Commit Graph

39 Commits

Author SHA1 Message Date
shitratgit[bot] 2784467284 feat: run agent-secrets as joelclaw service account 2026-08-18 19:40:40 +00:00
shitratgit[bot] 67636b707f fix: make Flagg headless runtime boot-safe 2026-07-19 23:42:13 +00:00
Joel Hooks c5be226d48 Teach clawmail launchd to survive git mailbox file descriptor pressure 2026-06-05 19:52:11 -07:00
Joel Hooks d26351cf6b Restore joelclaw post-reboot health by exporting Typesense, fixing memory recall/search, hardening Talon, and gating friction-fix 2026-05-30 19:51:04 -07:00
Joel Hooks 31a7ed0ef3 Document root cause and durable recovery for docs API host port failures 2026-05-02 09:37:27 -07:00
Joel Hooks faf900a197 Document how to diagnose and temporarily restore api docs search 502s caused by closed docs-api host port 2026-05-02 09:14:46 -07:00
Joel Hooks 0f95255c84 Restore the live joelclaw PDS operator surface by adding the missing pds CLI, canonical repo skill, and current health checks for the rebuilt service 2026-04-19 18:47:10 -07:00
Joel Hooks c32beaa5b0 Restore bluesky-pds after a rebuild by documenting the Helm/account recovery flow and resolving PDS session auth through the repo handle before dual-write logs in 2026-04-19 18:16:26 -07:00
Joel Hooks a7113d8265 Restore Typesense host access on NodePort 8108 so OTEL ingest and CLI observability stop hanging after the Colima rebuild 2026-04-19 16:41:36 -07:00
Joel Hooks 4c2e658592 Stop kube-operator-access from piggybacking Lima's ssh mux and cancel stale forwarded operator ports before launchd bootstrap 2026-04-19 16:30:29 -07:00
Joel Hooks 2b404923ab Harden kubectl and talos access with a dedicated launchd-managed operator tunnel on stable local ports 2026-04-19 15:50:04 -07:00
Joel Hooks 573d842c40 Patch Colima recovery so a restart only counts after a stable verification window and failed recoveries suppress repeat force-cycles 2026-04-19 14:18:57 -07:00
Joel Hooks 9956802557 Reproduce the H1-usernet discriminator: extend infra/colima-proof.sh with a non-destructive recover-usernet verdict contract so pre/post snapshots can explicitly support, reject, or mark inconclusive the usernet root-cause hypothesis 2026-04-16 11:56:59 -07:00
Joel Hooks 2e770a83a7 Reproduce Colima substrate proof capture: add infra/colima-proof.sh and hook k8s-reboot-heal to snapshot failure edges, hold states, force-cycle boundaries, and post-invariant outcomes with incident artifacts and OTEL payloads 2026-04-16 11:24:07 -07:00
Joel Hooks f445db5af9 Reproduce the stale Typesense forwarder fix: remove com.joel.typesense-portforward from the critical launchd set because Typesense is already exposed by joelclaw-controlplane-1 and the extra kubectl port-forward daemon only adds churn 2026-04-16 10:17:51 -07:00
Joel Hooks d3b1fde4d6 Reproduce the duplicate-forwarder fix: remove com.joel.colima-tunnel from the critical launchd set and turn the old tunnel script into a clean-exit compatibility stub so it stops fighting Lima's own port forwarders 2026-04-16 10:07:30 -07:00
Joel Hooks f93c1f0672 Reproduce the Colima timer fix: remove the 5-minute launchd StartInterval so com.joel.colima only starts the VM at boot instead of hammering colima start against a running instance 2026-04-16 09:47:27 -07:00
Joel Hooks 3394fa5b95 Reproduce the fast-but-earned healer escalation fix: add a rapid confirmation window and early host-path bailouts so real Colima collapse recovers faster without restoring single-tick panic cycles 2026-04-16 08:40:29 -07:00
