From 11c3ff67b6286f2bf4c453bc5ad487ef458391d1 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Fri, 28 Aug 2026 09:06:54 +0700 Subject: [PATCH] fleets-status: fleet01 IS ssh-reachable; correct the 'denied' claim The skill said SSH to fleet01 is denied, so every report wrote 'not reachable' for that fleet's daemon facts. That is true only for the user dai.ha. The host alias fleet01 maps to user ltms and key auth works. Checked 2026-08-28 while measuring #185: ssh fleet01 connects, and ltms has passwordless sudo there. So fleet01's PID, uptime, jar and /healthz can be reported over SSH even though its REST port is unreachable. --- .claude/skills/fleets-status/SKILL.md | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/.claude/skills/fleets-status/SKILL.md b/.claude/skills/fleets-status/SKILL.md index 92a15a9..e8b278d 100644 --- a/.claude/skills/fleets-status/SKILL.md +++ b/.claude/skills/fleets-status/SKILL.md @@ -113,8 +113,19 @@ PY **What this tier cannot see:** it proves facts only about the Mac daemon at `127.0.0.1:8765`. It cannot show the fleet01 daemon, broker queue depth, or broker consumers. The fleet01 REST service -at `10.10.20.13:8765` is not reachable from the Mac, and SSH as `dai.ha@10.10.20.13` is denied. -Say this in the report rather than omitting fleet01. +at `10.10.20.13:8765` is not reachable from the Mac. Say this in the report rather than omitting +fleet01. + +**But fleet01 IS reachable over SSH — checked 2026-08-28.** An older version of this line said SSH +was denied. That is true only for the user `dai.ha`. The host alias `fleet01` maps to user `ltms`, +and `ssh fleet01` works with key auth: + +```bash +ssh -o BatchMode=yes -o ConnectTimeout=6 fleet01 'echo $(id -un)@$(hostname)' +``` + +So fleet01's daemon PID, uptime, jar and `/healthz` **can** be reported — over SSH, not over REST. +Do that rather than writing `not reachable`. `ltms` also has passwordless sudo there. ## 3. Tier 2 — the shared broker (run when management access exists)