fix: correct Mumuni gateway lifecycle path (no sudo on kagentz) + 2 leftover CT100 mentions #55

Merged
mumuni-bot merged 1 commits from fix/restart-cmd-and-leftovers into master 2026-08-30 01:08:14 +00:00
Owner

Follow-up to PR #54 (post-merge verification findings)

Independent review + live runtime check of #54 caught two defects:

1. Wrong gateway lifecycle command (real bug)

zulip-health + zulip-self-heal said sudo systemctl restart hermes-gateway — sudo is not installed on kagentz (no /etc/sudoers.d, no polkit user rules; which sudo fails). Operator following the contract would hit a wall during an incident. Corrected to the actual working path: ssh root@192.168.68.14 "systemctl restart hermes-gateway" (root SSH from Proxmox host .10 — this is how the unit is actually managed; verified via last/journal).

2. Leftover stale mentions

  • hermes-zulip-restore.prose.md L5: 'Mumuni CT100' -> CT105 kagentz
  • zulip-resilience-v3.prose.md L423 (historical audit table): annotated with migration note

Evidence (live on kagentz, 2026-08-29)

  • which sudo -> not found; no sudoers entries for hermes
  • Unit: /etc/systemd/system/hermes-gateway.service User=hermes, active
  • last: root sessions from 192.168.68.10 (Proxmox host) manage the box

Local lint: PASSED (same 15 pre-existing warnings).

## Follow-up to PR #54 (post-merge verification findings) Independent review + live runtime check of #54 caught two defects: ### 1. Wrong gateway lifecycle command (real bug) `zulip-health` + `zulip-self-heal` said `sudo systemctl restart hermes-gateway` — **sudo is not installed on kagentz** (no `/etc/sudoers.d`, no polkit user rules; `which sudo` fails). Operator following the contract would hit a wall during an incident. Corrected to the actual working path: `ssh root@192.168.68.14 "systemctl restart hermes-gateway"` (root SSH from Proxmox host .10 — this is how the unit is actually managed; verified via `last`/journal). ### 2. Leftover stale mentions - `hermes-zulip-restore.prose.md` L5: 'Mumuni CT100' -> CT105 kagentz - `zulip-resilience-v3.prose.md` L423 (historical audit table): annotated with migration note ### Evidence (live on kagentz, 2026-08-29) - `which sudo` -> not found; no sudoers entries for hermes - Unit: `/etc/systemd/system/hermes-gateway.service` User=hermes, active - `last`: root sessions from 192.168.68.10 (Proxmox host) manage the box Local lint: PASSED (same 15 pre-existing warnings).
mumuni-bot added 1 commit 2026-08-30 01:07:10 +00:00
fix: correct Mumuni gateway lifecycle path (no sudo on kagentz) + 2 leftover CT100 mentions
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 1s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 1s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
ca39fead74
Post-merge verification of PR #54 found:
1. Lifecycle commands in zulip-health/zulip-self-heal used
   'sudo systemctl' for hermes-gateway - sudo is NOT installed
   on kagentz (no sudoers, no polkit user rules). Correct path:
   root SSH invocation (root@192.168.68.14), matching how the Proxmox
   host actually manages the unit.
2. hermes-zulip-restore.prose.md line 5 + zulip-resilience-v3 line 423
   still said 'Mumuni CT100' in prose - repointed.

Found via independent review + live runtime check (whoami, which sudo,
journalctl, systemctl show). Refs PR #54, relay #738/#739.
mumuni-bot merged commit 031ad814a0 into master 2026-08-30 01:08:14 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#55