Skip to content

[Deploy-S9] Bare-metal enterprise hardening (stable): cross-host HA + external secret store + signing #345

Description

@rickylabs

Scope

Bare-metal enterprise hardening — stable slice (decision D3 deferred set + D4 automation), re-scoped 2026-07-06 per the process-manager epic split (#510, owner-ratified OF-3):

  • Cross-host / target-level HA activation — e.g. N hosts behind a VIP, staged rollout across machines.
  • External secret-store adapters (Vault / cloud KMS) behind the shipped secrets port.
  • Automated deno compile code signing (Windows signtool, macOS Developer ID + notarization) via the hook point left by S4.

Explicitly out of scope (moved to the process-manager epic #510): per-host multi-instance / fork-of-one-app supervision — owned by the pm plugin's supervision core (#546, Backlog per owner OF-5 pick; concurrencyEnvVar self-fan-out ships in its milestone 1). Boundary line: deploy-lane HA = target-level (multiple servers); pm HA = per-host multi-instance/fork.

Target / adapter

Bare-metal (enterprise depth).

Acceptance criteria

  • Cross-host rollout + HA activation strategy (target-level; composes with the pm's per-host primitive).
  • External secret-store adapter (at least one: Vault or a cloud KMS) behind the secrets port.
  • Automated signing wired into the compile pipeline for at least Windows + macOS.
  • Tests / documented runbook.

Dependencies

S5 (beta hardening baseline) + S4 (compile hook) + #546 (pm per-host multi-instance primitive this slice composes with). Deferred to stable.

Tier / phase

STABLE · Phase 1 (stable) · milestone 0.0.1-stable

Parent epic: #327

Part of #327

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions