The Google document version of this artifact is here.

Operations record

The VM software we’ve added, accounted for.

A current-state map of agent frameworks, runtimes, utilities, backups, automation, and unfinished setup — with the paths and limits needed to rebuild the machine without relying on memory.

Last checked 27 Sep 2026

Tool versions and the reported operational states were refreshed on 27 Sep. No tool-version drift, new tools, or removed tools were found since 26 Sep. The 1Password session supervisor and Tailscale are healthy; Syncthing is not running and remote-device pairing remains pending. The enabled machine-inventory-refresh job maintains this record daily. Significant installs, upgrades, failures, and architecture decisions remain in the separate Machine Changelog.

3agent frameworks installed
14added tools & runtimes tracked
3programmatic jobs active
4setup items still pending
01

Agent frameworks

Hermes

hermes-agent 0.19.0Installed

Installed 11 Sep 2026 in an isolated Python virtual environment.

Environment~/workspace/venvs/hermes
Binary~/workspace/venvs/hermes/bin/hermes
Notebook~/workspace/agents/hermes/ops-notebook.md
NextPending Configure a model provider and API key; OpenRouter is the likely next provider.

OpenClaw

2026.9.5 (ec9c1a1)InstalledUpdated since 18 Sep

Installed 11 Sep 2026 globally with bun.

Installbun add -g
Binary~/.bun/bin/openclaw
NextPending No credentials or configuration are installed yet.

Codex CLI

0.154.0Installed

Installed 13 Sep 2026 globally with bun.

Installbun add -g @openai/codex
Binary~/.bun/bin/codex
Verifiedcodex exec runs non-interactively without a TUI; codex exec resume --last continues the latest session.
NextPending Sign in through the headless device-code flow with codex login --device-auth. Current status: Not logged in.
02

Runtimes & install lessons

bun1.4.2JavaScript package runnerReady
Node.jsv24.20.0JavaScript runtimeReady
Python3.12.3Python runtimeReady
Install rule for this machine

Global npm installs fail as root because npm attempts a chown operation that the /home/hatch mount rejects with EPERM. pnpm also fails because the mount rejects its hardlinks. bun works reliably, so global JavaScript tools should use bun. The bun.sh installer is URL-blocked from the shell; fetch bun from GitHub releases instead.

Temporary storage constraint

/tmp is a 512 MB noexec filesystem. Keep downloads small, use ~/workspace for working files, and never run binaries from /tmp.

03

1Password

Credential operations, session continuity, and nightly vault hygiene.

1Password CLI

op 2.39.0Ready

CLI installed under the workspace tool directory.

Binary~/workspace/bin/op

Nightly vault tidy

Running

Auto-tidy and auto-merge automation, with dated run reports and non-secret state.

Root~/workspace/1password-tidy/
Workertidy.py — nightly tidy and merge
Sessionsession_supervisor.py — keeps the user-mode session in process memory
Healthkeepalive.sh — pings the session and records checks
Statestate.json, README.md, and tidy-reports/
Known limitation: SSO writes

The ssoLogin / UNKNOWN-field validation bug remains present in op 2.39.0. The CLI can neither edit nor delete SSO-affected items; the my.1password.com web app is the only confirmed write path for them.

04

Network

Tailscale

Connected

Joined 9 Sep 2026.

ModeConnected to the user’s tailnet as a client-only node; connection re-checked 27 Sep 2026.

Fleet SSH self-healing

built 14 Sep 2026Running

Durable SSH configuration and wrapper path for ten enrolled fleet hosts, routed through the required tunnel proxy.

Canonical~/workspace/fleet/ssh_config
Hostshp-z-book + WSL, dell-latitude + WSL, dell-xps + WSL, lg-gram + WSL, hp-elitebook, and pixel-8-rooted.
Identity/home/hatch/.ssh/id_ed25519
Known hosts/home/hatch/.ssh/known_hosts_fleet
TransportProxyCommand ~/workspace/bin/tailscale-ssh-proxy.py through the HTTP CONNECT tunnel proxy on port 3130.
Wrappers~/workspace/bin/fleet-ssh, fleet-scp, and fleet-ssh-ensure.
Rulefleet-ssh-ensure restores /root/.ssh/config from the canonical copy; the wrappers then connect with ssh -F or scp -F. Always use the wrappers for fleet hosts, never bare ssh or scp.
Why self-healing is required

After a VM restart, the shell runs as root and OpenSSH reads configuration from the passwd home at /root/.ssh/config, ignoring $HOME. Because /root is ephemeral and wiped on restart while /home/hatch persists, the ensure step rebuilds root’s active config from the durable canonical copy.

05

Synergy toolkit

Most tools were installed 11 Sep 2026 under ~/workspace/bin through the reproducible installer at ~/workspace/bootstrap-tools.sh. The inotify utilities were added separately on 18 Sep and are now active in the transcript-watching stack.

inotify-tools

4.23.9.0Installed

Persistent event-driven file-watching utilities, installed 18 Sep 2026 and now used by the transcript-watching stack.

