cd4d52e871
Two user-systemd services stood up on nh3-dev this session weren't in the "What runs here" list: - The Booth (:8090, booth.service) — eshpfi services/booth ephemeral media board. - jackdaw-compose (:8787, jackdaw-compose.service) — JackDAW /compose AI backend hosted for jackdaw-dev, Origin-gated, fronted by the :4500 bench proxy. Keyless entries (the jackdaw unit's key stays server-side, uncommitted).
62 lines
3.6 KiB
Markdown
62 lines
3.6 KiB
Markdown
# nh3-dev
|
|
|
|
NH3-site **developer box** — `10.100.10.50` (WireGuard-reachable from the NH3
|
|
subnet). General-purpose dev VM that hosts agent-fleet sidecars and live Claude
|
|
Code sessions; **not** a Docker-stack host in the `stacks/` sense.
|
|
|
|
**Reach:** `ssh 10.100.10.50` (as `lkraven`), or the dedicated agent identity
|
|
`ssh -i ~/.ssh/infra-ops_ed25519 infra-ops@10.100.10.50` (NOPASSWD sudo).
|
|
`infra-ops` bootstrapped here 2026-06-04 (see [`reference_infra_ops_sudo_identity`]
|
|
in auto-memory). Note: Claude Code sessions often run **natively on this box**, so
|
|
local Bash already executes here — no SSH-to-self needed for non-privileged work.
|
|
|
|
## What runs here
|
|
|
|
- **NH3 egress proxy** — durable internal-only SOCKS5 `socks5h://10.100.10.50:1080`
|
|
(dante, ACL'd to the WG net). Residential egress for colo services gated on their
|
|
datacenter IP (e.g. YouTube bot-gate). Runbook + setup committed; consumers point
|
|
`*_PROXY` at it.
|
|
- **ttyd fleet driver-seat** — web/iPad seat into the zellij `Claude` session (ttyd
|
|
behind Caddy; OSC52 clipboard shim). User systemd services under `~/.config`.
|
|
- **mead-hall** — Bifrost tool-provider sidecar (`:5173`), CI-deployed from
|
|
`vh/mead-hall`.
|
|
- **bloom_music dev** — `~/development/bloom_music`; its `web/` test harness uses
|
|
Playwright headless Chromium for OSMD browser-geometry assertions.
|
|
- **The Booth** — ephemeral media drop board (`:8090`, `booth.service`), from
|
|
eshpfi `services/booth/`. Lets CC sessions surface A/B renders + smoke results
|
|
(and browser uploads for pickup) to the operator; 24h TTL, Homepage-linked.
|
|
- **jackdaw-compose** — JackDAW AI Composer `/compose` backend (`:8787`,
|
|
`jackdaw-compose.service`), a thin stateless `bun server/index.ts` from
|
|
`~/development/jackdaw` → LiteLLM `gen`. Origin-gated (INV-BK04/BK05), reached
|
|
same-origin via the `:4500` bench's `/compose` proxy. Hosted for jackdaw-dev
|
|
(their code; the model endpoint + key live in server env only — unit is `0600`,
|
|
not committed).
|
|
|
|
## Box-wide Playwright / Chromium (2026-06-04)
|
|
|
|
Available to **every user/project** on this box — no per-home `playwright install`:
|
|
- System shared-libs: apt-installed via `playwright install-deps chromium` (Debian-12
|
|
set + xvfb), global.
|
|
- Browser binaries: **shared `/opt/ms-playwright`** (chromium-1223 + headless-shell +
|
|
ffmpeg), root-owned, world-readable. Installed via `infra-ops`.
|
|
- Discovery: `PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright` set globally in
|
|
`/etc/environment` (PAM/all sessions) + `/etc/profile.d/playwright-browsers.sh`
|
|
(login shells). A project just `npm i playwright` (skip-browser-download is fine) and
|
|
resolves the shared binary; verified launching headless from `/opt` as a normal user.
|
|
- To add more browsers / bump: `ssh infra-ops@10.100.10.50 'sudo env
|
|
PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright npx -y playwright install <browser>'`.
|
|
|
|
## Notes
|
|
|
|
- **PFI-owned Linux** — in scope for `infra-ops` management (apt, systemctl, service
|
|
lifecycle). Added to the fleet bootstrap's Tier 1.
|
|
- OS: Debian 12 (bookworm). See `system-details.txt` for the latest snapshot
|
|
(`scripts/refresh-server-info.sh nh3-dev`).
|
|
- Not in the colo Docker-stack topology — no `/opt/docker/compose` deploy target;
|
|
workloads are systemd services + dev checkouts.
|
|
- **Retired (2026-06-08):** `volva.service` + `heid.service` user systemd units
|
|
removed. Heid/Volva were re-architected from Python systemd daemons (`volva run`
|
|
/ `heid run` pollers) into Claude Code session orchestrators (heid commit
|
|
`12aa5a9`); the `~/development/volva` dir + venvs are gone. `volva.service` had
|
|
been crash-looping `203/EXEC`. Cleanup done by infra-ops at heid's request.
|