fleet-ops

v2026.09.24

Inspect JoelClaw Mac fleet harness drift safely. Use for fleet status/diff, role-aware Pi and skill-policy checks, or planning a reviewed fleet change.

GitHub
安装命令
npx skhub add joelhooks/fleet-ops
Markdown
SKILL.md

Fleet Operations

Use this to inspect the JoelClaw Mac fleet without flattening intentional role differences into fake drift.

Resolve current Central ownership from the private manifest and live evidence. Satellites stay thin. A role difference is policy only when the local private fleet manifest says why.

Current commands: read-only

joelclaw fleet status
joelclaw fleet diff

Both commands read the local private fleet manifest and return JSON envelopes. They do not install packages, copy config, request repair, change services, or rewrite a Machine.

Use --host <alias> to inspect one declared host. Do not pass an undeclared target or publish the private manifest.

status reports observed facts and probe failures. diff classifies declared fields as:

  • in_sync
  • expected_difference — an explicit manifest exemption, including its reason
  • drift — an actionable mismatch
  • unavailable — a required fact could not be read

A failed or unavailable satellite health probe is actionable. Thin satellite skill policy alone is not.

Operator flow

  1. Probe — run joelclaw fleet status.
  2. Classify — run joelclaw fleet diff; read the exemption reason before calling a difference wrong.
  3. Inspect — verify unexpected drift with the relevant host/runbook. Do not infer host identity from an SSH alias alone.
  4. Plan — write a host-scoped, reviewable change plan. Fleet plan does not exist yet.
  5. Authorize — use authorization already given for the named host change. Ask only for a mutation outside that scope; an audit alone authorizes no repairs.
  6. Apply — use the approved, host-specific mechanism. Fleet apply does not exist yet. Never pretend it does.
  7. Verify — rerun status and diff, then capture a redacted receipt.

If a probe cannot reach a host, record unavailable and keep gathering the other hosts. Do not turn on Remote Login, alter Tailscale, copy credentials, or bootstrap a Machine as a side effect of an audit.

Role boundaries

  • Central: Use the verified owner in current service placement. Verify Central health through the established system runbooks before changing it.
  • Satellite: keep the Machine local, small, and recoverable. Load Satellite Rig for setup or repair.
  • Network and host routing: load the locally installed panda-host, tailnet-topology, and operator-network guidance. Those private/operator resources are not canonical content of this public repo; do not copy them here or expose their topology.

Guardrails

  • Keep actual host routing, auth, and other fleet details in the local private manifest, never a public repo, issue, or output envelope.
  • Treat SSH identity mismatch as actionable until independently explained.
  • Do not auto-converge role policy. A Central and a thin satellite should not have the same service or skill surface by default.
  • Run satellites first and Central last only after a reviewed mutation plan exists.
  • Keep fleet audit output redacted before sharing it outside the operator environment.
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

未指定

源路径

skills/fleet-ops

默认分支

main

最新提交

e313432

Tree SHA

eb9cad7