feat: Phase 1 FDA host-operator Role and railiance01 pilot (WP-0009 T02–T07)
Lock DEC-FDA-001 working defaults; add roles/host-operator package with OS/security and load protocols; scaffold eng-coulomb-railiance01-ho-001 with bound agent, vault, ramp checklists, and Kai quote/ledger.
This commit is contained in:
parent
ca7e4ead77
commit
2d347d062f
31 changed files with 1171 additions and 58 deletions
|
|
@ -0,0 +1,47 @@
|
|||
# Baseline — railiance01
|
||||
|
||||
**Engagement:** eng-coulomb-railiance01-ho-001
|
||||
**Status:** pending first observe session (RU-02)
|
||||
**Last captured:** —
|
||||
|
||||
## Identity
|
||||
|
||||
| Field | Value |
|
||||
|-------|-------|
|
||||
| Hostname | railiance01 |
|
||||
| Inventory | railiance-hosts |
|
||||
| Notes | k3s production; forgejo/apps |
|
||||
|
||||
## Capture checklist (fill on first session)
|
||||
|
||||
```bash
|
||||
hostname
|
||||
uptime
|
||||
uname -a
|
||||
cat /etc/os-release
|
||||
nproc
|
||||
free -h
|
||||
df -h
|
||||
ss -tuln | head -40
|
||||
# if k3s:
|
||||
kubectl get node -o wide 2>/dev/null || k3s kubectl get node -o wide 2>/dev/null
|
||||
```
|
||||
|
||||
## Recorded values
|
||||
|
||||
_To be filled during ramp-up._
|
||||
|
||||
## Known quirks (from docs, pre-session)
|
||||
|
||||
- Forgejo + in-cluster Actions runner documented in railiance-hosts ADR-004
|
||||
- State Hub / activity-core historically deployed on this cluster path
|
||||
- Access often via ops-bridge from workstation
|
||||
|
||||
## Envelope seed
|
||||
|
||||
| Metric | Baseline | Notes |
|
||||
|--------|----------|-------|
|
||||
| Load | | |
|
||||
| Memory | | |
|
||||
| Disk | | |
|
||||
| Top workloads | | |
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
# Handoff pack — eng-coulomb-railiance01-ho-001
|
||||
|
||||
Filled during **ramp-down** (RD-02).
|
||||
|
||||
## Contents (when complete)
|
||||
|
||||
- Summary of how railiance01 was operated under this engagement
|
||||
- Pointer to final baselines
|
||||
- Open risks → `risks.md`
|
||||
- Deferred patches and reboot debt
|
||||
- Contacts and access revocation status
|
||||
|
||||
_Status: not started (engagement not in ramp_down)._
|
||||
|
|
@ -0,0 +1,7 @@
|
|||
# Outstanding risks — eng-coulomb-railiance01-ho-001
|
||||
|
||||
_Populated during operate and finalised at ramp-down (RD-03)._
|
||||
|
||||
| Risk | Severity | Mitigation / owner | Status |
|
||||
|------|----------|--------------------|--------|
|
||||
| _none recorded_ | | | |
|
||||
|
|
@ -0,0 +1,74 @@
|
|||
---
|
||||
agent: host-operator
|
||||
engagement_id: eng-coulomb-railiance01-ho-001
|
||||
project: coulomb-railiance01
|
||||
last_updated: "2026-07-16"
|
||||
session_count: 0
|
||||
confidentiality: client_owned
|
||||
---
|
||||
|
||||
# Host Operator Memory — railiance01 pilot
|
||||
|
||||
## Engagement Charter
|
||||
|
||||
- **Duty:** Keep railiance01 operational and secure; OS currency; load and workload review
|
||||
- **Cadence:** daily health/load (business days); weekly OS/security pass
|
||||
- **Change windows:** prefer low-traffic periods; reboot only with human approval
|
||||
- **Escalation:** coulomb / railiance human operator (Bernd / on-call as designated)
|
||||
- **Out of scope:** app features; other hosts; secret vending
|
||||
|
||||
## Project Context
|
||||
|
||||
Coulomb ecosystem production host `railiance01` runs k3s and platform workloads
|
||||
(including Forgejo/apps per railiance-hosts docs). This engagement is the first
|
||||
forward-deployed host-operator pilot (KAIZEN-WP-0009).
|
||||
|
||||
## Host Profiles
|
||||
|
||||
| hostname | role | typical load | services | last review |
|
||||
|----------|------|--------------|----------|-------------|
|
||||
| railiance01 | k3s production | _TBD ramp-up_ | k3s, forgejo/apps (inventory) | never |
|
||||
|
||||
## OS & Patch State
|
||||
|
||||
_Pending first OS security pass (RU-05 / weekly protocol)._
|
||||
|
||||
## Security Posture
|
||||
|
||||
_Pending first security snapshot (RU-05)._
|
||||
|
||||
## Load & Workload Envelope
|
||||
|
||||
_Pending first load review (RU-06)._
|
||||
|
||||
## Accumulated Findings
|
||||
|
||||
_None yet._
|
||||
|
||||
## What Worked
|
||||
|
||||
_None yet._
|
||||
|
||||
## Watch Points
|
||||
|
||||
- Single-node production: privileged mistakes have full blast radius
|
||||
- DinD / Actions runner privilege model on railiance01 (see railiance-hosts ADRs)
|
||||
- Disk growth from images, logs, and backups
|
||||
|
||||
## Recurring Findings
|
||||
|
||||
_None yet._
|
||||
|
||||
## Cleared Issues
|
||||
|
||||
_None yet._
|
||||
|
||||
## Open Threads
|
||||
|
||||
- Complete RU-01 access verification
|
||||
- Capture baseline `vault/baselines/railiance01.md`
|
||||
- First health + load review report
|
||||
|
||||
## Session Log
|
||||
|
||||
<!-- YYYY-MM-DD · host(s) · key finding · outcome -->
|
||||
Loading…
Add table
Add a link
Reference in a new issue