2e138a199b
Two changes ship together here.
1. One shared herdr workspace. The lead and every worker now live in one
workspace called "fleet", so the operator sees one "session" with many
windows, not two. Before, the lead sat in a "leads" workspace and workers
in "bridged-workers", which read as two sessions. The lead is still told
apart from workers by its exact tab label ("lead: <name>"), so putting them
in one space is safe. LeadTabScanner keeps the exclude-by-label mechanism
for split layouts; Fleetd now passes an empty exclude set.
2. Rename the daemon from "bridged" to "fleetd" (the binary, config, scripts,
launchd/systemd units, module dir, and MCP mount).
- Module dir bridged/ -> fleetd/; jar finalName -> fleetd.jar.
- Log line, comments, docs, and CLAUDE.md updated to say fleetd.
- Scripts renamed: redeploy-bridged.sh -> redeploy-fleetd.sh,
bridged-launchd-wrapper.sh -> fleetd-launchd-wrapper.sh.
- Deploy units renamed: dev.ltms.bridged.plist -> dev.ltms.fleetd.plist,
bridged.service -> fleetd.service; launchd Label -> dev.ltms.fleetd.
- Config default bridged.yaml -> fleetd.yaml; the legacy bridged.yaml is
still read as a fallback, and still gitignored.
- MCP: drop the deprecated bridge_* tool twins; only fleet_* remain. The
server name is "fleet". The mount name in the local .mcp.json becomes
"fleet" (gitignored, not in this commit).
- Env var defaults BRIDGED_API_TOKEN -> FLEETD_API_TOKEN, fixture
BRIDGED_WORKER_TOKEN -> FLEETD_WORKER_TOKEN.
Kept on purpose: the BRIDGED_MEMBER marker. Renaming it is a coupled change to
the credential-scrub security control (an operator secrets.sh may guard on it),
so it stays until that migration is done on its own.
Metrics were already fleet_* (CB-632); MetricNamesTest still guards that no
name says bridged_.
The canonical CLAUDE.md block and the wiki template stay byte-identical
(wiki working tree edited, committed to the wiki repo separately).
949 tests pass (mvn clean install). 4 fewer than before = the 4 removed
bridge_* alias tests.
33 lines
1.8 KiB
Bash
Executable File
33 lines
1.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
#
|
|
# CB-594 — the only reason this file exists: launchd does not run a login shell.
|
|
#
|
|
# WORKER_GITEA_TOKEN and AI_GATEWAY_TOKEN live in ${SHARED_ENV}/tools/secrets.sh, sourced only by a
|
|
# LOGIN shell (.zprofile/.zshrc etc). launchd execs a job's ProgramArguments directly — no shell, no
|
|
# profile, nothing sourced (the plist's own PATH comment documents the same gap one variable over).
|
|
# A daemon started that way boots fine and looks healthy; the failure is invisible until a worker
|
|
# tries to open a PR (WORKER_GITEA_TOKEN empty) or a gateway profile gets a 401 (AI_GATEWAY_TOKEN
|
|
# empty) — hours later, with nothing tying the two together (CB-591, CLAUDE.md "Redeploying the
|
|
# daemon"). Fleetd now also logs which required secret names resolved at startup (see
|
|
# Fleetd.reportRequiredSecrets), but that log line can only tell the truth if the tokens had a
|
|
# chance to be sourced in the first place — which is this script's entire job.
|
|
#
|
|
# So: launchd execs THIS script instead of java directly. This script execs a login shell
|
|
# ('zsh -l'), which sources secrets.sh, and that shell execs the real command in its place — one
|
|
# process throughout (exec, not a subshell fork), so launchd's PID tracking, KeepAlive, and
|
|
# StandardOut/ErrorPath all still see the one process they expect.
|
|
#
|
|
# The plist passes the full command as THIS script's own arguments, e.g.:
|
|
# ProgramArguments = [ .../fleetd-launchd-wrapper.sh, /path/to/java, -jar, /path/to/fleetd.jar,
|
|
# fleetd.yaml ]
|
|
# so the wrapper stays generic and the actual command lives in exactly one place (the plist), not
|
|
# duplicated here.
|
|
set -euo pipefail
|
|
|
|
if [ "$#" -eq 0 ]; then
|
|
echo "fleetd-launchd-wrapper.sh: no command given — check the plist's ProgramArguments" >&2
|
|
exit 2
|
|
fi
|
|
|
|
exec /bin/zsh -lc 'exec "$@"' -- "$@"
|