feat(profile): add domain edition boundary [t_b45a5ac7] #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "kanban/t_b45a5ac7-task-073"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Kanban-Board: multi-alt
Kanban-Task: t_b45a5ac7
Goal and scope
Add the ALT P11 domain edition profile, SSSD/Samba client boundary, generic configuration templates, secret-free pending first-boot state, typed DNS/time/Kerberos preflight policy, and static rootfs validator. No package/image publication, domain join, remote AD object, runner, secret, or infrastructure mutation is included.
Changed files
Tests
zig fmt --check build.zig src/*.zig profiles/base/*.zig profiles/editions/domain/*.zig tests/*.zig— passed.zig build test --summary all— 64/64 passed.zig build test -Doptimize=ReleaseSafe --summary all— 64/64 passed.zig build -Doptimize=ReleaseSafe --summary all— 23/23 steps passed.python3 tests/verify-doc-links.py— 26 Markdown files passed.systemd-analyze verify profiles/editions/domain/templates/multi-alt-domain-enrollment.service— passed./etc/krb5.keytabrejected withBakedDomainCredential.git diff --check origin/main...HEAD— passed.CI and exact head
Head SHA:
9f93d32db68b22e85ea00518edfcf5265ae141dcBase SHA:
0ef62010c5937ed8ceaadda1dff8e03a05e8b5caForgejo CI/status: not claimed; reviewer must verify any exact-head status after PR creation.
Compatibility and provenance
Package names are immutable solver requests only; exact ALT P11 NEVRA, origins and digests remain owned by the Ember repository lock. The image validator requires ALT command paths and rejects baked keytab/SSSD/Samba identity. The profile does not claim a resolved closure, joined machine, RPM/APT compatibility, or QEMU boot evidence.
Residual risks and rollback
Residual risks: exact P11 package closure and command paths still require a repository-lock-bound rootfs test; privileged enrollment/compensation and disposable AD/QEMU E2E remain downstream; Winbind/multiple-forest support is explicitly outside MVP v1. Rollback is to revert this commit or select the prior composition lock without the domain layer; no stable artifact or external domain object was created.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.