Seat

Operator

You run one or more dUNL validators. In an incident you execute the fix on your own nodes - upgrade, downgrade, restart, config change, or halt. Nothing is ever done to your nodes for you.

held by the dUNL operators

Your only channel

#dunl-operators-only

The same channel you acknowledge version upgrades in today.

What you are waiting for

One thing: an instruction pinned by Brett Mollin.

Nothing reaches you any other way - not a DM, not an email, not a public post.

Your report

done in the instruction's thread.

Your acknowledgement is your status report; you never report upward any other way.

Your steps, in order

  1. The UNL Leader pins an instruction

    On #dunl-operators-only, from Brett Mollin by name. Until it arrives, keep your nodes running as normal and watch that one channel.

  2. Run the three checks

    All three pass, or you do not act. See the card below.

  3. Do exactly what it says, on your own nodes

    No more, no less. The instruction names the adjacent wrong action - do not reach for it.

  4. Post done in the instruction's thread

    Discussion goes in the channel around it; the thread stays instructions and acknowledgements. Under a declared incident your done is an acknowledgement, not a vote.

  5. Wait for the next instruction

    No news means proceed as planned.

 

The three checks - all three, every time

  • Pinned in #dunl-operators-only, not a DM, email, or public post.
  • From the named UNL Leader for this incident.
  • Binary: signed release, hashes fetched independently of the message. No binary - restart, config, halt: the Coordinator has countersigned in the thread, restating the action in their own words.

Two names, or you do not act. Any box fails: stop and tell the UNL Leader. The order most worth faking is the one that says stand down or go quiet - verify that one hardest.

Never

  • Act on an instruction from anywhere but the pinned post.
  • Upgrade from a link someone sent you.
  • Post logs, theories, or incident details publicly.
  • Go quiet on a "stand down" you have not verified.

If you see something

  1. Post it in #dunl-operators-only

    Fixed format so triage is fast: what you saw, when, which node, logs attached.

  2. Fire the page yourself when you see the pattern

    The same fault on other validators, or a network-wide symptom, is page-worthy - every operator holds the trigger. You are not asked to be right about the cause.

  3. Do not wait to be sure

    A page that turns out to be your own rack costs nothing and is never held against you. The failure is the 03:00 post that sits unread for forty minutes.

Declining

Declining is legitimate: your validator is your call, and nobody argues you out of it. Say so in the channel with the reason. What breaks the response is declining silently - a silent decliner and an unreachable operator look identical to the count.

Your full script, the readiness checklist, and the status template: governance/roles/operator.md