Correct the artifacts upgrade runbook and the bootstrap exception's stated reason
CI / full-gate (push) Successful in 2m39s

This commit is contained in:
2026-08-05 22:46:05 +02:00
parent 1cf34a0d45
commit 78f5f72151
2 changed files with 9 additions and 6 deletions
+4 -2
View File
@@ -226,8 +226,10 @@ Revisit only if the stated reason stops holding.
files, `.dockerignore` the image).
- **A container whose output a human then edits or deletes runs as `--user "$(id -u):$(id -g)"`** —
the E2E runner (artifacts) and a lockfile edit, or the output is root-owned and needs `sudo`, which
a dev box may not have at all. Not universal: `bootstrap` writes `jwks.json` as root on a first
boot, and a generated signing key is the operator's to leave alone. Three consequences.
a dev box may not have at all. Not universal: `bootstrap` writes `jwks.json` as root when it is
absent on first boot — the committed dev key makes that rare, and when it happens the rotation
runbook's host-side `>` needs the file re-owned first. Valid while the dev key ships committed.
Three consequences.
`e2e-tests/artifacts/` is *tracked* (`.gitkeep`), since an absent bind-mount source is
daemon-created as root and that uid then cannot write it — which also makes a root-owned leftover
an upgrade hazard (README → Breaking changes). The runner image sets `HOME=/tmp`, since an