127 Commits

Author SHA1 Message Date
jenkins
9d42ff33f5 Merge origin/main (#16 image-builder) into hermes-safe-gitea-pr
Resolve 8 conflicts, uniting #16's daemonless image-release lane with
#14's SCM broker + node-audit boundary. Nothing dropped from either side.

- quality_coverage.py / test_quality_coverage_helpers.py: take main's
  dual-metric gate (line+branch enforced per file at minimum_percent);
  drop #14's now-dead branch_tracked_files/minimum_branch_percent keys.
- quality_contract.json: union all lists (managed_modules, lint_paths,
  coverage_sources, tracked_files, hygiene globs) so #14's scm-broker,
  git_pack_objects, receive_pack_scan, deadline_http and node_polkit_audit
  are branch-checked alongside #16's image-builder modules.
- Vault auth (vault_k8s_auth_configure.sh): coexist both role sets. Keep
  #16's hermes-switchyard split + hermes-jenkins-token-seed; keep #14's
  hermes-scm-broker role. Preserve #14's security property: hermes-agent
  no longer holds developer-gitea (broker role carries it).
- agent-deployment.yaml / stage_runtime_access.py: keep #16's
  jenkins-image-build-token injection/staging; keep #14's removal of the
  agent's gitea-token/gitea-username.
- Bump vault-k8s-auth-hermes job -9 -> -10 (and its health check + test)
  so the merged auth config re-applies over any -9 already in-cluster.
- flux hermes dependsOn: union jenkins + hermes-scm-broker + observer-rbac.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 21:07:06 -03:00
jenkins
e8c26ecf85 hermes: add daemonless agent image release lane 2026-08-17 08:25:52 -03:00
jenkins
8c6e3acdac hermes: isolate Atlas SCM write authority 2026-08-17 07:58:44 -03:00
jenkins
762784da6b hermes: bound Atlas pull request client 2026-08-17 07:22:26 -03:00
Hermes Agent
750dfa241f hermes: fail closed on kanban created-event producer drift
The sticky-block gate added in the previous commit classifies a task from
the `created` event payload that upstream `create_task` writes. That
producer is code we do not own, so trusting it silently was the gap: if
upstream renamed the key, dropped it, or stopped deriving it from
`initial_status`, the image would still build and ship a consumer that
mis-classifies every task it reads.

Anchor the producer contract at build time, before the regression suite
runs, with three assert-only preconditions: the `initial_status="blocked"`
park resolves `task_status` to `"blocked"`, every non-park creation
resolves it to something else, and the `created` event carries that same
variable under `"status"`. None of them rewrite the producer.

Textual anchors cannot see dataflow, so add the runtime net the reviewer
asked for. The suite now drives the real API: create + claim an ordinary
task, trip the circuit breaker once at failure_limit=1 so it parks with a
`gave_up` event (leaving its own `created` event as the most recent
create/block/unblock row), then recompute at failure_limit=2 and require
promotion to ready. That case is red under an unconditional-true created
predicate and red under producer drift that labels every created event
blocked, while the explicit block/unblock, dependency-promotion and
circuit-breaker-at-current-limit cases stay green. Non-blocked and
malformed created payloads are pinned as controls, and the gate now
rejects non-dict payloads rather than trusting `.get`.

Also make the live placement correction durable: titan-04 is cordoned
after repeated kernel undervoltage and kubelet failure and titan-19 was
probe/Longhorn unstable under worker load, so both join the hard NotIn
list; titan-05 is healthy but sits at 3592m/3600m requested CPU, so the
main hermes container gives back 50m (350m -> 300m) to schedule there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 22:42:18 +00:00
Hermes Agent
4f8dcfbbf7 hermes: harden worker isolation and blocked-task semantics
Three narrowly scoped Hermes reliability fixes backed by live evidence
from the Cassandra/titan-iac proof run.

Worker concurrency. Three simultaneous direct CLI workers on the 4-core
hermes-agent node drove load to ~45 and made the hermes and oauth2-proxy
containers fail their probes, leaving the pod 8/10 Ready; two workers
stayed at 10/10. Cap HERMES_CLI_LANE_CONCURRENCY at 2 and lower the
cli-lane-runner CPU limit from 3 to 2 so the dashboard and auth sidecars
keep a guaranteed share of the node. Requests are unchanged: the pod
still asks for 745m total, so placement does not move.

Service links. Kubernetes injects a service-link variable pair for every
service in the namespace, and hermes-claude-broker produces
HERMES_CLAUDE_BROKER_PORT=tcp://10.43.31.76:9006 — a value the broker
parses as an int. That contaminated worker and test environments even
though the deployment already addresses every service by DNS name. Set
enableServiceLinks: false on the hermes-agent pod spec.

