Host Agent updates
Not implemented — explicitly deferred, not just unstarted. When Host Agent Phase 1+2 shipped (2026-07-19), agent auto-update distribution was scoped out on purpose: no artifact storage/versioning design exists yet, and building it alongside
edgezu-hostagent-gatewayrisked half-building both. Recommend a dedicated follow-up plan rather than resuming this inline. See rootTODO.md.
Policy
Section titled “Policy”Same transport preference as inventory:
- Edge available: Cloud publishes signed build → Edge caches → Host downloads from LAN gateway.
- Edge unavailable: Host downloads signed artifact directly from Cloud.
Response header X-Latest-Agent-Version on inventory push informs agent of newer builds.
Auto-update
Section titled “Auto-update”Optional per-site policy — may notify admins only (“N hosts need update”) or auto-install when allowed.
Signing
Section titled “Signing”Windows Authenticode vs Cosign — open question in TODO.md. Edge RAUC bundles use Updates CA (pki-ceremony.md).