Live offsite fleet upgraded to a2
Activated on Hetzner at 2026-09-09 21:23:06 UTC, after independent verification of the actual public PyPI wheel bytes, installation into a new isolated venv, service-account import/native-path checks, and a fresh live Nitro challenge.
The live proof binds the actual inner TLS peer to the exact reproduced production
PCR0 and software version 0.1.0+a10323dede4413fbf295916b8ad12e3dbad7514e. It
authenticates verified Graviton5 hardware, RandomX v2.0.1, seven segments,
43,768,124 iterations and a 24-hour epoch. The signed state is warming, with no
current epoch. This is not an application-readiness or completed-recovery claim.
The solver was freshly confirmed idle before its brief restart. Both solver and mirror now use exact released client/native versions 0.2.0a2. The solver remains limited to nine full workers, CPUQuota=900%, MemoryHigh=22G, MemoryMax=24G, no swap and Nice=10. Both units are enabled/running with zero automatic restarts. The direct tunnel retained its original PID and was not restarted.
The initial mirror scan completed with zero artifacts and zero failures during production warm-up. A separate post-upgrade readback, running as the service account in the new a2 environment, verified all four previously retained replacement-diagnostic artifacts in both the primary Hetzner archive and scoped AWS S3 archive. No writes were needed for that check.
The old a1 venv and all artifacts, receipts, keys and checkpoints remain on the
host. Prior runner, configuration and unit bytes were preserved as content-addressed
read-only backups. The first failed PyPI-index attempt and explicit empty-venv
resume inventory are also retained remotely under
/opt/attested-relay-fleet-v2/upgrade-0.2.0a2/.