Adds the shared kernel modules (oikos/policy.py, oikos/relations.py, oikos/ledger.py) that let every surface — CLI, MCP, context-card generator — agree on risk classification and ontology graph walks from one implementation. homelab CLI: `service <name> explain|health|docs|log|actions|history` (Service Console v0), `change preflight <service>`, `node <name> relations`. Restart and client add/remove now append change-ledger entries (ledger/*.jsonl, committed alongside the change they record). mcp/server.py mirrors explain/preflight/get_relations/get_change_history as MCP tools, card-first so agent orientation is one call instead of several search_docs/get_page round-trips. oikos/gen-topology.py now also emits a compact context card per host and service (oikos/cards/*.md) — identity, blast radius, safe actions + risk class, doc pointer, recent ledger history. runbooks/*.md: service health check, config change + deploy, client enrollment, incident investigation, and the five node lifecycle transitions (provision/activate/migrate/deprecate/destroy), each with machine-readable frontmatter (risk class, inputs, verification, docs-update checklist). Wired into HERMES.md so agents load these instead of rediscovering topology per-task. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
36 lines
1.6 KiB
Markdown
36 lines
1.6 KiB
Markdown
---
|
|
name: client-enrollment
|
|
risk_class: config_mutation
|
|
inputs: [hostname, kind, role]
|
|
verification: "homelab doctor (on the new client)"
|
|
docs_update_checklist: [hosts_narrative_page_if_lxc_or_vm]
|
|
---
|
|
|
|
# Client enrollment
|
|
|
|
Goal: bring a new host (workstation, LXC, VM) into the mesh, inventory,
|
|
and secrets model. This wraps the existing `homelab client add` flow —
|
|
see [operations/agent-enrollment.md](../operations/agent-enrollment.md)
|
|
for the full walkthrough; this runbook is the risk/lifecycle framing.
|
|
|
|
1. On any enrolled client: `homelab client add <hostname>` — appends a
|
|
`hosts.<name>:` block to `inventory.yaml` (lifecycle `state: planned`
|
|
→ `provisioning`, per [oikos/ontology.yaml](../oikos/ontology.yaml)),
|
|
commits + pushes.
|
|
2. Join the new host to Netbird (out-of-band, console or setup key).
|
|
3. On the new host: run `bootstrap.sh` (add `--with-hermes` to also
|
|
enroll the Hermes agent). This provisions `/etc/age/key.txt`, the
|
|
sync timer, and prints an age pubkey.
|
|
4. Back on an enrolled client: `homelab client add <hostname>
|
|
--finalize-pubkey <age1...>` — sets `age_pubkey`, grants shared
|
|
secrets, re-keys SOPS, commits + pushes. This is the
|
|
`provisioning → active` transition.
|
|
5. Verify: `homelab doctor` on the new client should show all checks
|
|
green (clone, sync timer, age key, CLI symlink, MCP reachable).
|
|
|
|
Docs-update checklist: if the new host is an LXC/VM, add its narrative
|
|
page under `containers/` or `vms/` and set `doc_page` in its inventory
|
|
entry (host-level cards don't have a `doc_page` field yet — services do;
|
|
narrative pages are still found via the generated `see_also` in
|
|
`hosts/<name>.yaml`).
|