Skip to content

Issue #56: Home cutover autopilot — one PR, many milestones - #58

Merged
amitkarpe merged 16 commits into
mainfrom
g/issue-56-home-cutover
Sep 28, 2026
Merged

amitkarpe merged 16 commits into
mainfrom
g/issue-56-home-cutover

Conversation

@amitkarpe

Copy link
Copy Markdown
Owner

Roadmap Autopilot execution PR

Owner: #56
Parent roadmap: #1

Amit granted standing approval on 2026-09-27 to execute the remaining Home cutover milestones continuously without asking for go between routine steps.

This PR intentionally remains open across multiple milestones:

  • M2 — real Home bootstrap;
  • M3 — real Home owner-login/browser acceptance;
  • M4 — one NEW-only temporary public tunnel;
  • M5 — after M1-M4 PASS, stop (never terminate) the retained amit EC2 and update cost/cutover evidence.

PR #57 already completed M1 runtime preservation and is the baseline.

Standing safety boundary

Allowed within #56:

  • Home local services/containers/config;
  • existing owner-approved read-only AWS SSO evidence;
  • one NEW-only provider-assigned public tunnel;
  • routine fixes/tests/docs in this same PR;
  • after M1-M4 PASS, stop exactly the retained amit EC2 and verify stopped state.

Not allowed:

  • EC2 termination or EBS/EIP deletion;
  • Lightsail or protected vagent mutation;
  • custom Route53 migration;
  • broad IAM/admin expansion;
  • live Approve/remediation or generic AWS write path;
  • secrets/private identifiers in Git.

The durable execution checklist is docs/current/HOME_CUTOVER_EXECUTION.md.

Do not merge until M2-M5 acceptance is complete and green.

Copy link
Copy Markdown
Owner Author

Owner boundary update — Home only for runtime/development

Amit explicitly clarified:

  • Office laptop / office WSL: DO NOT install Docker, MongoDB, LibreChat runtime, tunnel agents, or any other new development/runtime dependencies.
  • Office WSL may be used only for lightweight read/review/Git/documentation work that needs no new runtime installation.
  • Home system is the development/runtime machine for Issue Home demo reproducibility: canonicalize retained runtime before EC2 stop #56 M2-M4:
    • Docker / Docker Compose;
    • MongoDB;
    • LibreChat;
    • local config2/sec2 services;
    • Playwright/browser acceptance;
    • Cloudflare/Tailscale/ngrok-style tunnel tooling if needed;
    • any further local development dependencies.
  • Do not use the office laptop as a fallback merely because the Home environment is temporarily unavailable.
  • If execution is not actually on Amit's Home system, report the blocker and wait; do not install locally on office WSL.

This boundary overrides any earlier Home-bootstrap instruction that could be interpreted as allowing installation on the current Codex/office WSL host.

Copy link
Copy Markdown
Owner Author

M2 execution checkpoint — Home-only boundary enforced

Verified:

  • current Bridge worker = office WSL (Ubuntu 24.04 / WSL2);
  • therefore it is not an allowed Issue Home demo reproducibility: canonicalize retained runtime before EC2 stop #56 runtime host;
  • no Docker, MongoDB, LibreChat, Playwright browser, tunnel agent, or other runtime dependency was installed there;
  • the earlier M2 mission was stopped rather than using office WSL as a fallback;
  • Direct Home/Hermes Bridge still fails closed with missing trusted checkout;
  • aws-platform Issue #106 owns the operator-side trusted-profile/binding fix.

PR #58 remains the single execution PR. M2 is blocked only on reaching the actual Home system; repository/CI state is green.

Copy link
Copy Markdown
Owner Author

Bridge correction + blocker

Durable state corrected:

  • Home runtime target = dev@home, tracked in aws-platform #99.
  • Hermes/#106 is a separate bridge path and is not required for this Home cutover.
  • New Bridge2 control-plane defect discovered while resuming #99: mission_start says controller has an active mission, while worker_status says idle with active_mission_id=null.
  • That defect is reported as aws-platform #109.
  • vagent owner authority is also reconciled: STOP-only is allowed separately via aws-platform #107; destructive/configuration changes remain prohibited.

No office runtime installation and no AWS mutation occurred.

