Skip to content

docs: Mini remaining bootstrap runbook (#12) - #13

Open
chasehuh wants to merge 1 commit into
mainfrom
docs/mini-remaining-runbook
Open

chasehuh wants to merge 1 commit into
mainfrom
docs/mini-remaining-runbook

Conversation

@chasehuh

Copy link
Copy Markdown
Owner

Summary

  • Adds docs/MINI-REMAINING.md — ordered Mini-side checklist (Tailscale, Remote Login, laptop pubkey, install.sh, per-host logins, report-back strings).
  • Points MINI-WORKER-HOST.md at that page and cstack#12.

Test plan

Made with Cursor

Laptop Tailscale is already up; this is the leftover machine checklist so an agent on the Mini can finish join, SSH, install.sh, and auth without copying tokens.

Co-authored-by: Cursor <cursoragent@cursor.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-13T02:35:11.595747Z f8f951d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f8f951d8dc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MINI-REMAINING.md
```bash
mkdir -p ~/.cstack
if [ ! -d ~/.cstack/src/.git ]; then
git clone git@github.com:chasehuh/cstack.git ~/.cstack/src

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Authenticate GitHub before cloning over SSH

On the documented fresh-Mini path, the only key installed before this command is the laptop's public key in the Mini's authorized_keys; that permits inbound laptop-to-Mini SSH but gives the Mini no private key for outbound GitHub authentication. Consequently, this git@github.com clone can fail before the GitHub login/key setup in §5 is ever reached, blocking install.sh; move the Mini's GitHub SSH-key setup earlier or clone this public repository over HTTPS.

Useful? React with 👍 / 👎.

Comment thread docs/MINI-REMAINING.md
| Tool | Why | Command (typical) |
| --- | --- | --- |
| GitHub `gh` | issues, `gh pr`, CI | `gh auth login` (same `sumelabs` / `chasehuh` access as laptop) |
| SSH to GitHub | `cstack-clone`, `gt submit` | `gh auth setup-git` and/or Mini’s own `~/.ssh` key in GitHub |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Require an SSH key instead of the credential helper

If the operator follows gh auth setup-git as the advertised alternative, the later SSH acceptance check and cstack-clone still fail because gh auth setup-git --help states that it configures GitHub CLI as a Git credential helper, which applies to HTTP(S) credentials and does not create or register an SSH key. Since both git ls-remote git@github.com:sumelabs/sume-com.git and the default CSTACK_GIT_URL use SSH, require generation and registration of a Mini-owned SSH key rather than saying these options are interchangeable.

Useful? React with 👍 / 👎.

Comment thread docs/MINI-REMAINING.md
| SSH to GitHub | `cstack-clone`, `gt submit` | `gh auth setup-git` and/or Mini’s own `~/.ssh` key in GitHub |
| Graphite `gt` | sume-com PRs | `gt auth` / `gt config` |
| Claude Code / tokenmaxxing | Opus / Fable | tokenmaxxing init **on Mini** |
| Codex | Astra | Codex login **on Mini** |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Initialize the Codex supervisor rather than bare Codex

On a Mini with a directly installed Codex CLI, the suggested bare “Codex login” and subsequent command -v codex check can pass without creating the required tokenmaxxing Codex pool, causing workers to use the wrong credential/account path. The setup should run tokenmaxxing init --codex (or add --codex) and verify that codex resolves to ~/.config/tokenmaxxing/bin/codex, as required by this desk's Codex transport.

AGENTS.md reference: AGENTS.md:L52-L52

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant