Skip to content

Multiplayer U9: package private deployment and operator recovery #248

Description

@stephschofield

Outcome

Package and validate a private shared ECorp control plane with real authentication, private durable database/artifacts, safe lifecycle transitions, and an operator recovery path, while preserving the existing office and original execution lineage.

Current position

Pending as a complete unit. Local Azure foundation validation, the scoped Blob implementation/emulator contract, and the bounded startup/read-only lifecycle slice have evidence. They are not ARM/deployment validation, a complete drain/migration lifecycle, production sign-in, or shared-office acceptance. No Azure resource deployment is claimed by this checkpoint.

Acceptance criteria

  • Package server/web/database/private artifact storage with HTTPS/WSS, explicit allowed origins, trusted proxy handling, and no public database/storage exposure.
  • Require genuine production authentication and scoped secrets; disable demo actor selection and development bootstrap on the team endpoint.
  • Complete the reviewed standby/read-only, draining, migration, and activation boundaries; prove writes/workers cannot escape the selected lifecycle mode and fail closed on unsafe schema/authority states.
  • Preserve data across restart and validate backup/restore, schema upgrades, rollback constraints, runner credential recovery, and exact source/artifact provenance.
  • Use the single shared Corp/claim authority outcome tracked by Require a shared claim authority for contributor factories on the same backlog #161. Independent local ledgers or Project status do not provide distributed exclusion; do not re-key existing personal-Project execution histories.
  • Produce an operator runbook for independently enrolled machines and the selected private network, with explicit ownership, cost, secret, readiness, shutdown, and recovery boundaries.
  • Separately validate the actual operator-selected Azure/private environment, authentication, and network before deployment acceptance. New cloud effects and any migration of the current office require the appropriate explicit target/scope authority; filing this issue grants none.

Deployment research and bounded foundation preparation may accompany earlier units, but do not close this unit's product integration or live acceptance gates.

Dependencies

Blocked by #246 and #247. The shared-claim-authority requirement remains tracked in #161 and must be integrated rather than duplicated.

Coordination and execution boundary

Part of #239. This records the existing U1–U10 workstream, not a new execution request. All original R1–R14/M01–M37 requirements and review gates remain in force. Related issues retain their owners and lineage. Keep the existing office and retained evidence untouched. No factory:ready label, automatic dispatch, cloud deployment, publication, or merge is authorized by filing this issue.

Status reflects saved development checkpoints inspected September 13, 2026, not a new runtime verification.

Related pull requests

This is a non-closing related-work reference. Existing acceptance criteria, ownership, dependencies, Project status and execution authorization are unchanged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:docsProduct and engineering documentationarea:infraBuild, deployment, and operationsarea:serverControl-plane servermultiplayerMulti-human realtime behaviortype:featureNew product capability

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions