Skip to content

Deploy the Hyrule Beacon worker - #464

Open
Svaag wants to merge 5 commits into
mainfrom
feat/hyrule-beacon
Open

Deploy the Hyrule Beacon worker#464
Svaag wants to merge 5 commits into
mainfrom
feat/hyrule-beacon

Conversation

@Svaag

@Svaag Svaag commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What changed

  • add a validate-first Ansible role for the Hyrule Beacon worker using an immutable image SHA
  • bind the service to the private overlay, run it non-root/read-only with dropped capabilities, and persist only checkpoint state
  • add least-privilege Vault AppRole bootstrap, monitoring, firewall rules, promotion automation, and an operator runbook
  • pin the worker to commit 3682620bcf5c14d9f3fb7b3a67b1ba9c568900ac

Why

The visibility worker needs the same controlled, observable deployment posture as Hyrule's other operational agents without Git, publishing, wallet, or broad Vault credentials.

Impact

Automatic actions and scheduling remain disabled initially. Deployment requires the worker commit to be remotely available and Beacon/Vault credentials to be provisioned.

Validation

  • 133 infrastructure tests passed
  • ansible-playbook playbooks/engineering-loop.yml --syntax-check
  • generated network-flow checks passed

@Svaag
Svaag marked this pull request as ready for review July 18, 2026 23:17
@Svaag
Svaag requested a review from a team as a code owner July 18, 2026 23:17

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 504cc4af5f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/runbooks/bootstrap-seo-agent-vault.md Outdated
Comment thread ansible/inventory/host_vars/loop.yml
@github-actions

Copy link
Copy Markdown
Contributor

Failed to generate code suggestions for PR

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c7a87e199

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ansible/playbooks/engineering-loop.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b4eae34144

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ansible/inventory/host_vars/loop.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 29702842d2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/apply.yml
Comment thread ansible/roles/seo_agent/tasks/main.yml Outdated
Comment thread ansible/roles/seo_agent/tasks/apply.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant