no-mistakes(review): Fix report-only gate, dedupe list, correct fleet map

This commit is contained in:
root
2026-09-12 18:38:19 +00:00
parent 7b8cc5f9ac
commit 4ea2d0309f
5 changed files with 85 additions and 76 deletions
+21 -38
View File
@@ -1,17 +1,8 @@
---
report_only_agents:
- koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129
# ⛔ GUEST/HOST-KEYED report-only list. This is the gate the GC executor MUST honour.
# An agent-name marker above is NOT sufficient: the scan unit is a guest, and an agent
# marker can silently miss the guest it lives on. Key exclusions on the guest/host.
report_only_guests:
- guest: 111
hostname: tdunna
ip: 192.168.68.129
node: storepve
reason: >
Theo's box. Captain ruling 2026-08-17, re-confirmed 2026-09-10: Theo handles
CT 111 himself. DETECT-AND-REPORT-ONLY at every threat level.
# ⛔ The guest/host-keyed report-only gate the GC executor MUST honour lives in the body
# "Hard gate" YAML block below — that block is authoritative and is the only copy.
kind: responsibility
name: disk-gc-threat-response
description: >
@@ -37,7 +28,7 @@ logged within 5 minutes of discovery.
## Scope
All 20 Proxmox guests (17 LXC + 3 QEMU VMs) via `pct-run` + 3 GPU bare-metal hosts via direct SSH.
All 20 Proxmox guests (17 LXC via `pct-run` + 3 QEMU VMs via direct SSH) + 3 GPU bare-metal hosts via direct SSH.
Docker hosts get special attention:
| Host | CT | Disk Risk | GC Strategy |
@@ -128,7 +119,8 @@ agent-name marker can silently miss the guest it lives on — it must never be t
**The authoritative machine-readable exclusion list is the YAML block below.** The executor
reads it at run time; `scripts/disk-gc-plan.py` turns a fleet scan into the action plan using it.
Extend the list here, never by hand-maintaining a second copy.
Extend the list here, never by hand-maintaining a second copy. The Execution loop below MUST
call that planner and MUST NOT reimplement the gate.
```yaml
# disk-gc report-only guests — authoritative. Keyed on guest/host, not agent.
@@ -146,41 +138,32 @@ report_only_guests:
let fleet = call disk-scanner
scope: all
let report_only = load-report-only-guests() -- from the YAML block above
-- The report-only gate is IMPLEMENTED IN scripts/disk-gc-plan.py and MUST NOT be
-- reimplemented here. That planner reads the contract's `report_only_guests` YAML block
-- and matches on guest id OR hostname OR IP, so the tested gate is the executed gate.
let plan = call disk-gc-plan
fleet: fleet
let threats = []
for ct in fleet:
if ct.usage_pct >= 95:
push threats { ct: ct.id, level: "CRITICAL", pct: ct.usage_pct }
else if ct.usage_pct >= 85:
push threats { ct: ct.id, level: "RED", pct: ct.usage_pct }
else if ct.usage_pct >= 75:
push threats { ct: ct.id, level: "AMBER", pct: ct.usage_pct }
-- sort by severity descending
sort threats by pct desc
for threat in threats:
-- HARD GATE: an excluded guest is alerted and skipped. No gc-executor call is
-- constructed for it at any level, so no GC command can be emitted for it.
if threat.ct in report_only:
for row in plan:
if row.action == "report-only":
-- Excluded guest: alert only. No gc-executor call is constructed for it, at any level.
call alerter
threat: threat
result: { action: "report-only", reason: report_only[threat.ct].reason }
threat: row
result: { action: "report-only", reason: row.reason }
continue
let result = call gc-executor
ct: threat.ct
level: threat.level
strategy: lookup-gc-strategy(threat.ct)
ct: row.target
level: row.level
strategy: lookup-gc-strategy(row.target)
call alerter
threat: threat
threat: row
result: result
call summary-reporter
fleet: fleet
threats: threats
plan: plan
```
## GC Strategies by Host Type
@@ -292,7 +275,7 @@ dangling images and orphaned build cache. No automated GC was in place.
## Incident Log: 2026-07-09 — amdpve docker bloat
### Discovery
Scheduled fleet disk scan via `pct-run` across all 20 Proxmox guests (17 LXC + 3 QEMU VMs) + 3 GPU bare-metal hosts.
Scheduled fleet disk scan across all 20 Proxmox guests (17 LXC via `pct-run`, 3 QEMU VMs via direct SSH) + 3 GPU bare-metal hosts.
> **Report-only gate applies to this scan:** CT 111 (`tdunna`, 192.168.68.129) is alerted but never
> garbage-collected at any level.
amdpve (.15) flagged at 78% (AMBER threshold: 75%).