a39e67b6e9
adr: convert all diagrams to Mermaid (sequenceDiagram, stateDiagram-v2, flowchart, erDiagram, graph)
...
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
0013-signal-triggers.md:
- Thermals query: sequenceDiagram (Nomos→API→Scheduler→Hubris→TimescaleDB)
- Script deployment: sequenceDiagram
- Signal lifecycle: stateDiagram-v2
- DB data flow: flowchart
0014-entity-model.md:
- Entity type hierarchy: graph (56 types, 3 layers, 7 domains)
- Machine onboarding: sequenceDiagram
- OODA loop (5 phases): flowchart with color-coded subgraphs
- Infrastructure topology: graph
- Network relationships: graph
- Service dependencies: graph
- Cognition OODA edges: graph
- Governance: graph
- Infrastructure lifecycle: stateDiagram-v2
- Signal lifecycle: stateDiagram-v2
- Execution lifecycle: stateDiagram-v2
- Approval lifecycle: stateDiagram-v2
- DB physical schema: erDiagram
- Thermals query trace: sequenceDiagram
2026-07-08 22:38:19 +02:00
551497e0b3
adr: move to docs/adr/, renumber 0013 + 0014, update README index
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
2026-07-08 22:18:58 +02:00
b8bb29464b
checks: deploy scripts + define checks for strong and netbird-vps
...
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
Coverage:
- host:hubris (192.168.8.77) ✓ cpu, memory, load, disk, ping, cert-expiry
- host:strong (192.168.178.181) ✓ cpu, memory, load, disk, ping
- host:netbird-vps (82.165.190.79) ✓ cpu, memory, load, disk, ping
- ws:mac-mini ~ local disk/ping only (no SSH key on macOS host)
- ws:republic-laptop ✗ offline / not reachable
Move architecture doc to adr/signal-triggers.md
2026-07-08 21:45:09 +02:00
81acadec1d
docs: signal trigger architecture sequence diagram + full explanation
...
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
Add docs/signal-triggers.md covering:
- End-to-end sequence diagram (Nomos → API → Scheduler → target host)
- Two paths: autonomous collection (scheduler) + query (MCP)
- All 6 check kinds and 17 available scripts
- Script deployment flow via sync timer
- Signal lifecycle, threshold evaluation, data flow through DB tables
- Prerequisites for SSH checks in Docker
2026-07-08 21:37:31 +02:00
2b3aa248b1
N0: rename Hermes → Nomos (standalone commit)
...
Problem: "Hermes" collides with Nous Researchs unrelated product;
unclear identity for the resident agent.
Change: Rename the live service identity across 39 files:
- cmd/hermes/ → cmd/nomos/ (binary, env vars NOMOS_*)
- internal/config/ server.go (NomosAgentSlug, nomosAgentID)
- compose/hermes/ → compose/nomos/ (Dockerfile, service name)
- hermes/ → nomos/ (SOUL.md, config.yaml, skills/)
- .agents/HERMES.md → NOMOS.md (persona)
- tools/setup-hermes-soul.sh → setup-nomos-soul.sh
- seeds/inventory.yaml (agent:hermes → agent:nomos)
- migrations/014_rename_agent_hermes_to_nomos.up.sql
- Caddy vhost hermes.hubris.network → nomos.hubris.network
- All referencing docs, scripts, ADR notes
History preserved: archive/, plans/done/, ADRs not rewritten.
Matrix @hermes notifier account and Legacy bin/hermes on LXC 129
intentionally untouched (out of scope).
Risk: N0 is identity-only rename; zero behavioral changes.
Verification: go build ./... passes; docker compose --profile full
resolves nomos service; grep -ri hermes (excluding archive/plans)
returns only intentional refs (LLM model name, Matrix user).
2026-07-08 14:14:56 +02:00
7660e5681c
complete consolidation plan — scripts, watchdog, rollback runbook
...
Plan #1 at 98% (code complete). Three fixes applied to remaining cutover items:
1. watchdog.sh — dual-path health checking (LAN 192.168.8.175 + mesh/Caddy
proxy). Only pages when BOTH paths fail. Partial failure logged but not
paged (distinguishes stack problem from mesh/Caddy issue).
2. deploy.sh — pre-deploy pg_dump before each deploy saves to
/opt/oikos/backups/pre-deploy-<sha>.sql. Rollback script now has a
guaranteed recovery point.
3. docs/operations/rollback.md — runbook documenting automated rollback,
manual recovery, decision tree, backup schedule, and rehearsal log.
Two operational items remain (require operator on Proxmox/Gitea):
- Remove Gitea webhooks ids 10, 11 from dtoro/Homelab-Docs
- Archive apps/105 LXC (pct stop 105 + archive)
All active config (seeds, compose, scripts) is already clean of apps/105 refs.
Infisical bootstrap code is complete (bootstrap-infisical.sh + Go backend).
2026-07-08 11:25:43 +02:00
5b22f2367b
test: e2e client lifecycle + ADRs with sequence diagrams
...
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
- client_lifecycle_test.go: full end-to-end integration test
planned → provisioning (enroll) → active → migrating → active →
deprecated → failed. Validates age keypair generation, attrs,
context/secrets endpoints, invalid transition blocking, compute
entity provisioning with relationship edges and status tracking.
Also tests enrollment rejection for invalid states and duplicate
slug rejection for provisioning.
- adr/0011-client-lifecycle-flows.md: workstation self-enrollment,
compute entity provisioning, deprecation/destruction flows with
Mermaid sequence diagrams. Full lifecycle state diagram. Transition
check enforcement documentation.
- adr/0012-hermes-oikos-interactions.md: Hermes ↔ Oikos interaction
flow through OODA loop phases. Thin client bootstrap. Internal
component interactions (scheduler, actuator, notifier). Complete
30-tool ownership matrix.
- Fix: migration 012 FK reference (executions.id → executions.entity_id)
- Fix: provision handler null attributes JSONB
- Fix: provisioning steps use entity_id for execution FK
All 3 integration tests pass, go vet clean.
2026-07-08 00:56:16 +02:00
18cb79caf9
oikos phase 0: ontology + inventory + policy seeds, OpenAPI contract, ADRs
...
- seeds/ontology.yaml: 59 entity types (5 abstract, is-a hierarchy), 46
relationship types with cardinality, 6 lifecycles with terminal states
and named precondition checks
- seeds/inventory.yaml: 110 entities / 142 relationships translated from
legacy inventory.yaml (fleet, services, ingress, storage, governance,
archaeology); thin spots marked for backfill
- seeds/policy.yaml: 4 risk classes, 27 approval rules (hierarchy-aware,
per-entity overrides), autonomy kill-switch off (cold start)
- api/openapi.yaml: full v1 REST contract (40 paths), RFC 9457 errors,
cursor pagination, idempotency, ETag/If-Match, scopes; redocly-clean
- docs/adr/0001-0010: initial architecture decision records
- scripts/validate-seeds.py: Phase 0 gate — hierarchy, lifecycles,
endpoints, cardinality, policy cross-refs (0 errors)
- plan: layer CHECK gains 'meta' (root type), cardinality gains
'many-to-one'
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-07-07 00:17:15 +02:00