Skip to content

feat(deploy): installers — scopes, least-privilege ACLs, journaled operations, port registry [SD-3] #833

Description

@rickylabs

Part of #830.

MSI (via #825) / deb-rpm adapters + a narrow MaintenancePort behind the deploy target; per-user + per-machine scopes; elevation-once; updater least-privilege grants (scoped unit control + data-root-only); journaled install/repair/uninstall/purge state machines (claiming + ports.lock transaction, reverse-replay compensation, purge on a state-dir journal); per-platform reboot-barrier registration; Windows Job-Object wrapper wiring; machine-wide port-reservation registry; uninstall retain-by-default / --purge-data.

Depends on: #832, #831, PM-15 #526, PM-16 #527, PM-18 #529, #828, #825.

  • gate: install/repair/uninstall matrix on Win+Linux runners; transition-complete fault injection for install AND purge (early-effect boundaries, purge-after-root-gone, barrier roll-forward, claiming race)
  • gate: effective-ACL + least-privilege negatives (foreign unit / foreign data root refused); two-app port coexistence-or-clean-refusal; real Windows bootstrap replacement

Design source: PR #822 (rfc.md + plan.md rev 10, 9-cycle adversarial trail) in .llm/runs/rfc-single-deployment--orchestrator/. (plan.md §B.1/§B.3)

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions