Problem: runbooks are agent-executable procedures but lived at the repo root, separate from the other agent instruction now under .agents/. Change: - Move runbooks/<name>.md -> .agents/skills/<name>/SKILL.md (folder per skill, matching the wiki-hq skills layout). Frontmatter (name, risk_class, inputs, verification, docs_update_checklist, transition) preserved. - Rewrite links (inbound from plans; between-skill siblings) via the move map. - Update prose references in AGENTS.md, HERMES.md, .agents/OIKOS.md, and the operations schema; fix a pre-existing stale link to operations/commands.md. No code consumed runbooks/ by path, so nothing else changes. Verification: all SKILL.md frontmatter parses with valid risk_class; every lifecycle transition resolves to an oikos/ontology.yaml state; broken-link count 127 -> 126 (fixed one, introduced none). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.2 KiB
2.2 KiB
name, risk_class, inputs, verification, docs_update_checklist
| name | risk_class | inputs | verification | docs_update_checklist | ||||
|---|---|---|---|---|---|---|---|---|
| client-enrollment | config_mutation |
|
homelab doctor (on the new client) |
|
Client enrollment
Goal: bring a new host (workstation, LXC, VM) into inventory and the
secrets model, with mesh membership only where it's actually needed.
This wraps the existing homelab client add flow — see
operations/agent-enrollment.md for
the full walkthrough; this runbook is the risk/lifecycle framing.
- On any enrolled client:
homelab client add <hostname>— appends ahosts.<name>:block toinventory.yaml(lifecyclestate: planned→provisioning, per oikos/ontology.yaml), commits + pushes. - Netbird join is optional, not a required step — only needed for
hosts that must be reachable off-LAN (workstations that roam, e.g.
republic-laptop,mac-mini). A node reachable on the household LAN (192.168.8.0/24 — most LXCs/VMs) doesn't need it: it's already reachable directly, and off-LAN clients reach it too via hubris's routed192.168.8.0/24Netbird network resource. Skip this step for LAN-only nodes; do it (out-of-band, console or setup key) only for hosts that need independent off-LAN reachability. - On the new host: run
bootstrap.sh(add--with-hermesto also enroll the Hermes agent). This provisions/etc/age/key.txt, the sync timer, and prints an age pubkey. - Back on an enrolled client:
homelab client add <hostname> --finalize-pubkey <age1...>— setsage_pubkey, grants shared secrets, re-keys SOPS, commits + pushes. This is theprovisioning → activetransition. - Verify:
homelab doctoron the new client should show all checks green (clone, sync timer, age key, CLI symlink, MCP reachable).
Docs-update checklist: if the new host is an LXC/VM, add its narrative
page under containers/ or vms/ and set doc_page in its inventory
entry (host-level cards don't have a doc_page field yet — services do;
narrative pages are still found via the generated see_also in
hosts/<name>.yaml).