Paths: File paths (shared/, ../ln-030-vps-bootstrap/references/) are relative to skills repo root. If not found at CWD, locate this SKILL.md directory and go up one level for repo root.
ln-034-vps-environment-diagnostics
Type: L3 Worker
Category: 0XX Shared / Infrastructure
Inspects one VPS project environment and reports health, drift, logs, auth state, ports, systemd, tmux, and bounded safe repairs.
MANDATORY READ
MANDATORY READ: Load shared/references/worker_runtime_contract.md, shared/references/coordinator_summary_contract.md, and shared/references/vps_runtime_contract.md
MANDATORY READ: Load ../ln-030-vps-bootstrap/references/scope_layers.md, ../ln-030-vps-bootstrap/references/troubleshooting.md, and ../ln-030-vps-bootstrap/references/verification_recipes.md
Input / Output
| Direction |
Content |
| Input |
mode, project/VPS variables, optional repair_scope, optional dry_run, optional runId, optional summaryArtifactPath |
| Output |
vps-environment-diagnostics summary with status, findings, drift, safe repairs, warnings, blockers, and verification |
If summaryArtifactPath is provided, write the same summary JSON there. If not provided, return the summary inline and write it to the standalone run-scoped path. Generate a standalone run_id when runId is absent.
Modes
| Mode |
Behavior |
inspect |
Read-only health and drift report |
verify |
Read-only post-install/post-redeploy verification |
repair_safe |
Apply only documented bounded safe repairs selected by repair_scope |
Workflow
Phase 1: Scope And Safety
Resolve target environment and set mutation guard:
inspect and verify are read-only
repair_safe requires explicit repair_scope
dry_run=true converts repairs to planned actions
Phase 2: Host And Shared Runtime
Inspect:
- required binaries
${BOT_USER}
- Node/Claude/Codex versions
- auth health indicators without printing tokens
${AGENT_SKILLS_DIR} git state
- marketplace/plugin health
agent-update.timer and log tail
Phase 3: Project Runtime
Inspect:
${PROJECT_DIR} git state
/etc/${PROJECT_NAME} and /var/lib/${PROJECT_NAME}
${SERVICE_PREFIX}-god@*.service
- tmux socket and targets
- dispatch timer/service
- provider credential wiring without secret output
Phase 4: Relay Runtime
When Telegram/relay is enabled, inspect:
${SERVICE_PREFIX}-hex-relay.service
/opt/${SERVICE_PREFIX}-hex-relay
- HTTP
/health
- relay DB presence/schema
- old
relay-bot service/path drift
RELAY_HOOK_PORT listener collisions
Phase 5: Safe Repair
Allowed safe repairs only:
- restart a named inactive project service after confirming unit file exists
- re-enable an expected timer
- recreate missing non-secret directories with documented owner/mode
- rerun
systemctl daemon-reload
- report, but do not rewrite, missing auth or secrets
Forbidden repairs:
- secret creation or token edits
- deleting DB files
- deleting project repos
- changing Git remotes/branches
- changing shared auth
- broad package upgrades
Phase 6: Summary
Write a vps-environment-diagnostics summary artifact with:
- health verdict
- drift list
- repair actions applied or planned
- blockers
- warnings
- verification evidence
Critical Rules
- This worker diagnoses one environment at a time.
- Fleet target selection belongs outside this worker.
- Read-only modes must not mutate remote or local state.
- Repair actions are bounded and explicit.
- Never print secrets or auth tokens.
Definition of Done
Version: 1.0.0
Last Updated: 2026-05-05
1---2name: ln-034-vps-environment-diagnostics3description: Use when inspecting health, drift, logs, auth, ports, systemd, tmux, or safe repair needs for one VPS project environment.4license: MIT5---6
7<!-- markdownlint-disable MD012 MD022 MD032 MD040 MD041 MD060 -->
8
9> **Paths:** File paths (`shared/`, `../ln-030-vps-bootstrap/references/`) are relative to skills repo root. If not found at CWD, locate this `SKILL.md` directory and go up one level for repo root.
10
11# ln-034-vps-environment-diagnostics
12
13**Type:** L3 Worker
14**Category:** 0XX Shared / Infrastructure
15
16Inspects one VPS project environment and reports health, drift, logs, auth state, ports, systemd, tmux, and bounded safe repairs.