Copy link
Copy Markdown
Owner Author

Bridge checkpoint — automatic continuation safely paused

Progress in aws-platform:

  • #108 caller/worker capability split merged;
  • #109 active-route visibility fix merged;
  • #94 proven historical/orphan mission readback fix has now been ported directly to current main in PR #114.

Remaining live blocker:

  • one project-profile read-only acceptance mission and one Factory read-only Home-preflight mission are both still persisted as running without terminal results;
  • Bridge/app-server restart or force-clear is unsafe while execution cannot be disproved;
  • #96 owns the safe mission-cancel/reconciliation contract.

No office runtime was installed and no AWS/cloud mutation occurred. PR #58 remains the single Home-cutover execution PR.

Copy link
Copy Markdown
Owner Author

Home transport checkpoint

G resumed Roadmap Autopilot after the successful read-only office preflight.

Current state:

M2 remains Home-only. Next safe continuation is to consume the terminal #90/PR #91 Direct proof, then retry dev@home transport and start M2 from a fresh clean PR #58 checkout. No office runtime install and no AWS/cloud mutation occurred.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT

Issue #56 M2 + M3 completed on Amit's verified Home Ubuntu workstation.

  • Branch/head: g/issue-56-home-cutover @ d5a93e65320b26912c0ed9bdca63fb3e714f6814
  • Home proof: native Ubuntu 24.04 desktop, separate clean PR Issue #56: Home cutover autopilot — one PR, many milestones #58 checkout; office WSL and the unrelated dirty Home checkout were untouched.
  • M2 PASS: prerequisite check; immutable LibreChat pin prepare/verify; isolated loopback MongoDB; config2 build and loopback health; read-only Config evidence READY, non-partial, exactly 4 aliases / 8 checks / 2 controls. No retained-EC2 files or state were copied.
  • M3 PASS: normal local owner login; canonical AWS Ops Compliance Agent selected; exactly 1 read-only MCP tool / 0 actions. Status, Explain, and no-change Plan passed persisted-tool, persisted-assistant, and rendered-DOM binding. All 3 test conversations were archived. No browser auth or storage state was exported.
  • Runtime fixes: Node 24 requirement aligned with the pinned dependency; MCP stdio now uses the venv-resolved python3; owner-private AWS profile inputs propagate to the MCP child; timeout increased for the approved Harness; browser harness accepts only the canonical public origin or exact localhost/loopback origin.
  • Validation: python scripts/home_demo.py check; pinned source verify; Docker Compose config; 153 repository tests PASS; config2 npm ci, build, lint, and runtime preparation PASS; live config2 and browser readbacks PASS.
  • Docs: M2/M3 checklist and CONTEXT updated. Added the sanitized Home capability record at docs/current/HOME_DEV_CAPABILITY.md.
  • Public exposure: none. Services remain loopback-only. M4 temporary tunnel is technically safe to begin after review of this head; it has not started.

PASS: M2 and M3. GAPS: M4 temporary tunnel and M5 retained-host stop/cost cutover remain.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT

Issue #56 M2 + M3 completed on Amit's verified Home Ubuntu workstation.

  • Branch/head: g/issue-56-home-cutover @ 33bdc2e9e1e59ad5d13fefbb6f58ac7efa721b59
  • Home proof: native Ubuntu 24.04 desktop, separate clean PR Issue #56: Home cutover autopilot — one PR, many milestones #58 checkout; office WSL and the unrelated dirty Home checkout were untouched.
  • M2 PASS: prerequisite check; immutable LibreChat pin prepare/verify; isolated loopback MongoDB; config2 build and loopback health; read-only Config evidence READY, non-partial, exactly 4 aliases / 8 checks / 2 controls. No retained-EC2 files or state were copied.
  • M3 PASS: normal local owner login; canonical AWS Ops Compliance Agent selected; exactly 1 read-only MCP tool / 0 actions. Status, Explain, and no-change Plan passed persisted-tool, persisted-assistant, and rendered-DOM binding. All 3 test conversations were archived. No browser auth or storage state was exported.
  • Runtime fixes: Node 24 requirement aligned with the pinned dependency; MCP stdio now uses the venv-resolved python3; owner-private AWS profile inputs propagate to the MCP child; timeout increased for the approved Harness; browser harness accepts only the canonical public origin or exact localhost/loopback origin.
  • Validation: python scripts/home_demo.py check; pinned source verify; Docker Compose config; 153 repository tests PASS; config2 npm ci, build, lint, and runtime preparation PASS; live config2 and browser readbacks PASS. CI and GitGuardian PASS on the exact head.
  • Docs: M2/M3 checklist and CONTEXT updated. Added the sanitized Home capability record at docs/current/HOME_DEV_CAPABILITY.md.
  • Public exposure: none. Services remain loopback-only. M4 temporary tunnel is technically safe to begin after review of this head; it has not started.

