Full-depth rename per the approved plan; the 'claw' product vocabulary (claws, /claws routes, clawId, Claw Chat) stays — it is now the brand. - Display brand: Clawmates (manifest, titles, hero, login/rail logo 'clawmates'); default host app.clawmates.work; registry ghcr.io/clawmates - Crates tc-* -> cm-* (16 crates + all imports); binaries clawmates-server/broker/bundler; images clawmates/*; env prefix CLAWMATES_* (+ CM_TEST_DATABASE_URL / CM_LIVE_LLM); config clawmates.toml; helm chart deploy/helm/clawmates with clawmates-* resources; db names clawmates*; sockets /run/clawmates; cookie cm_session; kind cluster clawmates-test; seccomp node profile clawmates-agent-profile.json - All 9 Playwright brand assertions updated in lockstep; historical spec document left untouched as the only remaining 'TeamClaw' - Local env migrated: dev pg clawmates-dev-pg/clawmates_dev, shared test server clawmates-test-pg, kind cluster recreated with image + profile, compose images rebuilt under clawmates/* Verified end to end: 161 Rust + 68 frontend tests, 29 Playwright journeys, 4 live kind tests, helm/install/LOC/placeholder gates, and the clean-room install rehearsal serving the clawmates login page from a signed bundle of the rebuilt images. Co-Authored-By: Claude Fable 5 <[email protected]>
52 lines
1.7 KiB
Bash
Executable File
52 lines
1.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Clawmates air-gapped installer. Verifies the signed bundle FULLY OFFLINE
|
|
# (ed25519 signature over sha256 checksums) before anything is loaded;
|
|
# a failed verification aborts with nothing touched.
|
|
#
|
|
# Usage:
|
|
# ./install.sh <bundle-dir> <release.pub> [--verify-only]
|
|
#
|
|
# The bundle layout (produced by clawmates-bundler assemble):
|
|
# bin/clawmates-bundler verifier binary
|
|
# images/*.tar docker image tarballs
|
|
# compose/ docker-compose.yml + clawmates.toml + .env.example
|
|
# checksums.txt + checksums.sig + manifest.json
|
|
set -euo pipefail
|
|
|
|
BUNDLE="${1:?usage: install.sh <bundle-dir> <release.pub> [--verify-only]}"
|
|
PUBKEY="${2:?usage: install.sh <bundle-dir> <release.pub> [--verify-only]}"
|
|
MODE="${3:-install}"
|
|
|
|
BUNDLER="$BUNDLE/bin/clawmates-bundler"
|
|
if [ ! -x "$BUNDLER" ]; then
|
|
echo "install.sh: verifier missing at $BUNDLER" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Verifying bundle signature and checksums (offline)…"
|
|
"$BUNDLER" verify "$BUNDLE" "$PUBKEY"
|
|
|
|
if [ "$MODE" = "--verify-only" ]; then
|
|
echo "Verification complete; skipping install (--verify-only)."
|
|
exit 0
|
|
fi
|
|
|
|
echo "Loading container images…"
|
|
for tarball in "$BUNDLE"/images/*.tar; do
|
|
docker load --input "$tarball"
|
|
done
|
|
|
|
echo "Installing compose deployment…"
|
|
TARGET="${CLAWMATES_HOME:-/opt/clawmates}"
|
|
mkdir -p "$TARGET"
|
|
cp -R "$BUNDLE/compose/." "$TARGET/"
|
|
if [ ! -f "$TARGET/.env" ]; then
|
|
cp "$TARGET/.env.example" "$TARGET/.env"
|
|
echo "Edit $TARGET/.env (set POSTGRES_PASSWORD), then run:"
|
|
echo " docker compose --project-directory $TARGET up -d"
|
|
exit 0
|
|
fi
|
|
|
|
docker compose --project-directory "$TARGET" up -d
|
|
echo "Clawmates is starting; the server self-migrates on boot."
|