17
18## MANDATORY READ
19
20**MANDATORY READ:** Load `shared/references/worker_runtime_contract.md`, `shared/references/coordinator_summary_contract.md`, and `shared/references/vps_runtime_contract.md`
21**MANDATORY READ:** Load `../ln-030-vps-bootstrap/references/scope_layers.md`, `../ln-030-vps-bootstrap/references/troubleshooting.md`, and `../ln-030-vps-bootstrap/references/verification_recipes.md`
22
23---
24
25## Input / Output
26
27| Direction | Content |
28|---|---|
29| Input | `mode`, project/VPS variables, optional `repair_scope`, optional `dry_run`, optional `runId`, optional `summaryArtifactPath` |
30| Output | `vps-environment-diagnostics` summary with status, findings, drift, safe repairs, warnings, blockers, and verification |
31
32If `summaryArtifactPath` is provided, write the same summary JSON there. If not provided, return the summary inline and write it to the standalone run-scoped path. Generate a standalone `run_id` when `runId` is absent.
33
34## Modes
35
36| Mode | Behavior |
37|---|---|
38| `inspect` | Read-only health and drift report |
39| `verify` | Read-only post-install/post-redeploy verification |
40| `repair_safe` | Apply only documented bounded safe repairs selected by `repair_scope` |
41
42## Workflow
43
44### Phase 1: Scope And Safety
45
46Resolve target environment and set mutation guard:
47- `inspect` and `verify` are read-only
48- `repair_safe` requires explicit `repair_scope`
49- `dry_run=true` converts repairs to planned actions
50
51### Phase 2: Host And Shared Runtime
52
53Inspect:
54- required binaries
55- `${BOT_USER}`
56- Node/Claude/Codex versions
57- auth health indicators without printing tokens
58- `${AGENT_SKILLS_DIR}` git state
59- marketplace/plugin health
60- `agent-update.timer` and log tail
61
62### Phase 3: Project Runtime
63
64Inspect:
65- `${PROJECT_DIR}` git state
66- `/etc/${PROJECT_NAME}` and `/var/lib/${PROJECT_NAME}`
67- `${SERVICE_PREFIX}-god@*.service`
68- tmux socket and targets
69- dispatch timer/service
70- provider credential wiring without secret output
71
72### Phase 4: Relay Runtime
73
74When Telegram/relay is enabled, inspect:
75- `${SERVICE_PREFIX}-hex-relay.service`
76- `/opt/${SERVICE_PREFIX}-hex-relay`
77- HTTP `/health`
78- relay DB presence/schema
79- old `relay-bot` service/path drift
80- `RELAY_HOOK_PORT` listener collisions
81
82### Phase 5: Safe Repair
83
84Allowed safe repairs only:
85- restart a named inactive project service after confirming unit file exists
86- re-enable an expected timer
87- recreate missing non-secret directories with documented owner/mode
88- rerun `systemctl daemon-reload`
89- report, but do not rewrite, missing auth or secrets
90
91Forbidden repairs:
92- secret creation or token edits
93- deleting DB files
94- deleting project repos
95- changing Git remotes/branches
96- changing shared auth
97- broad package upgrades
98
99### Phase 6: Summary
100
101Write a `vps-environment-diagnostics` summary artifact with:
102- health verdict
103- drift list
104- repair actions applied or planned
105- blockers
106- warnings
107- verification evidence
108
109## Critical Rules
110
111- This worker diagnoses one environment at a time.
112- Fleet target selection belongs outside this worker.
113- Read-only modes must not mutate remote or local state.
114- Repair actions are bounded and explicit.
115- Never print secrets or auth tokens.
116
117## Definition of Done
118
119- [ ] Target environment and mutation guard resolved.
120- [ ] Host/shared runtime health inspected.
121- [ ] Project runtime health inspected.
122- [ ] Relay runtime health inspected or gated `N/A:`.
123- [ ] Drift and blockers reported with concrete evidence.
124- [ ] Safe repair actions were explicit, bounded, and recorded.
125- [ ] Forbidden repair categories were not performed.
126- [ ] `dry_run=true`, `inspect`, and `verify` performed no mutation.
127- [ ] Structured `vps-environment-diagnostics` summary artifact written.
128
129---
130
131**Version:** 1.0.0
132**Last Updated:** 2026-05-05