diff --git a/plan/aws-deploy.md b/plan/aws-deploy.md index 91ffb4f1..1939722b 100644 --- a/plan/aws-deploy.md +++ b/plan/aws-deploy.md @@ -20,8 +20,8 @@ an operator who has not cloned this source tree and should not need to. This project already has the precedent for splitting a component out: `vibescrobble-index`, its query service and the canvas were extracted into -their own repository (see the `build!` commit that removed -`crates/vibescrobble-index` and the rest, and left [index](index.md) and +their own repository (see `ff72f82f`, the `build!` commit that removed +`didbot-index`, `didbot-query` and the canvas, and left [index](index.md) and [canvas](canvas.md) in `plan/` naming no crates, "for now", until that repository is published). This epic is the same move applied to `infra/pds/`: extract it, version it, and leave a pointer here rather than the Terraform diff --git a/plan/dedupe-audit.md b/plan/dedupe-audit.md index eeca910e..76e40190 100644 --- a/plan/dedupe-audit.md +++ b/plan/dedupe-audit.md @@ -56,7 +56,7 @@ record-based mechanisms (`bot.did.operator`, read from the operator's own repository). A straggler from that removal was still readable by an operator or a maintainer, fixed in this branch: -- **`crates/didbot-serve/src/onboarding.rs`** told an operator in +- **`didbot-serve`'s `/onboarding` page** told an operator in `ServerState::Provisioning` to run `aws ssm put-parameter` for an `attestation-secret` and an `operator-secret`. Neither parameter is read by anything (`infra/pds/templates/user_data.sh.tftpl` no longer touches @@ -88,9 +88,9 @@ lines. what was found and that the operator shared secret is gone. - [x] **`normalize_pds_url`** left the workspace with the hook crates, in `53814041`, so there is nothing to export. -- [x] **`crates/didbot-attest`** was reachable from no crate, no binary and - no test, and is deleted. -- [x] **`crates/didbot-serve/src/onboarding.rs`**'s `Provisioning` step list - no longer tells an operator to write `attestation-secret` and - `operator-secret` SSM parameters that nothing reads; it now reflects - that this state requires no operator action. +- [x] **The `didbot-attest` crate** was reachable from no crate, no binary + and no test, and is deleted. +- [x] **No step list tells an operator to write `attestation-secret` and + `operator-secret` SSM parameters**, which nothing reads. The steps that + did were on `didbot-serve`'s `/onboarding` page, which `1acd3e12` + removed. diff --git a/plan/infra-review.md b/plan/infra-review.md index 9bf686dd..9355918a 100644 --- a/plan/infra-review.md +++ b/plan/infra-review.md @@ -203,5 +203,5 @@ is measured from inside the server or from CloudWatch. With the interval dropped the default ten-second window applied, and `RestartSec=5` means five restarts span twenty seconds and never fall inside it — so the limit the comment describes had never once tripped. - Both moved to `[Unit]` in `infra/templates/user_data.sh.tftpl`, which + Both moved to `[Unit]` in `infra/pds/templates/user_data.sh.tftpl`, which `systemd-analyze verify` now accepts silently. diff --git a/plan/updates.md b/plan/updates.md index 340fbd4a..34be422d 100644 --- a/plan/updates.md +++ b/plan/updates.md @@ -57,8 +57,8 @@ this file points there rather than restating it. ## What the framework already establishes -Carried from `headquarters`' own `plan/publishing.md` and `web/scripts/`, which -is worth reading before building any of this: +Carried from the `publishing` epic and `web/scripts/` in `headquarters`' own +repository, which are worth reading before building any of this: - [ ] **Ownership is proved by a well-known file.** `/.well-known/site.standard.publication` carries the publication's diff --git a/scripts/doc-paths-baseline.txt b/scripts/doc-paths-baseline.txt index a3c317a7..6e822b31 100644 --- a/scripts/doc-paths-baseline.txt +++ b/scripts/doc-paths-baseline.txt @@ -7,8 +7,3 @@ docs/deployment.md: infra/site/pds.auto.tfvars plan/adversarial.md: crates/didbot-serve/src/ownership_poll.rs -plan/aws-deploy.md: crates/vibescrobble-index -plan/dedupe-audit.md: crates/didbot-attest -plan/dedupe-audit.md: crates/didbot-serve/src/onboarding.rs -plan/infra-review.md: infra/templates/user_data.sh.tftpl -plan/updates.md: plan/publishing.md