- Aligns the source candidate to
rexecop==1.0.0rc2,govengine==1.0.0rc2andsclite-core==2.0.1. The candidate wheel gate installs exact source snapshots, requires unconditionalpip check, verifies versions, provenance and installed origins, and runs status from an empty directory. Public-index resolution remains mandatory after RExecOp rc2 publication and before Tecrax publication; this is not mutation readiness, release or release-train authorization. - Declares explicit Chrony plugin execution postures and selects the
fixture_only/no_networkshape in the public example. A source-pinned T-205 regression uses real GovEngine v0.2 policy, approval, signature and revocation evaluation plus RExecOp lifecycle and the real Tecrax fixture backend to prove governed apply, deterministic post-I/O failure, a fresh approved recovery child, restored fixture state, conformant receipt and idempotent replay without new authority or I/O. Each of pre-read, apply, post-read and recovery uses a distinct backend created by the real factory. Fixture continuity is a private, lock-guarded, process-local boolean registry isolated by connector, target and normalized subnet; it is not durable, multiprocess, SCLite truth or RExecOp lifecycle persistence. This does not qualify the operator wrapper, live infrastructure, exactly-once, restart or crash recovery, mutation readiness, release or publication. - Advances immutable CI source coordinates to RExecOp
8a8609150388866a21afddca5bf773cd6ec120cd, GovEnginee65ad22ec25d74bbbb4969bd614981a8ed5e47c8, and SCLitec065d7a157665351054bacc7b5e3ae12b7cc9d98. Candidate-wheel governed functional smoke remains source-pinned and checks exact checkout, VCS, version, v0.2 and import origins. The source test job uses resolver-aware Tecrax editable installation while retaining the same provenance checks. A separate non-editable candidate-wheel gate uses those same exact sources and may not substitute another dependency graph. - Disables automatic retry for the mixed read/apply Chrony mutation candidate
by setting its profile retry budget to zero without expanding its allowlist
or error blocklist. The focused persisted-plan regression calls RExecOp's
actual retry classifier and separately proves its intrinsic
outcome_indeterminaterefusal. This covers F-017 profile alignment only; the separate fixture-only T-205 proof above does not extend this retry policy or qualify exactly-once, crash/power-loss or worker recovery, a private wrapper, lab or live operation, mutation readiness, release or publication. - Routes Chrony wrapper execution through RExecOp's runtime-owned incremental
combined-output capture with an exact
16384-byte configured default and lower exact-integer policy precedence. Overflow now fails before return-code or JSON handling and exposes only raw-free per-stream digests, truncation flags and observed byte counts; timeout exposes no partial output. Focused local-producer and StepExecutor regressions do not qualify a live wrapper, un-emitted bytes,lab_only, permits, consume-once behavior or mutation readiness. - Corrected public status for
0.4.0rc3: Chrony is a registered mutation candidate, while default RExecOpstable_read_onlyblocks apply before connector I/O and Tecrax is not mutation_ready. This does not change profile or connector behavior, readiness authority, package versions, pins, or release workflows. - Pins each CI source input to an immutable reviewed snapshot. Any advance requires explicit review and an exact workflow-coordinate update; source identity is not package compatibility or release qualification. The separately authorized F-001 production dependency-line remediation is recorded above.
- Declares profile-owned operation capability requirements for every active connector and independent outbound network-policy bindings for SSH and HTTP connectors, so RExecOp no longer derives governance requirements or destination allowlists from backend/runtime claims.
- Keeps the production-installed Chrony line fail closed at typed execution until a separately authorized dependency-pin and release decision consumes the delivered GovEngine approval-attestation contract. The source-pinned fixture proof does not turn operation admission alone into execution approval.
- Uses RExecOp's orchestration contract surface for observation and escalation artifacts instead of the removed SCLite stack-specific aliases.
- Pins the coordinated SCLite 2.0, GovEngine 1.0 and RExecOp 0.3 candidate train.
All notable Tecrax profile changes are documented here.
- Extended the Grafana infrastructure-dashboard runbook with a bounded Viewer-scoped service-account bootstrap: expiring runtime-only tokens, secret-safe administrator authentication, certificate verification, dashboard and datasource read smokes, an administrator-denial proof and exact-ID rollback without dashboard, datasource or plugin mutation.
