Skip to content

Latest commit

 

History

History
400 lines (364 loc) · 24.4 KB

File metadata and controls

400 lines (364 loc) · 24.4 KB

Changelog

Unreleased — SCLite 2.0 owner migration

  • Aligns the source candidate to rexecop==1.0.0rc2, govengine==1.0.0rc2 and sclite-core==2.0.1. The candidate wheel gate installs exact source snapshots, requires unconditional pip check, verifies versions, provenance and installed origins, and runs status from an empty directory. Public-index resolution remains mandatory after RExecOp rc2 publication and before Tecrax publication; this is not mutation readiness, release or release-train authorization.
  • Declares explicit Chrony plugin execution postures and selects the fixture_only/no_network shape in the public example. A source-pinned T-205 regression uses real GovEngine v0.2 policy, approval, signature and revocation evaluation plus RExecOp lifecycle and the real Tecrax fixture backend to prove governed apply, deterministic post-I/O failure, a fresh approved recovery child, restored fixture state, conformant receipt and idempotent replay without new authority or I/O. Each of pre-read, apply, post-read and recovery uses a distinct backend created by the real factory. Fixture continuity is a private, lock-guarded, process-local boolean registry isolated by connector, target and normalized subnet; it is not durable, multiprocess, SCLite truth or RExecOp lifecycle persistence. This does not qualify the operator wrapper, live infrastructure, exactly-once, restart or crash recovery, mutation readiness, release or publication.
  • Advances immutable CI source coordinates to RExecOp 8a8609150388866a21afddca5bf773cd6ec120cd, GovEngine e65ad22ec25d74bbbb4969bd614981a8ed5e47c8, and SCLite c065d7a157665351054bacc7b5e3ae12b7cc9d98. Candidate-wheel governed functional smoke remains source-pinned and checks exact checkout, VCS, version, v0.2 and import origins. The source test job uses resolver-aware Tecrax editable installation while retaining the same provenance checks. A separate non-editable candidate-wheel gate uses those same exact sources and may not substitute another dependency graph.
  • Disables automatic retry for the mixed read/apply Chrony mutation candidate by setting its profile retry budget to zero without expanding its allowlist or error blocklist. The focused persisted-plan regression calls RExecOp's actual retry classifier and separately proves its intrinsic outcome_indeterminate refusal. This covers F-017 profile alignment only; the separate fixture-only T-205 proof above does not extend this retry policy or qualify exactly-once, crash/power-loss or worker recovery, a private wrapper, lab or live operation, mutation readiness, release or publication.
  • Routes Chrony wrapper execution through RExecOp's runtime-owned incremental combined-output capture with an exact 16384-byte configured default and lower exact-integer policy precedence. Overflow now fails before return-code or JSON handling and exposes only raw-free per-stream digests, truncation flags and observed byte counts; timeout exposes no partial output. Focused local-producer and StepExecutor regressions do not qualify a live wrapper, un-emitted bytes, lab_only, permits, consume-once behavior or mutation readiness.
  • Corrected public status for 0.4.0rc3: Chrony is a registered mutation candidate, while default RExecOp stable_read_only blocks apply before connector I/O and Tecrax is not mutation_ready. This does not change profile or connector behavior, readiness authority, package versions, pins, or release workflows.
  • Pins each CI source input to an immutable reviewed snapshot. Any advance requires explicit review and an exact workflow-coordinate update; source identity is not package compatibility or release qualification. The separately authorized F-001 production dependency-line remediation is recorded above.
  • Declares profile-owned operation capability requirements for every active connector and independent outbound network-policy bindings for SSH and HTTP connectors, so RExecOp no longer derives governance requirements or destination allowlists from backend/runtime claims.
  • Keeps the production-installed Chrony line fail closed at typed execution until a separately authorized dependency-pin and release decision consumes the delivered GovEngine approval-attestation contract. The source-pinned fixture proof does not turn operation admission alone into execution approval.
  • Uses RExecOp's orchestration contract surface for observation and escalation artifacts instead of the removed SCLite stack-specific aliases.
  • Pins the coordinated SCLite 2.0, GovEngine 1.0 and RExecOp 0.3 candidate train.

All notable Tecrax profile changes are documented here.

Unreleased

  • Extended the Grafana infrastructure-dashboard runbook with a bounded Viewer-scoped service-account bootstrap: expiring runtime-only tokens, secret-safe administrator authentication, certificate verification, dashboard and datasource read smokes, an administrator-denial proof and exact-ID rollback without dashboard, datasource or plugin mutation.
  • Added a management-plane TLS hardening runbook for network security devices: exact scope isolation, encrypted pre/post backups, active rollback access, tab-only CLI discovery, running-only protocol canaries, negotiated-version smokes from every management path and explicit handling of firmware defaults that do not represent the requested modern protocol set.
  • Extended the network SNMP adoption runbook with bounded vendor-license lifecycle visibility: read-only collection, no persistent license identifiers or payloads, deterministic current-expiration selection, separate collector-health signals and non-overlapping 60/30-day Zabbix thresholds while keeping firmware entitlement as a vendor-confirmation gate.
  • Clarified workload-aware monitoring hygiene: rotation-managed recording storage uses bounded free-byte and sustained-utilization signals instead of permanently firing percentage, ordinary HDD-latency or swap-occupancy alerts; Linux update visibility keeps metadata refresh separate from the read-only collector; network-device CLI discovery forbids contextual help after a syntactically complete configuration command prefix.
  • Extended the infrastructure control-plane recovery runbook with an explicitly approved recurring network-device configuration capture: exact-device identity, running/startup equality, non-overlapping execution, encryption before durable storage, append-only off-host artifacts, checksum and decrypt/read gates, and minimal backup-health monitoring without automatic prune.
  • Added a bounded network-security-device syslog-to-Wazuh onboarding runbook plus public-safe StoneOS decoder and local-rule reference artifacts. The gate keeps health monitoring in Zabbix, preserves existing Grafana dashboards, excludes bulk traffic/session/NAT/debug logging, and defers TLS, threat-rule promotion and GLPI routing to separate proofs.
  • Extended that runbook with a fail-closed rsyslog framing-normalization fallback for non-standard TCP record terminators, including same-session continuity, least-privilege file access, bounded rotation, duplicate-path and rollback gates.
  • Added bounded StoneOS threat-field decoding plus separate general-threat and observed log-only protocol-exception rules, without claiming unobserved block or prevention coverage.
  • Added a safe StoneOS management-audit projection for successful and failed administrator login, logout and persistent configuration save. Raw operation commands and configuration differences remain excluded until deterministic redaction can prevent credential-like values from reaching SIEM storage. Successful login and logout remain at the standard Wazuh alert threshold so they are retained as audit evidence.
  • Isolated the Chrony mutation fixture's RExecOp lab_only posture inside the single execution-path test so the normal test process and stable runtime keep the default read-only posture.
  • Advances the source profile candidate to 0.4.0rc3 with exact pins govengine==1.0.0rc1, rexecop==1.0.0rc1 and frozen sclite-core==2.0.0; profile semantics and activation posture are unchanged.
  • Pins every Tecrax GitHub Action to a reviewed full commit SHA and makes the existing public-truth gate reject future moving action refs.
  • Added the controlled BookStack documentation publication runbook covering exact-target resolution, least-privilege publishing, Polish service-card quality gates, writable cache/upload ownership checks, revision-history rollback, secret scanning and idempotent post-publication validation.
  • Added the BookStack application-aware backup runbook for supported CLI capture, runtime-memory encryption, append-only off-host custody, checksum validation and fail-closed plaintext cleanup without automatic NAS pruning.
  • Expanded the generic librarian role runbook with mandatory GIMP, Inkscape, NAPS2 and PDF Arranger packaging and non-administrator smoke gates.
  • Documented the promotion gate for a future governed Windows role-application convergence intent without claiming package custody or an active mutation.
  • Hardened public deployment helpers so Windows endpoint apply requires an exact live-hostname assertion, while Samba AD bulk provisioning validates the complete CSV, duplicate/unsafe logins and every target group before the first mutation.
  • Enforces Tecrax's production SCLite imports against the versioned wheel-shipped consumer contract through the existing public-truth CI gate.
  • The prior 0.4.0rc2 source candidate pinned govengine==0.17.0rc2 and rexecop==0.3.0rc2 for bounded HTTP destination admission and receipt binding.

[0.4.0rc1] - 2026-07-10

  • Unpublished source candidate: aligns the profile package to rexecop==0.3.0rc1, govengine==0.17.0rc1, and sclite-core==2.0.0 for the SCLite P0 integrity/lifecycle hardening train.

  • Publication boundary: tecrax==0.3.21a0 remains the latest published PyPI package until the candidate artifacts pass the complete local release gates.

  • Added the Synology NAS domain-home and GPO drive-mapping runbook for moving from a one-user AD-auth pilot to a neutral staff home mapping model without storing credentials, deleting NAS data or hand-building GPO objects.

