2424
restartPolicy: Never
2525
containers:
2626
- name: signer-diff
27-
image: dimozone/fleet-tenancy-api:0.20.0
27+
image: dimozone/fleet-tenancy-api:33e9e11
2828
envFrom:
2929
- configMapRef:
3030
name: fleet-tenancy-api-config

0 commit comments

Comments
 (0)