docs(dev): dual-distribution plan — the #77/#78 ADR#753
Merged
Conversation
The ratified architecture decision record for shipping Pithead through three channels from one release manifest: curl-installed Compose stack, flashable immutable appliance (Debian 13 + Rugix A/B, Podman Quadlet), and git clone. Records the rejected alternatives (bootc, Podman everywhere, apt channel) with evidence, the appliance mechanics (commit gate, migration-deadlock rule, Tor-routed updates, two-tier reset), the phase 0 go/no-go gates, and the risk register. Dev doc only — no behaviour change. Sequencing lives in #394. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Commits the ratified dual-distribution plan as
docs/dev/dual-distribution-plan.md, plus a CHANGELOG entry under Unreleased. Dev doc only — no behaviour change.What it records:
pithead-os: Debian 13 + Rugix A/B, Podman/Quadlet, rootful) · git clone. One release manifest across all three.Notify=healthyfloor), apt channel, k8s/Helm backends, repo split.pithead doctor --jsonas the Rugix commit gate; the migration-deadlock rule (data_migration-flagged chain services start only post-commit); Tor-routed resumable updates with manual clearnet fallback; labeled/data+ guarded/var/lib/containersmount; two-tier reset; first-boot wizard (pre-seed → Stack config editor: change any setting from the dashboard, applied via pithead (incl. P2Pool mode hot-swap) #33 form, HTTPS + console fingerprint + one-time token).Decision comments already posted on #77 and #78; #394 tracker body re-sequenced accordingly.
Checks:
lint-docs-voiceandmarkdownlintpass locally. Ponytail review: docs-only diff, lean already.🤖 Generated with Claude Code