Files
oikos/.agents/skills/client-enrollment/SKILL.md
dtoro 2b3aa248b1 N0: rename Hermes → Nomos (standalone commit)
Problem: "Hermes" collides with Nous Researchs unrelated product;
  unclear identity for the resident agent.

  Change: Rename the live service identity across 39 files:
  - cmd/hermes/ → cmd/nomos/ (binary, env vars NOMOS_*)
  - internal/config/ server.go (NomosAgentSlug, nomosAgentID)
  - compose/hermes/ → compose/nomos/ (Dockerfile, service name)
  - hermes/ → nomos/ (SOUL.md, config.yaml, skills/)
  - .agents/HERMES.md → NOMOS.md (persona)
  - tools/setup-hermes-soul.sh → setup-nomos-soul.sh
  - seeds/inventory.yaml (agent:hermes → agent:nomos)
  - migrations/014_rename_agent_hermes_to_nomos.up.sql
  - Caddy vhost hermes.hubris.network → nomos.hubris.network
  - All referencing docs, scripts, ADR notes

  History preserved: archive/, plans/done/, ADRs not rewritten.
  Matrix @hermes notifier account and Legacy bin/hermes on LXC 129
  intentionally untouched (out of scope).

  Risk: N0 is identity-only rename; zero behavioral changes.
  Verification: go build ./... passes; docker compose --profile full
  resolves nomos service; grep -ri hermes (excluding archive/plans)
  returns only intentional refs (LLM model name, Matrix user).
2026-07-08 14:14:56 +02:00

2.1 KiB

name, risk_class, inputs, verification, docs_update_checklist
name risk_class inputs verification docs_update_checklist
client-enrollment config_mutation
hostname
kind
role
homelab doctor (on the new client)
hosts_narrative_page_if_lxc_or_vm

Client enrollment

Goal: bring a new host (workstation, LXC, VM) into inventory and the secrets model, with mesh membership only where it's actually needed. This wraps the existing homelab client add flow — see operations/agent-enrollment.md for the full walkthrough; this runbook is the risk/lifecycle framing.

  1. On any enrolled client: homelab client add <hostname> — appends a hosts.<name>: block to inventory.yaml (lifecycle state: plannedprovisioning, per seeds/ontology.yaml), commits + pushes.
  2. Netbird join is optional, not a required step — only needed for hosts that must be reachable off-LAN (workstations that roam, e.g. republic-laptop, mac-mini). A node reachable on the household LAN (192.168.8.0/24 — most LXCs/VMs) doesn't need it: it's already reachable directly, and off-LAN clients reach it too via hubris's routed 192.168.8.0/24 Netbird network resource. Skip this step for LAN-only nodes; do it (out-of-band, console or setup key) only for hosts that need independent off-LAN reachability.
  3. On the new host: run bootstrap.sh (add --with-nomos to also enroll the Hermes agent). This provisions /etc/age/key.txt, the sync timer, and prints an age pubkey.
  4. Back on an enrolled client: homelab client add <hostname> --finalize-pubkey <age1...> — sets age_pubkey, grants shared secrets, re-keys SOPS, commits + pushes. This is the provisioning → active transition.
  5. Verify: homelab doctor on the new client should show all checks green (clone, sync timer, age key, CLI symlink, MCP reachable).

Docs-update checklist: if the new host is an LXC/VM, add its narrative page under containers/ or vms/ and set doc_page in its inventory entry (host-level cards don't have a doc_page field yet — services do; narrative pages are still found via the generated see_also in inventory.yaml).