rein-aharness/deploy
tegwick f6930ad115 Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.

Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).

Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.

deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00
..
k8s/railiance Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02) 2026-07-26 14:22:18 +02:00
scripts Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02) 2026-07-26 14:22:18 +02:00
README.md Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02) 2026-07-26 14:22:18 +02:00

Railiance deployment (HARNESS-WP-0001-T06)

Single shared harness instance on railiance01. Secrets stay on the host (Lanes 23); the container image is the portable runtime package.

Renamed from agent-harness (HARNESS-WP-0002-T02). Image tag, k8s namespace/labels, CLI command, and Python package are all renamed in this repo already. The commands below assume the rename cutover checklist just below has been done on railiance01 first — this is a live production deployment for binky-control, so the cutover itself is deliberately not automated from a workstation session.

Rename cutover checklist (do this on railiance01 before redeploying)

  1. Move the host-side secrets dir: mv ~/.local/agent-harness ~/.local/rein-aharness (or symlink, if anything else still reads the old path).
  2. Move/rename the checkout: mv ~/agent-harness ~/rein-aharness (or a fresh deploy-rsync to the new path — see Makefile).
  3. Verify no other host cron/systemd unit still references ~/agent-harness or the agent-harness command directly.
  4. Once the above is done, kubectl delete namespace agent-harness after confirming the new rein-aharness namespace deploys and smokes clean — don't delete the old one first, in case cutover needs a rollback.

Layout

Path Role
Containerfile Image: Python CLI + git + openssh; optional vendored llm-connect
deploy/k8s/railiance/ Namespace, ConfigMap, Deployment, smoke Job
deploy/scripts/railiance-smoke.sh Host e2e: clone sandbox → commit → push → hub
rein-aharness smoke Deterministic smoke (no Claude Code required)

Prerequisites (done 2026-07-17, paths renamed per checklist above)

  • Lane 2 deploy key on host + Forgejo write on coulomb/executor-sandbox
  • Lane 3 AppRole under ~/.local/rein-aharness/approle-binky-mail
  • source ~/.local/rein-aharness/env
  • Hub: http://127.0.0.1:18000 (ops-bridge) or in-cluster state-hub.state-hub.svc

Build & load image (workstation → railiance01)

# from rein-aharness repo root
make image                 # tags rein-aharness:railiance01
make image-export          # /tmp/rein-aharness-railiance01.tar
scp /tmp/rein-aharness-railiance01.tar railiance01:/tmp/
ssh railiance01 sudo k3s ctr images import /tmp/rein-aharness-railiance01.tar

Apply k8s

rsync -a deploy/k8s/railiance/ railiance01:rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl apply -k rein-aharness/deploy/k8s/railiance/
ssh railiance01 kubectl -n rein-aharness rollout status deploy/rein-aharness

Host smoke (authoritative e2e gate)

Full path uses the host deploy key and hub bridge:

ssh railiance01 'bash ~/rein-aharness/deploy/scripts/railiance-smoke.sh'

Expect: local commit + push to executor-sandbox, hub event harness_smoke, .kaizen/metrics/coach/ on the sandbox checkout.

Personal follow-ups (not T06)

  • At binky cutover only: attach the same deploy key to coulomb/binky-control
  • Claude Code on the host (or hosted adapter) for real agentic sessions
  • T03 issue-core intake for scheduled task consumption