Binaries~/workspace/bin/inotifywait and ~/workspace/bin/inotifywatch
Library~/workspace/lib/libinotifytools.so.0 → libinotifytools.so.0.4.1
RuntimeThe binaries require LD_LIBRARY_PATH=~/workspace/lib.
SourceExtracted with dpkg-deb -x from inotify-tools_4.23.9.0-2_amd64.deb and libinotifytools0_4.23.9.0-2_amd64.deb in Ubuntu 24.04 noble’s universe pool after apt fetching stalled. Nothing was installed under ephemeral /usr.
VerifiedSmoke-tested successfully: create and modify events both fire.
PurposeEvent-driven file automation, including the active Autostream transcript watcher documented under Programmatic scheduler.
rclonev1.75.1Off-machine backup; R2, B2, or NAS credentials not configuredPending
restic0.19.1 · go1.26.4 linux/amd64Backup snapshotsInstalled
yt-dlp2026.08.19Media retrievalInstalled
syncthingv2.1.5 “Hafnium Hornet” · go1.27.1 linux-amd64Build dated 2026-09-08. Daemon not running on 27 Sep: pgrep found no PIDs, and the syncthing-vm-watchdog schedule is disabled. Pairing remains pending: ~/workspace/syncthing/config.xml has only local device htch-runtime, no remote peers, and one shared folder.Stopped
fd10.5.0Fast file finderInstalled
bat0.26.1 · 979ba22Syntax-aware file viewerInstalled
pandoc3.11Document conversionInstalled
mise2026.9.5 · linux-x64Tool version manager; build dated 2026-09-10Installed
disk-watch.sh—Daily threshold check; enabled alongside Muse Machine’s 10-minute collector and silent unless disk usage reaches 80%Enabled
•

Image-provided tools

GitHub CLI2.100.0Image-providedProvided
ripgrep14.1.0Image-providedProvided
sqlite33.45.1Image-providedProvided
ffmpeg8.1.2Image-providedProvided
06

Backups

Revival Kit

Running

Platform-agnostic continuity backup. Rebuilds every Wednesday and Sunday at 09:20 ET and keeps the four newest kits.

Builder~/workspace/backup/build-revival-kit.sh
Latest~/workspace/your_files/moose-revival-kit-2026-09-16.tar.gz — produced by the Wed 16 Sep rebuild
Off-machinePending Destination awaits a choice of Cloudflare R2, Backblaze B2, or NAS.
07

Machine health

The collector and renderer behind the Muse Machine VM health cockpit.

monitor.py

Python 3.12.3Running

Installed and verified 15 Sep 2026. Uses only the Python standard library; no new packages were installed.

Path~/workspace/machine-monitor/monitor.py
CollectSamples CPU use, load average, RAM, filesystems, network rates, TCP egress latency to 1.1.1.1:443, DNS lookup latency, boot and uptime, top processes, and service health.
RenderBuilds the health cockpit at cockpit.html.
LogAppends entries to the cockpit’s health log.
RepositoryLocal Git repository at ~/workspace/machine-monitor/, pushed to the private GitHub repository muse-000-meta-hatch/muse-machine.
Cloud VM sensor limits

ICMP ping is blocked on this VM, so the monitor measures TCP connection latency to 1.1.1.1:443 and DNS lookup latency instead. No temperature sensor or thermal zone is exposed; the cockpit reports that absence rather than fabricating a value.

08

Programmatic scheduler

Two-tier scheduling architecture established 18 Sep 2026. The full SOP is the source of truth; Meta retains supervision and rollback while supercronic runs the high-frequency programmatic jobs.

supercronic

v0.2.33Running

Runs the workspace crontab with -inotify, so schedule changes reload live without restarting the process.

Binary~/workspace/bin/supercronic
Crontab~/workspace/scheduler/crontab
Runner~/workspace/bin/scheduler-run.sh
LogsPer-job logs under ~/workspace/scheduler/logs/; failures append to ~/workspace/scheduler/alerts.log.
SupervisorMeta cron programmatic-supervisor runs every 15 minutes through ~/workspace/bin/supervise-programmatic.sh to keep supercronic and the inotify watchers alive.
SOP~/workspace/scheduler/SOP.md — authoritative workflow, process, specification, and operating procedure.
Migration~/workspace/scheduler/MIGRATION.md — migration record and rollback context.
Every 10 min

Muse Machine sampling

Runs the existing muse-machine-collect job through the programmatic runner.

muse-machine-collect
Every 15 min

Completion enforcer

Runs the existing completion-enforcement job through the programmatic runner.

completion-enforcer-15m
Every 15 min

OpenClaw keepalive

Runs the OpenClaw keepalive watchdog through the programmatic runner.

openclaw-keepalive-watchdog

inotify file-watching stack

4.23.9.0Running

Persistent file watchers supervised alongside supercronic.

