Promote only after health checks and preserve tested rollback.
---
id: BB-ISSUE-84FBBB9E
type: issue
title: Luci deployment acceptance is blocked
specs:
- BB-SPEC-13004B6F
- BB-SPEC-9C4F71E1
---
# Luci deployment acceptance is blocked
## Deployment defects
- CI-user setup applies `ci` ownership to shared package and site roots used by existing `oli` deployment flows.
- Authorized-key import strips source, expiry, and other restrictions preceding key material.
- Non-default Luci peer ports are not propagated to klops firewalld.
- CI Quadlet deployment deletes the installed file before copying its replacement.
- Container sshd is backgrounded; its failure does not fail the container.
- Forced SSH sessions receive image-baked production values instead of deployment configuration.
- `just check-quadlets` scans no rendered Luci Quadlet.
- Image loading uses mutable `latest`, immediately restarts the service, retains no prior identity, and has no health-gated rollback.
- Shared deployment-script hashes caused the reviewed OpenTofu plan to replace ten klops resources rather than only Luci.
## Missing acceptance
- The manual E2E is non-hermetic and asserts the obsolete pre-dashboard UI.
- Statement coverage measured 87.3%.
- Mutation coverage measured 95.15%, below the declared 100% target.
- Local image build failed in Podman's overlay build-context setup.
- Public forced-SSH authentication failed with the available key.
- Production was observed on `265e469`, not reviewed HEAD.
## Closure sequence
1. Fix runtime and deployment blockers with regression tests.
2. Separate immutable image load from restart and retain the prior image and Quadlet.
3. Drain queue and active state; back up events and inbox.
4. Produce and review a Luci-only plan.
5. Canary HTTP, forced SSH, push, manual run, logs, cache, registry, package, site, interruption, and restart recovery.
6. Promote only after health checks and preserve tested rollback.