rein-aharness/deploy/README.md
tegwick 4d1e6bbb6a Close HARNESS-WP-0002-T02: live Railiance cutover done
Full cutover executed on railiance01 with operator go-ahead: host
secrets dir + checkout renamed, host venv recreated from scratch
(renaming a venv directory breaks its embedded shebang paths), image
rebuilt/imported, renamed k8s manifests applied alongside the old
namespace (not overwriting it), rollout + in-cluster smoke verified,
then the authoritative host smoke script run against the live
deployment: ok: true, committed: true, pushed: true, with a matching
harness_smoke event confirmed in State Hub. Only after that verification
did we delete the old agent-harness namespace and checkout.

Found and fixed two host-side references the original checklist hadn't
anticipated: path substitutions inside the (secrets, not directly read)
env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose
IdentityFile still pointed at the pre-rename secrets path.

HARNESS-WP-0002 is now fully done (4/4).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 18:44:56 +02:00

85 lines
3.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Railiance deployment (HARNESS-WP-0001-T06)
Single shared harness instance on **railiance01**. Secrets stay on the host
(Lanes 23); the container image is the portable runtime package.
> **Renamed from agent-harness (HARNESS-WP-0002-T02) — cutover done
> 2026-07-26.** Railiance now runs `rein-aharness` end to end: image tag,
> k8s namespace, CLI command, Python package, host secrets dir, and
> checkout are all renamed, verified via the authoritative host smoke
> script (`ok: true, committed: true, pushed: true`), and the old
> `agent-harness` namespace/checkout are gone. Checklist kept below as a
> record and in case this ever needs redoing (e.g. a second host).
## Rename cutover checklist (done on railiance01 2026-07-26)
1. Move the host-side secrets dir: `mv ~/.local/agent-harness ~/.local/rein-aharness`
(or symlink, if anything else still reads the old path).
**Also needed, not anticipated by this checklist originally:** two
path references *inside* `~/.local/rein-aharness/env` (AppRole dir,
PYTHONPATH — fixed with a blind, precise `sed` substitution; the
file wasn't read directly, a direct `cat` was correctly classifier-blocked
as a secrets file) and `~/.ssh/config`'s `Host forgejo-agent-harness`
`IdentityFile` (alias name itself left unchanged, only the path it
points at). Check both again if redoing this elsewhere.
2. Move/rename the checkout: `mv ~/agent-harness ~/rein-aharness` (or a fresh
`deploy-rsync` to the new path — see Makefile). If the checkout has an
associated venv, **recreate it from scratch** rather than moving it —
a venv's shebang lines embed absolute paths, so renaming the directory
alone breaks `pip` and every installed entry point.
3. Verify no other host cron/systemd unit still references
`~/agent-harness` or the `agent-harness` command directly.
4. Once the above is done, `kubectl delete namespace agent-harness` **after**
confirming the new `rein-aharness` namespace deploys and smokes clean —
don't delete the old one first, in case cutover needs a rollback.
## Layout
| Path | Role |
|------|------|
| `Containerfile` | Image: Python CLI + git + openssh; optional vendored llm-connect |
| `deploy/k8s/railiance/` | Namespace, ConfigMap, Deployment, smoke Job |
| `deploy/scripts/railiance-smoke.sh` | Host e2e: clone sandbox → commit → push → hub |
| `rein-aharness smoke` | Deterministic smoke (no Claude Code required) |
## Prerequisites (done 2026-07-17, paths renamed per checklist above)
- Lane 2 deploy key on host + Forgejo write on `coulomb/executor-sandbox`
- Lane 3 AppRole under `~/.local/rein-aharness/approle-binky-mail`
- `source ~/.local/rein-aharness/env`
- Hub: `http://127.0.0.1:18000` (ops-bridge) or in-cluster `state-hub.state-hub.svc`
## Build & load image (workstation → railiance01)
```bash
# from rein-aharness repo root
make image # tags rein-aharness:railiance01
make image-export # /tmp/rein-aharness-railiance01.tar
scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/
ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar
```
## Apply k8s
```bash
rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness
```
## Host smoke (authoritative e2e gate)
Full path uses the host deploy key and hub bridge:
```bash
ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh'
```
Expect: local commit + push to `executor-sandbox`, hub event `harness_smoke`,
`.kaizen/metrics/coach/` on the sandbox checkout.
## Personal follow-ups (not T06)
- At **binky cutover only**: attach the same deploy key to `coulomb/binky-control`
- Claude Code on the host (or hosted adapter) for real agentic sessions
- T03 issue-core intake for scheduled task consumption