Files
oikos/.agents/skills/lifecycle-destroy-node/SKILL.md
dtoro 5e3b946ded cleanup: fix all stale references across .agents/ docs
- Rewrite AGENTS.md: DB as source of truth, MCP knowledge tools, archive refs
- Fix OIKOS.md: seeds/ paths, remove Python-era notes, update deployment status
- Fix commands.md, agent-enrollment.md: archive/knowledge/ links
- Fix all SKILL.md files: remove hosts/*.yaml refs, point to inventory.yaml
- Fix HERMES.md, schema.md, page-templates.md, llm-wiki.md: update paths
- Fix bootstrap.sh: identity check reads inventory.yaml
- Fix README.md, cutover-checklist.md: stale wiki references
- Move convert-wiki.py to archive/ (one-shot done)
2026-07-07 21:00:39 +02:00

2.0 KiB

name, risk_class, inputs, verification, docs_update_checklist, transition
name risk_class inputs verification docs_update_checklist transition
lifecycle-destroy-node destructive
node_name
homelab node <name> relations returns unknown-entity; pct list on the backend no longer shows it
archaeology_entry
containers_index_update
deprecated -> destroyed

Lifecycle: destroy a node

Destructive. Requires operator approval + typed confirmation phrase per seeds/policy.yaml. Requires (ontology): backups verified, secrets recipients removed + re-keyed, ingress/DNS removed, archaeology entry, ledger entry.

  1. Confirm the node is deprecated with zero affected_by edges (homelab node <name> relations) — do not skip this even if the deprecation runbook was followed recently; state can drift.
  2. If it's an enrolled client: homelab client remove <name> — revokes the age key, re-keys SOPS, removes the inventory entry. This is already destructive-class and confirmed in the CLI.
  3. Remove any ingress route (Caddy config repo) and DNS record still pointing at it.
  4. Verify backups of anything on it are retained per policy before the disk goes away (see backs-up-to).
  5. Destroy the LXC/VM (pct destroy / qm destroy).
  6. Move the hosts.<name>: block (if any inventory remnant survives client remove, e.g. infra-only LXCs with no age key) into inventory.yaml's archaeology: section: pve_id, destroyed date, reason. Add a row to containers/index.md "Recently destroyed" table (kept for human-readable browsing alongside the structured data).
  7. oikos/ledger.py append host:<name> destroy destructive --result ok.
  8. Regenerate: python3 mcp/build_host_files.py && python3 inventory.yaml — the node drops out of inventory.yaml and appears in the topology doc's archaeology table.

If the destroy fails partway (e.g. secrets revoked but pct destroy errors), do not re-run step 2 — client remove is not idempotent against a second revocation attempt on the issuance server. Finish the remaining steps manually and note the partial state in an investigation.