DevOps runbooks — GuestKit
Operational docs for platform / migration / SRE teams who gate cutovers with GuestKit (doctor, migrate-plan, rescue, Passport) before hyper2kvm / HyperSDK convert.
| Runbook | When you need it |
|---|---|
| 01 — Passport CI gate | Fail convert if score < floor — GitHub Actions: zyvorai/guestkit action |
| 02 — Offline repair worker | Jump box / GHCR worker, root, NBD |
| 03 — Air-gap packages & VirtIO | Mirror, cache, GUESTKIT_VIRTIO_WIN |
| 04 — Fleet analyze at scale | Directory of images, snowflakes |
| 05 — Cutover weekend | Hour-by-hour ops checklist |
| 06 — Failure triage | Doctor red, BitLocker, GRUB, SAM |
| 07 — Cloud disk sources | s3:// gs:// azure:// pulls + cache |
| 08 — Forensic diff & IR | Offline drift / secrets / malware |
| 09 — SBOM / inventory CI | SPDX/CycloneDX artifacts |
| 10 — Rescue dry-run + SBOM diff | Action extras, sbom-diff --fail-on-drift |
Related: Wiki · Migration assurance · DOCKER / GHCR · Blogs: integrate pipeline · DevOps runbooks
Operating model
| Role | Owns |
|---|---|
| Migration / DevOps | Worker image, CI job, --fail-below, signing keys, mirror URL, change-ticket Passport attach |
| Platform | Disk staging (object store / NFS), runner privileges (qemu-nbd, loop), network to mirrors |
| App owners | Accept day-0 plans (RDP, SSH keys, domain leave), rotate temp passwords |
| Convert tool | hyper2kvm / suite — only after passport verify green |
Pin
CLI: GitHub Release v1.2.5 # crates.io guestkit is still 0.3.2
Worker: ghcr.io/zyvorai/guestkit-worker # pin digest/tag in compose/Helm