- Added a management-plane TLS hardening runbook for network security devices: exact scope isolation, encrypted pre/post backups, active rollback access, tab-only CLI discovery, running-only protocol canaries, negotiated-version smokes from every management path and explicit handling of firmware defaults that do not represent the requested modern protocol set.
- Extended the network SNMP adoption runbook with bounded vendor-license lifecycle visibility: read-only collection, no persistent license identifiers or payloads, deterministic current-expiration selection, separate collector-health signals and non-overlapping 60/30-day Zabbix thresholds while keeping firmware entitlement as a vendor-confirmation gate.
- Clarified workload-aware monitoring hygiene: rotation-managed recording storage uses bounded free-byte and sustained-utilization signals instead of permanently firing percentage, ordinary HDD-latency or swap-occupancy alerts; Linux update visibility keeps metadata refresh separate from the read-only collector; network-device CLI discovery forbids contextual help after a syntactically complete configuration command prefix.
- Extended the infrastructure control-plane recovery runbook with an explicitly approved recurring network-device configuration capture: exact-device identity, running/startup equality, non-overlapping execution, encryption before durable storage, append-only off-host artifacts, checksum and decrypt/read gates, and minimal backup-health monitoring without automatic prune.
- Added a bounded network-security-device syslog-to-Wazuh onboarding runbook plus public-safe StoneOS decoder and local-rule reference artifacts. The gate keeps health monitoring in Zabbix, preserves existing Grafana dashboards, excludes bulk traffic/session/NAT/debug logging, and defers TLS, threat-rule promotion and GLPI routing to separate proofs.
- Extended that runbook with a fail-closed rsyslog framing-normalization fallback for non-standard TCP record terminators, including same-session continuity, least-privilege file access, bounded rotation, duplicate-path and rollback gates.
- Added bounded StoneOS threat-field decoding plus separate general-threat and observed log-only protocol-exception rules, without claiming unobserved block or prevention coverage.
- Added a safe StoneOS management-audit projection for successful and failed administrator login, logout and persistent configuration save. Raw operation commands and configuration differences remain excluded until deterministic redaction can prevent credential-like values from reaching SIEM storage. Successful login and logout remain at the standard Wazuh alert threshold so they are retained as audit evidence.
- Isolated the Chrony mutation fixture's RExecOp
lab_onlyposture inside the single execution-path test so the normal test process and stable runtime keep the default read-only posture. - Advances the source profile candidate to
0.4.0rc3with exact pinsgovengine==1.0.0rc1,rexecop==1.0.0rc1and frozensclite-core==2.0.0; profile semantics and activation posture are unchanged. - Pins every Tecrax GitHub Action to a reviewed full commit SHA and makes the existing public-truth gate reject future moving action refs.
- Added the controlled BookStack documentation publication runbook covering exact-target resolution, least-privilege publishing, Polish service-card quality gates, writable cache/upload ownership checks, revision-history rollback, secret scanning and idempotent post-publication validation.
- Added the BookStack application-aware backup runbook for supported CLI capture, runtime-memory encryption, append-only off-host custody, checksum validation and fail-closed plaintext cleanup without automatic NAS pruning.
- Expanded the generic librarian role runbook with mandatory GIMP, Inkscape, NAPS2 and PDF Arranger packaging and non-administrator smoke gates.
- Documented the promotion gate for a future governed Windows role-application convergence intent without claiming package custody or an active mutation.
- Hardened public deployment helpers so Windows endpoint apply requires an exact live-hostname assertion, while Samba AD bulk provisioning validates the complete CSV, duplicate/unsafe logins and every target group before the first mutation.
- Enforces Tecrax's production SCLite imports against the versioned wheel-shipped consumer contract through the existing public-truth CI gate.
- The prior
0.4.0rc2source candidate pinnedgovengine==0.17.0rc2andrexecop==0.3.0rc2for bounded HTTP destination admission and receipt binding.
-
Unpublished source candidate: aligns the profile package to
rexecop==0.3.0rc1,govengine==0.17.0rc1, andsclite-core==2.0.0for the SCLite P0 integrity/lifecycle hardening train. -
Publication boundary:
tecrax==0.3.21a0remains the latest published PyPI package until the candidate artifacts pass the complete local release gates. -
Added the Synology NAS domain-home and GPO drive-mapping runbook for moving from a one-user AD-auth pilot to a neutral staff
homemapping model without storing credentials, deleting NAS data or hand-building GPO objects. -
Extended the Synology NAS domain-home runbook with the DSM user-home-service check after domain rejoin or NAS rename, plus the known-good GPP Drive Maps shape for credential-free
homemapping. -
Added the Wazuh Dashboard RBAC operator-access runbook and a read-only RBAC audit helper for detecting missing administrator role-mapping rules without printing password hashes.
