One-command enrollment, proven before mutation
Phase 2 turns the future node join into a deterministic, inspectable transaction. It verifies identity, preflight, recovery, trust and registry contracts while keeping every live mutation path locked.
Owner experience
Transaction groups
Tailscale pin, global collision checks, supported-host preflight.
Durable ledger, three-door snapshot, serial access convergence, existing host profile.
Ten-minute token metadata, pinned agent configuration, K3s join over tailscale0.
Exact Node identity, quarantine, node-pinned Job, token revocation, tokenless restart proof.
Paired non-dispatch registry publication and final audit receipt.
Trusted workstation
Owns the plan, ephemeral helpers, cluster observation, receipt validation and Git publication.
no reusable token in fileschecksum-verified helpersprotected labels controller-ownedCandidate cannot
Access Git credentials, cluster-admin kubeconfig, permanent K3s bootstrap authority or trusted scheduling state.
no self-trustno dispatch enablementno Phase 2 write commandPhase boundary
Phase 2: inspect, calculate, preview, validate, publish repository implementation.
Phase 3: bind one reviewed plan digest to one real candidate and unlock its transaction.
Paired source-of-truth preview
The two previews are content-addressed and must be published as one logical transaction. Enrollment cannot silently add dispatch capacity.
Package workflow
Return overdeck-k3s-phase2-result-<timestamp>.tar.gz to authorize Phase 3 design.