Files
truf-server/openspec/changes/improve-worker-operator-cheatsheets/validation.md
T
2026-09-30 20:30:56 +03:00

3.8 KiB

Worker Cheatsheet Validation - 2026-09-30

Scope

Validation used isolated fake device tokens, private local state roots, a local TLS no-work fixture, unique Docker names/volumes, and fresh artifacts. It did not contact production, issue assignments, or use production credentials.

Initial audit

  • Windows package exposed install, start, stop, status, attach, logs, history, and doctor; watch was rejected as an invalid command.
  • The Linux image exposed the same command set, but an assembled native Linux package had no package-root launcher or preparation workflow.
  • First installation required token-bearing process arguments. Later lifecycle commands already read the private installed JSON configuration.
  • Active quickstart and operations instructions recommended server cap zero for routine local maintenance.
  • An unreachable-server negative check made stop --timeout 120 return a non-drained receipt with exit code 2 instead of reporting false success.

Fresh artifact identities

Artifact Identity
Final Windows ZIP SHA-256 210eb61e8d6c35b014b39b18b4dd7e28e1e057a11d57790188f7904487bac004
Windows package manifest 4572e349cead890c4efdc113e4d41285981086db7c0783fb67493fdeb6bac04c
Linux/Docker image sha256:8bc99d9e7e5f5f364de9b7d2b30100942b5ce3d9170a64e5abf0068ffc3d02c4
Linux package manifest 19907f29382bd2b5a1de13fd53a829e97a5626fbacbed8f4286071ba4d5a9bec

The final Windows ZIP was rebuilt after the last documentation correction. Its full lifecycle run used the same package-manifest identity; the rebuild changed only packaged operator-document bytes outside worker code authority.

Checked command matrix

Environment YAML install Doctor Start Status Attach Watch Stop
Windows package pass pass pass pass pass pass drained=true, exit_code=0
Native Linux package under /opt pass pass pass pass pass pass drained=true, exit_code=0
Docker image with persistent volume stdin pass pass pass pass pass pass drained=true, exit_code=0

The stopped Docker container reported status=exited, exit=0, and oom=false. attach and watch detached without stopping the verified worker on every environment.

Documentation result

The active general guide and operations runbook contain no cap-zero routine and no token-bearing install command. Separate Windows, native Linux, and Docker cheatsheets contain copy-paste install, start, stop, attach, status, and watch commands. Historical dated validation reports retain factual records of earlier cap-zero experiments and are not active instructions.

Final gates

  • Focused worker/package/documentation matrix: 157 passed, 3 skipped.
  • Windows packaged watch --help: pass.
  • Linux image launcher, preparation script, packaged cheatsheets, and shell syntax smoke: pass.
  • Worker Compose rendering: pass.
  • Python compilation: pass.
  • Strict OpenSpec validation: pass.

Release build

The final dist/release-20260930-linux release includes both native Linux and Docker Linux artifacts plus all platform sheets under cheatsheets/. All entries in SHA256SUMS.txt passed verification. The Docker bundle also contains the sheets and both workerctl helpers, and all eight internal checksums passed. The native archive contained no absolute paths, parent traversal, or links; its launchers retained mode 0755 and passed an extracted /opt preparation and CLI smoke test.

Release artifact SHA-256
Native Linux package e44717c9e84fc73d1d0734189da5b809c1c2271648868c05caea954bf46f6ebc
Docker Linux image archive 80a59f180e7c1e4e5861427d94b44605a54ba08ed12198c63c3ae98c35678f63
Trusted Linux package manifest a3e8b73855d3b0854c5891cb5a10ff892aa0929e24046d2ce6fd28a245317e82