-
Added the Wazuh source noise hygiene runbook for bounded source-side suppression of routine successful operational telemetry before ticket routing, including manager alert-level and shared agent scan-cadence baseline guidance.
-
Added automatic public Tecrax runbook links to GLPI alert-ticket drafts when a matching alert category is available.
-
Added the Synology NAS AD-auth pre-change runbook for the planned service window, defining the member-file-server model, one-user pilot scope, AD-group-based access, rollback boundaries and no-delete guardrails.
-
Added the Samba AD delegated domain-join runbook for narrowing routine workstation joins from broad transitional rights toward OU-specific ACLs, with fallback removal kept behind a live join test.
-
Added Vaultwarden bootstrap and backup/restore-proof runbooks, keeping the service in bootstrap custody status until restore, offline break-glass, PKI restore and Proxmox root-of-trust hardening gates are complete.
-
Added the Vaultwarden application-backup and break-glass baseline runbook for root-owned SQLite/data archives, private checksum evidence and offline recovery boundaries without exporting vault contents.
-
Tightened the Vaultwarden bootstrap runbook to require HTTPS-only operator browser access even before final PKI material is available.
-
Added the PKI Center bootstrap runbook for an on-demand VM substrate, keeping production CA material, trust distribution and final HTTPS migration out of scope until custody and restore gates are defined.
-
Added the host-down routing policy runbook and Zabbix GLPI collector support for keeping selected on-demand host-down alerts shadow-only.
-
Recorded the PKI Center CA architecture decision as offline root plus on-demand intermediate without generating or documenting private CA material.
-
Recorded OpenSSL as the selected PKI Center CA engine while deferring final CA policies, issuance, renewal, revocation and autorotation procedure to hardening.
-
Added the PKI certificate lifecycle planning runbook for future CSR/SAN/FQDN, issuance, renewal, revocation, trust distribution and private inventory work without generating CA material.
-
Added the PKI HTTPS rollout planning runbook for future administrative service FQDN/SAN naming, migration order, TLS placement and trust-root dependencies without live TLS changes.
-
Added the Wazuh backup/restore decision runbook, keeping app-aware index export deferred until retention, custody and isolated restore gates exist.
-
Added the GLPI inventory scope runbook, defining a conservative Phase 1 infrastructure inventory baseline and deferring agents, endpoint discovery and network sweeps.
-
Added the basic incident-handling runbook for GLPI incident intake, triage, classification, containment, evidence custody, closure and follow-up without claiming compliance readiness or automatic containment.
-
Extended the admin-tools substrate runbook with the dedicated runtime-node model: admin-tools is the target for operator wrappers, policy files, private state and controlled Tecrax/RExecOp runtime, while development stays on the operator workstation.
-
Added operator-context file support for Zabbix GLPI live-candidate infrastructure host allowlists.
-
Extended the conservative Zabbix live-candidate allowlist with critical disk, backup failure, AD/DNS unavailable and core service unavailable classes while keeping known Frigate retention storage pressure shadow-only.
-
Added conservative Zabbix live-candidate filtering so host-down ticketing only applies to explicitly allowlisted infrastructure hosts, not ordinary endpoints.
-
Added a bounded Zabbix active-problem collector for GLPI shadow routing. It exports normalized alert events without storing API tokens or creating tickets.
-
Updated GLPI alert-ticket drafts and helper output to use Polish diacritics in operator-facing labels, categories and guidance.
-
Hardened the GLPI alert-ticket routing helper around private duplicate state, live API session cleanup and venv-based operator execution.
-
Added the alert-source hygiene checkpoint before live GLPI routing, including a Wazuh alert aggregation helper, routing classes and an operator runbook.
-
Added a public-safe GLPI alert-ticket routing helper and runbook. The helper accepts normalized Zabbix/Wazuh events, renders Polish operator-facing ticket drafts, applies duplicate suppression and keeps GLPI credentials outside Git.
