Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host secrets dir + checkout renamed, host venv recreated from scratch (renaming a venv directory breaks its embedded shebang paths), image rebuilt/imported, renamed k8s manifests applied alongside the old namespace (not overwriting it), rollout + in-cluster smoke verified, then the authoritative host smoke script run against the live deployment: ok: true, committed: true, pushed: true, with a matching harness_smoke event confirmed in State Hub. Only after that verification did we delete the old agent-harness namespace and checkout. Found and fixed two host-side references the original checklist hadn't anticipated: path substitutions inside the (secrets, not directly read) env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose IdentityFile still pointed at the pre-rename secrets path. HARNESS-WP-0002 is now fully done (4/4). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
ced68ea325
commit
4d1e6bbb6a
2 changed files with 47 additions and 15 deletions
|
|
@ -3,19 +3,30 @@
|
|||
Single shared harness instance on **railiance01**. Secrets stay on the host
|
||||
(Lanes 2–3); the container image is the portable runtime package.
|
||||
|
||||
> **Renamed from agent-harness (HARNESS-WP-0002-T02).** Image tag, k8s
|
||||
> namespace/labels, CLI command, and Python package are all renamed in
|
||||
> this repo already. The commands below assume the **rename cutover
|
||||
> checklist** just below has been done on railiance01 first — this is a
|
||||
> live production deployment for `binky-control`, so the cutover itself
|
||||
> is deliberately not automated from a workstation session.
|
||||
> **Renamed from agent-harness (HARNESS-WP-0002-T02) — cutover done
|
||||
> 2026-07-26.** Railiance now runs `rein-aharness` end to end: image tag,
|
||||
> k8s namespace, CLI command, Python package, host secrets dir, and
|
||||
> checkout are all renamed, verified via the authoritative host smoke
|
||||
> script (`ok: true, committed: true, pushed: true`), and the old
|
||||
> `agent-harness` namespace/checkout are gone. Checklist kept below as a
|
||||
> record and in case this ever needs redoing (e.g. a second host).
|
||||
|
||||
## Rename cutover checklist (do this on railiance01 before redeploying)
|
||||
## Rename cutover checklist (done on railiance01 2026-07-26)
|
||||
|
||||
1. Move the host-side secrets dir: `mv ~/.local/agent-harness ~/.local/rein-aharness`
|
||||
(or symlink, if anything else still reads the old path).
|
||||
**Also needed, not anticipated by this checklist originally:** two
|
||||
path references *inside* `~/.local/rein-aharness/env` (AppRole dir,
|
||||
PYTHONPATH — fixed with a blind, precise `sed` substitution; the
|
||||
file wasn't read directly, a direct `cat` was correctly classifier-blocked
|
||||
as a secrets file) and `~/.ssh/config`'s `Host forgejo-agent-harness`
|
||||
`IdentityFile` (alias name itself left unchanged, only the path it
|
||||
points at). Check both again if redoing this elsewhere.
|
||||
2. Move/rename the checkout: `mv ~/agent-harness ~/rein-aharness` (or a fresh
|
||||
`deploy-rsync` to the new path — see Makefile).
|
||||
`deploy-rsync` to the new path — see Makefile). If the checkout has an
|
||||
associated venv, **recreate it from scratch** rather than moving it —
|
||||
a venv's shebang lines embed absolute paths, so renaming the directory
|
||||
alone breaks `pip` and every installed entry point.
|
||||
3. Verify no other host cron/systemd unit still references
|
||||
`~/agent-harness` or the `agent-harness` command directly.
|
||||
4. Once the above is done, `kubectl delete namespace agent-harness` **after**
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue