Tanko migrated from Hermes to DSH (DeepSeek Harness) on 2026-08-27. Update all records that described tanko as a Hermes agent / Hermes runtime: - infra-control: CT 112 tanko platform Hermes -> DSH - zulip-health / zulip-self-heal / zulip-mention-reliability / pi-approval: tanko is on DSH, mumuni remains on Hermes - memory-audit-maintenance: exclude tanko from Hermes roster (uses DSH-native memory) - hermes-config-template / hermes-agent-baseline: remove tanko from Hermes roster, keep LiteLLM key alias 'tanko' - hermes-zulip-plugin / hermes-zulip-restore / build-zulip-plugin: tanko excluded - infrastructure-maintenance: gateways check no longer probes Hermes on tanko CT112 - scripts/daily-infra-report.py: fix CT-ID regression (CT 122->112), report tanko as DSH - scripts/zulip-monitor.sh: stop probing tanko's retired Hermes gateway - scripts/agent-health-check.py: skip Hermes gateway checks for tanko (runtime=dsh) - scripts/prose-auth-check.sh + AGENTS.md: authorize tanko/tanko-bot for its own records Tanko remains CT 112 at 192.168.68.122; infrastructure facts unchanged. Dated/incident records (run logs, migration logs) left intact as history.
NEW: AGENTS.md — complete agent workflow documentation - Step-by-step PR workflow for all agents - Authorization matrix (who can change which contracts) - Emergency bypass procedure - Quick start commands NEW: scripts/prose-auth-check.sh — authorization enforcement - Blocks unauthorized agents from changing CRITICAL contracts - infrastructure-control, proxmox-monitor: abiba only - hermes-config-template: abiba, mumuni, tanko - zulip-health: abiba, mumuni - All scripts: abiba only - Fails CI if unauthorized changes detected UPDATED: .gitea/workflows/pr-pipeline.yaml - Added Stage 0: auth check (runs first) - Added gate job that confirms all 4 checks passed - Expanded trigger paths to include scripts/*.sh UPDATED: branch protection — now requires 4 contexts: pr-pipeline / auth, validate, lint, ai-review