From 6195b5931717bf8e52d15512d7f50e05fab938d9 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 20 Aug 2026 07:42:22 +0000 Subject: [PATCH] =?UTF-8?q?Item=201:=20Koby=20report-only=20=E2=80=94=20en?= =?UTF-8?q?code=20HARD=20RULE=20in=20contracts=20(2026-08-17)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - hermes-config-template.prose.md: Add Rule 17 — Koby is never repaired, full stop - hermes-agent-baseline.prose.md: Document Koby report-only posture - contract-registry.yaml: Tag all healing contracts as Koby-eligible (skip heal) - scripts/agent-health-check.py: Mark Koby as report_only=True, skip repairs - All healing contracts: Add report_only_agents.koby marker Captain-approved ship via no-mistakes. PR auto-merges green. --- abiba-zulip-restore.prose.md | 4 ++ contract-registry.yaml | 70 +++++++++++++++++++++++++++++++ disk-gc-threat-response.prose.md | 5 ++- gpu-self-heal.prose.md | 7 ++++ hermes-agent-baseline.prose.md | 6 ++- hermes-config-template.prose.md | 11 +++++ hermes-zulip-restore.prose.md | 4 ++ litellm-self-heal.prose.md | 7 ++++ memory-audit-maintenance.prose.md | 5 ++- memory-fixer.prose.md | 3 ++ pm2-self-heal.prose.md | 2 + scripts/agent-health-check.py | 32 ++++++++------ zulip-health.prose.md | 2 + 13 files changed, 142 insertions(+), 16 deletions(-) diff --git a/abiba-zulip-restore.prose.md b/abiba-zulip-restore.prose.md index a02556d..dd0f8ac 100644 --- a/abiba-zulip-restore.prose.md +++ b/abiba-zulip-restore.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: function name: abiba-zulip-restore description: > @@ -11,6 +13,7 @@ version: 1.0.0 status: active runtime_contract: 2 --- +--- # Abiba Zulip Restore — Resume pi Zulip Communication @@ -304,6 +307,7 @@ module.exports = { }; ``` +--- --- **Last verified good state**: 2026-07-13 — Extension v2 running via `pi --mode rpc`, health endpoint :9200 returning `{status:"ok",connected:true}`, queue a669f21e. diff --git a/contract-registry.yaml b/contract-registry.yaml index 94d899e..864b6d1 100644 --- a/contract-registry.yaml +++ b/contract-registry.yaml @@ -1867,3 +1867,73 @@ contracts: last_run: null last_status: null drift_alerts: [] +# Koby Report-Only Registry (2026-08-17 — Captain) +# ⛔ KOBY IS NEVER REPAIRED — detect + report, never fix on .129 +koby_report_only: true +koby_host: "CT 111 (tdunna)" +koby_ip: ".129" +koby_user: "Theo" + +# Contracts that should be Koby-aware (detect only, no heal path) +koby_aware_contracts: + - name: pm2-self-heal + path: pm2-self-heal.prose.md + koby_action: skip_heal + koby_note: "Koby PM2 processes reported to Zulip, never auto-restarted on .129" + + - name: zulip-health + path: zulip-health.prose.md + koby_action: skip_heal + koby_note: "Koby Zulip bridge issues reported to Zulip, never repaired on .129" + + - name: hermes-zulip-restore + path: hermes-zulip-restore.prose.md + koby_action: skip_heal + koby_note: "Koby Zulip restoration skipped, only diagnostic alerts" + + - name: abiba-zulip-restore + path: abiba-zulip-restore.prose.md + koby_action: skip_heal + koby_note: "Abiba-Zulip restoration not applicable to Koby" + + - name: litellm-self-heal + path: litellm-self-heal.prose.md + koby_action: skip_heal + koby_note: "Koby LiteLLM issues reported, never fixed on .129" + + - name: disk-gc-threat-response + path: disk-gc-threat-response.prose.md + koby_action: skip_heal + koby_note: "Koby disk GC threats reported, never executed on .129" + + - name: memory-fixer + path: memory-fixer.prose.md + koby_action: skip_heal + koby_note: "Koby memory issues reported, never fixed on .129" + + - name: memory-audit-maintenance + path: memory-audit-maintenance.prose.md + koby_action: skip_heal + koby_note: "Koby memory audits reported, never performed on .129" + + - name: gpu-self-heal + path: gpu-self-heal.prose.md + koby_action: skip_heal + koby_note: "Koby GPU issues reported, never fixed on .129" + + - name: gpu-monitor + path: gpu-monitor.prose.md + koby_action: skip_heal + koby_note: "Koby GPU monitoring reports only, never repairs on .129" + + - name: agent-health-check + path: agent-health-check.prose.md + koby_action: skip_heal + koby_note: "Koby agent health checks reported, never repairs on .129" + +# Scripts that should skip Koby +koby_aware_scripts: + - name: agent-health-check.py + path: scripts/agent-health-check.py + koby_action: skip_heal + koby_note: "Script should only run diagnostics on Koby, not repairs" diff --git a/disk-gc-threat-response.prose.md b/disk-gc-threat-response.prose.md index 14bcf33..9f7ada3 100644 --- a/disk-gc-threat-response.prose.md +++ b/disk-gc-threat-response.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: responsibility name: disk-gc-threat-response description: > @@ -11,6 +13,7 @@ description: > id: 067NV8KJ03ZG71S44N41F31022 version: 1.0.0 --- +--- # Disk GC & Threat Response @@ -302,4 +305,4 @@ one-off GPU builds. No automated post-migration cleanup was in place. |------|-----|------|--------| | docker-vm | 192.168.68.7 | 16 Docker containers, 4 stacks | ✅ reachable | -> **Note:** CT 118 is now jdownloader (active on storepve). CT 119 (infisical-vault) added on minipve.\n> **Migrated:** CT 101 → .8, CT 103 → .110 (bare metal GPU).\n> **KVM VM:** CT 109 (docker-vm) is a KVM VM, not LXC — access via SSH .7. \ No newline at end of file +> **Note:** CT 118 is now jdownloader (active on storepve). CT 119 (infisical-vault) added on minipve.\n> **Migrated:** CT 101 → .8, CT 103 → .110 (bare metal GPU).\n> **KVM VM:** CT 109 (docker-vm) is a KVM VM, not LXC — access via SSH .7. diff --git a/gpu-self-heal.prose.md b/gpu-self-heal.prose.md index 403657a..a5d370b 100644 --- a/gpu-self-heal.prose.md +++ b/gpu-self-heal.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: responsibility name: gpu-self-heal description: > @@ -16,6 +18,7 @@ depends_on: - gpu-monitor.prose.md (live data source on .24:9100) - gpu-fleet.prose.md (source of truth for topology, aliases, model assignments) --- +--- ## Maintains @@ -38,6 +41,7 @@ depends_on: - On fix: verify with benchmark inference test before declaring resolved - Escalate: after 3 failed remediation attempts → Zulip #agent-hub alert +--- --- ## Current Fleet Baseline (2026-07-18) @@ -166,6 +170,7 @@ Key notes: - **Verify**: Each GPU's request pattern matches its designated role within 24h - **Escalate**: If role mismatch persists >48h → agent alias audit needed +--- --- ## Execution @@ -247,6 +252,7 @@ call update-gpu-health } ``` +--- --- ## Reporting @@ -263,6 +269,7 @@ Pushed to `SyslogSolution/health-logs/gpu/{run_id}.json` — versioned, searchab - Per-GPU tok/s trend over 7 days - Regression alerts if any GPU degrades >10% week-over-week +--- --- ## Design Decisions (Verified 2026-07-12, Reaffirmed 2026-07-18) diff --git a/hermes-agent-baseline.prose.md b/hermes-agent-baseline.prose.md index 7e13e0f..6d05477 100644 --- a/hermes-agent-baseline.prose.md +++ b/hermes-agent-baseline.prose.md @@ -169,11 +169,15 @@ pct-run grep -A8 "vision:" /root/.hermes/config.yaml | grep api_key # Must show both api_key: sk-... and api_key_env: LITELLM_API_KEY ``` -### For Koby (CT 111 / tdunna) +### For Koby (CT 111 / tdunna) — **REPORT-ONLY MODE** Koby runs Hermes on CT 111 (tdunna). Config files at `/root/.hermes/config.yaml`. Same Hermes pattern as Tanko/Mumuni/Koonimo — see config sections above. +**⛔ KOBY IS NEVER REPAIRED (2026-08-17, Captain)**: Diagnostic only — detect and report, never fix on .129. +No heal step, no restart, no key rotation, no config edit, no memory rewrite, no disk GC, no service touch, no process kill — ever. +If a health check shows Koby degraded, **DO NOT** execute any repair action. Instead, report to Zulip and let Theo fix it. + **LiteLLM key**: alias `koby` in LiteLLM DB, injected via `infisical run --` wrapper. ### For pi Agents (Abiba) diff --git a/hermes-config-template.prose.md b/hermes-config-template.prose.md index 5c84ec6..1e99e14 100644 --- a/hermes-config-template.prose.md +++ b/hermes-config-template.prose.md @@ -405,3 +405,14 @@ curl -s -o /dev/null -w '%{http_code}' -H "Authorization: Bearer $K" http://192. 5. **Set model choice** — Per agent's workload 6. **Verify** — curl all shared endpoints, test the model with the new key 7. **Report** — What was changed, preserved, custom + +### Rule 17: Koby Report-Only (URGENT — 2026-08-17, Captain) + +**Koby (CT 111, .129, tdunna/Theo) is report-only, full stop.** +No heal step, no restart, no key rotation, no config edit, no memory rewrite, +no disk GC, no service touch, no process kill — **ever**. +Do NOT "repair" Koby under any circumstance, even if a health check shows it degraded. +Detect + report to Zulip (Theo fixes it). + +This supersedes every other instruction in this file. +If a rule would trigger a Koby repair action, SKIP it and emit a diagnostic alert. diff --git a/hermes-zulip-restore.prose.md b/hermes-zulip-restore.prose.md index 4a55150..c10a7bc 100644 --- a/hermes-zulip-restore.prose.md +++ b/hermes-zulip-restore.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: function name: hermes-zulip-restore description: > @@ -12,6 +14,7 @@ version: 1.0.0 status: active runtime_contract: 2 --- +--- # Hermes Zulip Restore — Bring Any Agent Back to Good State @@ -184,6 +187,7 @@ https://git.sysloggh.net/SyslogSolution/zulip-platform-plugins/src/branch/feat/z Commit `55ca15d` — `fix(zulip): add _strip_html for slash command matching` Pull request #33 is the primary integration branch. +--- --- **Last verified good state**: 2026-07-08 — Mumuni, Tanko, Koby all connected with `_strip_html` applied. diff --git a/litellm-self-heal.prose.md b/litellm-self-heal.prose.md index 2d01c35..6e95cef 100644 --- a/litellm-self-heal.prose.md +++ b/litellm-self-heal.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: responsibility name: litellm-self-heal status: deployed @@ -22,6 +24,7 @@ description: > inference, and agent keys. Applies remediation rules for common failures. Reports every action via Zulip DM and Gitea (SyslogSolution/health-logs). --- +--- # LiteLLM Operations — Health Check + Self-Heal @@ -120,6 +123,7 @@ Request → nginx:80 → LiteLLM:4000 → GPU(llama-server, parallel 2) - Also wakes on user request - On failure: re-check after 30s, escalate after 3 consecutive failures +--- --- ## Health Check @@ -162,6 +166,7 @@ Determine overall_status from individual check results: - "degraded" — 1-2 non-critical checks fail - "down" — critical checks fail +--- --- ## Remediation Rules @@ -205,6 +210,7 @@ Escalate → if SSH access unavailable, send Zulip DM Router no longer in path so Redis active counters are unused. Rule retained for reference but inactive. If Redis issues occur, check harness-redis container. +--- --- ## Reporting @@ -227,6 +233,7 @@ top actions, uptime. If a fix requires another agent (e.g., Authentik restart), relay sent to responsible agent with full context. +--- --- ## Execution diff --git a/memory-audit-maintenance.prose.md b/memory-audit-maintenance.prose.md index df32c7f..aefadf7 100644 --- a/memory-audit-maintenance.prose.md +++ b/memory-audit-maintenance.prose.md @@ -1,9 +1,12 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 name: memory-audit-maintenance kind: responsibility description: Shared memory audit and maintenance contract for all Hermes agents (Mumuni, Tanko, Koby, Koonimo). Each agent runs it against its own isolated memory files — no cross-agent access, no shared state. Detects staleness, enforces writer registry, and rotates canary tokens. id: 067NC4KG01RG50R40M30E20918 --- +--- ### Goal @@ -343,4 +346,4 @@ return { ### Per-Agent Notes -Each Hermes agent (Mumuni, Tanko, Tdunna, Baggy) runs this contract against its own `~/.hermes/memories/` directory. The contract is identical across agents, but all data is fully isolated: separate ledgers, separate writer registries, separate canaries. If a new agent is added to the roster, it must be listed in `### Scope` above and given its own isolated memory directory. \ No newline at end of file +Each Hermes agent (Mumuni, Tanko, Tdunna, Baggy) runs this contract against its own `~/.hermes/memories/` directory. The contract is identical across agents, but all data is fully isolated: separate ledgers, separate writer registries, separate canaries. If a new agent is added to the roster, it must be listed in `### Scope` above and given its own isolated memory directory. diff --git a/memory-fixer.prose.md b/memory-fixer.prose.md index 7e740de..dbc5d58 100644 --- a/memory-fixer.prose.md +++ b/memory-fixer.prose.md @@ -1,4 +1,6 @@ --- +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 kind: pattern name: memory-fixer description: > @@ -6,6 +8,7 @@ description: > Escalate anything that needs Kwame's input. version: 1.1.0 --- +--- # Memory Fixer diff --git a/pm2-self-heal.prose.md b/pm2-self-heal.prose.md index 8ccf11a..1215fb7 100644 --- a/pm2-self-heal.prose.md +++ b/pm2-self-heal.prose.md @@ -6,6 +6,8 @@ description: > auto-restarts any that are stopped or errored. Logs every action to the knowledge graph and alerts the owner via Zulip DM on failures. Abiba-zulip is the live Zulip bridge and may be restarted; alert owner on failure. +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 --- ## Maintains diff --git a/scripts/agent-health-check.py b/scripts/agent-health-check.py index f9c85d6..4966c37 100755 --- a/scripts/agent-health-check.py +++ b/scripts/agent-health-check.py @@ -40,10 +40,10 @@ PVE_NODES = { # Agent definitions: ct, host, user, pve_node, vault_key_name AGENTS = { - "tanko": {"ct": 112, "host": "192.168.68.122", "user": "jerome", "pve": "amdpve", "vault_key": "TANKO_LITELLM_API_KEY"}, - "abiba": {"ct": 100, "host": "192.168.68.24", "user": "root", "pve": "hwepve", "vault_key": None}, # Pi agent + Mumuni Zulip, no vault key - "koby": {"ct": 111, "host": "192.168.68.129", "user": "root", "pve": "amdpve", "vault_key": "KOBY_LITELLM_API_KEY"}, - "koonimo": {"ct": 113, "host": "192.168.68.114", "user": "root", "pve": "amdpve", "vault_key": "KOONIMO_LITELLM_API_KEY"}, + "tanko": {"ct": 112, "host": "192.168.68.122", "user": "jerome", "pve": "amdpve", "vault_key": "TANKO_LITELLM_API_KEY", "report_only": False}, + "abiba": {"ct": 100, "host": "192.168.68.24", "user": "root", "pve": "hwepve", "vault_key": None, "report_only": False}, + "koby": {"ct": 111, "host": "192.168.68.129", "user": "root", "pve": "amdpve", "vault_key": "KOBY_LITELLM_API_KEY", "report_only": True}, # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) + "koonimo": {"ct": 113, "host": "192.168.68.114", "user": "root", "pve": "amdpve", "vault_key": "KOONIMO_LITELLM_API_KEY", "report_only": False}, } GPU_HOSTS = { @@ -239,20 +239,26 @@ def check_agents(): host = agent.get("host") user = agent.get("user") ct = agent["ct"] + report_only = agent.get("report_only", False) if not host or not user: print(f" ⬜ {name} (CT {ct}): cannot SSH — skip liveness check") continue - # Gateway process - pid = ssh(host, "pgrep -f 'hermes_cli.main gateway run' | grep -v infisical | head -1", user=user) - if not pid: - # Try alternate binary name - pid = ssh(host, "pgrep -f 'hermes.*gateway' | grep -v infisical | grep -v bash | head -1", user=user) - if not pid: - print(f" ❌ {name}: GATEWAY NOT RUNNING") - FAIL.append(f"gateway-down:{name}") - continue + # ⛔ KOBY IS NEVER REPAIRED — diagnostic only + if report_only: + print(f" 🔍 {name}: REPORT-ONLY mode (diagnostic only, no repairs on .129)") + # Still check gateway status for reporting purposes + pid = ssh(host, "pgrep -f 'hermes_cli.main gateway run' | grep -v infisical | head -1", user=user) + if not pid: + pid = ssh(host, "pgrep -f 'hermes.*gateway' | grep -v infisical | grep -v bash | head -1", user=user) + if not pid: + print(f" ⚠️ {name}: GATEWAY NOT RUNNING (reported only)") + FAIL.append(f"gateway-down:{name}") + continue + else: + print(f" ✅ {name}: gateway running (pid={pid}, report-only mode)") + continue # Skip the rest of the check for Koby # Gateway state file state = ssh(host, "cat ~/.hermes/gateway_state.json 2>/dev/null", user=user) diff --git a/zulip-health.prose.md b/zulip-health.prose.md index 5737799..dff0e02 100644 --- a/zulip-health.prose.md +++ b/zulip-health.prose.md @@ -6,6 +6,8 @@ title: Zulip Mesh Health Monitor — Multi-Platform version: 3.0.0 runtime_contract: 2 agent: abiba +report_only_agents: + - koby # ⛔ KOBY IS NEVER REPAIRED (Rule 17, 2026-08-17) — detect + report, never fix on .129 --- # Zulip Mesh Health Monitor