  • Extended the Synology NAS domain-home runbook with the DSM user-home-service check after domain rejoin or NAS rename, plus the known-good GPP Drive Maps shape for credential-free home mapping.

  • Added the Wazuh Dashboard RBAC operator-access runbook and a read-only RBAC audit helper for detecting missing administrator role-mapping rules without printing password hashes.

  • Added the Wazuh source noise hygiene runbook for bounded source-side suppression of routine successful operational telemetry before ticket routing, including manager alert-level and shared agent scan-cadence baseline guidance.

  • Added automatic public Tecrax runbook links to GLPI alert-ticket drafts when a matching alert category is available.

  • Added the Synology NAS AD-auth pre-change runbook for the planned service window, defining the member-file-server model, one-user pilot scope, AD-group-based access, rollback boundaries and no-delete guardrails.

  • Added the Samba AD delegated domain-join runbook for narrowing routine workstation joins from broad transitional rights toward OU-specific ACLs, with fallback removal kept behind a live join test.

  • Added Vaultwarden bootstrap and backup/restore-proof runbooks, keeping the service in bootstrap custody status until restore, offline break-glass, PKI restore and Proxmox root-of-trust hardening gates are complete.

  • Added the Vaultwarden application-backup and break-glass baseline runbook for root-owned SQLite/data archives, private checksum evidence and offline recovery boundaries without exporting vault contents.

  • Tightened the Vaultwarden bootstrap runbook to require HTTPS-only operator browser access even before final PKI material is available.

  • Added the PKI Center bootstrap runbook for an on-demand VM substrate, keeping production CA material, trust distribution and final HTTPS migration out of scope until custody and restore gates are defined.

  • Added the host-down routing policy runbook and Zabbix GLPI collector support for keeping selected on-demand host-down alerts shadow-only.

  • Recorded the PKI Center CA architecture decision as offline root plus on-demand intermediate without generating or documenting private CA material.

  • Recorded OpenSSL as the selected PKI Center CA engine while deferring final CA policies, issuance, renewal, revocation and autorotation procedure to hardening.

  • Added the PKI certificate lifecycle planning runbook for future CSR/SAN/FQDN, issuance, renewal, revocation, trust distribution and private inventory work without generating CA material.

  • Added the PKI HTTPS rollout planning runbook for future administrative service FQDN/SAN naming, migration order, TLS placement and trust-root dependencies without live TLS changes.

  • Added the Wazuh backup/restore decision runbook, keeping app-aware index export deferred until retention, custody and isolated restore gates exist.

  • Added the GLPI inventory scope runbook, defining a conservative Phase 1 infrastructure inventory baseline and deferring agents, endpoint discovery and network sweeps.

  • Added the basic incident-handling runbook for GLPI incident intake, triage, classification, containment, evidence custody, closure and follow-up without claiming compliance readiness or automatic containment.

  • Extended the admin-tools substrate runbook with the dedicated runtime-node model: admin-tools is the target for operator wrappers, policy files, private state and controlled Tecrax/RExecOp runtime, while development stays on the operator workstation.

  • Added operator-context file support for Zabbix GLPI live-candidate infrastructure host allowlists.

  • Extended the conservative Zabbix live-candidate allowlist with critical disk, backup failure, AD/DNS unavailable and core service unavailable classes while keeping known Frigate retention storage pressure shadow-only.

  • Added conservative Zabbix live-candidate filtering so host-down ticketing only applies to explicitly allowlisted infrastructure hosts, not ordinary endpoints.

  • Added a bounded Zabbix active-problem collector for GLPI shadow routing. It exports normalized alert events without storing API tokens or creating tickets.

  • Updated GLPI alert-ticket drafts and helper output to use Polish diacritics in operator-facing labels, categories and guidance.

  • Hardened the GLPI alert-ticket routing helper around private duplicate state, live API session cleanup and venv-based operator execution.

  • Added the alert-source hygiene checkpoint before live GLPI routing, including a Wazuh alert aggregation helper, routing classes and an operator runbook.

  • Added a public-safe GLPI alert-ticket routing helper and runbook. The helper accepts normalized Zabbix/Wazuh events, renders Polish operator-facing ticket drafts, applies duplicate suppression and keeps GLPI credentials outside Git.

[0.3.17a0-0.3.21a0] - 2026-07-05

  • Current supported line: tecrax==0.3.21a0, aligned to rexecop==0.2.24a0, govengine==0.16.11 and sclite-core==1.0.9.
  • Profile delta: none since 0.3.11a0. 0.3.12a0-0.3.21a0 are coordinated stack repair artifacts only: dependency pins, public-truth markers and the 0.3.21a0 wheel packaging repair for public examples/.
  • 0.3.19a0 was a source-only intermediate during release-train repair and was not published to PyPI.

