feat(device-plane): accept core edge transport ADR

This commit is contained in:
Codex
2026-08-10 16:40:48 +03:00
parent 07224c6f0d
commit bf0bc50abb
27 changed files with 5034 additions and 26 deletions
@@ -0,0 +1,114 @@
{
"schemaVersion": "nodedc.device-edge.core-channel.v1",
"status": "accepted-design",
"authority": "DCPLATFORM-76/ADR-0001",
"direction": "device-gateway-core-initiated",
"transport": {
"protocol": "http2-bidirectional-stream",
"tls": "TLSv1.3-mutual-authentication",
"edgeListen": "0.0.0.0:8443",
"endpointSource": "device-control-core.edge-registration",
"browserAccess": "forbidden",
"bearerOnlyAuthentication": "forbidden",
"genericTcpForwarding": "forbidden"
},
"identity": {
"corePrivateKeyLocation": "synology-canonical-secret-boundary",
"edgePrivateKeyLocation": "edge-runner-managed-trust-boundary",
"privateKeysInArtifacts": false,
"certificateRotation": "generation-bound-audited",
"unknownOrRevokedEdge": "reject"
},
"networkBoundary": {
"synologyPublicIngress": false,
"synologyPortForward": false,
"vpsInitiatedSynologyConnection": false,
"subnetRoutes": false,
"exitNode": false,
"tailscaleSsh": false,
"dockerSocket": false,
"allowedEdgeListeners": [
"management-ssh",
"raw-device-tcp/9921",
"core-channel-mtls/8443"
]
},
"messageContract": {
"versioned": true,
"bounded": true,
"requiredKeys": [
"schemaVersion",
"edgeRegistrationId",
"channelGeneration",
"trackerSessionId",
"adapterProfileRef",
"sequence",
"eventAt",
"receivedAt",
"messageKind",
"correlationId"
],
"unknownKind": "close-logical-session",
"rawArbitraryDestination": "forbidden"
},
"acknowledgement": {
"trackerPackageAck": "only-after-bounded-core-acceptance",
"coreUnavailable": "do-not-acknowledge-tracker-package",
"deduplicationKey": [
"edgeRegistrationId",
"channelGeneration",
"trackerSessionId",
"packageNumber",
"contentDigest"
],
"deliverySemantics": "at-least-once"
},
"pilotLimits": {
"maxTrackerSessions": 128,
"maxSessionsPerObservedSource": 16,
"maxNewConnectionsPerMinutePerObservedSource": 60,
"maxBufferedBytesPerTrackerSession": 262144,
"maxAggregateBufferedBytes": 33554432,
"maxEnvelopePayloadBytes": 1048576,
"keepaliveSeconds": 15,
"deadPeerSeconds": 45,
"reconnectMinimumSeconds": 1,
"reconnectMaximumSeconds": 30,
"durableEdgeSpool": false
},
"pilotSlo": {
"trackerAckBeforeDurableCoreAcceptance": 0,
"lossOfCoreAcceptedPackages": 0,
"edgeReceiveToCoreAcceptanceP95Milliseconds": 2000,
"edgeReceiveToCoreAcceptanceP99Milliseconds": 5000,
"channelReestablishmentP95Seconds": 60,
"channelReestablishmentHardCeilingSeconds": 120,
"deadCoreDetectionHardCeilingSeconds": 45,
"malformedOrUnauthenticatedAcceptedRecords": 0,
"availabilityCommitment": "deferred-until-measured"
},
"commandBoundary": {
"typedOnly": true,
"rawPayload": "forbidden",
"durableEdgeQueue": false,
"sentEqualsSuccess": false,
"protocolAckMeans": "acknowledged-not-verified",
"unsafeAutomaticRetry": "forbidden"
},
"preserved": [
"device-control-core-database",
"device-gateway-core",
"hub-authentik",
"engine",
"foundry-runtime",
"gelios-production-path"
],
"rollout": [
"source-and-ops-contract",
"closed-port-synthetic-core-channel",
"negative-network-and-identity-acceptance",
"separate-public-device-ingress-transition",
"one-device-pilot"
