cc-ci host: the orchestrator is an opencode agent; no Claude on the box; /secrets convention
Operator 2026-09-07 (evening): Claude sessions stay on notplants-orchestrator; on the cc-ci host the orchestrator is an opencode agent (agents.toml: opencode/glm-5.2) steered from https://oc.ci.commoninternet.net, next to the upgrader/report sessions. claude-install and CLAUDE_BIN are gone from the modules; launch-upgrader/report print the real UI URL; README "Operating the orchestrator" rewritten and a "Weekly upgrade run" section added. Secrets: only cc-ci's, under /secrets/files with runtime paths symlinked (README §4 table), nothing from other projects — tangled key and the tailscale line dropped from the host. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
This commit is contained in:
@@ -31,8 +31,9 @@ the orchestrator watches from outside.
|
||||
Reboot resilience is handled by **`cc-ci-loops.service`** (system unit): on boot it logs the reboot
|
||||
to `REBOOTS.md` (boot_id-gated) and runs `launch.sh start` with `RESUME_PHASE=1`, so the loops +
|
||||
watchdog auto-resume the saved phase. The orchestrator session itself is relaunched by
|
||||
`cc-ci-orchestrator.service` (`agents.py up orchestrator`) — the operator reconnects to it (that's
|
||||
why the startup notification matters). Since 2026-09 the orchestrator runs on the **same Hetzner
|
||||
`cc-ci-orchestrator.service` (`agents.py up orchestrator`) as an **opencode agent** the operator
|
||||
steers from https://oc.ci.commoninternet.net (no Claude on the cc-ci host; Claude sessions run on
|
||||
the notplants-orchestrator box and reach cc-ci over ssh). Since 2026-09 the orchestrator runs on the **same Hetzner
|
||||
host as the cc-ci CI server** (`cc-ci`, public `195.201.88.249`, tailnet `cc-ci`), declared by
|
||||
`nixosConfigurations.cc-ci` in this repo's `flake.nix`, which imports the CI server from the cc-ci
|
||||
repo's `nixosModules.cc-ci-server`. `ssh cc-ci` from the loops user therefore goes to loopback.
|
||||
|
||||
Reference in New Issue
Block a user