forked from bai/curriculum-project-hub
feat: automate managed silo provisioning
This commit is contained in:
@@ -11,6 +11,11 @@ The repeatable entry point is:
|
||||
bash hub/deploy/new_silo.sh
|
||||
```
|
||||
|
||||
After collecting the Organization inputs, the wizard shows the assigned
|
||||
resources and asks once before applying them directly over SSH. The generated
|
||||
bundle is only a root-secret-safe retry and audit checkpoint; the operator does
|
||||
not execute it manually during the normal path.
|
||||
|
||||
It gathers values and writes a private deployment bundle below
|
||||
`~/.cph-silo-plans/<instance-id>/`. The directory and all generated files are
|
||||
mode `0700`/`0600`. Never commit, paste into chat, or copy that directory into
|
||||
@@ -19,20 +24,35 @@ from another Organization.
|
||||
|
||||
## Inputs to collect
|
||||
|
||||
The platform operator chooses the host, release, unique instance id, short
|
||||
workspace path, unique loopback port, database name/role, resource ceilings and
|
||||
public domain. The Organization administrator supplies:
|
||||
The wizard derives the instance/Organization id from the slug, uses the current
|
||||
release and managed Alpha defaults, connects to the managed host (currently
|
||||
`39.107.254.4`), derives
|
||||
`https://<organization-slug>.educraft.paradigm-edu.net` from the wildcard DNS,
|
||||
and allocates an unused loopback port plus short workspace path by inspecting
|
||||
existing Silo environments, listening sockets and workspace paths over
|
||||
read-only SSH. The Organization administrator supplies:
|
||||
|
||||
- Organization display name and slug;
|
||||
- Feishu App ID, App Secret and bot Open ID;
|
||||
- Feishu App ID and App Secret (the wizard resolves the bot Open ID);
|
||||
- the first OWNER's Open ID and display name;
|
||||
- an Organization-exclusive provider token and provider base URL.
|
||||
- an Organization-exclusive OpenRouter token.
|
||||
|
||||
Everything else is platform-managed or derived: instance/Organization id,
|
||||
server, SSH settings, release, resource ceilings, database coordinates and
|
||||
generated password, domain, port, workspace, provider/base URL, model/role,
|
||||
curated skills, concurrency, request/file limits and the managed Mihomo proxy
|
||||
environment.
|
||||
|
||||
The Feishu app is scoped to this Silo. OAuth users authenticated by that app are
|
||||
automatically admitted to this Organization; OWNER remains the initial
|
||||
privileged membership used for controlled administration and bootstrap. An
|
||||
empty initial team list does not block the Alpha.
|
||||
|
||||
To target a replacement platform-managed host, the platform operator may set
|
||||
`CPH_ALPHA_HOST`, `CPH_ALPHA_DEPLOY_USER`, `CPH_ALPHA_SSH_PORT` and
|
||||
`CPH_ALPHA_BASE_DOMAIN` before running the wizard. These are fleet controls,
|
||||
not Organization setup questions.
|
||||
|
||||
Obtain a person's Open ID from the Feishu user-get documentation page by
|
||||
clicking the `user_id` value picker and selecting the person. Configure the
|
||||
redirect URL shown by the generated `OPERATE.md`; it is required for first-time
|
||||
|
||||
Reference in New Issue
Block a user