deploy/graviton5-STATUS.md

Graviton5 deployment status

Current, 2026-09-14: process-worker release 190b518 is deployed and warming with Mullvad up. Fresh Nitro verification and independent builds passed. Existing archives and solvers are preserved. Current evidence. The observations below describe earlier deployments.

Current rollout, 2026-09-11: non-debug production 30feebb is warming on 24 reserved CPUs (1โ€“24) with 8 GiB. The same EC2 instance was stopped, resized to c9g.8xlarge, 32 cores / 64 GiB, and restarted; its root disk and old recovery checkpoints were preserved. Parent CPUs are 0 and 25โ€“31. The old puzzle recovery job runs on CPU 31 at nice 19. The new puzzle has 96 groups of 4,843,750 hashes, exactly 465,000,000 in total.

Fresh Nitro verification confirms the release, c9g.8xlarge, Mullvad up and warming. Method and paste commands, 100 KiB POST, archive recovery, public GET transport, S3 COMPLIANCE retention and reproducible builds passed diagnostic checks. PyPI 0.2.0a4 is published. A separate eight-worker follower waits for this release's first puzzle while the previous epoch keeps solving. The public progress feed and dashboard are live. Full-work production completion and rollover are pending. Current evidence.

Historical observations (superseded where noted above)

Updated 2026-09-10. The separate parent has been provisioned and is running; real non-debug Nitro hardware verification and short-work end-to-end recovery have passed. Production epoch readiness is still pending its full calibration-sized warm-up.

Hardware parser/verification unit tests: five passed, including independent AWS botocore SigV4 and published AWS PCR4 vectors, and rejection of wrong CPUs, wrong parent/type, duplicated XML fields and debug PCRs. The credential bridge passed normal response and instance/role injection checks.

Private launch request, AWS output, resumable provisioning journal, SSH key and known-host records are under gitignored .local/. The key is mode 0600. No credentials are included in this document.

Actual non-debug Nitro diagnostic passed in-enclave CPU MIDR, fresh NSM PCR4 parent binding, authenticated live EC2 API evidence, fresh client attestation and SPKI binding, HTTPS GET, archive authentication, native offline RandomX solve, and exact record decryption. Diagnostic evidence. This uses only eight iterations per segment and proves no seven-day delay.

Production source commit 92bd47508d7ad48442c98148f6b4e09c6169ab5e uses 43,768,124 iterations per segment and requires Mullvad egress. It includes the native race/erasure/page-permission fixes. The non-debug image launched on 2026-09-10 at 02:39:40 UTC; fresh AWS attestation verified its exact PCR0, TLS peer, hardware and policy with mullvad_up=true, state=warming. Ordinary SDK verification rejects it until ready, and forwarding returns 503. One fixed Mullvad device, deluxe gerbil, is reused across boots; the two existing account devices were preserved. The nine-worker solver has the new PCR0 pin. Build, actual Nitro request/recovery and deployment evidence. The earlier a10323d image and its artifacts remain preserved; its warm-up was replaced. Two independent GitHub ARM builds and the separate measurement/signing job passed for this release; the signed report and an actual EIF verified locally. Full production warm-up completion and daily rollover remain pending. The measured host benchmark predicts about 25.14 hours to generate an epoch; the service fails closed if the next epoch misses the 24-hour rollover. Public Cloudflare transport is tracked separately by the parent task.

RandomX tuning candidate 490c4b99abe12f7593ea265f0f25060f1942c737 is built and independently reproduced by GitHub run 34440508901. Its Linux allocator requests aligned transparent huge pages. Pinned single-core parent tests improved from 479 H/s to 564โ€“569 H/s; native ARM hardening/vector checks passed. The live enclave is still production-mullvad-92bd475; activating the candidate would restart its in-memory warm-up and awaits an explicit restart decision under the no-discard instruction. Host THP policy and Nitro page reservations were restored. Tuning measurements and candidate build proof.

Fresh launch review, 2026-09-10 07:36 UTC

A new cryptographically verified Nitro challenge confirmed production 92bd475, non-debug PCR0, Graviton5 hardware, Mullvad up and state=warming with no active epoch. The parent, Hetzner SSH tunnel, mirror and solver controller are running; the current artifact index is empty. relay.girl.surgery does not resolve and no dedicated Cloudflare connector service is running on this parent.

The S3 artifacts/ prefix is now publicly readable/listable with all existing objects and a fresh scoped uploader copy hash-verified anonymously. Object Lock, public recovered-key publication and the third-provider replica remain absent. See the complete launch review.

Public endpoint deployed through Wrangler

https://relay.sparrowsystems.co now uses Worker attested-relay-v2-front, a managed custom domain and a VPC Service bound to the dedicated healthy tunnel's loopback HTTP origin. Public transport smoke and fresh Nitro/TLS checks passed from Hetzner using the SDK source user-agent fix. Application state is still warming; the original enclave/image/PCR and generation progress are preserved. The previous DNS-pending observation is superseded by public deployment evidence.