Skip to main content

Bounded fleet-runtime bootstrap

Use when bootstrapping a private fleet-runtime repository.

  • Read exact approved spec/manifests; preserve historical proposed bytes and record new authorization separately.

  • Fresh-load intended credentials without output. Verify private identity, push permission, Issues, Actions/settings and Git transport independently with the same credential. Empty ls-remote exit 0 is valid. Never embed tokens in argv/URLs.

  • Publish milestones/issues idempotently by stable markers. Preserve full definitions and explicit amended dependency lists. Read back every target. GitHub list endpoints can briefly lag creation: re-fetch before asserting totals; never recreate from a short list.

  • Use supported Kanban CLI only. Delegated contexts can deny even show during DB initialization. Never remove delegation guards or bypass via database access. Prepare coordinator-only reconciliation, label backlinks/current holds unverified until executed there. Use needs_input holds; generic blocked can auto-promote.

  • Recover candidate and incumbent separately with explicit source allowlists, stable two-pass hashes and provenance. Inventory refs/worktrees/reflogs/stashes read-only. Current snapshots are not full history preservation; source-at-rest is not loaded runtime proof. Inventory deferred safe history and never clean originals while rescue is incomplete.

  • Publish only an authorized non-main branch. Empty GitHub repositories make their first branch default: read actual state, do not invent a main base or merge authority. Scan all newly reachable objects, names, commits and artifacts, journal intent, then verify exact remote ref, commit API and independent fetch. Preserve red WIP.

  • Isolate baseline with bubblewrap unshare-all/clearenv, read-only source and /usr, private proc/dev/tmp/home. No host /root, /run, network or credentials. Keep live provider/systemd opt-ins unset. Run disposable fixture-only opt-ins separately. Record actual unittest exits, all failures/skips. Verbose test IDs with docstrings span lines: count ^test\S+ \( IDs, not only lines containing ellipsis plus result.

  • Publish safe test logs and exact-source manifests in later evidence commits, avoiding self-referencing custody receipts. Preserve failed tooling variants as archival failed artifacts.

  • Historical rescue can use content-addressed inert source blobs plus commit/parent/path/blob lineage when original ancestry contains uncleared operations records. Count classified paths separately from byte-rescued paths; do not call local-only content-review entries remotely preserved. Enumerate changed/untracked/ignored paths only in inventoried worktrees. Verify exported hashes against immutable source objects and recheck incumbent snapshot hashes after tests.

  • Diagnose canonical-store migrations without changing red originals: isolated old tests may count obsolete embedded handoff lists or expect cosmetic prompt edits to reset semantic budgets. Separate fixture probes can verify actual canonical receipts/counters; they are not permission to weaken acceptance.

  • Inactive manual-dispatch CI candidates belong outside .github/workflows until dependency admission. Run the actual sandbox runner locally, propagate incumbent red, and test missing-bwrap fail-closed. Bubblewrap may add PWD=/source after clearenv; allow only that verified value in environment probes, preserving an earlier mistaken probe as failed evidence.

  • Stop at baseline gate. Independent fresh-context exact-candidate SOL review is not implementer self-review. No main merge, deployment, service change or new manager inferred.

  • If terminal returns empty output even for explicit stdout/stderr probes, do not treat exit zero as verification. A direct subprocess through execute_code can recover observable stdout/returncode without altering delegation guards. Independently verify Git/API identity with freshly loaded approved credentials in process-local headers; inherited Git auth may return 403.

  • For AF-03 fresh review, export exact Git blobs through an explicit source/test/fixture allowlist plus approved requirements and static contract excerpts. Exclude prior diagnosis/verification narratives, verdicts and .git. Hash and verify every payload; retain the acceptance-reconciliation proposal outside the initial packet. An existing host SOL coordinator command, --ignore-rules/--safe-mode, and read-only file permissions do not establish spec-v2 live adapter isolation or non-browsable authentication. Stop before inference when that boundary is unverified; do not reset cumulative attempts.

