Expand description
Shared signing-payload shapes for host event-stream payloads. Adding a field invalidates existing signatures - bump signing version.
Structs§
- Activation
Failed Signed Payload - Closure
Signature Mismatch Signed Payload - Last
Confirmed AtSigned Payload - Soak-state attestation, bound to (hostname, rollout) so a stale signature
can’t replay across rollouts. Without this signature CP cannot trust the
agent’s claimed confirmation time (replay would short-circuit the soak gate).
Verified against
hosts.<hostname>.pubkeyfrom fleet.resolved. - Manifest
Mismatch Signed Payload - Manifest signed but agent’s content-bound checks failed (hash, host_set membership, or pinned-bytes drift).
- Manifest
Missing Signed Payload - Agent could not load + parse the advertised rollout manifest.
- Manifest
Verify Failed Signed Payload - Manifest signature didn’t verify against trust roots.
- Realise
Failed Signed Payload - Rollback
Triggered Signed Payload - Stale
Target Signed Payload - Verify
Mismatch Signed Payload