Joel Hooks 4fcc853465 Reproduce the healer guardrail fix: persist Colima unhealthy streaks and cooldowns so k8s-reboot-heal stops single-tick warmup from force-cycling the VM, and document the new escalation contract 2026-04-16 08:34:54 -07:00
Joel Hooks 2f558b82e4 Reproduce the reboot-heal state fix: persist flannel and recovery markers across launchd ticks so Typesense is not re-warmed by repeated flannel restarts 2026-04-15 17:57:14 -07:00
Joel Hooks fca46a276d Reproduce the stale-tunnel reboot fix: make colima-tunnel restart on SSH port drift, harden k8s-reboot-heal against false Colima cycling, and make gateway status require real daemon reachability 2026-04-15 17:37:35 -07:00
Joel Hooks 4fa2bcee59 Reproduce the final reboot tunnel fix: stop forwarding 6443 from colima-tunnel and document that Caddy owns the port 2026-04-14 17:49:03 -07:00
Joel Hooks f96157b683 Reproduce the reboot root-cause fix: add a repo-canonical colima tunnel launchd service, wire it into the critical installer, and make gateway CLI inspect system launchd services 2026-04-14 17:00:47 -07:00
Joel Hooks 5ff6a9a7df Correct the boot-safe agent-mail runtime so launchd resolves joelhooks/mcp_agent_mail instead of hardcoding the legacy Dicklesworthstone checkout path 2026-04-12 09:03:34 -07:00
Joel Hooks 3384b45d9a Replace the failed ADR-0239 bridge with boot-safe LaunchDaemons for critical host services and retire user/501 bootstrap 2026-04-12 08:57:27 -07:00
Joel Hooks 5fb084569f Install a headless boot bridge for critical launchd services and track gateway/typesense/agent-mail plists in repo 2026-04-12 08:27:08 -07:00
Joel Hooks 555b20851e Document the k8s Restate runtime, Firecracker path, workload rig DAG flow, and docs-api surfaces across AGENTS, docs, and skills 2026-03-16 21:30:24 -07:00
Joel Hooks 5c871a79cd Create the Restate worker Dockerfile, k8s deployment/service, publish script, and deploy docs for ADR-0230 Step 3 2026-03-16 08:40:52 -07:00
Joel Hooks 0296337596 Add the ADR-0224 phase-1 ClickHouse k8s manifest with local-path storage, probes, and smoke verification docs 2026-03-10 08:56:07 -07:00
Joel Hooks c2f2152a9d Install the repo-managed ADR-0221 launchd janitor for local sandboxes and document the bounded stale-residue cleanup pass 2026-03-09 20:05:14 -07:00
Joel Hooks 8156a62355 Wire an opt-in ADR-0217 k8s sandbox backend into agent-dispatch and document how external repos should submit work through joelclaw queue emit 2026-03-07 22:24:23 -08:00
Joel Hooks 5b48e6e120 Add a Restate drainer stall watchdog so ADR-0217 queue pilots self-heal instead of silently wedging until a manual restart 2026-03-07 13:32:04 -08:00
Joel Hooks f3ef5fc60f Replace the ad-hoc Restate host worker with a repo-managed launchd service so ADR-0217 soak windows stop getting poisoned by opaque nohup restarts 2026-03-07 11:35:51 -08:00
Joel Hooks d206c29a41 Move the content-sync watcher into repo-canonical launchd assets and let QUEUE_PILOTS=content switch it between queue and direct emission 2026-03-07 09:50:07 -08:00
Joel Hooks a03f270fbf Start the Restate queue drainer and align sandbox runtime docs with live reality 2026-03-07 07:56:40 -08:00
Joel Hooks 08338a6c9f Add repo materialization and patch artifact export to @joelclaw/agent-execution
Implement sandbox runtime PRD Story 3: clean repo materialization and patch-artifact export so sandbox runs mutate only their own checkout and return auditable output instead of touching the host worktree.