Publish follow-up repair line (superseded, pin-only)

Tecrax RExecOp extra pin GovEngine SCLite Commit Note
0.3.21a0 0.2.24a0 0.16.11 1.0.9 07a55e2 Current line; includes public examples/ in the wheel.
0.3.20a0 0.2.24a0 0.16.11 1.0.9 c526a5c Superseded; dependency/public-truth repair, missing wheel examples.
0.3.18a0 0.2.23a0 0.16.9 1.0.8 08aeb41 Superseded; coordinated public line before automation-chain release train.
0.3.17a0 0.2.22a0 0.16.9 1.0.8 341e231 Superseded; pin repair.
0.3.16a0 0.2.21a0 0.16.9 1.0.8 48d8e87 Superseded; pin repair.
0.3.15a0 0.2.20a0 0.16.9 1.0.8 26eab3e Superseded; pin repair.
0.3.14a0 0.2.19a0 0.16.9 1.0.8 e7b8260 Superseded; pin repair.
0.3.13a0 0.2.18a0 0.16.9 1.0.8 e281e88 Superseded; pin repair.
0.3.12a0 0.2.17a0 0.16.9 1.0.8 b50f1b1 Superseded; pin repair.

[0.3.11a0] - 2026-07-04

  • Published tecrax==0.3.11a0 on PyPI aligned to rexecop==0.2.16a0, govengine==0.16.8 and sclite-core==1.0.8 (9fdc216).
  • Profile delta: none — dependency pin and public-truth markers only.
  • Repaired coordinated stack pin after rexecop==0.2.15a0 published with a stale tecrax==0.3.9a0 extra.

[0.3.10a0] - 2026-07-04

  • Published tecrax==0.3.10a0 on PyPI aligned to rexecop==0.2.15a0, govengine==0.16.8 and sclite-core==1.0.8 (6ffaa61).
  • Profile delta: none — dependency pin and public-truth markers only.

[0.3.9a0] - 2026-07-04

  • Published tecrax==0.3.9a0 on PyPI aligned to govengine==0.16.8, rexecop==0.2.14a0 and sclite-core==1.0.8 (8e3267e).
  • a9e4038, d8198ab: align dependency pins and public-truth markers with GovEngine 0.16.6 / 0.16.8 and RExecOp 0.2.12a0 / 0.2.14a0 before release.

Added

  • eefe5d1: first governed mutating slice configure_chrony_ntp_server with tecrax_chrony_ntp connector backend, mutation facts contract, active-profile gates and negative apply tests.
  • 10b82f1: profile-owned operator catalog metadata for all 14 active intents in operator_metadata.yaml, validated by validate_active_profile.py.
  • Operator runbooks under docs/runbooks/ (Proxmox/PBS, admin-tools, Samba AD, Windows pilots, AdGuard, Zabbix, Grafana, Wazuh, alerting, BookStack, GLPI, network devices, chrony/NTP); 27358b3 moved them from repo-root layout.
  • 759ab0f: Synology Zabbix community template runbook.

Changed

  • Kept the public documentation boundary explicit: operator-owned live wrappers, credentials, target addresses and private topology remain outside the repository.

Deferred

  • No active claims were added for arbitrary host management, CMDB sync, automatic discovery, production readiness or a second truth layer.

[0.3.8a0] - 2026-06-29

  • Declared the single supported alpha stack line for the current solo-development phase: tecrax==0.3.8a0, rexecop==0.2.11a0, govengine==0.16.5, and sclite-core==1.0.8.
  • Replaced broad cross-stack dependency ranges with exact pins so fresh installs use one coherent current stack line instead of mixing older alpha wheels.
  • Removed historical tag compatibility selection from CI; source checks now test the current main stack line only while older PyPI artifacts remain archived.

[0.3.7a0] - 2026-06-28

  • diagnose_monitoring_host now persists a profile-owned SCLite reaction_observation envelope in workflow shared state so RExecOp can plan deterministic reactions from a completed operation without constructing Tecrax domain facts in core.
  • Declared the diagnose_monitoring_host reaction-observation contract in intent metadata and extended the active-profile gate to reject drift between the declaration and workflow producer step.
  • Added source-line Tecrax trigger rules for bounded network.host_observed events: known catalog hosts plan collect_basic_host_inventory in dry-run mode, while unknown hosts escalate without execution.
  • Published the coordinated trigger/reaction profile line over govengine>=0.16.2,<0.17, sclite-core>=1.0.6,<1.1, and rexecop>=0.2.8a0,<0.3 without moving event intake, execution, governance, scheduler ownership or evidence truth into Tecrax.

