Commit Graph
489 Commits
Author SHA1 Message Date
autonomic-bot ac73f1b63a Merge pull request 'chore: bump recipe-maintainer submodule to 6698723 - recipe-upstream detects the upstream default branch (main vs master)' (#26) from recipe-upstream-default-branch into main 2026-09-21 16:50:40 +00:00
autonomic-bot 71ca680c86 chore: bump recipe-maintainer submodule to 6698723 — recipe-upstream detects the upstream default branch (main vs master) instead of trusting the PR base 2026-09-21 16:49:30 +00:00
autonomic-bot a1c37185d8 Merge pull request 'plan: migrate cc-ci domains to ci.autonomic.zone' (#25) from plan-domain-migration into main 2026-09-21 16:31:12 +00:00
autonomic-bot e52767665b plan: migrate cc-ci domains to ci.autonomic.zone — DNS records, dual-cert SNI, phased cutover 2026-09-21 16:31:03 +00:00
autonomic-bot fa73b81427 Merge pull request 'chore: bump recipe-maintainer submodule to ef3d703 (recipe-upstream laptop-fetch fix)' (#24) from submodule-arm-bump-upstream-fetch into main 2026-09-21 16:29:59 +00:00
autonomic-bot 04eb8b4896 chore: bump recipe-maintainer submodule to ef3d703 — recipe-upstream prints step-0 fetch-from-mirror for the operator's laptop 2026-09-21 16:29:38 +00:00
autonomic-bot edf1e2bd39 Merge pull request 'launchers: default LOOP_TIER to go (zen endpoint dead server-side)' (#23) from tier-default-go into main 2026-09-21 16:15:55 +00:00
autonomic-bot 5aee9551d0 launchers: default LOOP_TIER to 'go' — zen endpoint dead server-side, silently ate the 2026-09-18 weekly report 2026-09-21 16:15:11 +00:00
autonomic-bot e29b5b4101 upstream(mattermost-lts): 2026-09-18 re-check — 11.7.11 newest ESR patch; PR #2 extended 11.7.10→11.7.11, GREEN (drone 1373); CVE-2026-13426 re-adjudicated FIXED (window count 14) 2026-09-18 07:54:13 +00:00
autonomic-bot 6f63214d30 upstream(n8n): 2.38.7 / 2.39.3-2.39.7 / 2.40.0-2.40.3 release notes (2026-09-18 window) 2026-09-18 07:43:19 +00:00
loops 9202936b2e upstream(lasuite-drive): minio Docker Hub repo removed — quay.io pin notes (PR #7 carries the switch) 2026-09-18 03:34:58 +00:00
autonomic-bot 935a411c0c upstream(lasuite-docs): docspec switch (docspec/docspec, port 3000), minio quay pin notes 2026-09-18 03:27:52 +00:00
autonomic-bot e85094a8e9 upstream(immich): v3.2.1/v3.2.2 pins researched (sidecar pins unchanged) 2026-09-18 03:02:53 +00:00
autonomic-bot bb2aac39c8 upstream(hedgedoc): PG18 mount fix resolved on PR #3, multi-major pgautoupgrade verified 2026-09-18 02:54:26 +00:00
autonomic-bot 8b79c4db20 upstream(custom-html): note nginx 1.31.6 security release (CVE-2026-90439) 2026-09-18 02:12:54 +00:00
autonomic-bot 2d312b366e cctest-recipe-upstream: verify merge-base before rebasing; beware stray upstream main vs master 2026-09-14 19:24:24 +00:00
autonomic-bot 43f2cf074b cctest-recipe-upstream: derive upstream base branch (mirror main vs upstream master) 2026-09-14 19:19:45 +00:00
autonomic-bot 1b8c3966cb cctest-recipe-upstream: guard against diverged mirror history (rebase before compare) 2026-09-14 19:16:25 +00:00
autonomic-bot c6dad5f11b cctest-recipe-upstream: step 0 fetches by URL, remote-name agnostic 2026-09-14 19:10:57 +00:00
autonomic-bot b8161f15e4 cctest-recipe-upstream: step 0 is just the mirror fetch (remote-add only as fallback) 2026-09-14 16:57:55 +00:00
autonomic-bot 7934367f15 cctest-recipe-upstream: always emit step 0 fetch-from-mirror commands for the operator 2026-09-14 16:57:07 +00:00
autonomic-bot d48e47adfe Merge pull request 'cctest-recipe-upstream: support non-sandboxed execution' (#22) from cctest-upstream-nonsandbox into main 2026-09-14 16:55:02 +00:00
autonomic-bot 0c115ea714 cctest-recipe-upstream: support non-sandboxed execution (anonymous git/API access) 2026-09-14 16:54:55 +00:00
autonomic-bot 060978209c memory+journal: report STATUS round-2 — Gitea Anubis 307-challenges browser UAs; /pr/ proxy pins non-browser UA (cc-ci PR #38, deployed) 2026-09-14 16:48:01 +00:00
autonomic-bot 9e7770ff43 flake.lock: move cc-ci input to main (PR #38) — report /pr/ proxy UA fix, test+switch health-checked 2026-09-14 16:46:52 +00:00
autonomic-bot f33c1fe36f journal: session 2026-09-14 — report STATUS column fixed (gitea/wordpress mirrors flipped public, enroll skill patched) 2026-09-14 16:38:29 +00:00
autonomic-bot 6e93922e01 recipe-enroll: create mirrors public (gitea/wordpress were private-from-birth, darkening report STATUS) 2026-09-14 16:38:15 +00:00
autonomic-bot 0e5995960a Merge pull request 'memory: zen-tier dead on this host; go+glm-5.3-flash defaults documented' (#21) from memory-zen-dead into main 2026-09-14 14:20:57 +00:00
autonomic-bot 0354b1714d memory: weekly upgrader — go tier + glm-5.3-flash defaults, ZEN dead on this host (PR #20 context) 2026-09-14 14:20:55 +00:00
autonomic-bot 4454fe49ef Merge pull request 'launch-*: default tier go + glm-5.3-flash (zen model ids dead on this host)' (#20) from launcher-go-model-default into main 2026-09-14 14:20:34 +00:00
autonomic-bot ed6e70928f launch-*: hardcode the default tier to go + glm-5.3-flash (zen model ids are dead on this host)
Every manual launch of launch-report/launch-upgrader bypasses the systemd EnvironmentFile (/srv/cc-ci/upgrader.env sets LOOP_TIER=go + the go models) and fell back to hardcoded zen defaults, which die instantly here (ProviderModelNotFoundError: opencode/glm-5.2 — the host holds no ZEN key and zen models vanished from the provider catalogue, 2026-09-14). This crashed the 2026-09-11 report agent at launch and again on every manual retry.

- launch-upgrader.py + launch-report.py: default TIER go, go-tier model default glm-5.3-flash (mirrors the 2026-09-08 operator choice in upgrader.env); zen stays an explicit opt-in on a host with a key.
- launch-supervisor.py: default SUPERVISOR_MODEL glm-5.3-flash.
- docstrings updated to match.

Verified with env -i: bare invocation resolves tier=go, model=opencode-go/glm-5.3-flash on all three. The 2026-09-11 weekly report is published live (report.ci.commoninternet.net/week-2026-09-11.html) after a fresh glm-5.3-flash report run.
2026-09-14 14:20:25 +00:00
autonomic-bot dc6aa1c2c4 upstream(n8n): release-notes sources 2.38.5-2.39.2 (2026-09-11 run) 2026-09-11 07:27:07 +00:00
nptest2 951a108c1f upstream(immich): v3.2.0 pins (valkey 70739f85, pg combo unchanged) + ghcr pagination gotcha 2026-09-11 07:23:17 +00:00
notplants 55ce8e3830 upstream(mattermost-lts): 2026-09-11 re-check — 11.7.10 still ESR tip; CVE-2026-13426 adjudicated FIXED (window count 14) 2026-09-11 07:20:26 +00:00
notplants 8e9d2ef759 upstream(hedgedoc): PG18 layout gotcha + 1.12.0 notes (17 settled on PR #3) 2026-09-11 03:13:32 +00:00
notplants f58a600fbd upstream(gitea): add mariadb release-notes sources (overlay db pin was invisible to abra survey) 2026-09-11 02:41:09 +00:00
notplants 193befdb99 upstream(bluesky-pds): add @atproto/pds changelog URL (image 0.4.5NNN == pds 0.5.NN) 2026-09-11 02:11:06 +00:00
notplantsandClaude Opus 5 f3c871665a README + journal: the /secrets layout, and the weekly run's flash models
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:30:18 +00:00
notplantsandClaude Opus 5 e7aa055784 /secrets is the authoritative location for every secret, incl. the ssh host keys
Operator rule: secrets live in /secrets and consumers reach them from there.
Three subdirectories with the ownership each consumer needs — files/ (loops),
host/ (root: ssh host keys + sops age identity), nginx/ (root:nginx: the
opencode UI htpasswd) — under a 0711 /secrets so nginx can traverse to its own
without the directory being listable.

sshd's hostKeys and sops-nix's sshKeyPaths/keyFile are pointed at /secrets
DIRECTLY rather than through symlinks: the ed25519 host key is load-bearing
beyond ssh, since its age identity (age1tmvg…) is a recipient of cc-ci-secrets,
and a dangling symlink would let sshd write a NEW key and silently make every
cc-ci secret undecryptable. The /etc/ssh symlinks are added for discoverability
only, so nothing depends on activation ordering.

nginx's htpasswd path becomes an option (opencodeUiHtpasswdFile) defaulting
under /secrets, rather than a hard-coded /etc/nginx path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:23:28 +00:00
notplantsandClaude Opus 5 360999d623 journal: secrets audit of the cc-ci host; leaked keys found in rsynced agent logs and redacted
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 17:07:23 +00:00
cc-ci-orchestrator 8af6c5fb45 journal: orchestrator startup entry (opencode agent, phase sequence confirmed DONE) 2026-09-08 16:53:57 +00:00
notplantsandClaude Opus 5 c14c56147d launchers: the opencode UI is oc.ci.commoninternet.net (not tailnet-only); journal the key switch
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 16:53:20 +00:00
notplantsandClaude Opus 5 79f69b0d35 cc-ci host on the OpenCode Go subscription key (opencode-go), not ZEN
The operator's AUTONOMIC_OPENCODE_KEY is a Go subscription key. Put in the
`opencode` (ZEN) slot it authenticates but every request fails "Insufficient
balance", because ZEN is pay-as-you-go credit; on the `opencode-go` endpoint
the same key answers fine. So the orchestrator agent moves to
opencode-go/glm-5.2, and README records that this host is a Go host and that
its opencode config must carry no inline apiKey.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 16:50:20 +00:00
notplantsandClaude Opus 5 7abea67ad4 host toolbox: vi/vim, sqlite, bat, bc, moreutils, pv, man-pages; set EDITOR
`vi` and `vim` were both absent on the cc-ci host (operator hit it over ssh);
the vim package ships a `vi` binary, so one entry covers both names, and
EDITOR=vim makes git/systemctl/visudo open something that exists.

sqlite earns its place beyond convenience: Drone's build and step logs live in
its sqlite volume, and the runbook plus /cc-ci-status tell you to read them
there — until now every such check needed an ad-hoc `nix-shell -p sqlite`.

Installed via environment.systemPackages, so they are on PATH for BOTH root and
loops through /run/current-system/sw/bin.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 16:32:45 +00:00
auto-update ec8b2fef0f flake.lock: weekly auto-update, health-checked 2026-09-08 03:06:27 +00:00
notplantsandClaude Opus 5 1eb176cf09 gitignore the auto-update lock backup; journal the tested auto-update + skill rewrites
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-08 02:02:26 +00:00
auto-update d1f5e916f3 flake.lock: weekly auto-update, health-checked 2026-09-07 22:27:16 +00:00
notplantsandClaude Fable 5.1 a8af8429f2 weekly health-gated auto-update of the cc-ci host; skills rewritten for the combined host
nix/modules/auto-update.nix (own module, no notplants-nix dependency): Tuesday
03:00 UTC, busy-gated (CI run, weekly upgrader, report, sweep, running Drone
builds → skip), `nix flake update` → build → switch-to-configuration test →
cc-ci health checks (sshd, 0 failed units, core units, every swarm service at
replica count, sops decrypted, dashboard/reports/drone 200, opencode UI 401)
→ profile + bootloader → flake.lock committed and pushed to main → /etc/cc-ci
fast-forwarded; revert + lock restore on failure; one-line state file for
/cc-ci-status.

Skills (.opencode canonical, .claude pointers' descriptions synced):
- cc-ci-orchestrator-update: THE host update — drives the auto-update unit by
  hand; --cc-ci-only for a cc-ci-main-only move; failure playbook.
- cc-ci-server-update: delegates to it and explains why the old procedure
  (rebuilding the cc-ci repo's standalone #cc-ci) must not be run on this host.
- cc-ci-update: chains orchestrator-update then tests-update.
- cc-ci-status: §5/§6 for one host — auto-update state, generation vs boot
  generation, front doors (oc.ci = 401), sops, fail2ban, timers, orchestrator
  agent session, secrets inventory; verdict updated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-07 22:22:50 +00:00
notplantsandClaude Fable 5.1 48226dd78f opencode UI stack is ccci-opencode-ui, on the weekly sweep's keep-list; journal: first weekly run on the new host
The 2026-09-07 weekly run's step-0 orphan sweep removed the `opencode-ui`
swarm stack (the traefik route to the opencode web UI) because it was not
on sweep-orphans.sh's keep-list. Renamed to ccci-opencode-ui alongside the
other control-plane stacks and added to KEEP_RE.

Journal: the run itself (lasuite-docs #8, n8n #7 GREEN on the new Drone,
report week-2026-09-07 published) ran entirely on the new host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-07 22:13:43 +00:00
autonomic-bot be9687962c upstream(n8n): release-notes sources 2.38.x 2026-09-07 21:49:50 +00:00