docs: migrate Authentik (SSO keystone) to edge2 CT 105

- Authentik -> edge2 CT 105 (Postgres pg_dump/restore; SECRET_KEY carried verbatim; zero-downtime until ~2s cutover)
- Multi-block Caddy cutover: auth.echo6.co + notes.echo6.co outpost/forward_auth -> 100.64.0.36:9000
- runbook: add reboot tailscale-before-docker gotcha; clarify dnsmasq must NOT be repointed (points at Caddy host)
- source left stopped + intact on Contabo as cold rollback

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Matt Johnson 2026-06-18 05:49:07 +00:00
commit 44f0257376
140 changed files with 4013 additions and 24 deletions

66
engine/sweep.sh Executable file
View file

@ -0,0 +1,66 @@
#!/usr/bin/env bash
# sweep.sh — Echo6 Vault Engine daily maintenance sweep
#
# Invoked by cron (schedule: "0 9 * * *" from config.yaml).
# Also callable manually: ./sweep.sh
#
# What this does (when fully implemented):
# 1. GPU-busy guard: check VRAM usage; defer if > defer_if_gpu_busy_mib (6000 MiB default)
# 2. Run lint (lib/lint.py) over all vault docs — fix or flag frontmatter issues
# 3. Run agent (lib/agent.py) over changed/new docs since last run — tag + embed
# 4. Append a summary entry to changelog.md
#
# Configuration is read from config.yaml (engine_dir, vault_dir, thresholds, changelog path).
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
CONFIG="${SCRIPT_DIR}/config.yaml"
echo "==> Echo6 vault sweep — $(date -u '+%Y-%m-%dT%H:%M:%SZ')"
# ---------------------------------------------------------------------------
# Step 1 — GPU-busy guard
# ---------------------------------------------------------------------------
# TODO: Query nvidia-smi for used VRAM; compare to defer_if_gpu_busy_mib from config.yaml.
# If busy, log a deferred entry to changelog and exit 0 (not an error, just deferred).
#
# Example skeleton:
# USED_MIB=$(nvidia-smi --query-gpu=memory.used --format=csv,noheader,nounits | head -1)
# THRESHOLD=6000 # read from config.yaml
# if [ "$USED_MIB" -gt "$THRESHOLD" ]; then
# echo "GPU busy (${USED_MIB} MiB > ${THRESHOLD} MiB threshold) — deferring sweep."
# exit 0
# fi
echo "[1/4] TODO — GPU-busy guard not yet implemented."
# ---------------------------------------------------------------------------
# Step 2 — Run lint
# ---------------------------------------------------------------------------
# TODO: Call lib/lint.py to validate/fix frontmatter across vault docs.
# Lint should be idempotent and log all changes to changelog.
#
# python3 "${SCRIPT_DIR}/lib/lint.py" --config "${CONFIG}"
echo "[2/4] TODO — lint.py not yet implemented (Step 2)."
# ---------------------------------------------------------------------------
# Step 3 — Run agent over changed/new docs
# ---------------------------------------------------------------------------
# TODO: Call lib/agent.py to tag + embed documents modified since last sweep.
# Agent tracks last-run timestamp in a state file (e.g. engine/.last_sweep).
#
# python3 "${SCRIPT_DIR}/lib/agent.py" --config "${CONFIG}"
echo "[3/4] TODO — agent.py not yet implemented (Step 5)."
# ---------------------------------------------------------------------------
# Step 4 — Append changelog summary
# ---------------------------------------------------------------------------
# TODO: agent.py and lint.py both append to changelog.md directly.
# This step adds a sweep-level summary entry.
echo "[4/4] TODO — changelog summary not yet implemented."
echo "==> sweep.sh done."