shitratgit[bot]
2784467284
feat: run agent-secrets as joelclaw service account
2026-08-18 19:40:40 +00:00
shitratgit[bot]
67636b707f
fix: make Flagg headless runtime boot-safe
2026-07-19 23:42:13 +00:00
Joel Hooks
c5be226d48
Teach clawmail launchd to survive git mailbox file descriptor pressure
2026-06-05 19:52:11 -07:00
Joel Hooks
d26351cf6b
Restore joelclaw post-reboot health by exporting Typesense, fixing memory recall/search, hardening Talon, and gating friction-fix
2026-05-30 19:51:04 -07:00
Joel Hooks
31a7ed0ef3
Document root cause and durable recovery for docs API host port failures
2026-05-02 09:37:27 -07:00
Joel Hooks
faf900a197
Document how to diagnose and temporarily restore api docs search 502s caused by closed docs-api host port
2026-05-02 09:14:46 -07:00
Joel Hooks
0f95255c84
Restore the live joelclaw PDS operator surface by adding the missing pds CLI, canonical repo skill, and current health checks for the rebuilt service
2026-04-19 18:47:10 -07:00
Joel Hooks
c32beaa5b0
Restore bluesky-pds after a rebuild by documenting the Helm/account recovery flow and resolving PDS session auth through the repo handle before dual-write logs in
2026-04-19 18:16:26 -07:00
Joel Hooks
a7113d8265
Restore Typesense host access on NodePort 8108 so OTEL ingest and CLI observability stop hanging after the Colima rebuild
2026-04-19 16:41:36 -07:00
Joel Hooks
4c2e658592
Stop kube-operator-access from piggybacking Lima's ssh mux and cancel stale forwarded operator ports before launchd bootstrap
2026-04-19 16:30:29 -07:00
Joel Hooks
2b404923ab
Harden kubectl and talos access with a dedicated launchd-managed operator tunnel on stable local ports
2026-04-19 15:50:04 -07:00
Joel Hooks
573d842c40
Patch Colima recovery so a restart only counts after a stable verification window and failed recoveries suppress repeat force-cycles
2026-04-19 14:18:57 -07:00
Joel Hooks
9956802557
Reproduce the H1-usernet discriminator: extend infra/colima-proof.sh with a non-destructive recover-usernet verdict contract so pre/post snapshots can explicitly support, reject, or mark inconclusive the usernet root-cause hypothesis
2026-04-16 11:56:59 -07:00
Joel Hooks
2e770a83a7
Reproduce Colima substrate proof capture: add infra/colima-proof.sh and hook k8s-reboot-heal to snapshot failure edges, hold states, force-cycle boundaries, and post-invariant outcomes with incident artifacts and OTEL payloads
2026-04-16 11:24:07 -07:00
Joel Hooks
f445db5af9
Reproduce the stale Typesense forwarder fix: remove com.joel.typesense-portforward from the critical launchd set because Typesense is already exposed by joelclaw-controlplane-1 and the extra kubectl port-forward daemon only adds churn
2026-04-16 10:17:51 -07:00
Joel Hooks
d3b1fde4d6
Reproduce the duplicate-forwarder fix: remove com.joel.colima-tunnel from the critical launchd set and turn the old tunnel script into a clean-exit compatibility stub so it stops fighting Lima's own port forwarders
2026-04-16 10:07:30 -07:00
Joel Hooks
f93c1f0672
Reproduce the Colima timer fix: remove the 5-minute launchd StartInterval so com.joel.colima only starts the VM at boot instead of hammering colima start against a running instance
2026-04-16 09:47:27 -07:00
Joel Hooks
3394fa5b95
Reproduce the fast-but-earned healer escalation fix: add a rapid confirmation window and early host-path bailouts so real Colima collapse recovers faster without restoring single-tick panic cycles
2026-04-16 08:40:29 -07:00
Joel Hooks
4fcc853465
Reproduce the healer guardrail fix: persist Colima unhealthy streaks and cooldowns so k8s-reboot-heal stops single-tick warmup from force-cycling the VM, and document the new escalation contract
