Problem: "Hermes" collides with Nous Researchs unrelated product; unclear identity for the resident agent. Change: Rename the live service identity across 39 files: - cmd/hermes/ → cmd/nomos/ (binary, env vars NOMOS_*) - internal/config/ server.go (NomosAgentSlug, nomosAgentID) - compose/hermes/ → compose/nomos/ (Dockerfile, service name) - hermes/ → nomos/ (SOUL.md, config.yaml, skills/) - .agents/HERMES.md → NOMOS.md (persona) - tools/setup-hermes-soul.sh → setup-nomos-soul.sh - seeds/inventory.yaml (agent:hermes → agent:nomos) - migrations/014_rename_agent_hermes_to_nomos.up.sql - Caddy vhost hermes.hubris.network → nomos.hubris.network - All referencing docs, scripts, ADR notes History preserved: archive/, plans/done/, ADRs not rewritten. Matrix @hermes notifier account and Legacy bin/hermes on LXC 129 intentionally untouched (out of scope). Risk: N0 is identity-only rename; zero behavioral changes. Verification: go build ./... passes; docker compose --profile full resolves nomos service; grep -ri hermes (excluding archive/plans) returns only intentional refs (LLM model name, Matrix user).
42 lines
2.7 KiB
Markdown
42 lines
2.7 KiB
Markdown
# Cutover checklist — Phase 6: apps/105 → Docker stack on mac-mini
|
|
|
|
Status: [x] = done, [ ] = pending
|
|
|
|
## Pre-cutover
|
|
|
|
- [x] **Backup**: `pg_dump oikos > backups/pre-cutover-20260707.sql` (145K)
|
|
- [x] **CI green**: pushed to main, `.gitea/workflows/ci.yml` exists
|
|
- [x] **Deploy test**: Docker stack running with api + scheduler + notifier + nomos
|
|
- [x] **Caddy config**: `compose/caddy/Caddyfile.oikos` pushed to `dtoro/caddy-conf` (ed20908). Auto-deploys to caddy (121).
|
|
- [x] **DNS**: `oikos.hubris.network` already resolves to 192.168.8.175 (mac-mini mesh)
|
|
- [x] **Secrets**: Infisical bootstrapped + migration complete 2026-07-07. All 11 SOPS secrets migrated to Infisical (oikos project, dev env). Machine identity `oikos-api` has RW access verified via Go SDK. ENCRYPTION_KEY must be 32-char raw string (docs incorrect). SOPS fallback preserved for DR. secrets-issuance decommissioned — stopped/disabled on apps/105; superseded by Infisical.
|
|
- [x] **Watchdog**: crontab entry added (every 2 min → `scripts/watchdog.sh`). Path fixed 2026-07-07 (was stale worktree path).
|
|
|
|
## Cutover
|
|
|
|
- [x] **Stop apps/105 services**: homelab-mcp-deploy, secrets-issuance, secrets-issuance-deploy, oikos-console, oikos-console-deploy
|
|
- [x] **Disable apps/105 services**: all 5 units disabled
|
|
- [x] **Deploy to mac-mini**: Docker stack running (`docker compose --profile full up -d`)
|
|
- [x] **Caddy reload**: pushed to `dtoro/caddy-conf` — auto-deploy triggers on LXC 121.
|
|
- [x] **DNS verify**: `oikos.hubris.network` → 192.168.8.175
|
|
|
|
## Post-cutover verification
|
|
|
|
- [x] **./scripts/verify-phase6.sh** — all 14 checks pass
|
|
- [x] **Nomos query**: `curl http://localhost:8092/query -d '{"query":"fleet health"}'` → HTTP 200
|
|
- [x] **Agent activity**: `curl http://localhost:8090/api/v1/agent-activity` → returns data
|
|
- [x] **Scheduler ticking**: 30s ticks logged
|
|
- [x] **Notifier polling**: running
|
|
- [x] **Watchdog tested**: 2026-07-07 — full cycle verified. API down → failure counting → Matrix alert sent (!alerts:hubris.network) → API recovery → counter reset. Crontab path fixed (was stale worktree path, now /Users/dtoro/Projects/oikos). MATRIX_TOKEN wired in crontab env.
|
|
|
|
## Rollback drill
|
|
|
|
- [x] **./scripts/rollback.sh** — rehearsed 2026-07-07. Backup (674KB) → stop stack → restore DB → checkout 7ac2521 → rebuild → health OK (20 tools working) → re-deploy latest (21 tools). Full cycle verified.
|
|
|
|
## Cleanup
|
|
|
|
- [x] Remove Gitea webhooks for apps/105 (ids 10, 11, 14) from `dtoro/oikos` — deleted 2026-07-08 via Gitea API
|
|
- [ ] Archive apps/105 LXC (keep for 30 days, then destroy)
|
|
→ `ssh hubris pct stop 105 && pct snapshot 105 archive-$(date +%Y%m%d)`
|
|
- [x] Update auto-deploy docs — apps/105 entries marked deprecated
|