[0.3.6a0] - 2026-06-27

  • Added stack-quality developer gates for ruff and mypy, plus the PEP 561 py.typed marker, so Tecrax profile code participates in the same typed tooling baseline as RExecOp, GovEngine and SCLite.
  • Added active-profile gates that keep fixture-only operations out of the active Tecrax profile and validate declared facts contract references.
  • Added the versioned tecrax.basic_host_inventory@1.0 facts contract with a packaged schema artifact, bounded model builder, and pure validator.
  • Added versioned local SSH/systemd facts contracts for NTP local health, Docker service health, host security posture, and NTP server observation.
  • Added versioned network-device inventory and network-management posture facts contracts for existing bounded legacy CLI observations.
  • Extended the host security posture slice with a bounded available-update count summary while continuing to exclude package names, repositories, changelogs and paths.
  • Added authenticated, read-only Zabbix T4 summaries for bounded problem counts and host/agent availability counts, using an operator-owned token outside git.
  • Recorded the T5 AdGuard, Portainer and Docker boundary decision: keep Docker systemd-only, AdGuard DNS/login-only and Portainer /api/status-only until a constrained read-only projection is proven.
  • Added the monitoring-host diagnosis v1 schema and deterministic bounded findings with stable reason codes over existing read-only component observations.
  • Added explicit monitoring-host unavailable reaction rules so unavailable component states escalate through traceable profile-owned findings instead of falling through to the unclassified fallback.
  • Added bounded monitoring-host escalation proposal vectors with negative tests for unknown intents, raw command payloads, unsafe evidence refs and secret-like explanations; proposals remain untrusted and never grant execution.
  • Split network-device CLI parsing into explicit TP-Link SG2452 and HPE V1910 parser families with sanitized golden fixtures and fail-closed unsupported output tests.
  • Activated the network management-posture read-only lite slice over existing inventory facts, with bounded SSH findings and example policy admission.
  • Added the VLAN and port-security read-only design checkpoint, keeping those observations out of the active profile until separate contracts and fixtures exist.
  • Expanded future-product activation gates for Proxmox, PBS, Wazuh, Samba, Grafana, Frigate, Hillstone, printers and future backup support while keeping placeholder intents out of the active profile.
  • Added CI/profile hardening for active-profile drift, future-product placeholders, premature VLAN/port-security actions and tracked secret/topology leak patterns.
  • Documented the HTTP action identity checkpoint for future Zabbix, AdGuard and Portainer API expansion while preserving RExecOp core neutrality.
  • Refactored fact normalizer storage so active normalizers share the same finalize_facts and shared_state write path.
  • Split active normalizers into host, services, network, diagnostics, and common modules while preserving the tecrax.internal_actions RExecOp entrypoint.
  • Published the coordinated domain-profile line over govengine>=0.16.1,<0.17, sclite-core>=1.0.5,<1.1, and rexecop>=0.2.7a0,<0.3 without adding mutation, credential management, scheduler ownership, a second policy engine, or a second truth layer.

[0.3.5a0] - 2026-06-24

  • Published the profile after GovEngine 0.16.0 and RExecOp 0.2.6a0 passed their public-index install gates.
  • Raised the GovEngine/RExecOp floors to the coordinated B2 release lines.
  • Removed the obsolete fixture extra that required RExecOp <0.2 while the package itself required RExecOp >=0.2.5a0.

B2 policy enforcement vector

  • The sanitized Ubuntu collect_basic_host_inventory example now declares profile-owned receipt, output-digest, timeout, step-count, and output-size policy controls.
  • Cross-repository tests verify that GovEngine projects those controls into a digest-bound admission consumed by RExecOp.
  • Tecrax still owns only the intent, workflow, connector shapes, validation, and policy-pack semantics. Runtime enforcement remains in RExecOp, governance in GovEngine, and canonical evidence/receipt truth in SCLite.

[0.3.4a0] - 2026-06-23

  • Added profile-owned target/operation catalog metadata and sanitized operator catalog examples.
  • Added bounded read-only Ubuntu monitoring-host and legacy network-device inventory/health slices with private runtime configuration kept outside Git.
  • Added deterministic profile-owned reaction vectors over existing read-only intents.