HydraIssues

HydraMancer: guide developers from the Unreal template to a verified body experience
closed feature Project: hydramancer Parent: #490 Reporter: 15 Sep 2026 18:46

Description

COMPLETED 2026-09-15: v0.2.11 image deployed and verified

The guide now runs from the published container image; the temporary binary update is superseded.

Root cause of the remaining blocker: the GitHub registry secret and user-level credential copies were stale. HydraSkin's documented system credentials at /etc/hydraskin/registry-auth.json and /run/containers/0/auth.json on pi-node-004 both authenticated successfully. Refreshed only Hydramancer's SCALE_REGISTRY_TOKEN using the verified system credential through cluster exec and an encrypted handoff; no global registry rotation or remote config-file edits.

Released v0.2.11 from source 9496b53. CI passed both binary and OCI jobs, including Go tests/vet and Linux amd64/arm64 verification:
https://github.com/cederikdotcom/hydramancer/actions/runs/35014889212

Reviewed the HydraSkin dry run, then applied hydraskin update hydramancer --tag v0.2.11 --apply on node-50ab5309. The container was recreated from the new image in 12 seconds with its state disk, domain labels and mesh proxy preserved. Runtime and Incus image ID both identify v0.2.11. The recorded digest matches the published manifest index:
sha256:674b693c97486a4e408c91de0e8500f9b3c70b6eb4cb51c9ed71149e25dd2299

Mesh and public health passed. Both public platform guides returned HTTP200 and matched the target-specific commands, UE5.7.3 baseline and WiVRn #741 link. Auto-update remains off. The access panel remains unconfigured as before; broader self-service #490/#484 is outside this completed first increment. MSI1060 sessions, WiVRn runtime and Perforce infrastructure were untouched.

Deployment documentation committed/pushed as 2995465:
https://github.com/cederikdotcom/hydramancer/blob/master/docs/runbooks/runbook.md
Live guide: https://hydramancer.experiencenet.com/experience

Historical implementation and temporary-deployment notes follow.

User-requested next step after the Hydragon template deployment, 2026-09-15. Turn the verified path into developer onboarding in HydraMancer.

First increment: replace obsolete root-SSH/rsync and missing-editor-receipt bypass advice on /experience with platform-specific instructions using hydraunrealtemplate validation scripts. Preserve iamnim sign-in and organization-scoped Perforce provisioning. Pin the current baseline to UE 5.7.3; Linux target files and Epic v26 clang 20.1.8 are required for Windows-to-Linux packaging. Separate preflight, compile/cook, artifact delivery, library staging, body installation, interactive flat rendering and connected-client/XR acceptance.

Expose an actionable creator/operator handoff with source revision, target platform/body, organization/district/venue, artifact URL/SHA256, launch path, logs and render evidence. Never imply that registering/promoting a record proves body installation. Show source-submit cooking as pending under #634; the Perforce watcher publishes already packaged Builds content. Link separate WiVRn validation task under Hydragon #615.

Known reference: native Linux build 2 renders on MSI1060 at bxl1/ad6. Chunky is the intended Windows development machine, but this Linux artifact is not installed/compatible there and its toolchain readiness is not established. Preserve dedicated Perforce and deployed Unreal typemap.

Acceptance for first increment: developer can select Windows or Linux target and follow commands matching repository scripts; all existing access-panel states still render; meaningful HTTP rendering checks and Go validation pass; source and deployment documentation are committed/pushed and the portal release is verified after deployment.

Remaining self-service automation belongs to parent #490 and access handoff #484: authenticated library actions, actual body readiness/install status and artifact delivery. Library #721 must be resolved before claiming automatic installation on a fresh body. No browser admin credentials or alternate identity system.

Implementation and live verification — 2026-09-15

The new guide is live at https://hydramancer.experiencenet.com/experience. Select platform=linux or platform=windows. Source b6e8d46, release authentication fix c287278, binary v0.2.9. Template evidence is pushed in hydraunrealtemplate commit efe2183. Master #615 updated with the verified handoff; WiVRn acceptance is the separate issue #741.

Checks passed: go test ./..., go vet ./...; HTTP rendering tests cover both targets, unknown-target fallback, signed-out/expired identity, no organizations, organization membership and escaping. Desktop Linux and narrow Windows browser rendering inspected. CI binary jobs for v0.2.9 and v0.2.10 passed, including tests/vet. After the live update, public and mesh health plus both target pages returned HTTP 200 and contained the correct commands and issue links.

DEPLOYMENT LIMITATION: normal OCI publication failed with registry HTTP 401. Both the existing SCALE_REGISTRY_TOKEN and a trial of the documented shared release token were rejected; Linux runner cached credentials were rejected too. The workflow retains dedicated SCALE_REGISTRY_TOKEN. No remote registry configuration or credential files were edited. Private Go access is fixed using GO_PRIVATE_TOKEN; Docker uses a BuildKit secret mount to keep credentials out of layers.

The documented built-in updater downloaded and checksum-verified the published arm64 v0.2.9 binary, followed by Incus restart on pi-node-004. The guide is running, but the underlying image is still v0.2.7. A container recreation would revert the guide. Keep this issue open until the image deployment is durable.

Current live configuration has no Perforce provisioning URL; that access panel is disabled as it was before the update. The existing auth/provisioning behavior is preserved and tested, but enabling self-service access remains operator configuration work under #484/#490. No new browser admin credentials or identity system were introduced. MSI1060's running flat session and WiVRn setup were untouched.

Durable log: https://github.com/cederikdotcom/hydramancer/blob/master/docs/runbooks/runbook.md
Failed image / successful binary run: https://github.com/cederikdotcom/hydramancer/actions/runs/35010254946