Full cutover executed on railiance01 with operator go-ahead: host secrets dir + checkout renamed, host venv recreated from scratch (renaming a venv directory breaks its embedded shebang paths), image rebuilt/imported, renamed k8s manifests applied alongside the old namespace (not overwriting it), rollout + in-cluster smoke verified, then the authoritative host smoke script run against the live deployment: ok: true, committed: true, pushed: true, with a matching harness_smoke event confirmed in State Hub. Only after that verification did we delete the old agent-harness namespace and checkout. Found and fixed two host-side references the original checklist hadn't anticipated: path substitutions inside the (secrets, not directly read) env file, and ~/.ssh/config's forgejo-agent-harness Host block, whose IdentityFile still pointed at the pre-rename secrets path. HARNESS-WP-0002 is now fully done (4/4). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
85 lines
3.9 KiB
Markdown
85 lines
3.9 KiB
Markdown
# Railiance deployment (HARNESS-WP-0001-T06)
|
||
|
||
Single shared harness instance on **railiance01**. Secrets stay on the host
|
||
(Lanes 2–3); the container image is the portable runtime package.
|
||
|
||
> **Renamed from agent-harness (HARNESS-WP-0002-T02) — cutover done
|
||
> 2026-07-26.** Railiance now runs `rein-aharness` end to end: image tag,
|
||
> k8s namespace, CLI command, Python package, host secrets dir, and
|
||
> checkout are all renamed, verified via the authoritative host smoke
|
||
> script (`ok: true, committed: true, pushed: true`), and the old
|
||
> `agent-harness` namespace/checkout are gone. Checklist kept below as a
|
||
> record and in case this ever needs redoing (e.g. a second host).
|
||
|
||
## Rename cutover checklist (done on railiance01 2026-07-26)
|
||
|
||
1. Move the host-side secrets dir: `mv ~/.local/agent-harness ~/.local/rein-aharness`
|
||
(or symlink, if anything else still reads the old path).
|
||
**Also needed, not anticipated by this checklist originally:** two
|
||
path references *inside* `~/.local/rein-aharness/env` (AppRole dir,
|
||
PYTHONPATH — fixed with a blind, precise `sed` substitution; the
|
||
file wasn't read directly, a direct `cat` was correctly classifier-blocked
|
||
as a secrets file) and `~/.ssh/config`'s `Host forgejo-agent-harness`
|
||
`IdentityFile` (alias name itself left unchanged, only the path it
|
||
points at). Check both again if redoing this elsewhere.
|
||
2. Move/rename the checkout: `mv ~/agent-harness ~/rein-aharness` (or a fresh
|
||
`deploy-rsync` to the new path — see Makefile). If the checkout has an
|
||
associated venv, **recreate it from scratch** rather than moving it —
|
||
a venv's shebang lines embed absolute paths, so renaming the directory
|
||
alone breaks `pip` and every installed entry point.
|
||
3. Verify no other host cron/systemd unit still references
|
||
`~/agent-harness` or the `agent-harness` command directly.
|
||
4. Once the above is done, `kubectl delete namespace agent-harness` **after**
|
||
confirming the new `rein-aharness` namespace deploys and smokes clean —
|
||
don't delete the old one first, in case cutover needs a rollback.
|
||
|
||
## Layout
|
||
|
||
| Path | Role |
|
||
|------|------|
|
||
| `Containerfile` | Image: Python CLI + git + openssh; optional vendored llm-connect |
|
||
| `deploy/k8s/railiance/` | Namespace, ConfigMap, Deployment, smoke Job |
|
||
| `deploy/scripts/railiance-smoke.sh` | Host e2e: clone sandbox → commit → push → hub |
|
||
| `rein-aharness smoke` | Deterministic smoke (no Claude Code required) |
|
||
|
||
## Prerequisites (done 2026-07-17, paths renamed per checklist above)
|
||
|
||
- Lane 2 deploy key on host + Forgejo write on `coulomb/executor-sandbox`
|
||
- Lane 3 AppRole under `~/.local/rein-aharness/approle-binky-mail`
|
||
- `source ~/.local/rein-aharness/env`
|
||
- Hub: `http://127.0.0.1:18000` (ops-bridge) or in-cluster `state-hub.state-hub.svc`
|
||
|
||
## Build & load image (workstation → railiance01)
|
||
|
||
```bash
|
||
# from rein-aharness repo root
|
||
make image # tags rein-aharness:railiance01
|
||
make image-export # /tmp/rein-aharness-railiance01.tar
|
||
scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/
|
||
ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar
|
||
```
|
||
|
||
## Apply k8s
|
||
|
||
```bash
|
||
rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/
|
||
ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/
|
||
ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness
|
||
```
|
||
|
||
## Host smoke (authoritative e2e gate)
|
||
|
||
Full path uses the host deploy key and hub bridge:
|
||
|
||
```bash
|
||
ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh'
|
||
```
|
||
|
||
Expect: local commit + push to `executor-sandbox`, hub event `harness_smoke`,
|
||
`.kaizen/metrics/coach/` on the sandbox checkout.
|
||
|
||
## Personal follow-ups (not T06)
|
||
|
||
- At **binky cutover only**: attach the same deploy key to `coulomb/binky-control`
|
||
- Claude Code on the host (or hosted adapter) for real agentic sessions
|
||
- T03 issue-core intake for scheduled task consumption
|