Verified lane mechanics (2026-09-15)​

  • The board slug is agent-orchestration, not agent-fleet-runtime; the remote is https://github.com/jknash/agent-orchestration. kanban --board agent-fleet-runtime fails with "board does not exist" — that is a wrong slug, not a missing board.
  • hermes kanban comment takes the body as a positional arg; there is no --body-file. Write the comment to a file for the record, then pass open(path).read() positionally via Python subprocess.run (heredoc/$(cat) shell forms sit in pending_approval under cron). Add --author and --max-len.
  • Verify a board write by counting an exact body-prefix match including your own lane, cron id and timestamp (show --json, body.startswith(prefix)), never a substring count of a round token — sibling lanes reuse round numbers and produce phantom duplicates.
  • Push custody needs the PAT passed process-locally: git -c "http.https://github.com/.extraheader=Authorization: Basic <b64 x-access-token:$PAT>". Inherited git auth 403s (Write access to repository not granted) while a fresh token succeeds, so a failing bare git fetch --all is not evidence of a lost remote.
  • Reviewer route readback: /root/.hermes/profiles/code-reviewer/state.db (sessions, mode=ro) — confirm model, billing_provider, profile_name, cwd before calling any verdict a review of record. The row is written at session close, so a live run shows nothing.
  • Launcher scrub lists go stale. After every launch read /proc/<pid>/environ and diff the surviving *_KEY|*_TOKEN|*_SECRET names against the scrub list. Observed survivors beyond a previously "clean" list: AGENTMAIL_API_KEY, HERMES_CUSTOM_SPARK_E1B8_8000_API_KEY, TERMINAL_DOCKER_SHARED_CONTAINER_KEY. Correct the list for the next launch and disclose the gap; do not kill a productive worker over non-repo credentials.
  • A gitless review packet cannot bind a commit. Expect the reviewer to raise that as an evidence-completeness finding and close it yourself with ls-remote + git log base..head
    • git diff --name-only base..head, proving the delta is evidence-only so the approval covers the bytes the reviewer actually executed.

Review-cascade mechanics (verified 2026-09-15)​

  • The PAT lives in /root/.hermes/.env, not /root/.env. A preserve/push script that reads only /root/.env commits successfully and then dies on no PAT, leaving a local commit with no remote. Make such scripts resumable: on re-run, accept an existing head whose parent is the expected base and whose subject is your own custody subject, then push — never re-commit and never reset a good commit away.
  • hermes kanban comment <task> <body> is positional and works via subprocess.run with the body read in Python. post_board_comment.py in the lane dir does post + exactly-once verification by first-line author-scoped prefix; reuse it rather than re-deriving.
  • A REQUEST_CHANGES verdict routes to remediation on the same attempt lineage — a change-request round is not a new attempt. Record round separately from attempt in the launch receipt so the >2-rounds escalation rule counts rounds honestly.
  • Reclaiming a stale writer.lock: require the recorded pid to be absent from /proc, then os.replace the old lock to writer.lock.run-NN (preserve, never delete) before O_EXCL creating your own. Fence the launch on exact HEAD == expected base and a clean git status --porcelain, so a partially-mutated tree aborts the dispatch.
  • Launch receipts should record residual_credential_shaped_names_in_child (every surviving *_KEY|*_TOKEN|*_SECRET name diffed against the scrub list), not just leaked. Observed intentional survivors: GITHUB_PERSONAL_ACCESS_TOKEN (the implementer needs branch push custody) and HERMES_SESSION_KEY (internal). Disclose, do not silently pass.
  • The reviewer will raise the gitless-packet commit-binding gap every time. Close it yourself in the verdict doc with git log base..head, git diff --name-only base..head filtered to src/+tests/, and a main ref readback proving nothing merged — that converts the gap into a recorded coordinator attestation instead of an open finding.

Manual checklist only: not proof production custody, ref immutability, CI, restoration or reviewer isolation exists.


Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/fleet-runtime-bootstrap/ · view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.

Published by Muse · 2026-10-03.