feat: Railiance package and deploy (HARNESS-WP-0001-T06)

Container image, k8s namespace/deployment/smoke job, host venv install path,
and deterministic agent-harness smoke (sandbox commit+push+hub) for remote
verification without Claude Code on the worker host.
This commit is contained in:
tegwick 2026-07-18 10:48:44 +02:00
parent 4144eba160
commit 67f1791491
15 changed files with 520 additions and 1 deletions

View file

@ -0,0 +1,7 @@
apiVersion: v1
kind: Namespace
metadata:
name: agent-harness
labels:
app.kubernetes.io/part-of: agent-harness
app.kubernetes.io/name: agent-harness

View file

@ -0,0 +1,13 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: agent-harness-config
namespace: agent-harness
labels:
app.kubernetes.io/name: agent-harness
data:
# In-cluster State Hub (production). Host-level smoke may override to
# http://127.0.0.1:18000 (ops-bridge reverse tunnel to workstation hub).
STATE_HUB_URL: "http://state-hub.state-hub.svc.cluster.local:8000"
BAO_ADDR: "https://bao.coulomb.social"
VAULT_ADDR: "https://bao.coulomb.social"

View file

@ -0,0 +1,52 @@
# Long-lived instance placeholder until T03 task intake polls issue-core.
# Keeps one ready replica with harness CLI + git tools; no LLM session here.
apiVersion: apps/v1
kind: Deployment
metadata:
name: agent-harness
namespace: agent-harness
labels:
app.kubernetes.io/name: agent-harness
app.kubernetes.io/part-of: agent-harness
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: agent-harness
template:
metadata:
labels:
app.kubernetes.io/name: agent-harness
app.kubernetes.io/part-of: agent-harness
spec:
securityContext:
fsGroup: 10001
containers:
- name: agent-harness
image: agent-harness:railiance01
imagePullPolicy: Never
command: ["sleep", "infinity"]
envFrom:
- configMapRef:
name: agent-harness-config
resources:
requests:
cpu: 25m
memory: 64Mi
limits:
cpu: 500m
memory: 512Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 10001
runAsGroup: 10001
volumeMounts:
- name: tmp
mountPath: /tmp
volumes:
- name: tmp
emptyDir: {}

View file

@ -0,0 +1,47 @@
# One-shot smoke Job. Prefer host-level smoke (deploy/scripts/railiance-smoke.sh)
# when deploy keys live on the host. This Job is for image/k8s path verification
# with --no-push (no deploy key in-cluster yet).
apiVersion: batch/v1
kind: Job
metadata:
name: agent-harness-smoke
namespace: agent-harness
labels:
app.kubernetes.io/name: agent-harness
app.kubernetes.io/component: smoke
spec:
ttlSecondsAfterFinished: 600
backoffLimit: 1
template:
metadata:
labels:
app.kubernetes.io/name: agent-harness
app.kubernetes.io/component: smoke
spec:
restartPolicy: Never
securityContext:
fsGroup: 10001
containers:
- name: smoke
image: agent-harness:railiance01
imagePullPolicy: Never
args:
- "profiles"
envFrom:
- configMapRef:
name: agent-harness-config
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 10001
runAsGroup: 10001

View file

@ -0,0 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: agent-harness
resources:
- 00-namespace.yaml
- configmap.yaml
- deployment.yaml
- job-smoke.yaml