Full cutover executed on railiance01 with operator go-ahead: host secrets dir + checkout renamed, host venv recreated from scratch (renaming a venv directory breaks its embedded shebang paths), image rebuilt/imported, renamed k8s manifests applied alongside the old namespace (not overwriting it), rollout + in-cluster smoke verified, then the authoritative host smoke script run against the live deployment: ok: true, committed: true, pushed: true, with a matching harness_smoke event confirmed in State Hub. Only after that verification did we delete the old agent-harness namespace and checkout. Found and fixed two host-side references the original checklist hadn't anticipated: path substitutions inside the (secrets, not directly read) env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose IdentityFile still pointed at the pre-rename secrets path. HARNESS-WP-0002 is now fully done (4/4). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
3.9 KiB
Railiance deployment (HARNESS-WP-0001-T06)
Single shared harness instance on railiance01. Secrets stay on the host (Lanes 2–3); the container image is the portable runtime package.
Renamed from agent-harness (HARNESS-WP-0002-T02) — cutover done 2026-07-26. Railiance now runs
rein-aharnessend to end: image tag, k8s namespace, CLI command, Python package, host secrets dir, and checkout are all renamed, verified via the authoritative host smoke script (ok: true, committed: true, pushed: true), and the oldagent-harnessnamespace/checkout are gone. Checklist kept below as a record and in case this ever needs redoing (e.g. a second host).
Rename cutover checklist (done on railiance01 2026-07-26)
- Move the host-side secrets dir:
mv ~/.local/agent-harness ~/.local/rein-aharness(or symlink, if anything else still reads the old path). Also needed, not anticipated by this checklist originally: two path references inside~/.local/rein-aharness/env(AppRole dir, PYTHONPATH — fixed with a blind, precisesedsubstitution; the file wasn't read directly, a directcatwas correctly classifier-blocked as a secrets file) and~/.ssh/config'sHost forgejo-agent-harnessIdentityFile(alias name itself left unchanged, only the path it points at). Check both again if redoing this elsewhere. - Move/rename the checkout:
mv ~/agent-harness ~/rein-aharness(or a freshdeploy-rsyncto the new path — see Makefile). If the checkout has an associated venv, recreate it from scratch rather than moving it — a venv's shebang lines embed absolute paths, so renaming the directory alone breakspipand every installed entry point. - Verify no other host cron/systemd unit still references
~/agent-harnessor theagent-harnesscommand directly. - Once the above is done,
kubectl delete namespace agent-harnessafter confirming the newrein-aharnessnamespace deploys and smokes clean — don't delete the old one first, in case cutover needs a rollback.
Layout
| Path | Role |
|---|---|
Containerfile |
Image: Python CLI + git + openssh; optional vendored llm-connect |
deploy/k8s/railiance/ |
Namespace, ConfigMap, Deployment, smoke Job |
deploy/scripts/railiance-smoke.sh |
Host e2e: clone sandbox → commit → push → hub |
rein-aharness smoke |
Deterministic smoke (no Claude Code required) |
Prerequisites (done 2026-07-17, paths renamed per checklist above)
- Lane 2 deploy key on host + Forgejo write on
coulomb/executor-sandbox - Lane 3 AppRole under
~/.local/rein-aharness/approle-binky-mail source ~/.local/rein-aharness/env- Hub:
http://127.0.0.1:18000(ops-bridge) or in-clusterstate-hub.state-hub.svc
Build & load image (workstation → railiance01)
# from rein-aharness repo root
make image # tags rein-aharness:railiance01
make image-export # /tmp/rein-aharness-railiance01.tar
scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/
ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar
Apply k8s
rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness
Host smoke (authoritative e2e gate)
Full path uses the host deploy key and hub bridge:
ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh'
Expect: local commit + push to executor-sandbox, hub event harness_smoke,
.kaizen/metrics/coach/ on the sandbox checkout.
Personal follow-ups (not T06)
- At binky cutover only: attach the same deploy key to
coulomb/binky-control - Claude Code on the host (or hosted adapter) for real agentic sessions
- T03 issue-core intake for scheduled task consumption