You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Snapshot, revert, and delete behind an explicit destructive-operation review and permission — FM-603: the unforgeable review token (SHA-256 over the exact operation bytes, validated in Operations::create) and the proxmox.destructive permission (catalog 40)
Compensation and reconciliation when a clone or snapshot fails midway — FM-603: every post-UPID failure carries the UPID and node for reconciliation; nothing is deleted on failure
Recorded/simulated API tests plus a dedicated real-cluster suite — FM-603: e2e through the real worker plus live verification on the integration PVE 9.2 host (create/idempotent re-run/delete confirmed on the host)
M6 acceptance (exit gate) — complete 2026-10-02
All PRs target the dev branch. Plan: docs/planning/m6-acceptance.md.
Tracking issue. Dependency and status checklists only — implementation stays in narrow linked issues.
Outcome
Template, clone, snapshot, revert, and delete operations are available only after idempotency and destructive-operation review.
Supersedes
Replaces the "VM reset/clone/snapshot" and "golden-image / template workflow" scope items of #3.
Depends on
Scope checklist
M6 acceptance (exit gate) — complete 2026-10-02
All PRs target the
devbranch. Plan:docs/planning/m6-acceptance.md.agent:codex) — merged, PR #231, PR #236agent:claude) — merged, PR #238, PR #245agent:glm) — merged, PR #246Constrained by
docs/PLAN.md— M6; ADR-0008Non-goals