docs: ifrit's gate is #414, and two of its three prerequisites are done (#421) - #490
Merged
Merged
Conversation
…ne (#421) #96 closed on 2026-09-04, on the decision and on the runbook. The purchase it deferred had no tracker for five days, #421 was opened on 2026-09-09 to be it, and this repository went on describing the work through the closed issue for another eight days. #421's own body names the first of the two passages below; the second it does not, and that one is the more expensive of the two. roadmap.md's Infrastructure entry was keyed to #96 and ended "What is left is the purchase itself and the build" — which reads as though the money were the next thing to spend. It is not: the purchase is gated on #414's domain and is the last on the estate's list. Everything still to buy, at the top of the same file, has said exactly that since #421 was opened, so the file has been contradicting itself for eight days. The entry is now keyed to #421 and says so, in the habit this file keeps of naming what it used to say. Its ADR-0014/ADR-0017 body paragraph is unchanged, because it was never wrong. The gate sentence named three issues and two of them have closed: #234's tripwire armed and verified 2026-09-08, #235 decided the same day with the hardening it owed done 2026-09-09. Both are recorded in full under Done four hundred lines below, so the entry cites the dates and leaves the evidence there — two places holding the same fact is what this file's header warns about. What is left of the gate is #101, which is an umbrella rather than a thing anyone builds, so the entry names what it means here instead: #414 and #266/#267. build-the-playground.md §0 was the more expensive one. Its three-row table read as three open to-dos, and two of those rows had been closed for over a week, so a reader arriving on build day would re-arm an armed tripwire and re-harden a hardened BMC. The table gains a State column: #101 is marked as the one that still gates the build and is decomposed into #414 and #266/#267; #234 says armed and verified with its date and that nothing here re-arms it; #235 says decided, with the 2026-09-09 hardening listed and pointed at SECURITY.md's row rather than restated. The blocking now happens in a paragraph under the table, where it cannot be skimmed past as a row. build-the-lab-guest.md's address table said `Saruman` .20 "(after #96)". The move to 10.0.30.20 is §3 of the playground runbook and step 2 of #421's order of work, so it is after #421. Not touched, deliberately: the buy table and the "One more, later" ifrit paragraph, which were already right and which check_buy_list ties to README's count; ADR-0015's "ifrit is unpurchased", which is still true; the #96 references in ADR-0014, -0017, -0029 and -0031 and in the #86 Done entry, which are history and correct as history (ADR-0001). make lint and make check-docs both pass. Refs #421. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Three documents that still described
ifrit's purchase through the closed #96.docs/roadmap.md— the Infrastructure entry is re-keyed from#96 to
#421, and its tail — "What is
left is the purchase itself and the build" — is replaced with the gate as it
actually stands: Arm the lab tripwire on ImaginationLAN (ADR-0014) #234 and Decide whether the iLO (shiva) stays on the lab segment #235 closed (2026-09-08 and 2026-09-09), and what
remains is ADR-0007: build the defended estate on Saruman — the umbrella #101, which here means the domain (Build the lab Windows domain on Saruman (ADR-0029) #414) and the SOC stack
(Run Wazuh on Saruman — the heaviest component in ADR-0007 #266/Run Velociraptor on Saruman #267). Its ADR-0014/ADR-0017 body paragraph is untouched.
docs/runbooks/build-the-playground.md— §0's prerequisite table gains aState column. Two of its three rows had been closed for over a week while
the table went on reading as three open to-dos. The blocking moves into a
paragraph beneath the table.
docs/runbooks/build-the-lab-guest.md— one cell:Saruman.20 is afterBuy ifrit and build the range (ADR-0017) #421, not after Procure ifrit and build the playground — after the main network is finished #96.
Why
#96 closed on 2026-09-04 on the decision and the runbook, leaving the purchase
without a tracker; #421 was opened on 2026-09-09 to be it. These three files
kept pointing at the closed issue for another eight days.
The roadmap was contradicting itself for that whole period: Everything still to
buy at the top of the file has said since #421 opened that
ifritis "the lastpurchase on this list, not the next", while the Infrastructure entry eight
hundred lines down read as though the money were the next thing to spend. This
is the failure that file's own header warns about, and
2c0d93ais theprecedent — the same reconciliation done for
smauglast night.§0 was the costlier of the two. A reader arriving on build day would have
re-armed an already-armed tripwire and re-hardened an already-hardened BMC.
Nothing about the purchase or the build changes. #421 stays open: the
purchase is gated on #414 and remains unmade.
Blast radius
Documentation only — no stack, rule, dashboard, firewall or secret is touched.
Deliberately left alone: the buy table and the
One more, laterifritparagraph (already correct, and tied to README's count by
check_buy_list);ADR-0015's "
ifritis unpurchased", which is still true; and the#96references in ADR-0014, -0017, -0029, -0031 and in the #86 Done entry, which are
history and correct as history (ADR-0001).
Verification
No counted fact moves, so
check_docs' output is identical to the baselinetaken before the edits. The three added relative links
(
ADR-0030,ADR-0033,SECURITY.md) were each resolved on disk by hand,since CI runs no link checker.
secrets/*.sops.yamlmake validatepassesRefs #421.
🤖 Generated with Claude Code