Commit Graph

35 Commits

Author SHA1 Message Date
shitratgit[bot] 9b863cc8fa fix(infra): session-index-health reads the live SQLite index; health.sh reports instead of repairing 2026-07-31 12:07:21 -07:00
shitratgit[bot] 6bf6c477b5 fix(ops): restore executable script modes 2026-07-11 02:42:22 +00:00
shitratgit[bot] b0fc896911 ops(storage): harden central NAS mount verification 2026-07-11 02:39:14 +00:00
shitratgit[bot] 7ca885833b fix(nas): preserve executable mount scripts 2026-07-10 18:56:11 +00:00
shitratgit[bot] 8f86b59bcd feat(nas): mount badass media on Flagg 2026-07-10 18:51:36 +00:00
Joel Hooks 546fd62f0e chore(infra): satellite-rig setup, NAS-by-IP, brain notes, fn registry
Satellite rig runbook/setup hardening, NAS_HOST pinned to LAN IP per
mount contract, agent-mail daemon uv resolution, CLAUDE.md + brain
areas/pipeline notes, and function registry wiring for the new
usage/webhook/backup functions.

"direct exposure and experience, documentation, or a runbook" -- the
three ways knowledge transfers, Observability Engineering, Ch. 11

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 09:29:40 -07:00
Joel Hooks 6ba907a1c9 fix(central): stop sync-service-checkout from deleting the service .env
The .env presence check ran after rsync --delete, so syncing from a
source checkout without a shadow .env stripped the service checkout's
live .env before the check could fire (hit on 2026-07-09; restored from
the sibling dev checkout). Refuse before the destructive step instead.

Document the sudo split in infra/central/README.md and the three-body
skill: verify-nas.sh proves the full NAS contract unprivileged (plist +
log-freshness liveness); sudo is reserved for installers, manual
resvport mounts, and the sync, whose password prompt is a deliberate
security boundary. Includes an optional read-only sudoers line for
system-domain launchctl print.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 08:33:14 -07:00
Joel Hooks 6ced43d97c feat(nas): prove nas-mounts daemon liveness without sudo via log freshness
The daemon fires every 60s and its stdout log is world-readable, so a
recent mtime on nas-mounts.out.log proves the service is loaded and
running from an unprivileged shell. launchctl print on the system
domain stays as the root-only probe.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 08:33:14 -07:00
Joel Hooks 711b670e7e fix(nas): catch missing nas-mounts LaunchDaemon and stale hostname source
verify-nas.sh now hard-fails when the com.joelclaw.central.nas-mounts
plist is missing (and checks the loaded system-domain service when run
as root). On 2026-07-09 both NFS mounts were live and tuned while the
plist was gone, so a reboot would have silently dropped them and the
verifier said all-ok.

nas-soak.ts NVMe sample metadata now reports 192.168.1.163:/volume2/data,
matching the live mount and THREE_BODY_SRC instead of the three-body
hostname, which MagicDNS resolves to the tailnet address.

Document the regression, reinstall command, and two-checkout hygiene in
skills/three-body/SKILL.md and the Flagg LAN NAS contract brain note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 08:33:14 -07:00
shitratgit[bot] aa99bcbe4e docs: capture central topology and operator skills 2026-06-26 08:05:41 -07:00
Joel Hooks 925dc48868 fix(central): tolerate mounted NAS dirs during install 2026-06-26 08:02:57 -07:00
shitratgit[bot] 6e02a6cd8e infra: add bounded central recovery scaffold 2026-06-14 18:45:22 +00:00
shitratgit[bot] 4cffb074ef infra: add Chorus Rhizomatic launchd service 2026-06-14 16:13:46 +00:00
Joel Hooks d36b52f207 Document Flagg NAS Gate 5 write proof 2026-05-30 15:42:16 -07:00
Joel Hooks 249457babb Capture Flagg NAS Gate 5 pickup state and set expected 10GbE interface 2026-05-30 14:37:24 -07:00
Joel Hooks e5fa2e5487 Create three-body joelclaw NFS identity during prep 2026-05-28 16:23:22 -07:00
Joel Hooks 5d276a2471 Make Flagg NAS remount recovery less brittle 2026-05-28 16:17:07 -07:00
Joel Hooks dcffc7a1ab Improve Flagg NAS verifier diagnostics 2026-05-28 16:11:47 -07:00
Joel Hooks a65a45885a Add three-body NAS object root prep script 2026-05-28 16:06:08 -07:00
Joel Hooks be2e16533e Probe Flagg NAS object roots instead of mount roots 2026-05-28 14:59:31 -07:00
Joel Hooks 39859018f2 Add repo-managed Flagg NAS mount proof scripts 2026-05-28 14:10:38 -07:00
Joel Hooks e3d1063fa0 Fix MinIO smoke bucket naming 2026-05-28 09:07:54 -07:00
Joel Hooks c881bd83bf Fix Flagg smoke harness script path 2026-05-28 08:25:49 -07:00
Joel Hooks 77f3cfac80 Add Flagg Phase A smoke harness 2026-05-28 07:44:01 -07:00
Joel Hooks 38bed86cad Use Docker volume for Flagg Restate data 2026-05-27 15:21:18 -07:00
Joel Hooks 0c94ccccaa Fix Flagg shadow verification and Inngest keys 2026-05-27 13:46:13 -07:00
Joel Hooks 37979a0329 Fix Flagg shadow compose service startup 2026-05-27 13:36:24 -07:00
Joel Hooks 9933b98ed4 Add Flagg Gate 4 diagnostic script 2026-05-27 13:30:12 -07:00
Joel Hooks 8a72d6cada Disable Flagg Central LaunchDaemons before Gate 4 2026-05-27 13:12:37 -07:00
Joel Hooks 6e3385d535 Support standalone Docker Compose on Flagg 2026-05-27 13:07:43 -07:00
Joel Hooks 31d8944c60 Prepare Flagg Gate 3 runtime bootstrap 2026-05-27 13:05:54 -07:00
Joel Hooks 7bbd5fc6f8 Target Flagg system tailscaled socket explicitly 2026-05-27 12:44:36 -07:00
Joel Hooks 584945d58d Add Flagg system tailscaled migration gate 2026-05-27 12:39:42 -07:00
Joel Hooks d0ad3d25c9 Require Flagg no-login reboot recovery proof 2026-05-27 12:10:35 -07:00
Joel Hooks 3a1798b6f7 Scaffold Flagg Central shadow runtime assets 2026-05-27 10:14:03 -07:00