Blocked-task scheduling. create_task(initial_status="blocked") records a
created event carrying status=blocked but never a blocked event, while
_has_sticky_block() only inspects blocked/unblocked events. recompute_ready()
considers blocked tasks, so an explicitly parked task with no incomplete
parent auto-promoted on the next dispatcher cycle. Teach _has_sticky_block()
to also recognize a created event whose payload status is blocked, which
covers tasks created before this image patch without adding a persisted
field. Dependency-driven promotion and the circuit-breaker failure-limit
guard are untouched; unblock_task() still releases either kind of block.

hermes-kanban-blocked-regression.py runs against the real upstream
kanban_db API during the image build, so the build fails if any of these
semantics regress.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 20:53:22 +00:00
jenkins
ba590c2518 hermes: retain native auth failure health 2026-08-16 13:47:19 -03:00
jenkins
e8b4f0c57c hermes: widen local goal judge timeout 2026-08-16 13:29:10 -03:00
jenkins
2a103f9895 hermes: require findings in worker schema 2026-08-16 12:04:27 -03:00
jenkins
1ea8e16286 hermes: separate review findings from blockers 2026-08-16 11:54:26 -03:00
jenkins
42ac76fe67 hermes: carry goal-loop controller evidence 2026-08-16 11:27:24 -03:00
jenkins
64dd9c9be4 hermes: roll out goal completion judge 2026-08-16 11:14:07 -03:00
jenkins
2a94c7c74f hermes: isolate worker database lifetimes 2026-08-16 10:30:58 -03:00
jenkins
e758ee1059 hermes: survive transient Kanban storage faults 2026-08-16 09:33:30 -03:00
jenkins
943fa71ac5 hermes: roll forge workflow instructions 2026-08-16 08:25:02 -03:00
jenkins
c7ac16d206 hermes: harden Atlas forge workflow 2026-08-16 07:59:35 -03:00
jenkins
ece52b1f2e hermes: harden routed vision normalization 2026-08-16 07:24:20 -03:00
jenkins
8f7b57419a hermes: accept routed base64 vision 2026-08-16 07:12:11 -03:00
jenkins
8ada8e062e hermes: roll routed vision broker 2026-08-16 07:03:36 -03:00
jenkins
cef7241f11 hermes: avoid empty ad hoc task lookups 2026-08-16 06:06:26 -03:00
jenkins
7ac7f21a04 hermes: roll out Go toolchain bootstrap 2026-08-16 05:40:15 -03:00
jenkins
612cefad23 monitoring(ai): add provider quota operations dashboard 2026-08-16 05:13:20 -03:00
jenkins
012e5fc2ba hermes: recover stale kanban status pages 2026-08-16 04:49:02 -03:00
jenkins
ece8b009f8 hermes: refresh Claude runtime credential 2026-08-16 03:05:06 -03:00
jenkins
eace0ed0df hermes: scope stale activity lineage 2026-08-16 02:51:33 -03:00
jenkins
9bc47f9ce3 hermes: keep durable worker activity visible 2026-08-16 01:20:08 -03:00
jenkins
e9efec4ddf hermes: keep provider lanes available under load 2026-08-15 22:15:40 -03:00
jenkins
89b9f1a4c7 hermes: isolate runtime access and expose activity 2026-08-15 22:15:40 -03:00
jenkins
07b64a0245 hermes: expose Vault SSH config to OpenSSH 2026-08-15 14:45:27 -03:00
jenkins
d27a9649cf hermes: secure node access and expose live workers 2026-08-15 13:58:42 -03:00
jenkins
2ae88973be hermes: add audited Atlas operator access 2026-08-15 13:22:01 -03:00
jenkins
29eeb1ebf8 hermes: recover workers after pod restart 2026-08-15 07:07:21 -03:00
jenkins
b4634fa275 hermes: roll durable worker lifecycle 2026-08-15 06:54:24 -03:00
jenkins
dca4249599 hermes: recover Kanban event indexes 2026-08-15 05:37:53 -03:00
jenkins
01b250de0b hermes: roll durable lane resolver 2026-08-15 04:09:12 -03:00
jenkins
846c890527 hermes: load tool credentials before s6 2026-08-15 03:44:00 -03:00
jenkins
f7492defdd hermes: recover Kanban and tool execution 2026-08-15 03:35:26 -03:00
jenkins
9909f78386 hermes: roll Atlas repository remotes 2026-08-15 00:02:50 -03:00
jenkins
e486e53d7d hermes: use contributor Gitea identity 2026-08-13 21:25:44 -03:00
jenkins
046dd6fae4 hermes: activate Telegram and isolate corrupt boards 2026-08-13 12:24:35 -03:00
jenkins
6d492a9a65 hermes: tolerate preserved Kanban corruption 2026-08-13 04:42:04 -03:00
jenkins
9fa7612cd4 hermes: restore terminal rendering and worker lineage 2026-08-13 02:49:41 -03:00
jenkins
39ee0d5918 hermes: roll out lineage cleanup 2026-08-13 01:31:48 -03:00
jenkins
2b540118d6 hermes: correct provider status and session lineage 2026-08-12 23:48:06 -03:00
jenkins
2ffe2d1002 hermes: size provider setup init 2026-08-12 23:17:47 -03:00
jenkins
c11408258c hermes: restore native provider routing 2026-08-12 23:08:21 -03:00
jenkins
d8566f007f hermes: recover interrupted provider streams 2026-08-12 10:41:47 -03:00
jenkins
dc9b2d153f hermes: restore image and Cassandra continuity 2026-08-12 08:30:01 -03:00
jenkins
b4c45a4989 hermes: normalize Codex tool streams 2026-08-12 07:55:35 -03:00
jenkins
0b94e04d64 hermes: deduplicate streamed tool arguments 2026-08-12 07:45:35 -03:00