2026-04-16 08:34:54 -07:00
Joel Hooks
2f558b82e4
Reproduce the reboot-heal state fix: persist flannel and recovery markers across launchd ticks so Typesense is not re-warmed by repeated flannel restarts
2026-04-15 17:57:14 -07:00
Joel Hooks
fca46a276d
Reproduce the stale-tunnel reboot fix: make colima-tunnel restart on SSH port drift, harden k8s-reboot-heal against false Colima cycling, and make gateway status require real daemon reachability
2026-04-15 17:37:35 -07:00
Joel Hooks
4fa2bcee59
Reproduce the final reboot tunnel fix: stop forwarding 6443 from colima-tunnel and document that Caddy owns the port
2026-04-14 17:49:03 -07:00
Joel Hooks
f96157b683
Reproduce the reboot root-cause fix: add a repo-canonical colima tunnel launchd service, wire it into the critical installer, and make gateway CLI inspect system launchd services
2026-04-14 17:00:47 -07:00
Joel Hooks
5ff6a9a7df
Correct the boot-safe agent-mail runtime so launchd resolves joelhooks/mcp_agent_mail instead of hardcoding the legacy Dicklesworthstone checkout path
2026-04-12 09:03:34 -07:00
Joel Hooks
3384b45d9a
Replace the failed ADR-0239 bridge with boot-safe LaunchDaemons for critical host services and retire user/501 bootstrap
2026-04-12 08:57:27 -07:00
Joel Hooks
5fb084569f
Install a headless boot bridge for critical launchd services and track gateway/typesense/agent-mail plists in repo
2026-04-12 08:27:08 -07:00
Joel Hooks
555b20851e
Document the k8s Restate runtime, Firecracker path, workload rig DAG flow, and docs-api surfaces across AGENTS, docs, and skills
2026-03-16 21:30:24 -07:00
Joel Hooks
5c871a79cd
Create the Restate worker Dockerfile, k8s deployment/service, publish script, and deploy docs for ADR-0230 Step 3
2026-03-16 08:40:52 -07:00
Joel Hooks
0296337596
Add the ADR-0224 phase-1 ClickHouse k8s manifest with local-path storage, probes, and smoke verification docs
2026-03-10 08:56:07 -07:00
Joel Hooks
c2f2152a9d
Install the repo-managed ADR-0221 launchd janitor for local sandboxes and document the bounded stale-residue cleanup pass
2026-03-09 20:05:14 -07:00
Joel Hooks
8156a62355
Wire an opt-in ADR-0217 k8s sandbox backend into agent-dispatch and document how external repos should submit work through joelclaw queue emit
2026-03-07 22:24:23 -08:00
Joel Hooks
5b48e6e120
Add a Restate drainer stall watchdog so ADR-0217 queue pilots self-heal instead of silently wedging until a manual restart
2026-03-07 13:32:04 -08:00
Joel Hooks
f3ef5fc60f
Replace the ad-hoc Restate host worker with a repo-managed launchd service so ADR-0217 soak windows stop getting poisoned by opaque nohup restarts
2026-03-07 11:35:51 -08:00
Joel Hooks
d206c29a41
Move the content-sync watcher into repo-canonical launchd assets and let QUEUE_PILOTS=content switch it between queue and direct emission
2026-03-07 09:50:07 -08:00
Joel Hooks
a03f270fbf
Start the Restate queue drainer and align sandbox runtime docs with live reality
2026-03-07 07:56:40 -08:00
Joel Hooks
08338a6c9f
Add repo materialization and patch artifact export to @joelclaw/agent-execution
...
Implement sandbox runtime PRD Story 3: clean repo materialization and patch-artifact export so sandbox runs mutate only their own checkout and return auditable output instead of touching the host worktree.
New capabilities:
- materializeRepo(): Clone or checkout repo at exact SHA in sandbox-local workspace. Fresh clone if target doesn't exist, fetch+checkout otherwise. SHA verification with automatic unshallow. Isolated from host worktree.
- generatePatchArtifact(): Export auditable patch from baseSha..headSha with touched-file inventory, verification summary, and log references. Uses git format-patch for commits, git diff for uncommitted changes.
- getTouchedFiles(): Capture modified/untracked files via git status --porcelain.
- verifyRepoState(): Validate repo is at expected SHA.
- writeArtifactBundle()/readArtifactBundle(): Serialize ExecutionArtifacts to/from JSON.
Promotion boundary: Phase 1 output is patch bundle + metadata. Runtime does NOT merge to main or push to remote. Operator reviews patch + verification, then applies to host repo or discards.
Tests: Full coverage for repo materialization, artifact export, touched-file inventory, and bundle serialization. All 84 tests pass.
Docs: Updated deploy.md, architecture.md, and system-architecture skill with new contract details and Phase 1 promotion boundary explanation.
Files:
- packages/agent-execution/src/repo.ts (new)
- packages/agent-execution/src/artifacts.ts (new)
- packages/agent-execution/src/index.ts (exports)
- packages/agent-execution/__tests__/repo.test.ts (new)
- packages/agent-execution/__tests__/artifacts.test.ts (new)
- docs/deploy.md (updated)
- docs/architecture.md (updated)
- skills/system-architecture/SKILL.md (updated)
Verification: bunx tsc --noEmit ✓, pnpm biome check ✓, bun test packages/agent-execution ✓ (84/84 pass)
2026-03-06 17:20:54 -08:00
Joel Hooks
9c8f3fef1f
Add cold isolated k8s Job runner for sandboxed story execution
...
Implement sandbox runtime PRD Story 2: cold-runner Job spec, runtime image contract, deterministic naming, and resource cleanup policy for isolated story runs in k8s Jobs.
Outcomes:
- Deterministic k8s Job spec generation via @joelclaw/agent-execution/job-spec
- Job naming keyed by requestId (DNS-1123 compliant)
- Runtime image contract: Git, Bun, agent tooling, /workspace, env-driven config
- Resource limits: 500m-2 CPU, 1-4Gi memory (configurable)
- TTL cleanup: auto-delete after 5 minutes (default)
- Active deadline: 1 hour max runtime
- Backoff limit: 0 (no retries)
- Security: non-root (UID 1000), no privilege escalation, capabilities dropped
- Cancellation support at Job level (delete Job -> SIGTERM)
- Environment variables: WORKFLOW_ID, REQUEST_ID, STORY_ID, TASK_PROMPT_B64, VERIFICATION_COMMANDS_B64, etc.
- Comprehensive test coverage (37 tests for job-spec, 69 total)
Changes:
- packages/agent-execution/src/job-spec.ts: NEW - Job spec generator
- packages/agent-execution/src/index.ts: export job-spec functions
- packages/agent-execution/__tests__/job-spec.test.ts: NEW - comprehensive tests
- k8s/agent-runner.yaml: NEW - runtime contract documentation
- docs/architecture.md: document cold k8s Jobs and runtime contract
- docs/deploy.md: deployment procedures for agent runner
- skills/k8s/SKILL.md: agent runner operations guide
No live infrastructure deployed - code, manifests, and contracts only.
Verification:
- bunx tsc --noEmit ✓
- pnpm biome check ✓
- bun test packages/agent-execution ✓ (69 passing)
Next stories:
- Story 3: Build runtime image with Git + Bun + codex + pi
- Story 4: Hot-image CronJob for pre-warmed images
- Story 5: Warm-pool scheduler for instant dispatch
- Story 6: Wire Restate DAG orchestrator to launch Jobs
2026-03-06 17:13:21 -08:00
Joel Hooks
41b3051880
Migrate ADR-0216 tier-1 crons to Dkron/Restate, add direct host runners, and drop the matching Inngest cron triggers
2026-03-05 22:51:17 -08:00
Joel Hooks
551f2a2b10
Deploy Dkron phase-1 in k8s, add joelclaw restate cron commands, and prove the health DAG can run on a scheduler independent of Inngest
2026-03-05 21:57:15 -08:00