New capabilities:
- materializeRepo(): Clone or checkout repo at exact SHA in sandbox-local workspace. Fresh clone if target doesn't exist, fetch+checkout otherwise. SHA verification with automatic unshallow. Isolated from host worktree.
- generatePatchArtifact(): Export auditable patch from baseSha..headSha with touched-file inventory, verification summary, and log references. Uses git format-patch for commits, git diff for uncommitted changes.
- getTouchedFiles(): Capture modified/untracked files via git status --porcelain.
- verifyRepoState(): Validate repo is at expected SHA.
- writeArtifactBundle()/readArtifactBundle(): Serialize ExecutionArtifacts to/from JSON.

Promotion boundary: Phase 1 output is patch bundle + metadata. Runtime does NOT merge to main or push to remote. Operator reviews patch + verification, then applies to host repo or discards.

Tests: Full coverage for repo materialization, artifact export, touched-file inventory, and bundle serialization. All 84 tests pass.

Docs: Updated deploy.md, architecture.md, and system-architecture skill with new contract details and Phase 1 promotion boundary explanation.

Files:
- packages/agent-execution/src/repo.ts (new)
- packages/agent-execution/src/artifacts.ts (new)
- packages/agent-execution/src/index.ts (exports)
- packages/agent-execution/__tests__/repo.test.ts (new)
- packages/agent-execution/__tests__/artifacts.test.ts (new)
- docs/deploy.md (updated)
- docs/architecture.md (updated)
- skills/system-architecture/SKILL.md (updated)

Verification: bunx tsc --noEmit ✓, pnpm biome check ✓, bun test packages/agent-execution ✓ (84/84 pass)
2026-03-06 17:20:54 -08:00
Joel Hooks 9c8f3fef1f Add cold isolated k8s Job runner for sandboxed story execution
Implement sandbox runtime PRD Story 2: cold-runner Job spec, runtime image contract, deterministic naming, and resource cleanup policy for isolated story runs in k8s Jobs.

Outcomes:
- Deterministic k8s Job spec generation via @joelclaw/agent-execution/job-spec
- Job naming keyed by requestId (DNS-1123 compliant)
- Runtime image contract: Git, Bun, agent tooling, /workspace, env-driven config
- Resource limits: 500m-2 CPU, 1-4Gi memory (configurable)
- TTL cleanup: auto-delete after 5 minutes (default)
- Active deadline: 1 hour max runtime
- Backoff limit: 0 (no retries)
- Security: non-root (UID 1000), no privilege escalation, capabilities dropped
- Cancellation support at Job level (delete Job -> SIGTERM)
- Environment variables: WORKFLOW_ID, REQUEST_ID, STORY_ID, TASK_PROMPT_B64, VERIFICATION_COMMANDS_B64, etc.
- Comprehensive test coverage (37 tests for job-spec, 69 total)

Changes:
- packages/agent-execution/src/job-spec.ts: NEW - Job spec generator
- packages/agent-execution/src/index.ts: export job-spec functions
- packages/agent-execution/__tests__/job-spec.test.ts: NEW - comprehensive tests
- k8s/agent-runner.yaml: NEW - runtime contract documentation
- docs/architecture.md: document cold k8s Jobs and runtime contract
- docs/deploy.md: deployment procedures for agent runner
- skills/k8s/SKILL.md: agent runner operations guide

No live infrastructure deployed - code, manifests, and contracts only.

Verification:
- bunx tsc --noEmit ✓
- pnpm biome check ✓
- bun test packages/agent-execution ✓ (69 passing)

Next stories:
- Story 3: Build runtime image with Git + Bun + codex + pi
- Story 4: Hot-image CronJob for pre-warmed images
- Story 5: Warm-pool scheduler for instant dispatch
- Story 6: Wire Restate DAG orchestrator to launch Jobs
2026-03-06 17:13:21 -08:00
Joel Hooks 41b3051880 Migrate ADR-0216 tier-1 crons to Dkron/Restate, add direct host runners, and drop the matching Inngest cron triggers 2026-03-05 22:51:17 -08:00
Joel Hooks 551f2a2b10 Deploy Dkron phase-1 in k8s, add joelclaw restate cron commands, and prove the health DAG can run on a scheduler independent of Inngest 2026-03-05 21:57:15 -08:00