From cf33fe34865d9946edfd7cb239fee8f9dcd9385e Mon Sep 17 00:00:00 2001 From: mfowler Date: Thu, 20 Aug 2026 16:06:29 +0000 Subject: [PATCH] fleet: register cc-ci-orchestrator-backup, emily-lichen, gateway-coop MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three new projects, all running one operator-driven agent over Claude Code Remote Control: - cc-ci-orchestrator-backup — self-contained standby for the cc-ci orchestrator on the claude backend + Fable (claude-fable-5); isolated from the live loops (own dir/state/prefix) and must not drive them without deliberate promotion. - emily-lichen — plans/builds a sandboxed opencode UI at emily.commoninternet.net for editing a lichen.page site with GLM 5.2. Planning only: the sandbox is not built and nothing serves that hostname yet. - gateway-coop — the tunnel gateway (upstream codeberg notplants/tunnel-gateway-server) that emily-lichen depends on. Pre-existing repo, not scaffolded by the PO, and its harness is deliberately NOT vendored: engine/, agents.toml, prompts/ and .ao-state/ are excluded via the project's .git/info/exclude so nothing about the harness reaches the public upstream. `ref` is therefore a plain-clone checkout, not a submodule pin. Registry validates at 8 projects, schema v1. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_016L6nYYwkCWnrEFKTnKAfet --- fleet.toml | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/fleet.toml b/fleet.toml index ed4b070..22d56cb 100644 --- a/fleet.toml +++ b/fleet.toml @@ -80,3 +80,50 @@ enabled = true # RUNNING — operator- secrets = ".env" # atproto creds; gitignored, not yet populated config = "agents.toml" notes = "Created 2026-08-01. Analysis of the operator's atproto data, and possibly custom feeds; the operator sets direction interactively. Single persistent agent 'analyst' (claude-opus-5, watch=heal, resume=true) exposed over Claude Code Remote Control as session notplants-atproto-analyst. Engine sourced from the bot's Tangled repo by operator choice (see comment above). Scope is deliberately open — the operator drives." + +# Standby orchestrator for cc-ci, on the Claude Code backend + Fable model (claude-fable-5). The +# PRIMARY cc-ci orchestrator runs on opencode + glm-5.2 elsewhere; this is a SELF-CONTAINED standby +# (own dir/state/prefix cc-ci-backup-) that never touches the live cc-ci loops. Operator-driven via +# Remote Control. Engine from the bot's Tangled repo (same as the two projects above). +[[project]] +name = "cc-ci-orchestrator-backup" +location = "/srv/project-orchestrator/projects/cc-ci-orchestrator-backup" +harness = "agent-orchestrator" +ref = "26d93c1eda36dd68d1f59e5bec5e4cea9bc0d761" # latest engine (v0.1.0-33-g26d93c1) from the bot's Tangled repo +enabled = true # RUNNING — operator-driven via Remote Control +secrets = ".env" # none required — claude backend uses the loops user's Claude login; gitignored placeholder +config = "agents.toml" +notes = "Created 2026-08-03. Self-contained STANDBY for the cc-ci orchestrator (primary runs on opencode + glm-5.2). Single persistent agent 'orchestrator' on the claude backend with the Fable model (claude-fable-5), watch=heal, resume=true, exposed over Claude Code Remote Control as session cc-ci-backup-orchestrator. Isolated from the live cc-ci system: own dir, own session prefix cc-ci-backup-, own state — it must NOT drive the live loops unless the operator deliberately promotes it. Engine from the bot's Tangled repo." + +# Design/build project for a sandboxed opencode interface at emily.commoninternet.net (the +# operator's mother edits her lichen.page site via GLM 5.2). Architecture is in the project's own +# PLAN.md. NOTE: this entry is the PLANNING project — the sandbox itself is NOT built yet, and +# nothing is serving emily.commoninternet.net. +[[project]] +name = "emily-lichen" +location = "/srv/project-orchestrator/projects/emily-lichen" +harness = "agent-orchestrator" +ref = "26d93c1eda36dd68d1f59e5bec5e4cea9bc0d761" # latest engine (v0.1.0-33-g26d93c1) from the bot's Tangled repo +enabled = true # RUNNING — operator-driven via Remote Control +secrets = ".env" # none yet; the sandbox's 3 creds are operator-supplied (see PLAN.md §2) +config = "agents.toml" +notes = "Created 2026-08-13. Plans + builds a sandboxed opencode web UI at emily.commoninternet.net for editing a lichen.page site with GLM 5.2. Design: a Docker container that joins the tailnet as its OWN node (tag:emily-sandbox), reached via the operator's gateway — the app host exposes nothing new publicly; the container is the security boundary and holds only 3 scoped creds. Single persistent agent 'implementer' (claude-opus-5, watch=heal, resume=true) over Remote Control as session emily-lichen-implementer. STATUS: planning — sandbox not built; blocked on operator input (dedicated opencode-go key, Emily's lichen token, tailscale tagged auth key + ACL, gateway forwarding, whether her site exists). Engine from the bot's Tangled repo." + +# The tunnel gateway (upstream: codeberg.org/notplants/tunnel-gateway-server) — nginx SNI/stream +# routing + a Flask admin app, forwarding public domains to tailnet backends. This is the gateway +# the emily-lichen design depends on. +# +# HARNESS IS NOT VENDORED IN THE PROJECT REPO (operator's choice, 2026-08-20): engine/, agents.toml, +# prompts/ and .ao-state/ are excluded via the project's .git/info/exclude (per-clone, never +# committed) rather than a submodule + .gitignore, so nothing about the harness reaches the public +# upstream repo or its pull requests. `ref` below is therefore the pinned commit of a PLAIN CLONE at +# /engine, not a submodule pin — re-pin by checking that clone out at a new ref. +[[project]] +name = "gateway-coop" +location = "/srv/gateway-coop" +harness = "agent-orchestrator" +ref = "26d93c1eda36dd68d1f59e5bec5e4cea9bc0d761" # plain clone at engine/ (NOT a submodule); v0.1.0-33-g26d93c1 +enabled = true # RUNNING — operator-driven via Remote Control +secrets = ".secrets/" # Hetzner API token + Tailscale auth keys; gitignored upstream, never in git +config = "agents.toml" +notes = "Registered 2026-08-20 (pre-existing repo, not scaffolded by the PO). Tunnel gateway: nginx SNI/stream routing driven by tunnel_map.conf + Flask admin (app.py, ports.py) mapping domain -> tailnet backend, with regex/wildcard entries and ip:port backends for remapping 443. Two deploy paths: imperative Debian (setup.sh) and declarative NixOS (nix/, flake.nix), with e2e/ tests. Single persistent agent 'orchestrator' (claude-opus-5, watch=heal, resume=true) over Remote Control as session gateway-coop-orchestrator. CAUTION: live infrastructure other projects depend on (it forwards emily.commoninternet.net per the emily-lichen plan), and the working tree carries substantial in-flight STAGED work (NixOS deploy: nix/, flake.nix, e2e/, terraform) that is not the PO's and must not be committed."