diff --git a/11-Features.md b/11-Features.md index 0eaa4bf..899ad9a 100644 --- a/11-Features.md +++ b/11-Features.md @@ -67,7 +67,7 @@ six weeks, and the table alone will not carry it. | [Tell a usage-limit refusal from a real reply](#tell-a-usage-limit-refusal-from-a-real-reply) | profile `exhaustedPattern:` | CB-578 | `inject/CompletionResolver` | | [Stop spawning onto an exhausted account](#stop-spawning-onto-an-exhausted-account) | `quarantineCooldownSeconds:` + profile `credentialId:` | CB-578 | `placement/BackendQuarantine` | | [See which charter a member got](#see-which-charter-a-member-got) | automatic | CB-571 | `peer/CharterReceipt` | -| [Redeploy the daemon safely](#redeploy-the-daemon-safely) | run the script | — | `scripts/redeploy-fleetd.sh` | +| [Redeploy the daemon safely](#redeploy-the-daemon-safely) | `redeploy-fleetd` skill, then run the script | — | `scripts/redeploy-fleetd.sh` | | [Run members on a second herdr daemon](#memberherdrsocket--run-members-on-a-second-herdr-daemon) | `memberHerdrSocket:` | CB-185 | `herdr/HerdrRouter` | | [Let a member under another OS user write its worktree](#worktreegroup--let-a-member-under-another-os-user-write-its-worktree) | `worktreeGroup:` | CB-185 | `session/GitWorktrees` | | [Resume an opencode member's prior session](#opencode-session-ids-come-from-opencodedb) | automatic | CB-206 | `member/OpenCodeSessionDiscovery` | @@ -1361,6 +1361,14 @@ the restart. `--check` reports state and changes nothing; `--yes` skips the drai **On.** Run it. Nothing is automatic — the daemon never restarts itself. +An agent gets there through the **`redeploy-fleetd` skill** (`.claude/skills/redeploy-fleetd/`). It is +a primary-side skill, and it holds the flags, the drain step, the operator's allow-list entry, and five +numbered checks — login shell, drain members, deferred config keys, re-check `fleet_whoami`, prove the +new jar runs — each of which has gone wrong here before. Workers must never load it: stopping the +daemon kills the worker's own channel mid-turn. `CLAUDE.md` used to carry all 58 lines, and paid for +them in every session's context. It now keeps only the two rules that must stay resident — a merge is +not a deployment, and workers never redeploy — plus the line that names the skill. + **Why.** A merge is not a deployment: the running daemon holds the jar it was started with, so merged code does nothing until this runs. That gap has silently shipped inert features more than once — the whole `health:` stack sat merged and doing nothing for two tickets. The script also exists so the