A machine's role is now the interview's first question and the one answer Panama records. Servers get the same shell minus the screen: core packages, nvm, Bun, Claude Code and Codex (desktops get Codex too), linger, rootless ports from 80, firewalld, the nginx-bridge network, and a nightly image updater that replaced watchtower for cause. server/containers/ carries junior's 23 compose services -- secrets moved to per-machine .env files that never enter this public repo, every transformed compose proven to render byte-identical to what is live. 'panama server' enables, disables and relinks them; nothing here restarts a running service. 'boot --server' walks a fresh VPS from its root login to a normal install. Five new contracts pin the secrets rule, the catalog's shape, panama-server's behavior, the role plumbing, and the dotfile classification. Claude-Session: https://claude.ai/code/session_01NU5JGiN3JfzqrLQB6wmJ1E
14 lines
669 B
Plaintext
14 lines
669 B
Plaintext
# Only on role=server, on top of core-packages. Deliberately short: a server
|
|
# is the shell environment plus containers, and almost everything it needs is
|
|
# already core.
|
|
#
|
|
# setup-server opens 80/443/81 through it. Fedora Server ships it; a minimal
|
|
# cloud image may not, and a server whose firewall step silently no-ops is a
|
|
# server somebody believes is firewalled.
|
|
firewalld
|
|
# Node comes through nvm here for the same reason as on the desktop --
|
|
# config/bash/shell switches versions per project from .nvmrc -- and because
|
|
# install-packages puts Codex on with npm, agents' MCP servers want a node,
|
|
# and a system nodejs earlier on PATH would win every switch.
|
|
nvm
|