Lane D deliverable: reproducible execution-plane deployment on a fresh Debian dedicated server (~12 cores, 40 GB RAM, single-node). Artifacts: - bootstrap.sh: Docker Engine, Bun, repo clone, build, systemd install, firewall (deny-by-default), optional Tailscale, disk monitor cron - .env.template: all 8 environment groups documented (Convex, Gitea, model gateway, AgentOS/RivetKit, Zopu agent, daemon, Docker sandbox, service auth) - systemd units: zopu-daemon, zopu-agent (both Restart=always), zopu-health timer (60s), zopu-docker-cleanup timer (daily) - scripts: health-check, update, rollback, docker-cleanup, disk-monitor - Caddyfile: optional reverse proxy (documentation-only by default) - README.md: full runbook with start/stop/log/update/rollback/cleanup procedures, topology documentation, and boundary notes Verified topology (from installed RivetKit source): - registry.start() boots an in-process RivetKit engine (envoy mode) with a native Rust sidecar at http://localhost:6420 (DEFAULT_ENDPOINT in chunk-YDUQHING.js line 4751). createClient() connects back to it. - No separate Rivet Engine process required for single-node operation. - Linux x64 sidecar packages (@rivet-dev/agentos-sidecar-linux-x64-gnu) are available as optional dependencies. Docker / Orb boundary: - Docker Engine installed and zopu user in docker group. - No Docker-backed sandbox code wired; Orb lane contract not yet landed. - Volume pruning omitted from docker-cleanup.sh to protect durable data. Validated: bash -n on all 6 shell scripts; mocked health-check smoke (nc-based TCP probes, mocked systemctl/docker); systemd unit structural checks. No JS/TS/agent files changed.
41 lines
938 B
Desktop File
41 lines
938 B
Desktop File
[Unit]
|
|
Description=Zopu Daemon (Bun/Effect + AgentOS/RivetKit)
|
|
After=network-online.target docker.service
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=__SERVICE_USER__
|
|
Group=__SERVICE_USER__
|
|
WorkingDirectory=__INSTALL_DIR__
|
|
|
|
EnvironmentFile=__INSTALL_DIR__/.env
|
|
|
|
# RivetKit in-process engine: envoy mode (serverful).
|
|
# registry.start() boots the native Rust sidecar and actor envoy.
|
|
# RIVET_ENDPOINT defaults to http://localhost:6420 inside the daemon process.
|
|
ExecStart=__INSTALL_DIR__/apps/daemon/dist/code-daemon
|
|
|
|
Restart=always
|
|
RestartSec=10
|
|
|
|
StandardOutput=journal
|
|
StandardError=journal
|
|
SyslogIdentifier=zopu-daemon
|
|
|
|
# Resource limits (12-core, 40 GB host)
|
|
MemoryMax=8G
|
|
CPUWeight=100
|
|
|
|
# Security hardening
|
|
NoNewPrivileges=true
|
|
ProtectSystem=full
|
|
ProtectHome=true
|
|
PrivateTmp=true
|
|
|
|
# Docker socket access (for future Orb sandboxes; group membership required)
|
|
SupplementaryGroups=docker
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|