# IEI → Eagle Migration — Detailed Work Record — 2026-09-17

## Objective
继续将 IEI production 环境安全迁移到 Eagle，同时保持 IEI 可作为 rollback source。今天重点完成 Protected Small Data production capture，并建立迁移 checkpoint。

## A. Eagle one-shot receiver

在 Eagle：
`bash ~/RemoteOffice/review/protected-small-data-20260917/human-eagle-receiver-command.txt`

Receiver 成功进入：
`EAGLE_ONE_SHOT_RECEIVER_READY`

Capture ID:
`small-20260917-c64cf47955104069`

Eagle receiver 保持等待，期间没有启动 production service 或进行 cutover。

## B. IEI dedicated migration SSH key

在 IEI 启动 ssh-agent：
`eval "$(ssh-agent -s)"`

结果：
`Agent pid 5707`

加载 migration key：
`ssh-add ~/.ssh/iei_to_eagle_migration`

成功：
`Identity added: /home/foo/.ssh/iei_to_eagle_migration (iei-to-eagle-migration)`

验证 fingerprint：
`ssh-add -l`

确认：
`SHA256:YRwl1op6nDOBX0xJwqZKQLVRMzcpLdr1vP+VvjaC4ec`

## C. Protected Small Data production capture

从 IEI 执行 Codex 已准备的 capture command：
`ssh foo@eagle 'cat /home/foo/RemoteOffice/review/protected-small-data-20260917/human-capture-command.txt' | bash`

IEI 输出：
- `TRANSPORT_READY_NO_SOURCE_READ_YET`
- `CAPTURE_DASHBOARD_START`
- `CAPTURE_DASHBOARD_CHECKED`
- `CAPTURE_MONITOR_START`
- `CAPTURE_MONITOR_CHECKED`
- `CAPTURE_CREDENTIALS_START`
- `CAPTURE_CREDENTIALS_CHECKED`
- `PROTECTED_SMALL_CAPTURE_VERIFIED`

涉及三项 protected data：
1. `/opt/remoteoffice-data/dashboard/device_presence.sqlite3`
2. `/opt/remoteoffice-secrets/qnap-monitor-password`
3. `/root/.qnap-credentials`

Secret values 没有显示到 terminal。

Eagle receiver 随后输出：
- `RECEIVER_DASHBOARD_VERIFIED`
- `RECEIVER_MONITOR_VERIFIED`
- `RECEIVER_CREDENTIALS_VERIFIED`
- `CAPTURE_VERIFIED_PUBLISHED`

结论：
三项 Protected Small Data 已完成 source capture、receiver verification 和 atomic publication。此 subset 现在冻结，除非有明确 corruption evidence 或人工授权，否则不要重新读取/传输。

## D. Protected Filedrop ZIP checkpoint

之前完成的 protected ZIP subset 保持冻结：
- 17/17 ZIP
- 135,742,078,994 bytes
- 126.42 GiB

今天 checkpoint 明确确认：
- Frozen ZIP payload bytes read: ZERO
- 没有重新读取 ZIP content
- 没有重新 hash
- 没有重新 copy

## E. Codex checkpoint

Codex 创建：
`review/iei-to-eagle-checkpoint-after-protected-small-2026-09-17.md`

Codex summary：
- PASS: Frozen ZIPs 17/17, 135,742,078,994 bytes / 126.42 GiB
- PASS: Published three-item small-data capture confirmed from metadata
- PASS: Frozen ZIP payload bytes read = ZERO
- PASS: IEI production modified = NO
- INCOMPLETE: HA final consistency
- INCOMPLETE: mutable final sync
- INCOMPLETE: Eagle production setup
- INCOMPLETE: cutover/writer coordination
- INCOMPLETE: functional and recovery validation
- INCOMPLETE: temporary sudo removal
- INCOMPLETE: rollback validation
- UNKNOWN used where evidence was insufficient rather than guessing

Codex recommended next phase:
Planning-only HA consistency and cutover/rollback readiness. A separately authorized graceful-stop capture window is recommended for HA. Nothing was executed.

## F. Migration status at end of day

### Completed / frozen
- Phase 1 audit
- Phase 2A staging
- RemoteOffice/FRO application tree staging
- Protected Filedrop ZIP: 17/17, 126.42 GiB
- Protected Small Data: 3/3 verified and published

### Still incomplete
1. Home Assistant final consistent data handling
2. Mutable data final sync
3. Eagle production configuration/service setup
4. Cutover coordination and prevention of two production writers
5. FRO/Qingtian/RemoteOffice/Media/HA functional validation
6. Watchdog/reboot/recovery validation
7. Remove temporary Eagle NOPASSWD sudo after migration
8. Final IEI rollback validation

## G. Safety state / decisions
- IEI production was not modified by today's checkpoint.
- No final cutover performed.
- No two-writer production state created.
- Frozen ZIP subset remains untouched.
- Protected Small Data is now frozen after successful verification/publication.
- IEI remains production and rollback source until Eagle validation is complete.
- Do not remove temporary Eagle migration sudo permission until final migration cleanup.
- Do not declare the whole migration complete yet.

## H. Tomorrow's starting point
Start directly with **Home Assistant final consistency planning**.

First task:
Have Codex inspect existing migration evidence/configuration and design the minimum-risk HA consistency procedure, including graceful stop window, consistent capture, verification, restart/rollback and expected downtime.

Planning first; do not stop HA or perform cutover until the procedure is reviewed and explicitly authorized.

After HA:
HA final consistency → mutable final sync → Eagle production setup → functional/recovery validation → coordinated cutover → rollback confirmation → temporary sudo cleanup.
