Skip to content

NA-0684 — the reference runbook stops naming retired operator hostnames - #42

Merged
Tebbens4832 merged 1 commit into
mainfrom
na0684-hostname-sanitization
Jul 29, 2026
Merged

NA-0684 — the reference runbook stops naming retired operator hostnames#42
Tebbens4832 merged 1 commit into
mainfrom
na0684-hostname-sanitization

Conversation

@Tebbens4832

Copy link
Copy Markdown
Member

Goals: G4, G1

Five occurrences in docs/NA-0004_reference_deployment_runbook.md become angle-bracket
placeholders — <attachments-public-host> on the reference-profile line, the TLS-termination
line, the Caddyfile block and the public probe; <relay-public-host> on the mandatory relay
preflight. Command structure is unchanged; one substitution per line.

Spine directive D619 (a8dab7f1…7ea65092, 539 lines), lane NA-0684, repo-local
D-0013.

The authority, and the property that bounds it

The retired public hostnames are operator-owned, retired from service, and their
registrations are held indefinitely
(operator, 2026-07-28, in D-1320's follow-up map). Live
instructions must stop naming them; dated history stays intact, and no history is
rewritten
— the mitigation for what git already carries is the registration hold, not
scrubbing.

The property, ruled and recorded verbatim in the spine decision: a line is in scope
when, read today, it directs traffic — a default, a command, a configuration a reader
copies. It is out of scope when it reports what was true — a measurement, a
decision, an evidence capture.

That is why the runbook changes and the NA-0003 / NA-0004 / NA-0005 evidence files do
not: 8 occurrences in tests/ are left byte-identical, and the lane's gate prints them
in every run
so a leave cannot hide inside a green result.

⚠ The ssh aliases stay — measured, not preferred

qatt is a project term: it names the canonical attachment-service contract
(DOC-CAN-006) and appears in this crate's own source; qsl is the project. Only the DNS
names are operator infrastructure.
This closes "should the aliases go too?" with evidence.

Impact

Documentation only. No source, no test, no workflow, no dependency, no behaviour. The runbook
still reads as a runbook — a reader supplies their own host where the placeholder sits.

No-regression

2 files: the runbook (5 substitutions) and DECISIONS.md (D-0013). Nothing else in this
repository is touched. Census for this repo: 13 occurrences over 41 tracked files / 13 764
lines
, split 5 live-instruction + 8 dated record, with the classes asserted to sum to
the raw count
— a lost hit crashes the instrument rather than being miscounted.

Tests-Vectors

infra-literal-scan --mode staged: clean (2 files, 33 lines). --mode tree: clean (41
files, 13 792 lines)
. ⚠ Note the committed gate cannot see this class — the retired names
are in no digest list and match no structural pattern — which is exactly why the lane brought
its own instrument, run RED first at base. No code paths touched, so there are no vectors
to add.

…r hostnames

Five occurrences in docs/NA-0004_reference_deployment_runbook.md become angle-bracket
placeholders: <attachments-public-host> on the reference-profile line, the TLS-termination
line, the Caddyfile block and the public probe; <relay-public-host> on the mandatory relay
preflight. Command structure is unchanged, one substitution per line.

AUTHORITY: the operator disposition of 2026-07-28 recorded in spine D-1320's follow-up map --
the retired public hostnames are operator-owned, retired from service, and their registrations
are HELD INDEFINITELY. Live instructions must stop naming them; dated history stays intact.
No history is rewritten anywhere: the mitigation for what git history already carries is the
registration hold, a standing operator action, not scrubbing.

THE PROPERTY THAT DECIDES WHAT MOVES, ruled by the Director and recorded verbatim in the spine
decision: a line is in scope when, read today, it DIRECTS TRAFFIC -- a default, a command, a
configuration a reader copies; a line is out of scope when it REPORTS WHAT WAS TRUE -- a
measurement, a decision, an evidence capture.

So the runbook is fixed and the NA-0003 / NA-0004 / NA-0005 evidence files are NOT: eight
occurrences in tests/ are left byte-identical, and the lane's gate prints them in every run so
the exception cannot hide inside a green result.

THE SSH ALIASES STAY, and that is a measured finding rather than a preference: qatt is a
PROJECT TERM -- it names the canonical attachment-service contract DOC-CAN-006 and appears in
this crate's own source -- and qsl is the project. Only the DNS names are operator
infrastructure.

Census for this repo: 13 occurrences over 41 tracked files / 13764 lines, split 5 live
instruction + 8 dated record, with the classes asserted to sum to the raw count.

infra-literal-scan (staged): clean, 2 files, 33 lines. (tree): clean, 41 files, 13792 lines.
Note the gate CANNOT see this class -- the retired names are in no digest list and match no
structural pattern -- which is why the lane brought its own instrument.
@Tebbens4832
Tebbens4832 merged commit a71d348 into main Jul 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant