Commit Graph
4 Commits
Author SHA1 Message Date
tanko-bot 0d5064f49d fix: correct tanko runtime to DSH across contracts & scripts
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
Tanko migrated from Hermes to DSH (DeepSeek Harness) on 2026-08-27. Update all
records that described tanko as a Hermes agent / Hermes runtime:

- infra-control: CT 112 tanko platform Hermes -> DSH
- zulip-health / zulip-self-heal / zulip-mention-reliability / pi-approval:
  tanko is on DSH, mumuni remains on Hermes
- memory-audit-maintenance: exclude tanko from Hermes roster (uses DSH-native memory)
- hermes-config-template / hermes-agent-baseline: remove tanko from Hermes roster,
  keep LiteLLM key alias 'tanko'
- hermes-zulip-plugin / hermes-zulip-restore / build-zulip-plugin: tanko excluded
- infrastructure-maintenance: gateways check no longer probes Hermes on tanko CT112
- scripts/daily-infra-report.py: fix CT-ID regression (CT 122->112), report tanko as DSH
- scripts/zulip-monitor.sh: stop probing tanko's retired Hermes gateway
- scripts/agent-health-check.py: skip Hermes gateway checks for tanko (runtime=dsh)
- scripts/prose-auth-check.sh + AGENTS.md: authorize tanko/tanko-bot for its own records

Tanko remains CT 112 at 192.168.68.122; infrastructure facts unchanged.
Dated/incident records (run logs, migration logs) left intact as history.
2026-08-27 03:00:31 +00:00
root 1d027f71f6 feat(contracts): add infrastructure-maintenance contract
New responsibility contract consolidating host-level system maintenance
and Docker image lifecycle management, filling the gap left by
infrastructure-update (which owns cluster-wide apt waves).

Scope:
- OS package updates on primary host with pre-update snapshot/backup check
- Docker image pulls for LiteLLM, SearXNG, and other running containers
- Container restarts with per-stack health verification
- Post-update verification: LiteLLM, SearXNG, Zulip, Gitea, PM2, Hermes gateways
- Rollback on failure (image/apt/config restore) with circuit breaker

Owner: ops (firstmate secondmate). Trigger: weekly Sunday 2am ET.
Escalation: warning/critical->abiba+mumuni, fatal->abiba+mumuni+kwame.
circuit_breaker: max_retries 2, window 7200, trip_action escalate_to_fatal.
depends_on: infrastructure-monitoring (pre-update health baseline).

Registry:
- Add infrastructure-maintenance to by_category.maintenance, by_domain.infrastructure,
  by_owner.ops (new), by_trigger.scheduled, by_sensitivity.high
- Add 'ops' to owners list
- Move infrastructure-update owner abiba -> ops (in contracts entry + by_owner index)

Also adds '## Maintaining this file' section to AGENTS.md per fm-ensure-agents-md.
2026-07-18 22:02:45 +00:00
root 4eec96b851 docs: link authoring guide from AGENTS.md 2026-07-04 22:31:44 +00:00
root 57605c6f16 docs: add AGENTS.md + authorization enforcement gates
NEW: AGENTS.md — complete agent workflow documentation
- Step-by-step PR workflow for all agents
- Authorization matrix (who can change which contracts)
- Emergency bypass procedure
- Quick start commands

NEW: scripts/prose-auth-check.sh — authorization enforcement
- Blocks unauthorized agents from changing CRITICAL contracts
- infrastructure-control, proxmox-monitor: abiba only
- hermes-config-template: abiba, mumuni, tanko
- zulip-health: abiba, mumuni
- All scripts: abiba only
- Fails CI if unauthorized changes detected

UPDATED: .gitea/workflows/pr-pipeline.yaml
- Added Stage 0: auth check (runs first)
- Added gate job that confirms all 4 checks passed
- Expanded trigger paths to include scripts/*.sh

UPDATED: branch protection — now requires 4 contexts:
  pr-pipeline / auth, validate, lint, ai-review
2026-07-04 22:25:05 +00:00