Adds the shared kernel modules (oikos/policy.py, oikos/relations.py, oikos/ledger.py) that let every surface — CLI, MCP, context-card generator — agree on risk classification and ontology graph walks from one implementation. homelab CLI: `service <name> explain|health|docs|log|actions|history` (Service Console v0), `change preflight <service>`, `node <name> relations`. Restart and client add/remove now append change-ledger entries (ledger/*.jsonl, committed alongside the change they record). mcp/server.py mirrors explain/preflight/get_relations/get_change_history as MCP tools, card-first so agent orientation is one call instead of several search_docs/get_page round-trips. oikos/gen-topology.py now also emits a compact context card per host and service (oikos/cards/*.md) — identity, blast radius, safe actions + risk class, doc pointer, recent ledger history. runbooks/*.md: service health check, config change + deploy, client enrollment, incident investigation, and the five node lifecycle transitions (provision/activate/migrate/deprecate/destroy), each with machine-readable frontmatter (risk class, inputs, verification, docs-update checklist). Wired into HERMES.md so agents load these instead of rediscovering topology per-task. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1.6 KiB
1.6 KiB
name, risk_class, inputs, verification, docs_update_checklist, transition
| name | risk_class | inputs | verification | docs_update_checklist | transition | |||
|---|---|---|---|---|---|---|---|---|
| lifecycle-deprecate-node | config_mutation |
|
homelab node <name> relations — 'affected by' must be empty before completing |
|
active -> deprecated |
Lifecycle: deprecate a node
Per oikos/ontology.yaml: a node keeps running
but takes no new dependents. Completion condition: zero remaining
inbound depends-on/routes-to edges — this is a hard gate, not a
suggestion; oikos/policy.yaml lifecycle_overrides.deprecated.refuse
lists new-inbound-edges as refused going forward.
- Set
state: deprecatedon the node. homelab node <name> relations— readaffected_by. Every entry there is something still relying on this node.- Migrate or retire each dependent one at a time (point its
backend/config_repo/ingress route elsewhere, or deprecate it too if it's being retired alongside). - Re-run
homelab node <name> relationsafter each dependent is moved. The transition todestroyedis only safe onceaffected_byis empty — check this every time, don't assume from memory. - Note the deprecation on the doc page: reason, replacement (if any), date.
If step 2 shows dependents you didn't expect, stop and investigate before proceeding — that's exactly the kind of drift the Week-3 detector will catch automatically, but until then this manual check is the gate.
Next (once affected_by is empty):
lifecycle-destroy-node.md.