PASS: M2 and M3. GAPS: M4 temporary tunnel and M5 retained-host stop/cost cutover remain.

Copy link
Copy Markdown
Owner Author

G review — M2/M3 ACCEPTED; M4 may begin

Reviewed exact head 33bdc2e9e1e59ad5d13fefbb6f58ac7efa721b59.

Accepted evidence:

  • verified Home Ubuntu execution, with office and unrelated worktrees preserved;
  • M2 local rebuild PASS with loopback-only MongoDB/config2 and READY/non-partial 4 aliases x 2 controls;
  • M3 normal-owner browser acceptance PASS for Status / Explain / no-change Plan;
  • exactly 1 read-only MCP tool / 0 actions;
  • 153 tests PASS;
  • GitHub Actions CI #244 PASS on exact head;
  • GitGuardian PASS / no secrets detected on exact head;
  • public-safe Home capability documentation added; no public exposure yet.

Review finding: no blocking issue found in the M2/M3 delta. Runtime changes are proportional to the proven Home execution gaps (Node 24, venv-resolved Python, owner-private AWS profile propagation, timeout, strict local/public browser origin handling).

Verdict: ACCEPT M2 + M3.

Roadmap Autopilot may continue to M4 only under existing Issue #56 authority: one NEW-only temporary provider-assigned HTTPS tunnel from Home, no custom DNS/Route53, no home-router port forwarding, no broad IAM/new paid infrastructure. Re-run the three canonical prompts remotely and document stop/restart procedure. Do not start M5 EC2 stop until M4 is independently PASS.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT

Issue #56 M4 is PASS on the verified Home Ubuntu workstation.

  • Stable PR head: ce58df93e3552964a24ec430e704573aa6d98e88
  • Remote browser code head: 5a09325e75e3e4acdc10aea942d0914e01e6cef4; the stable head adds only the M4 context/runbook record.
  • Tunnel: one NEW-only Cloudflare quick tunnel to Home sec2 loopback. The provider-assigned hostname remains private. No custom DNS, Route53, router forwarding, IAM, AWS runtime or retained EC2 change occurred.
  • Public path: HTTPS 200 with certificate verification enabled.
  • Browser acceptance: Status PASS, Explain PASS, no-change Plan PASS.
  • Contract: exactly one read-only MCP tool, zero actions, eight checks per result, persisted/rendered binding PASS.
  • Cleanup: all three exact test conversations archived with Archive readback; no browser auth or storage state exported.
  • Config2 regression: READY, partial=false, four aliases and eight checks.
  • Existing validation: focused browser tests PASS; full repository suite PASS (153 tests); git diff --check PASS; CI PASS; GitGuardian PASS.
  • Files changed in M4: integration/compliance_agent/browser_acceptance.cjs, integration/compliance_agent/README.md, tests/test_compliance_agent_browser.py, CONTEXT.md, docs/current/HOME_CUTOVER_EXECUTION.md.
  • Operational note: Tailscale Funnel required a tailnet policy enablement, so the authorized provider-assigned Cloudflare quick tunnel was used instead. No tailnet policy was changed.
  • M5 retained EC2 stop was not executed. M4 now clears the technical prerequisite for a separately executed M5 step.

Copy link
Copy Markdown
Owner Author

G review — M4 ACCEPTED; M5 may begin

Reviewed exact head ce58df93e3552964a24ec430e704573aa6d98e88 and the M4 handoff.

