Files
oikos/runbooks/client-enrollment.md
dtoro f6b57cbe3a Oikos Week 2: Service Console v0, change ledger, node relations, runbooks
Adds the shared kernel modules (oikos/policy.py, oikos/relations.py,
oikos/ledger.py) that let every surface — CLI, MCP, context-card
generator — agree on risk classification and ontology graph walks
from one implementation.

homelab CLI: `service <name> explain|health|docs|log|actions|history`
(Service Console v0), `change preflight <service>`, `node <name>
relations`. Restart and client add/remove now append change-ledger
entries (ledger/*.jsonl, committed alongside the change they record).

mcp/server.py mirrors explain/preflight/get_relations/get_change_history
as MCP tools, card-first so agent orientation is one call instead of
several search_docs/get_page round-trips.

oikos/gen-topology.py now also emits a compact context card per host
and service (oikos/cards/*.md) — identity, blast radius, safe actions +
risk class, doc pointer, recent ledger history.

runbooks/*.md: service health check, config change + deploy, client
enrollment, incident investigation, and the five node lifecycle
transitions (provision/activate/migrate/deprecate/destroy), each with
machine-readable frontmatter (risk class, inputs, verification,
docs-update checklist). Wired into HERMES.md so agents load these
instead of rediscovering topology per-task.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 23:02:32 +02:00

1.6 KiB

name, risk_class, inputs, verification, docs_update_checklist
name risk_class inputs verification docs_update_checklist
client-enrollment config_mutation
hostname
kind
role
homelab doctor (on the new client)
hosts_narrative_page_if_lxc_or_vm

Client enrollment

Goal: bring a new host (workstation, LXC, VM) into the mesh, inventory, and secrets model. This wraps the existing homelab client add flow — see operations/agent-enrollment.md for the full walkthrough; this runbook is the risk/lifecycle framing.

  1. On any enrolled client: homelab client add <hostname> — appends a hosts.<name>: block to inventory.yaml (lifecycle state: plannedprovisioning, per oikos/ontology.yaml), commits + pushes.
  2. Join the new host to Netbird (out-of-band, console or setup key).
  3. On the new host: run bootstrap.sh (add --with-hermes to also enroll the Hermes agent). This provisions /etc/age/key.txt, the sync timer, and prints an age pubkey.
  4. Back on an enrolled client: homelab client add <hostname> --finalize-pubkey <age1...> — sets age_pubkey, grants shared secrets, re-keys SOPS, commits + pushes. This is the provisioning → active transition.
  5. Verify: homelab doctor on the new client should show all checks green (clone, sync timer, age key, CLI symlink, MCP reachable).

Docs-update checklist: if the new host is an LXC/VM, add its narrative page under containers/ or vms/ and set doc_page in its inventory entry (host-level cards don't have a doc_page field yet — services do; narrative pages are still found via the generated see_also in hosts/<name>.yaml).