Problem: after the wiki-hq reorg, agent-instruction and human-doc domains were still scattered across the repo root, with three now-redundant stub files cluttering it. The organizing principle wasn't visible in the layout. Change — enforce three clear buckets: - .agents/ = how agents operate: OIKOS.md, HERMES.md (moved from root), shared/ conventions, domains/ schemas, skills/, and operations/ (operator cheatsheet + enrollment + hermes-agent, moved from root). - knowledge/ = what exists + evidence: wiki/, GLOSSARY.md, and sources/ now including investigations/ (incident records are evidence/sources). - root = substrate + two entry points (AGENTS.md, README.md), plus plans/ as its own design-intent domain. Moves: - investigations/ -> knowledge/sources/investigations/ (incl. archive/, index). - operations/ -> .agents/operations/. - HERMES.md -> .agents/HERMES.md. - Deleted unreferenced root stubs CAVEMAN.md, CONTRIBUTING.md, and OIKOS.md (its 7 remaining linkers repointed to .agents/OIKOS.md). Consumers updated: - inventory.yaml doc_page (agent-enrollment) + regenerated hosts/*.yaml + cards. - tools/setup-hermes-soul.sh and bootstrap.sh (x2) -> .agents/HERMES.md. - bin/homelab help string -> .agents/operations/hermes-agent.md. - knowledge/operations schemas, llm-wiki, page-templates, incident-investigation skill, AGENTS.md/README nav -> new investigations/operations paths. - All markdown links rewritten via the path-resolving mapper. Left in place (substrate/executable/separate-domain): hosts/, ledger/, tools/, plans/, oikos/, mcp/, secrets/, bin/, inventory.yaml. Verification: docs-lint at baseline (2 intentional cross-repo refs, no new breakage); gen-topology.py --check exit 0; build_host_files.py idempotent; all doc_page targets resolve; Hermes provisioning scripts point at the new path. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
44 lines
2.2 KiB
Markdown
44 lines
2.2 KiB
Markdown
---
|
|
name: client-enrollment
|
|
risk_class: config_mutation
|
|
inputs: [hostname, kind, role]
|
|
verification: "homelab doctor (on the new client)"
|
|
docs_update_checklist: [hosts_narrative_page_if_lxc_or_vm]
|
|
---
|
|
|
|
# Client enrollment
|
|
|
|
Goal: bring a new host (workstation, LXC, VM) into inventory and the
|
|
secrets model, with mesh membership only where it's actually needed.
|
|
This wraps the existing `homelab client add` flow — see
|
|
[operations/agent-enrollment.md](../../operations/agent-enrollment.md) for
|
|
the full walkthrough; this runbook is the risk/lifecycle framing.
|
|
|
|
1. On any enrolled client: `homelab client add <hostname>` — appends a
|
|
`hosts.<name>:` block to `inventory.yaml` (lifecycle `state: planned`
|
|
→ `provisioning`, per [oikos/ontology.yaml](../../../oikos/ontology.yaml)),
|
|
commits + pushes.
|
|
2. Netbird join is **optional, not a required step** — only needed for
|
|
hosts that must be reachable off-LAN (workstations that roam, e.g.
|
|
`republic-laptop`, `mac-mini`). A node reachable on the household LAN
|
|
(192.168.8.0/24 — most LXCs/VMs) doesn't need it: it's already
|
|
reachable directly, and off-LAN clients reach it too via hubris's
|
|
routed `192.168.8.0/24` Netbird network resource. Skip this step for
|
|
LAN-only nodes; do it (out-of-band, console or setup key) only for
|
|
hosts that need independent off-LAN reachability.
|
|
3. On the new host: run `bootstrap.sh` (add `--with-hermes` to also
|
|
enroll the Hermes agent). This provisions `/etc/age/key.txt`, the
|
|
sync timer, and prints an age pubkey.
|
|
4. Back on an enrolled client: `homelab client add <hostname>
|
|
--finalize-pubkey <age1...>` — sets `age_pubkey`, grants shared
|
|
secrets, re-keys SOPS, commits + pushes. This is the
|
|
`provisioning → active` transition.
|
|
5. Verify: `homelab doctor` on the new client should show all checks
|
|
green (clone, sync timer, age key, CLI symlink, MCP reachable).
|
|
|
|
Docs-update checklist: if the new host is an LXC/VM, add its narrative
|
|
page under `containers/` or `vms/` and set `doc_page` in its inventory
|
|
entry (host-level cards don't have a `doc_page` field yet — services do;
|
|
narrative pages are still found via the generated `see_also` in
|
|
`hosts/<name>.yaml`).
|