# Railiance deployment (HARNESS-WP-0001-T06) Single shared harness instance on **railiance01**. Secrets stay on the host (Lanes 2–3); the container image is the portable runtime package. > **Renamed from agent-harness (HARNESS-WP-0002-T02).** Image tag, k8s > namespace/labels, CLI command, and Python package are all renamed in > this repo already. The commands below assume the **rename cutover > checklist** just below has been done on railiance01 first — this is a > live production deployment for `binky-control`, so the cutover itself > is deliberately not automated from a workstation session. ## Rename cutover checklist (do this on railiance01 before redeploying) 1. Move the host-side secrets dir: `mv ~/.local/agent-harness ~/.local/rein-aharness` (or symlink, if anything else still reads the old path). 2. Move/rename the checkout: `mv ~/agent-harness ~/rein-aharness` (or a fresh `deploy-rsync` to the new path — see Makefile). 3. Verify no other host cron/systemd unit still references `~/agent-harness` or the `agent-harness` command directly. 4. Once the above is done, `kubectl delete namespace agent-harness` **after** confirming the new `rein-aharness` namespace deploys and smokes clean — don't delete the old one first, in case cutover needs a rollback. ## Layout | Path | Role | |------|------| | `Containerfile` | Image: Python CLI + git + openssh; optional vendored llm-connect | | `deploy/k8s/railiance/` | Namespace, ConfigMap, Deployment, smoke Job | | `deploy/scripts/railiance-smoke.sh` | Host e2e: clone sandbox → commit → push → hub | | `rein-aharness smoke` | Deterministic smoke (no Claude Code required) | ## Prerequisites (done 2026-07-17, paths renamed per checklist above) - Lane 2 deploy key on host + Forgejo write on `coulomb/executor-sandbox` - Lane 3 AppRole under `~/.local/rein-aharness/approle-binky-mail` - `source ~/.local/rein-aharness/env` - Hub: `http://127.0.0.1:18000` (ops-bridge) or in-cluster `state-hub.state-hub.svc` ## Build & load image (workstation → railiance01) ```bash # from rein-aharness repo root make image # tags rein-aharness:railiance01 make image-export # /tmp/rein-aharness-railiance01.tar scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/ ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar ``` ## Apply k8s ```bash rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/ ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/ ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness ``` ## Host smoke (authoritative e2e gate) Full path uses the host deploy key and hub bridge: ```bash ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh' ``` Expect: local commit + push to `executor-sandbox`, hub event `harness_smoke`, `.kaizen/metrics/coach/` on the sandbox checkout. ## Personal follow-ups (not T06) - At **binky cutover only**: attach the same deploy key to `coulomb/binky-control` - Claude Code on the host (or hosted adapter) for real agentic sessions - T03 issue-core intake for scheduled task consumption