],
"rollback": "restore-closed-port-predecessor-without-vps-initiated-backhaul"
}
@@ -0,0 +1,22 @@
{
"schemaVersion": "nodedc.device-edge-vps.backhaul.v1",
"mode": "tailscale-userspace-key-only-ssh-local-forward",
"runtimeHost": "koffyvngij",
"component": "device-edge-vps",
"tailscaleNodeName": "nodedc-b2-vps",
"tailnetDnsSuffix": "tail8d32ac.ts.net",
"targetHost": "100.109.216.21",
"targetPort": 2222,
"targetHostKeyFingerprint": "SHA256:QERJ5CIUXRj0nLChGT6HMtoX+WTaeaEY5ZgaWqT8d30",
"targetUser": "device-backhaul",
"runtimeUser": "nodedc-backhaul",
"credentialBoundary": "private-key-readable-only-by-nodedc-backhaul",
"permitOpen": "127.0.0.1:9921",
"localForward": "127.0.0.1:19921",
"proxy": "tailscale-userspace-socks5-127.0.0.1:1055",
"keyIdentity": "nodedc-device-edge-vps-backhaul",
"publicB2Ingress": "disabled",
"commandTransport": "disabled",
"gelios": "untouched",
"rollback": "remove-backhaul-unit-and-user-restore-foundation-key-ownership"
}
@@ -0,0 +1,22 @@
{
"schemaVersion": "nodedc.device-edge-vps.foundation.v1",
"mode": "static-runtime-key-only-ssh-default-deny-no-public-b2",
"runtimeHost": "koffyvngij",
"publicIpv4": "155.212.211.15",
"component": "device-edge-vps",
"nodeVersion": "22.23.2",
"nodeArchiveSha256": "d60acfe00a2932254bb0ad20e01b0d74397a0875595de719654b214f4b03f307",
"tailscaleVersion": "1.102.2",
"tailscaleArchiveSha256": "ad2cde12f8de95f7b93a1e0401e652291c603d42b9d60a33fb1741eb38ab04d8",
"serviceUser": "nodedc-edge",
"managementSsh": "root-key-only",
"managementKeyFingerprint": "SHA256:DYYy1E3DaxIQGC0jnsW6SP7gXdBHUy3A1zn4pvgVUEw",
"serverHostKeyFingerprint": "SHA256:mhqNn2S6zstkYL7VFdvt3SYHv1nLjB4J7/s57RrKG6w",
"firewall": "default-deny-public-22-only",
"tailscale": "userspace-needs-external-enrollment",
"backhaulKey": "runner-managed-new-ed25519",
"publicB2Ingress": "disabled",
"commandTransport": "disabled",
"gelios": "untouched",
"rollback": "restore-exact-ssh-firewall-service-and-absent-runtime-predecessor"
}
@@ -0,0 +1,27 @@
{
"schemaVersion": "nodedc.device-edge-vps.relay.v1",
"mode": "public-b2-opaque-bounded-relay",
"runtimeHost": "koffyvngij",
"publicIpv4": "155.212.211.15",
"component": "device-edge-vps",
"runtimeUser": "nodedc-relay",
"credentialAccess": "none",
"listen": "0.0.0.0:9921",
"health": "127.0.0.1:18221",
"privateUpstream": "127.0.0.1:19921",
"sourceAdmission": "public-ipv4-only",
"maxSessions": 128,
"maxSessionsPerAddress": 16,
"maxConnectionsPerMinutePerAddress": 60,
"maxTrackedSourceAddresses": 4096,
"maxBytesPerDirection": 67108864,
"sessionTimeoutMs": 300000,
"protocolInspection": "gateway-owned",
"identityTrust": "claimed-not-ownership-proof",
"discoveryLifecycle": "quarantine",
"commandTransport": "disabled",
"gelios": "untouched",
"dns": "unchanged",
"b2Routes": "unchanged",
"rollback": "close-9921-stop-relay-remove-user-and-restore-accepted-backhaul"
}
@@ -0,0 +1,28 @@
{
"schemaVersion": "nodedc.device-plane.backhaul-vps-enrollment.v1",
"mode": "rotate-backhaul-client-mini-to-vps",
"predecessorPatchId": "device-plane-backhaul-target-tailnet-serve-20260804-002",
"predecessorArtifactSha256": "219408705dd4d80a962ed00eeb53a69df0b9ab6458443734d5c9cd1d1f795eba",
"sourceAction": "publish-vps-enrollment-marker-only",
"runtimeAction": "rotate-authorized-key-and-recreate-backhaul-target",
"selectedServices": [
"device-backhaul-target"
],
"preservedServices": [
"device-control-core",
"device-gateway",
"device-postgres"
],
"previousEnrollment": "device-edge-backhaul.pub",
"nextEnrollment": "device-edge-vps-backhaul.pub",
"nextKeyFingerprint": "SHA256:HHTiDYiCRxSiKjBLCip6JMSzGfLGrDz5g8SIkosJcVw",
"permittedTarget": "127.0.0.1:9921",
"tailnetAddress": "100.109.216.21",
"dockerPortPublication": "disabled",
"routerNatFirewall": "unchanged",
"edgePublicIngress": "disabled",
"funnel": "disabled",
"commandTransport": "disabled",
"gelios": "untouched",
"rollback": "restore-previous-authorized-key-and-recreate-target"
}
@@ -0,0 +1,33 @@
{
"schemaVersion": "nodedc.device-edge.superseded-transport.v1",
"status": "frozen",
"frozenAt": "2026-08-10",
"authority": "DCPLATFORM-76/ADR-0001",
"reason": "The public VPS must not initiate a private connection to Synology.",
"successor": "nodedc.device-edge.core-channel.v1",
"forbiddenForNewPlanOrApply": [
"nodedc.device-edge-vps.backhaul.v1",
"nodedc.device-edge-vps.relay.v1:privateUpstream=127.0.0.1:19921",
"nodedc.device-plane.backhaul-vps-enrollment.v1",
"tailscale-userspace-key-only-ssh-local-forward",
"rotate-backhaul-client-mini-to-vps"
],
"historicalSource": [
"deployment/device-edge-vps-backhaul-v1.json",
"deployment/device-edge-vps-relay-v1.json",
"deployment/device-plane-backhaul-vps-enrollment-v1.json",
"deployment/tailscale-device-edge-policy.hujson",
"vps/config/backhaul_ssh_config",
"vps/systemd/nodedc-b2-backhaul.service",
"vps/systemd/nodedc-b2-relay.service",
"infra/deploy-runner/build-device-edge-vps-artifact.mjs:backhaul|relay",
"infra/deploy-runner/build-device-plane-backhaul-vps-enrollment-artifact.mjs",
"infra/deploy-runner/nodedc-b2-vps-deploy:backhaul|relay"
],
"testOnlyReconstruction": {
"environment": "NODEDC_ALLOW_SUPERSEDED_TRANSPORT",
"value": "test-only",
"deployCandidate": false
},
"runtimeMutationInPhase0": false
}
@@ -0,0 +1,55 @@
// NODE.DC tailnet policy: user devices retain self-access while the public
// Robot2B Device Edge VPS receives one purpose-bound egress grant.
{
"tagOwners": {
"tag:device-edge-vps": ["autogroup:admin"],
},
"hosts": {
"device-plane-backhaul": "100.109.216.21",
"nodedc-admin-macbook": "100.114.248.4",
"nodedc-device-edge": "100.64.19.31",
},
"grants": [
// Preserve unrestricted connectivity only between devices owned by the
// same authenticated tailnet member. Tagged service nodes are excluded.
{
"src": ["autogroup:member"],
"dst": ["autogroup:self"],
"ip": ["*"],
},
// The public VPS can reach exactly the private SSH forwarding target.
{
"src": ["tag:device-edge-vps"],
"dst": ["device-plane-backhaul"],
"ip": ["tcp:2222"],
},
],
// Preserve the existing Tailscale SSH policy for user-owned devices.
"ssh": [
{
"action": "check",
"src": ["autogroup:member"],
"dst": ["autogroup:self"],
"users": ["autogroup:nonroot", "root"],
},
],
// These assertions are evaluated by Tailscale before every policy save.
"tests": [
{
"src": "tag:device-edge-vps",
"proto": "tcp",
"accept": ["device-plane-backhaul:2222"],
"deny": [
"device-plane-backhaul:22",
"device-plane-backhaul:5001",
"nodedc-admin-macbook:22",
"nodedc-device-edge:22",
],
},
],
}