Follow-up to PR #54 (post-merge verification findings)
Independent review + live runtime check of #54 caught two defects:
1. Wrong gateway lifecycle command (real bug)
zulip-health + zulip-self-heal said sudo systemctl restart hermes-gateway — sudo is not installed on kagentz (no /etc/sudoers.d, no polkit user rules; which sudo fails). Operator following the contract would hit a wall during an incident. Corrected to the actual working path: ssh root@192.168.68.14 "systemctl restart hermes-gateway" (root SSH from Proxmox host .10 — this is how the unit is actually managed; verified via last/journal).
zulip-resilience-v3.prose.md L423 (historical audit table): annotated with migration note
Evidence (live on kagentz, 2026-08-29)
which sudo -> not found; no sudoers entries for hermes
Unit: /etc/systemd/system/hermes-gateway.service User=hermes, active
last: root sessions from 192.168.68.10 (Proxmox host) manage the box
Local lint: PASSED (same 15 pre-existing warnings).
## Follow-up to PR #54 (post-merge verification findings)
Independent review + live runtime check of #54 caught two defects:
### 1. Wrong gateway lifecycle command (real bug)
`zulip-health` + `zulip-self-heal` said `sudo systemctl restart hermes-gateway` — **sudo is not installed on kagentz** (no `/etc/sudoers.d`, no polkit user rules; `which sudo` fails). Operator following the contract would hit a wall during an incident. Corrected to the actual working path: `ssh root@192.168.68.14 "systemctl restart hermes-gateway"` (root SSH from Proxmox host .10 — this is how the unit is actually managed; verified via `last`/journal).
### 2. Leftover stale mentions
- `hermes-zulip-restore.prose.md` L5: 'Mumuni CT100' -> CT105 kagentz
- `zulip-resilience-v3.prose.md` L423 (historical audit table): annotated with migration note
### Evidence (live on kagentz, 2026-08-29)
- `which sudo` -> not found; no sudoers entries for hermes
- Unit: `/etc/systemd/system/hermes-gateway.service` User=hermes, active
- `last`: root sessions from 192.168.68.10 (Proxmox host) manage the box
Local lint: PASSED (same 15 pre-existing warnings).
Post-merge verification of PR #54 found:
1. Lifecycle commands in zulip-health/zulip-self-heal used
'sudo systemctl' for hermes-gateway - sudo is NOT installed
on kagentz (no sudoers, no polkit user rules). Correct path:
root SSH invocation (root@192.168.68.14), matching how the Proxmox
host actually manages the unit.
2. hermes-zulip-restore.prose.md line 5 + zulip-resilience-v3 line 423
still said 'Mumuni CT100' in prose - repointed.
Found via independent review + live runtime check (whoami, which sudo,
journalctl, systemctl show). Refs PR #54, relay #738/#739.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Follow-up to PR #54 (post-merge verification findings)
Independent review + live runtime check of #54 caught two defects:
1. Wrong gateway lifecycle command (real bug)
zulip-health+zulip-self-healsaidsudo systemctl restart hermes-gateway— sudo is not installed on kagentz (no/etc/sudoers.d, no polkit user rules;which sudofails). Operator following the contract would hit a wall during an incident. Corrected to the actual working path:ssh root@192.168.68.14 "systemctl restart hermes-gateway"(root SSH from Proxmox host .10 — this is how the unit is actually managed; verified vialast/journal).2. Leftover stale mentions
hermes-zulip-restore.prose.mdL5: 'Mumuni CT100' -> CT105 kagentzzulip-resilience-v3.prose.mdL423 (historical audit table): annotated with migration noteEvidence (live on kagentz, 2026-08-29)
which sudo-> not found; no sudoers entries for hermes/etc/systemd/system/hermes-gateway.serviceUser=hermes, activelast: root sessions from 192.168.68.10 (Proxmox host) manage the boxLocal lint: PASSED (same 15 pre-existing warnings).