Panama learns what a server is: from a root login to running containers

A machine's role is now the interview's first question and the one answer
Panama records. Servers get the same shell minus the screen: core packages,
nvm, Bun, Claude Code and Codex (desktops get Codex too), linger, rootless
ports from 80, firewalld, the nginx-bridge network, and a nightly image
updater that replaced watchtower for cause.

server/containers/ carries junior's 23 compose services -- secrets moved to
per-machine .env files that never enter this public repo, every transformed
compose proven to render byte-identical to what is live. 'panama server'
enables, disables and relinks them; nothing here restarts a running service.
'boot --server' walks a fresh VPS from its root login to a normal install.

Five new contracts pin the secrets rule, the catalog's shape, panama-server's
behavior, the role plumbing, and the dotfile classification.

Claude-Session: https://claude.ai/code/session_01NU5JGiN3JfzqrLQB6wmJ1E
This commit is contained in:
Gabriel Brown
2026-08-25 23:11:49 -04:00
parent 9b338608ef
commit f33da41cc6
93 changed files with 4735 additions and 247 deletions
+11 -4
View File
@@ -166,13 +166,20 @@ grep -q 'PANAMA_USER_CONTENT' "$interview" \
|| note 'the interview never asks about personal content'
# Order matters: link-user must land the tracked espanso identity before
# setup-identity would seed one from the interview answers.
# setup-identity would seed one from the interview answers. Checked in every
# role's literal stage list (the upgrade filter reassigns from a variable and
# is not a list).
python3 - "$installer" <<'PY' || note 'link-user does not run before setup-identity'
import re, sys
line = next(l for l in open(sys.argv[1], encoding="utf-8") if l.startswith("STAGES="))
stages = re.findall(r"[\w-]+", line)
if stages.index("link-user") > stages.index("setup-identity"):
lines = [l.strip() for l in open(sys.argv[1], encoding="utf-8")
if l.strip().startswith("STAGES=(") and "upgrade_stages" not in l]
if not lines:
raise SystemExit(1)
for line in lines:
stages = re.findall(r"[\w-]+", line)
if "link-user" in stages and "setup-identity" in stages:
if stages.index("link-user") > stages.index("setup-identity"):
raise SystemExit(1)
PY
if (( ${#findings[@]} > 0 )); then