feat(inventory): bring nh3-dev under infra-ops management
Adds the NH3 dev box (10.100.10.50) as a managed host: README, first system-details snapshot, ssh-target. Adds it to the fleet bootstrap's Tier 1 and the CLAUDE.md servers table. infra-ops identity bootstrapped there (operator-run) — NOPASSWD sudo + key, so root-level infra work on the box (it runs the egress proxy, ttyd seat, mead-hall, volva, and dev checkouts) no longer needs a per-task password. First use: installed Playwright headless-Chromium system deps + binary for bloom_music's OSMD browser-geometry test harness; headless launch + real SVG geometry verified.
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
# nh3-dev
|
||||
|
||||
NH3-site **developer box** — `10.100.10.50` (WireGuard-reachable from the NH3
|
||||
subnet). General-purpose dev VM that hosts agent-fleet sidecars and live Claude
|
||||
Code sessions; **not** a Docker-stack host in the `stacks/` sense.
|
||||
|
||||
**Reach:** `ssh 10.100.10.50` (as `lkraven`), or the dedicated agent identity
|
||||
`ssh -i ~/.ssh/infra-ops_ed25519 infra-ops@10.100.10.50` (NOPASSWD sudo).
|
||||
`infra-ops` bootstrapped here 2026-06-04 (see [`reference_infra_ops_sudo_identity`]
|
||||
in auto-memory). Note: Claude Code sessions often run **natively on this box**, so
|
||||
local Bash already executes here — no SSH-to-self needed for non-privileged work.
|
||||
|
||||
## What runs here
|
||||
|
||||
- **NH3 egress proxy** — durable internal-only SOCKS5 `socks5h://10.100.10.50:1080`
|
||||
(dante, ACL'd to the WG net). Residential egress for colo services gated on their
|
||||
datacenter IP (e.g. YouTube bot-gate). Runbook + setup committed; consumers point
|
||||
`*_PROXY` at it.
|
||||
- **ttyd fleet driver-seat** — web/iPad seat into the zellij `Claude` session (ttyd
|
||||
behind Caddy; OSC52 clipboard shim). User systemd services under `~/.config`.
|
||||
- **mead-hall** — Bifrost tool-provider sidecar (`:5173`), CI-deployed from
|
||||
`vh/mead-hall`.
|
||||
- **volva** — Codex peer agent on the althing bus (single-turn oracle, systemd
|
||||
daemon).
|
||||
- **bloom_music dev** — `~/development/bloom_music`; its `web/` test harness uses
|
||||
Playwright headless Chromium. System deps + the managed Chromium binary
|
||||
(`~/.cache/ms-playwright`) installed 2026-06-04 via `infra-ops`; headless launch +
|
||||
real SVG geometry verified.
|
||||
|
||||
## Notes
|
||||
|
||||
- **PFI-owned Linux** — in scope for `infra-ops` management (apt, systemctl, service
|
||||
lifecycle). Added to the fleet bootstrap's Tier 1.
|
||||
- OS: Debian 12 (bookworm). See `system-details.txt` for the latest snapshot
|
||||
(`scripts/refresh-server-info.sh nh3-dev`).
|
||||
- Not in the colo Docker-stack topology — no `/opt/docker/compose` deploy target;
|
||||
workloads are systemd services + dev checkouts.
|
||||
Reference in New Issue
Block a user