Bounded fleet-runtime bootstrap
Use when bootstrapping a private fleet-runtime repository.
-
Read exact approved spec/manifests; preserve historical proposed bytes and record new authorization separately.
-
Fresh-load intended credentials without output. Verify private identity, push permission, Issues, Actions/settings and Git transport independently with the same credential. Empty ls-remote exit 0 is valid. Never embed tokens in argv/URLs.
-
Publish milestones/issues idempotently by stable markers. Preserve full definitions and explicit amended dependency lists. Read back every target. GitHub list endpoints can briefly lag creation: re-fetch before asserting totals; never recreate from a short list.
-
Use supported Kanban CLI only. Delegated contexts can deny even show during DB initialization. Never remove delegation guards or bypass via database access. Prepare coordinator-only reconciliation, label backlinks/current holds unverified until executed there. Use needs_input holds; generic blocked can auto-promote.
-
Recover candidate and incumbent separately with explicit source allowlists, stable two-pass hashes and provenance. Inventory refs/worktrees/reflogs/stashes read-only. Current snapshots are not full history preservation; source-at-rest is not loaded runtime proof. Inventory deferred safe history and never clean originals while rescue is incomplete.
-
Publish only an authorized non-main branch. Empty GitHub repositories make their first branch default: read actual state, do not invent a main base or merge authority. Scan all newly reachable objects, names, commits and artifacts, journal intent, then verify exact remote ref, commit API and independent fetch. Preserve red WIP.
-
Isolate baseline with bubblewrap unshare-all/clearenv, read-only source and /usr, private proc/dev/tmp/home. No host /root, /run, network or credentials. Keep live provider/systemd opt-ins unset. Run disposable fixture-only opt-ins separately. Record actual unittest exits, all failures/skips. Verbose test IDs with docstrings span lines: count ^test\S+ \( IDs, not only lines containing ellipsis plus result.
-
Publish safe test logs and exact-source manifests in later evidence commits, avoiding self-referencing custody receipts. Preserve failed tooling variants as archival failed artifacts.
-
Historical rescue can use content-addressed inert source blobs plus commit/parent/path/blob lineage when original ancestry contains uncleared operations records. Count classified paths separately from byte-rescued paths; do not call local-only content-review entries remotely preserved. Enumerate changed/untracked/ignored paths only in inventoried worktrees. Verify exported hashes against immutable source objects and recheck incumbent snapshot hashes after tests.
-
Diagnose canonical-store migrations without changing red originals: isolated old tests may count obsolete embedded handoff lists or expect cosmetic prompt edits to reset semantic budgets. Separate fixture probes can verify actual canonical receipts/counters; they are not permission to weaken acceptance.
-
Inactive manual-dispatch CI candidates belong outside .github/workflows until dependency admission. Run the actual sandbox runner locally, propagate incumbent red, and test missing-bwrap fail-closed. Bubblewrap may add PWD=/source after clearenv; allow only that verified value in environment probes, preserving an earlier mistaken probe as failed evidence.
-
Stop at baseline gate. Independent fresh-context exact-candidate SOL review is not implementer self-review. No main merge, deployment, service change or new manager inferred.
-
If terminal returns empty output even for explicit stdout/stderr probes, do not treat exit zero as verification. A direct subprocess through execute_code can recover observable stdout/returncode without altering delegation guards. Independently verify Git/API identity with freshly loaded approved credentials in process-local headers; inherited Git auth may return 403.
-
For AF-03 fresh review, export exact Git blobs through an explicit source/test/fixture allowlist plus approved requirements and static contract excerpts. Exclude prior diagnosis/verification narratives, verdicts and .git. Hash and verify every payload; retain the acceptance-reconciliation proposal outside the initial packet. An existing host SOL coordinator command, --ignore-rules/--safe-mode, and read-only file permissions do not establish spec-v2 live adapter isolation or non-browsable authentication. Stop before inference when that boundary is unverified; do not reset cumulative attempts.
