Implement guarded Nova remediation worker and Forgejo proposals #130
Labels
No labels
area:authentication
area:flake-utilities
area:performance
area:tbd
host:chaos
host:electra
host:fleet
host:lyra
host:nova
host:vega
investigation
phase:cutover
phase:deploy
phase:mcp
phase:module
phase:packaging
phase:prep
phase:validation
priority:high
priority:medium
project:attic-postgres-lyra-rollout
project:auto-update-reliability
project:auto-update-remediation
project:declarative-purity-cleanup
project:external-review
project:fleet-boundary-cleanup
project:host-facts-refactor
project:lyra-nixos-deploy
project:lyra-service-stack-migration
project:nebula-mesh-network
project:nixos-build-deployment-pipeline
project:security-hardening
project:service-stack-migration
project:vega-sillytavern-cutover
project:wiki-rebuild
repo:numtide/flake-utils
repo:numtide/nix-auth
repo:numtide/nixos-passthru-cache
repo:numtide/nix-relay
service:auto-update
service:mem0
service:nix
service:sillytavern
service:slskd
service:synthseek
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
nimmo/nixos-config#130
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
When the producer rejects a genuine package regression, a local model on Nova should diagnose it, propose a narrow temporary pin where safe, validate the candidate, and create review material. The model must remain advisory; deterministic code owns credentials, validation and publication.
Scope
Implement the isolated OpenCode worker and controller around the model policy from #128 and incident bundle from #129.
Checklist
Completion criteria
An eligible fixture produces a validated issue-linked PR; unsafe and ineligible fixtures produce diagnosis-only issues; no model process holds Forgejo publication or deployment authority.
Depends on #128 and #129.
Recommended Codex model
Use
codex/gpt-5.6-solwithmaxreasoning.This is the highest-risk and most architecturally coupled phase: it combines untrusted-input handling, least privilege, bounded autonomous tool use, Nix validation, Forgejo side effects, cleanup, and fleet publication invariants. OpenAI recommends reserving max effort for the hardest quality-first workloads; that tradeoff is justified for the controller and security boundary. Use Terra only for mechanical test expansion after the design is fixed.
Model guidance: https://developers.openai.com/api/docs/guides/latest-model
nimmo referenced this issue2026-08-01 06:19:08 +01:00
PR #134 implementation and deterministic CI are green, but merge is blocked by the required automated-review service. Three bounded review attempts failed before publishing any review comment or code finding because Qwen returned empty/malformed JSON (latest: Extra data). Automatic retries have stopped. PR #134 remains open and unmerged pending repair of the separate forgejo-auto-pr-review path or explicit direction to bring that external repository into scope. No check is being bypassed, and dependent issue #131 has not started.
Passive rollout and no-op evidence
PR #134 merged as revision
32bb4093c9cca08bcf717146bb690289a9f409ca. The normal fleet timers deployed it without any forced or manual run:a90a87ato32bb409, verified deployed revision32bb4093c9cca08bcf717146bb690289a9f409caat 10:00:41, and completed at 10:00:47.a90a87ato32bb409, verified the same deployed revision at 10:06:48, and completed at 10:06:49.The subsequent normal even-hour window supplied the required no-op follow-up:
32bb4093c9cca08bcf717146bb690289a9f409ca, thenNothing changed in pull, system is current.Evidence was read from
nixos-auto-update.serviceand detached-switch journals on both hosts. No deployment or updater run was forced. With deterministic CI, independent automated review, clean merge, genuine deployment, and the required no-op follow-up all complete, #130 is complete.