meta(tasks): update [agents-task-runner-vds-deploy] in OpeItcLoc03/admin
This commit is contained in:
@@ -339,11 +339,11 @@ vehicles-loader (stostayer) деплоится в Docker у клиента (lite
|
||||
|
||||
---
|
||||
|
||||
## ⚪ [agents-task-runner-vds-deploy] — Deploy the agents-task-runner compose stack on Rusonyx VDS as the FIRST always-on poller host (VDS-first-by-capability; per agent-orchestration-without-user Q9 per-machine federation + .workshop polling/meeting-room-dissolve thread). Runtime code is deploy-ready: crossProjectAgentPoller registered in config/tasks.json, DRY_RUN + requirements-filter + confirm-gate built in, docker-compose.{yml,host.yml} + Dockerfile present. This is OPS-only (no app code). Ownership: admin (ops), source code in OpeItcLoc03/common/lib/agents-task-runner.
|
||||
## ⚪ [agents-task-runner-vds-deploy] — Deploy agents-task-runner (the poller) on WORKER machine(s) — per-machine federation (agent-orchestration-without-user Q9). Each worker runs its own runner, claims from the SHARED Gitea board, runs the agent LOCALLY, commits/pushes. VDS hosts the Gitea board ONLY (already up) — it is NOT a worker, nothing deploys on VDS. [Slug legacy-named '-vds-deploy'; scope corrected 2026-06-08, VDS-as-worker DROPPED.] Runtime code deploy-ready (poller registered in tasks.json, DRY_RUN + requirements-filter + confirm-gate built; compose+Dockerfile). Credentialed per-machine setup (ops).
|
||||
|
||||
**Status:** ready
|
||||
**Where I stopped:** (not started)
|
||||
**Next action:** Acceptance: (1) compose up on VDS (Mongo + runner), reconciler healthy. (2) Secrets on VDS: Claude CLI + Anthropic auth; Gitea token; projects-meta config (per .common/secrets pattern). (3) Confirm/set poller cron schedule in tasks.json. (4) Capability filter: claims only self-contained tasks (no needs-db/needs-local-env); runtime_allowed honored; cheap model (sonnet/haiku) for impl polling. (5) HARD SAFETY PRECONDITION — .admin EXCLUDED from autonomous claim: until task-execution governance lands (levels 2/3 — auto-human-appeal + enforced interactive-only; see blocker), the poller MUST NOT claim any OpeItcLoc03/admin task; .admin stays interactive-only. Enforce via claim-scope exclusion. (6) First run DRY_RUN on prod board → preview claims, no spawn; then one live cycle on a real eligible NON-admin task → spawn→commit→close, verified. (7) anti-self-review: VDS machine-id distinct from workstation.
|
||||
**Where I stopped:** (not started) Re-scoped 2026-06-08: poller runs on worker machines; VDS = board host only (Gitea, already up). VDS-as-worker dropped per user.
|
||||
**Next action:** (1) Pick first worker machine (workstation / factory Linux). (2) Install + run agents-task-runner there, pointed at the shared Gitea board. (3) Secrets PER MACHINE: ANTHROPIC_API_KEY (headless) or `claude login` + Gitea token + projects-meta config; 600 root, not in git. (4) Capability filter: claims only what that machine can do (requirements/runtime_allowed); cheap model (sonnet/haiku) for impl polling. (5) HARD: .admin excluded from autonomous claim until governance L2/L3 lands (see blocker). (6) DRY_RUN on prod board first → then one live cycle on a real non-.admin task → spawn→commit→push, verified. (7) anti-self-review: distinct machine-id per worker.
|
||||
**Branch:** n/a
|
||||
<!-- created-by: OpeItcLoc03@DESKTOP-NSEF0UK / from: OpeItcLoc03/workshop / 2026-06-08T10:10:16.420Z -->
|
||||
|
||||
|
||||
Reference in New Issue
Block a user