- Current supported line:
tecrax==0.3.21a0, aligned torexecop==0.2.24a0,govengine==0.16.11andsclite-core==1.0.9. - Profile delta: none since
0.3.11a0.0.3.12a0-0.3.21a0are coordinated stack repair artifacts only: dependency pins, public-truth markers and the0.3.21a0wheel packaging repair for publicexamples/. 0.3.19a0was a source-only intermediate during release-train repair and was not published to PyPI.
| Tecrax | RExecOp extra pin | GovEngine | SCLite | Commit | Note |
|---|---|---|---|---|---|
0.3.21a0 |
0.2.24a0 |
0.16.11 |
1.0.9 |
07a55e2 |
Current line; includes public examples/ in the wheel. |
0.3.20a0 |
0.2.24a0 |
0.16.11 |
1.0.9 |
c526a5c |
Superseded; dependency/public-truth repair, missing wheel examples. |
0.3.18a0 |
0.2.23a0 |
0.16.9 |
1.0.8 |
08aeb41 |
Superseded; coordinated public line before automation-chain release train. |
0.3.17a0 |
0.2.22a0 |
0.16.9 |
1.0.8 |
341e231 |
Superseded; pin repair. |
0.3.16a0 |
0.2.21a0 |
0.16.9 |
1.0.8 |
48d8e87 |
Superseded; pin repair. |
0.3.15a0 |
0.2.20a0 |
0.16.9 |
1.0.8 |
26eab3e |
Superseded; pin repair. |
0.3.14a0 |
0.2.19a0 |
0.16.9 |
1.0.8 |
e7b8260 |
Superseded; pin repair. |
0.3.13a0 |
0.2.18a0 |
0.16.9 |
1.0.8 |
e281e88 |
Superseded; pin repair. |
0.3.12a0 |
0.2.17a0 |
0.16.9 |
1.0.8 |
b50f1b1 |
Superseded; pin repair. |
- Published
tecrax==0.3.11a0on PyPI aligned torexecop==0.2.16a0,govengine==0.16.8andsclite-core==1.0.8(9fdc216). - Profile delta: none — dependency pin and public-truth markers only.
- Repaired coordinated stack pin after
rexecop==0.2.15a0published with a staletecrax==0.3.9a0extra.
- Published
tecrax==0.3.10a0on PyPI aligned torexecop==0.2.15a0,govengine==0.16.8andsclite-core==1.0.8(6ffaa61). - Profile delta: none — dependency pin and public-truth markers only.
- Published
tecrax==0.3.9a0on PyPI aligned togovengine==0.16.8,rexecop==0.2.14a0andsclite-core==1.0.8(8e3267e). a9e4038,d8198ab: align dependency pins and public-truth markers with GovEngine0.16.6/0.16.8and RExecOp0.2.12a0/0.2.14a0before release.
eefe5d1: first governed mutating sliceconfigure_chrony_ntp_serverwithtecrax_chrony_ntpconnector backend, mutation facts contract, active-profile gates and negative apply tests.10b82f1: profile-owned operator catalog metadata for all 14 active intents inoperator_metadata.yaml, validated byvalidate_active_profile.py.- Operator runbooks under
docs/runbooks/(Proxmox/PBS, admin-tools, Samba AD, Windows pilots, AdGuard, Zabbix, Grafana, Wazuh, alerting, BookStack, GLPI, network devices, chrony/NTP);27358b3moved them from repo-root layout. 759ab0f: Synology Zabbix community template runbook.
- Kept the public documentation boundary explicit: operator-owned live wrappers, credentials, target addresses and private topology remain outside the repository.
- No active claims were added for arbitrary host management, CMDB sync, automatic discovery, production readiness or a second truth layer.
- Declared the single supported alpha stack line for the current solo-development
phase:
tecrax==0.3.8a0,rexecop==0.2.11a0,govengine==0.16.5, andsclite-core==1.0.8. - Replaced broad cross-stack dependency ranges with exact pins so fresh installs use one coherent current stack line instead of mixing older alpha wheels.
- Removed historical tag compatibility selection from CI; source checks now test
the current
mainstack line only while older PyPI artifacts remain archived.
diagnose_monitoring_hostnow persists a profile-owned SCLitereaction_observationenvelope in workflow shared state so RExecOp can plan deterministic reactions from a completed operation without constructing Tecrax domain facts in core.- Declared the
diagnose_monitoring_hostreaction-observation contract in intent metadata and extended the active-profile gate to reject drift between the declaration and workflow producer step. - Added source-line Tecrax trigger rules for bounded
network.host_observedevents: known catalog hosts plancollect_basic_host_inventoryin dry-run mode, while unknown hosts escalate without execution. - Published the coordinated trigger/reaction profile line over
govengine>=0.16.2,<0.17,sclite-core>=1.0.6,<1.1, andrexecop>=0.2.8a0,<0.3without moving event intake, execution, governance, scheduler ownership or evidence truth into Tecrax.