Binaries~/workspace/bin/inotifywait and ~/workspace/bin/inotifywatch
Libraries~/workspace/lib; requires LD_LIBRARY_PATH=~/workspace/lib.
Watchdog~/workspace/bin/inotify-watchdog.sh
Manifest~/hooks/state/inotify-watches.json
ProcessesPIDs 8845 and 8857 were running on 22 Sep, watching MUSE-DECISIONS.md and TEAM-DECISIONS.md.

stream-hook__second-thought

Running

Rebuilt as an echo-only file-watcher relay; Variant #01 remains the judge.

SourceTails /home/hatch/agents/*/sessions/*.jsonl, covering every session thread.
Idle pollsSilent when no new transcript content is available.
Role splitThe watcher only relays eligible messages; Variant #01 performs judgment.
09

Running processes & schedules

Core process and schedule states were refreshed 27 Sep 2026. No scheduler changes were found since 26 Sep: 1Password keepalive, session revive, nightly tidy, daily disk watch, both Revival Kit rebuilds, the programmatic supervisor, the OpenClaw gateway keepalive, and the daily inventory refresh remain enabled. The inotify watchdog remains disabled and dormant by design in ~/workspace/cron.d/_archive; when no watch manifest exists, it verifies the inotifywait binary only. Other unchanged scheduler entries retain their last recorded states below; programmatic schedules are listed above.

1Password session supervisor

Running

The standalone session_supervisor.py process was running as PID 6672 on 27 Sep after routine churn since 26 Sep. At 06:40:50 ET, the latest keepalive.log check reported OK user session alive and supervisor alive, pid 30928.

SessionHolds OP_SESSION_my in process memory only; the value is never written to disk.
ContinuityThe standalone supervisor holds the user-mode 1Password session in memory, with the re-enabled 1password-session-keepalive schedule providing regular health checks and the new 1password-session-revive schedule providing recovery.
TidyRuns user-mode tidy daily at 03:20 ET and writes tidy-reports/YYYY-MM-DD.md.
Every 20 min · verified 27 Sep

1Password session keepalive Enabled

The latest check at 06:40:50 ET recorded OK user session alive and supervisor alive, pid 30928.

1password-session-keepalive
Every 20 min · verified 27 Sep

1Password session revive Enabled

Companion recovery job for the user-mode 1Password session.

1password-session-revive
Daily · 03:20 ET · verified 27 Sep

1Password nightly tidy Enabled

Delivers the morning report to the “1Password vault cleanup” side chat.

1password-nightly-tidy
Daily · 08:20 ET · verified 27 Sep

Disk health check Enabled

Stays silent unless disk usage reaches 80%.

daily-disk-watch
Wednesday · 09:20 ET · verified 27 Sep

Revival Kit rebuild Enabled

Rebuilds the continuity archive and keeps the newest four kits.

revival-kit-rebuild-wed
Sunday · 09:20 ET · verified 27 Sep

Revival Kit rebuild Enabled

Rebuilds the continuity archive and keeps the newest four kits.

revival-kit-rebuild-sun
Every 15 min · verified 27 Sep

Programmatic supervisor Enabled

Reports supercronic and the manifest-driven inotify watchers healthy through ~/workspace/bin/supervise-programmatic.sh.

programmatic-supervisor
Every 5 min · verified 27 Sep

OpenClaw gateway keepalive Enabled

Maintains gateway availability through the Meta scheduler.

openclaw-gateway-keepalive
Daily · 07:00 ET · verified 27 Sep

Machine Inventory refresh Enabled

Maintains this inventory every day without changing the separate manual Machine Changelog.

machine-inventory-refresh
Disabled · verified 27 Sep

Syncthing VM watchdog Disabled

No watchdog is restarting Syncthing. The daemon had no running PIDs on 27 Sep, and remote-device pairing remains pending.

syncthing-vm-watchdog
Disabled · verified 27 Sep

inotify watcher recovery Dormant

Archived in ~/workspace/cron.d/_archive and disabled by design; when no watch manifest exists, it verifies the inotifywait binary only.

inotify-watchdog · owner goal:machine-health-monitoring
Disabled · rollback

Muse Machine sampling Migrated

The Meta schedule is retained but disabled. The active job now runs every 10 minutes through supercronic.

muse-machine-collect
Disabled · rollback

Completion enforcer Migrated

The Meta schedule is retained but disabled. The active job now runs every 15 minutes through supercronic.

completion-enforcer-15m
Disabled · rollback

OpenClaw keepalive Migrated

The Meta schedule is retained but disabled. The active watchdog now runs every 15 minutes through supercronic.

openclaw-keepalive-watchdog
10

Pending setup

Hermes & OpenClaw

Configure model-provider credentials.

Codex CLI

Sign in through the headless device-code flow.

Syncthing

Pair with the user’s devices.

Off-machine backup

Choose and configure Cloudflare R2, Backblaze B2, or NAS.

No matching inventory itemsTry a different word or status filter.
Path copied