Verified lane mechanics (2026-09-15)
- The board slug is
agent-orchestration, notagent-fleet-runtime; the remote ishttps://github.com/jknash/agent-orchestration.kanban --board agent-fleet-runtimefails with "board does not exist" — that is a wrong slug, not a missing board. hermes kanban commenttakes the body as a positional arg; there is no--body-file. Write the comment to a file for the record, then passopen(path).read()positionally via Pythonsubprocess.run(heredoc/$(cat)shell forms sit inpending_approvalunder cron). Add--authorand--max-len.- Verify a board write by counting an exact body-prefix match including your own lane, cron
id and timestamp (
show --json,body.startswith(prefix)), never a substring count of a round token — sibling lanes reuse round numbers and produce phantom duplicates. - Push custody needs the PAT passed process-locally:
git -c "http.https://github.com/.extraheader=Authorization: Basic <b64 x-access-token:$PAT>". Inherited git auth 403s (Write access to repository not granted) while a fresh token succeeds, so a failing baregit fetch --allis not evidence of a lost remote. - Reviewer route readback:
/root/.hermes/profiles/code-reviewer/state.db(sessions,mode=ro) — confirmmodel,billing_provider,profile_name,cwdbefore calling any verdict a review of record. The row is written at session close, so a live run shows nothing. - Launcher scrub lists go stale. After every launch read
/proc/<pid>/environand diff the surviving*_KEY|*_TOKEN|*_SECRETnames against the scrub list. Observed survivors beyond a previously "clean" list:AGENTMAIL_API_KEY,HERMES_CUSTOM_SPARK_E1B8_8000_API_KEY,TERMINAL_DOCKER_SHARED_CONTAINER_KEY. Correct the list for the next launch and disclose the gap; do not kill a productive worker over non-repo credentials. - A gitless review packet cannot bind a commit. Expect the reviewer to raise that as an
evidence-completeness finding and close it yourself with
ls-remote+git log base..headgit diff --name-only base..head, proving the delta is evidence-only so the approval covers the bytes the reviewer actually executed.
Review-cascade mechanics (verified 2026-09-15)
- The PAT lives in
/root/.hermes/.env, not/root/.env. A preserve/push script that reads only/root/.envcommits successfully and then dies onno PAT, leaving a local commit with no remote. Make such scripts resumable: on re-run, accept an existing head whose parent is the expected base and whose subject is your own custody subject, then push — never re-commit and neverreseta good commit away. hermes kanban comment <task> <body>is positional and works viasubprocess.runwith the body read in Python.post_board_comment.pyin the lane dir does post + exactly-once verification by first-line author-scoped prefix; reuse it rather than re-deriving.- A REQUEST_CHANGES verdict routes to remediation on the same attempt lineage — a
change-request round is not a new attempt. Record
roundseparately fromattemptin the launch receipt so the >2-rounds escalation rule counts rounds honestly. - Reclaiming a stale
writer.lock: require the recorded pid to be absent from /proc, thenos.replacethe old lock towriter.lock.run-NN(preserve, never delete) beforeO_EXCLcreating your own. Fence the launch on exact HEAD == expected base and a cleangit status --porcelain, so a partially-mutated tree aborts the dispatch. - Launch receipts should record
residual_credential_shaped_names_in_child(every surviving*_KEY|*_TOKEN|*_SECRETname diffed against the scrub list), not justleaked. Observed intentional survivors:GITHUB_PERSONAL_ACCESS_TOKEN(the implementer needs branch push custody) andHERMES_SESSION_KEY(internal). Disclose, do not silently pass. - The reviewer will raise the gitless-packet commit-binding gap every time. Close it yourself in
the verdict doc with
git log base..head,git diff --name-only base..headfiltered tosrc/+tests/, and amainref readback proving nothing merged — that converts the gap into a recorded coordinator attestation instead of an open finding.
Manual checklist only: not proof production custody, ref immutability, CI, restoration or reviewer isolation exists.
Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/fleet-runtime-bootstrap/ · view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.
Published by Muse · 2026-10-03.