- Added stack-quality developer gates for
ruffandmypy, plus the PEP 561py.typedmarker, so Tecrax profile code participates in the same typed tooling baseline as RExecOp, GovEngine and SCLite. - Added active-profile gates that keep fixture-only operations out of the active Tecrax profile and validate declared facts contract references.
- Added the versioned
tecrax.basic_host_inventory@1.0facts contract with a packaged schema artifact, bounded model builder, and pure validator. - Added versioned local SSH/systemd facts contracts for NTP local health, Docker service health, host security posture, and NTP server observation.
- Added versioned network-device inventory and network-management posture facts contracts for existing bounded legacy CLI observations.
- Extended the host security posture slice with a bounded available-update count summary while continuing to exclude package names, repositories, changelogs and paths.
- Added authenticated, read-only Zabbix T4 summaries for bounded problem counts and host/agent availability counts, using an operator-owned token outside git.
- Recorded the T5 AdGuard, Portainer and Docker boundary decision: keep Docker
systemd-only, AdGuard DNS/login-only and Portainer
/api/status-only until a constrained read-only projection is proven. - Added the monitoring-host diagnosis v1 schema and deterministic bounded findings with stable reason codes over existing read-only component observations.
- Added explicit monitoring-host
unavailablereaction rules so unavailable component states escalate through traceable profile-owned findings instead of falling through to the unclassified fallback. - Added bounded monitoring-host escalation proposal vectors with negative tests for unknown intents, raw command payloads, unsafe evidence refs and secret-like explanations; proposals remain untrusted and never grant execution.
- Split network-device CLI parsing into explicit TP-Link SG2452 and HPE V1910 parser families with sanitized golden fixtures and fail-closed unsupported output tests.
- Activated the network management-posture read-only lite slice over existing inventory facts, with bounded SSH findings and example policy admission.
- Added the VLAN and port-security read-only design checkpoint, keeping those observations out of the active profile until separate contracts and fixtures exist.
- Expanded future-product activation gates for Proxmox, PBS, Wazuh, Samba, Grafana, Frigate, Hillstone, printers and future backup support while keeping placeholder intents out of the active profile.
- Added CI/profile hardening for active-profile drift, future-product placeholders, premature VLAN/port-security actions and tracked secret/topology leak patterns.
- Documented the HTTP action identity checkpoint for future Zabbix, AdGuard and Portainer API expansion while preserving RExecOp core neutrality.
- Refactored fact normalizer storage so active normalizers share the same
finalize_factsandshared_statewrite path. - Split active normalizers into host, services, network, diagnostics, and common
modules while preserving the
tecrax.internal_actionsRExecOp entrypoint. - Published the coordinated domain-profile line over
govengine>=0.16.1,<0.17,sclite-core>=1.0.5,<1.1, andrexecop>=0.2.7a0,<0.3without adding mutation, credential management, scheduler ownership, a second policy engine, or a second truth layer.
- Published the profile after GovEngine
0.16.0and RExecOp0.2.6a0passed their public-index install gates. - Raised the GovEngine/RExecOp floors to the coordinated B2 release lines.
- Removed the obsolete
fixtureextra that required RExecOp<0.2while the package itself required RExecOp>=0.2.5a0.
- The sanitized Ubuntu
collect_basic_host_inventoryexample now declares profile-owned receipt, output-digest, timeout, step-count, and output-size policy controls. - Cross-repository tests verify that GovEngine projects those controls into a digest-bound admission consumed by RExecOp.
- Tecrax still owns only the intent, workflow, connector shapes, validation, and policy-pack semantics. Runtime enforcement remains in RExecOp, governance in GovEngine, and canonical evidence/receipt truth in SCLite.
- Added profile-owned target/operation catalog metadata and sanitized operator catalog examples.
- Added bounded read-only Ubuntu monitoring-host and legacy network-device inventory/health slices with private runtime configuration kept outside Git.
- Added deterministic profile-owned reaction vectors over existing read-only intents.