Skip to content

docs(dev): dual-distribution plan — the #77/#78 ADR#753

Merged
VijitSingh97 merged 1 commit into
developfrom
claude/dual-distribution-releases-9bdf8c
Jul 23, 2026
Merged

docs(dev): dual-distribution plan — the #77/#78 ADR#753
VijitSingh97 merged 1 commit into
developfrom
claude/dual-distribution-releases-9bdf8c

Conversation

@VijitSingh97

Copy link
Copy Markdown
Collaborator

Commits the ratified dual-distribution plan as docs/dev/dual-distribution-plan.md, plus a CHANGELOG entry under Unreleased. Dev doc only — no behaviour change.

What it records:

  • Channels: curl installer (Docker Compose, unchanged stack) · flashable immutable appliance (pithead-os: Debian 13 + Rugix A/B, Podman/Quadlet, rootful) · git clone. One release manifest across all three.
  • Rejected with evidence (kept as the ADR trail): bootc/image-mode, Podman-everywhere (Ubuntu 24.04 ships Podman 4.9 < the 5.0 Notify=healthy floor), apt channel, k8s/Helm backends, repo split.
  • Appliance mechanics: pithead doctor --json as the Rugix commit gate; the migration-deadlock rule (data_migration-flagged chain services start only post-commit); Tor-routed resumable updates with manual clearnet fallback; labeled /data + guarded /var/lib/containers mount; two-tier reset; first-boot wizard (pre-seed → Stack config editor: change any setting from the dashboard, applied via pithead (incl. P2Pool mode hot-swap) #33 form, HTTPS + console fingerprint + one-time token).
  • Phase 0 go/no-go table (netavark egress-firewall port first) and the phase 2 minimum-shippable bar (boot / atomic update / rollback / 7-day soak on the Comprehensive end-to-end infrastructure test matrix on a real Ubuntu server (full Monero + Tari node) #54 bench).
  • Risk register incl. Rugix bus factor (RAUC escape hatch), signing-key custody, Secure Boot + at-rest encryption decided out for v1.

Decision comments already posted on #77 and #78; #394 tracker body re-sequenced accordingly.

Checks: lint-docs-voice and markdownlint pass locally. Ponytail review: docs-only diff, lean already.

🤖 Generated with Claude Code

The ratified architecture decision record for shipping Pithead through
three channels from one release manifest: curl-installed Compose stack,
flashable immutable appliance (Debian 13 + Rugix A/B, Podman Quadlet),
and git clone. Records the rejected alternatives (bootc, Podman
everywhere, apt channel) with evidence, the appliance mechanics (commit
gate, migration-deadlock rule, Tor-routed updates, two-tier reset), the
phase 0 go/no-go gates, and the risk register.

Dev doc only — no behaviour change. Sequencing lives in #394.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@VijitSingh97
VijitSingh97 merged commit 1094c14 into develop Jul 23, 2026
15 checks passed
@VijitSingh97
VijitSingh97 deleted the claude/dual-distribution-releases-9bdf8c branch July 24, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant