2026-07-18 10:48:44 +02:00
|
|
|
|
# Railiance deployment (HARNESS-WP-0001-T06)
|
|
|
|
|
|
|
|
|
|
|
|
Single shared harness instance on **railiance01**. Secrets stay on the host
|
|
|
|
|
|
(Lanes 2–3); the container image is the portable runtime package.
|
|
|
|
|
|
|
Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host
secrets dir + checkout renamed, host venv recreated from scratch
(renaming a venv directory breaks its embedded shebang paths), image
rebuilt/imported, renamed k8s manifests applied alongside the old
namespace (not overwriting it), rollout + in-cluster smoke verified,
then the authoritative host smoke script run against the live
deployment: ok: true, committed: true, pushed: true, with a matching
harness_smoke event confirmed in State Hub. Only after that verification
did we delete the old agent-harness namespace and checkout.
Found and fixed two host-side references the original checklist hadn't
anticipated: path substitutions inside the (secrets, not directly read)
env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose
IdentityFile still pointed at the pre-rename secrets path.
HARNESS-WP-0002 is now fully done (4/4).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 18:44:56 +02:00
|
|
|
|
> **Renamed from agent-harness (HARNESS-WP-0002-T02) — cutover done
|
|
|
|
|
|
> 2026-07-26.** Railiance now runs `rein-aharness` end to end: image tag,
|
|
|
|
|
|
> k8s namespace, CLI command, Python package, host secrets dir, and
|
|
|
|
|
|
> checkout are all renamed, verified via the authoritative host smoke
|
|
|
|
|
|
> script (`ok: true, committed: true, pushed: true`), and the old
|
|
|
|
|
|
> `agent-harness` namespace/checkout are gone. Checklist kept below as a
|
|
|
|
|
|
> record and in case this ever needs redoing (e.g. a second host).
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
|
Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host
secrets dir + checkout renamed, host venv recreated from scratch
(renaming a venv directory breaks its embedded shebang paths), image
rebuilt/imported, renamed k8s manifests applied alongside the old
namespace (not overwriting it), rollout + in-cluster smoke verified,
then the authoritative host smoke script run against the live
deployment: ok: true, committed: true, pushed: true, with a matching
harness_smoke event confirmed in State Hub. Only after that verification
did we delete the old agent-harness namespace and checkout.
Found and fixed two host-side references the original checklist hadn't
anticipated: path substitutions inside the (secrets, not directly read)
env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose
IdentityFile still pointed at the pre-rename secrets path.
HARNESS-WP-0002 is now fully done (4/4).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 18:44:56 +02:00
|
|
|
|
## Rename cutover checklist (done on railiance01 2026-07-26)
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
|
|
|
|
|
|
1. Move the host-side secrets dir: `mv ~/.local/agent-harness ~/.local/rein-aharness`
|
|
|
|
|
|
(or symlink, if anything else still reads the old path).
|
Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host
secrets dir + checkout renamed, host venv recreated from scratch
(renaming a venv directory breaks its embedded shebang paths), image
rebuilt/imported, renamed k8s manifests applied alongside the old
namespace (not overwriting it), rollout + in-cluster smoke verified,
then the authoritative host smoke script run against the live
deployment: ok: true, committed: true, pushed: true, with a matching
harness_smoke event confirmed in State Hub. Only after that verification
did we delete the old agent-harness namespace and checkout.
Found and fixed two host-side references the original checklist hadn't
anticipated: path substitutions inside the (secrets, not directly read)
env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose
IdentityFile still pointed at the pre-rename secrets path.
HARNESS-WP-0002 is now fully done (4/4).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 18:44:56 +02:00
|
|
|
|
**Also needed, not anticipated by this checklist originally:** two
|
|
|
|
|
|
path references *inside* `~/.local/rein-aharness/env` (AppRole dir,
|
|
|
|
|
|
PYTHONPATH — fixed with a blind, precise `sed` substitution; the
|
|
|
|
|
|
file wasn't read directly, a direct `cat` was correctly classifier-blocked
|
|
|
|
|
|
as a secrets file) and `~/.ssh/config`'s `Host forgejo-agent-harness`
|
|
|
|
|
|
`IdentityFile` (alias name itself left unchanged, only the path it
|
|
|
|
|
|
points at). Check both again if redoing this elsewhere.
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
2. Move/rename the checkout: `mv ~/agent-harness ~/rein-aharness` (or a fresh
|
Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host
secrets dir + checkout renamed, host venv recreated from scratch
(renaming a venv directory breaks its embedded shebang paths), image
rebuilt/imported, renamed k8s manifests applied alongside the old
namespace (not overwriting it), rollout + in-cluster smoke verified,
then the authoritative host smoke script run against the live
deployment: ok: true, committed: true, pushed: true, with a matching
harness_smoke event confirmed in State Hub. Only after that verification
did we delete the old agent-harness namespace and checkout.
Found and fixed two host-side references the original checklist hadn't
anticipated: path substitutions inside the (secrets, not directly read)
env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose
IdentityFile still pointed at the pre-rename secrets path.
HARNESS-WP-0002 is now fully done (4/4).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 18:44:56 +02:00
|
|
|
|
`deploy-rsync` to the new path — see Makefile). If the checkout has an
|
|
|
|
|
|
associated venv, **recreate it from scratch** rather than moving it —
|
|
|
|
|
|
a venv's shebang lines embed absolute paths, so renaming the directory
|
|
|
|
|
|
alone breaks `pip` and every installed entry point.
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
3. Verify no other host cron/systemd unit still references
|
|
|
|
|
|
`~/agent-harness` or the `agent-harness` command directly.
|
|
|
|
|
|
4. Once the above is done, `kubectl delete namespace agent-harness` **after**
|
|
|
|
|
|
confirming the new `rein-aharness` namespace deploys and smokes clean —
|
|
|
|
|
|
don't delete the old one first, in case cutover needs a rollback.
|
|
|
|
|
|
|
2026-07-18 10:48:44 +02:00
|
|
|
|
## Layout
|
|
|
|
|
|
|
|
|
|
|
|
| Path | Role |
|
|
|
|
|
|
|------|------|
|
|
|
|
|
|
| `Containerfile` | Image: Python CLI + git + openssh; optional vendored llm-connect |
|
|
|
|
|
|
| `deploy/k8s/railiance/` | Namespace, ConfigMap, Deployment, smoke Job |
|
|
|
|
|
|
| `deploy/scripts/railiance-smoke.sh` | Host e2e: clone sandbox → commit → push → hub |
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
| `rein-aharness smoke` | Deterministic smoke (no Claude Code required) |
|
2026-07-18 10:48:44 +02:00
|
|
|
|
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
## Prerequisites (done 2026-07-17, paths renamed per checklist above)
|
2026-07-18 10:48:44 +02:00
|
|
|
|
|
|
|
|
|
|
- Lane 2 deploy key on host + Forgejo write on `coulomb/executor-sandbox`
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
- Lane 3 AppRole under `~/.local/rein-aharness/approle-binky-mail`
|
|
|
|
|
|
- `source ~/.local/rein-aharness/env`
|
2026-07-18 10:48:44 +02:00
|
|
|
|
- Hub: `http://127.0.0.1:18000` (ops-bridge) or in-cluster `state-hub.state-hub.svc`
|
|
|
|
|
|
|
|
|
|
|
|
## Build & load image (workstation → railiance01)
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
# from rein-aharness repo root
|
|
|
|
|
|
make image # tags rein-aharness:railiance01
|
|
|
|
|
|
make image-export # /tmp/rein-aharness-railiance01.tar
|
|
|
|
|
|
scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/
|
|
|
|
|
|
ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar
|
2026-07-18 10:48:44 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## Apply k8s
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/
|
|
|
|
|
|
ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/
|
|
|
|
|
|
ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness
|
2026-07-18 10:48:44 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## Host smoke (authoritative e2e gate)
|
|
|
|
|
|
|
|
|
|
|
|
Full path uses the host deploy key and hub bridge:
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.
Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).
Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.
deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
|
|
|
|
ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh'
|
2026-07-18 10:48:44 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
Expect: local commit + push to `executor-sandbox`, hub event `harness_smoke`,
|
|
|
|
|
|
`.kaizen/metrics/coach/` on the sandbox checkout.
|
|
|
|
|
|
|
|
|
|
|
|
## Personal follow-ups (not T06)
|
|
|
|
|
|
|
|
|
|
|
|
- At **binky cutover only**: attach the same deploy key to `coulomb/binky-control`
|
|
|
|
|
|
- Claude Code on the host (or hosted adapter) for real agentic sessions
|
|
|
|
|
|
- T03 issue-core intake for scheduled task consumption
|