Accepted evidence:

  • one NEW-only Cloudflare quick tunnel from Home sec2 loopback;
  • provider-assigned HTTPS path only; no Route53/custom DNS, router forwarding, IAM, AWS runtime or retained-host mutation;
  • remote Status / Explain / no-change Plan PASS 3/3;
  • exactly 1 read-only MCP tool / 0 actions;
  • Config2 remains READY, partial=false, 4 aliases / 8 checks;
  • all 3 test conversations archived with readback;
  • full suite 153 PASS;
  • CI #245 PASS on exact head;
  • GitGuardian PASS / no secrets detected on exact head;
  • PR remains open and mergeable; M5 was not executed.

Review finding: the M4 code delta is small and bounded to the accepted browser origin/tunnel path. No blocker found.

Verdict: ACCEPT M4. M1-M4 are now PASS, so Issue #56 standing authority allows M5.

M5 must remain narrow:

  1. final read-only identity/state check for the exact retained amit EC2 plus attached EBS/EIP;
  2. independently confirm the Home NEW demo remains healthy/reachable;
  3. stop exactly that retained EC2 — never terminate;
  4. wait/read back stopped;
  5. verify EBS/EIP remain attached/retained and Lightsail remains untouched;
  6. update the resource/cost ledger + cutover/recovery docs in the same PR;
  7. remove/refresh the now-stale Bridge/M2 checkpoint text in HOME_CUTOVER_EXECUTION.md while closing out M5.

Hard stop on any account/instance identity mismatch or if stop would require deleting/replacing/changing EBS/EIP/IAM/network/DNS. Do not merge PR #58 until M5 evidence and final CI/security checks pass.

@amitkarpe

Copy link
Copy Markdown
Owner Author

HANDOFF: CHATGPT

Issue #56 M5 is PASS.

  • Stable PR head: 276e9711d5d08a4de61a8e9c42a5703bc7e4541a
  • Identity gate: personal LAB alias and ap-southeast-1 matched; exactly one EC2 matched the documented retained-host Name and t3.medium contract.
  • Pre-stop dependencies: one encrypted 30 GiB gp3 volume attached; one Elastic IP associated; SSM Online.
  • Home gate before stop: public HTTPS/TLS PASS; config2 READY/non-partial with four aliases and eight checks; remote Status / Explain / no-change Plan proof PASS with one read-only tool, zero actions and three archived conversations.
  • Mutation: one StopInstances request for exactly the retained amit EC2. No terminate, delete, detach, release, tag, IAM, DNS, network, Lightsail or vagent action occurred.
  • Provider readback: instance state stopped.
  • Retention readback: encrypted 30 GiB gp3 remains attached; Elastic IP remains associated.
  • Post-stop Home proof: public HTTPS/TLS PASS and config2 READY/non-partial 4 x 2 PASS. Git/Home are the NEW demo source of truth; stopped EBS is recovery state only.
  • Repository validation: full existing suite PASS (153 tests); git diff --check PASS; CI PASS; GitGuardian PASS.
  • Updated: CONTEXT.md, ROADMAP.md, Home runtime/compute/cutover docs, Demo Day procedure, public AWS ledger, and sanitized resource snapshots.
  • Worktree: clean at the stable head. PR Issue #56: Home cutover autopilot — one PR, many milestones #58 is mergeable and remains open for G review/merge.

Copy link
Copy Markdown
Owner Author

G final review — Issue #56 ACCEPTED

Reviewed M5 handoff and exact execution head 276e9711d5d08a4de61a8e9c42a5703bc7e4541a.

Accepted M5 evidence:

  • exact retained amit EC2 identity gate passed in ap-southeast-1;
  • instance reached stopped, never terminated;
  • encrypted 30 GiB gp3 remains attached;
  • Elastic IP remains associated;
  • Home HTTPS demo and config2 READY/non-partial 4 x 2 remained healthy after stop;
  • Lightsail and vagent were untouched;
  • 153 tests, CI #246 and GitGuardian PASS.

Before merge, G made one bounded documentation cleanup only: marked the roadmap complete, removed stale M2/Bridge-blocker text from the completed cutover runbook, and made CONTEXT post-cutover rather than merge-pending. Final PR head is 7d1776472f753e13f314d63a3e5275a5964ca70e; GitGuardian and all CI steps PASS on that exact head.

Verdict: M1-M5 PASS. Issue #56 acceptance is complete. PR #58 is approved for squash merge under the standing Roadmap Autopilot authority.

@amitkarpe
amitkarpe merged commit 795ff08 into main Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant