archive/ contained the old narrative wiki (superseded by DB as source of truth), hermes-plans, oikos-cards, ledger, secrets-issuance, and SOPS backups — all Python-era artifacts with no ongoing value. Updated all cross-references in: - AGENTS.md, README.md - .agents/operations/commands.md (point to docs/infrastructure/) - .agents/shared/llm-wiki.md, page-templates.md - .agents/domains/knowledge/schema.md, operations/schema.md - .agents/skills/*/SKILL.md - docs/infrastructure/*.md (removed archive link targets) - docs-lint/SKILL.md known-baseline note
1.5 KiB
1.5 KiB
name, risk_class, inputs, verification, docs_update_checklist
| name | risk_class | inputs | verification | docs_update_checklist | ||||
|---|---|---|---|---|---|---|---|---|
| config-change-deploy | config_mutation |
|
curl -sf <service_url> (or MCP get_service_status) |
|
Config change + deploy
Goal: change a tracked config repo (Caddy, Gitea customizations, an app's own repo) and get it live, safely.
- MCP
preflight— current health, the service'sconfig_repo, its risk class, and the verification command to run after. If risk class requires approval (config_mutationordestructive), stop and get operator sign-off before editing — seeseeds/policy.yaml. - Clone/pull the
config_repo(never edit the backend's working tree directly — tracked configs change by commit + push, per OIKOS.md conventions). - Make the change, commit, push to
main. - The Gitea webhook fires the deploy pipeline for that repo (see infrastructure/auto-deploy.md for the exact receiver/reload for this service).
- Run the preflight's verification command. If it fails, check
MCP
tail_logfor the reload/restart error. - No manual record-keeping step needed — mutations made through the API
(e.g. via the
runMCP tool) are recorded automatically in theaudit_logtable.
Docs-update checklist: update the service's doc_page if the change
alters its behavior, ingress route, or ownership; add a changelog entry
if the page has one.