feat(ansible): install sentrux so the structural gate runs on fleet hosts - #33
Merged
Merged
Conversation
…fied The fleet runs `sentrux gate .` every session, but Code-Factory installed no sentrux, so on a fresh host the gate silently did not run. scripts/install_tools.py installs sentrux as a core tool from the latest sentrux/sentrux GitHub release (the source sentrux's own install.sh uses), verified against the GitHub release-asset SHA-256 and linked into ~/.local/bin. The binary otherwise downloads its tree-sitter grammars itself, unverified, on first run (even for --version); the installer installs the same release's grammars-<platform>.tar.gz, also digest-verified, and links each grammar into ~/.sentrux/plugins/<lang>/grammars/ so that never happens. Both assets come from one /latest lookup per repository. The only release binary links GTK 3 even for its CLI, so libgtk-3-0t64 joins the base packages. verify.yml checks ~/.local/bin/sentrux.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
once all is done, sync setup to code factory
Context: that is the standing order that the fleet host's generic setup is reproduced by Code-Factory on every run, latest versions, never pinned, downloads verified by published checksums. The fleet's standing rule is that every session runs the Sentrux structural gate (
sentrux gate ., whose line readsQuality: <baseline> -> <current>; a drop of more than 250 points against the repository's own baseline blocks), and the captain's machine conventions put a sentrux baseline on every new repo. On the new fleet hostcommand -v sentruxis empty and Code-Factory installs no sentrux at all, so on 2026-10-01 a worker reported "sentrux exit n/a (no sentrux binary or config on this host/tree)" and the gate silently did not run.What Changed
scripts/install_tools.pynow installs the latest sentrux release, checked against the GitHub release-asset digest, and links the binary into~/.local/bin. It also installs that same release'sgrammars-<platform>.tar.gzand links the grammars into~/.sentrux/plugins/<language>/grammars/, so sentrux doesn't download them unverified on first run. Tools from the same repo now share one "latest release" lookup.sentruxis added tofactory_core_tools, the installer's default--tools, thetools.ymlcontract comment, theverify.ymlexpected-files list and the container smoke script.libgtk-3-0t64is added to the base packages, because the sentrux release binary links GTK 3 even for CLI use.docs/dependencies.mddocuments the sentrux install, the GTK package, and the updated GitHub API request bound (at most ten).tests/test_install_tools.pyis updated to match.Risk Assessment
✅ Low: The change is a small, well-bounded addition that follows the existing btop/uv install pattern with digest verification, and every source path I traced works. The only gap is a smoke check that never runs the installed sentrux.
Testing
I ran the installer against live GitHub into a disposable home. It installed the latest sentrux (0.5.7) and linked its verified grammars, and a repeat run changed nothing. The installed binary then saved a baseline in a throwaway repo, andsentrux gate .printedQuality: 3981 -> 3981, exit 0. A tampered checksum aborted with a mismatch, exit 1, and installed nothing.tests/test_install_tools.pypasses (57). The Ansible playbook wiring is untested, becauseansible-playbookis not on PATH andtests/container-smoke.shneeds a Docker daemon this user cannot reach (permission denied on/var/run/docker.sock). The disposable homes and temp venv were removed.--tools sentrux --resolveoutput: sentrux and sentrux-grammars both v0.5.7, with sha256 valuessentrux gate --save .thensentrux gate .gaveQuality: 3981 -> 3981, 'No degradation detected', exit 0ansible-playbookandansibleare not on PATH.dockeris installed but the daemon is unreachable (permission denied on /var/run/docker.sock), sotests/container-smoke.shcannot build or run the…Evidence: sentrux install and gate transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
tests/container-smoke.sh:231- The smoke script now resolves and installs sentrux, but never runs it.check_resolved_releasesloops overherdr gh no-mistakes treehouse, andcheck_core_toolsloops overnode bun uv, so neither runssentrux --version. The reported failure was a gate that silently did not run. A missing GTK library, a broken symlink, or a wrong release asset would pass the smoke and only show up when a worker runssentrux gate. Smallest remedy: addsentruxto thecheck_resolved_releasesloop, since it already compares the reported version with the resolved stamp.✅ **Test** - passed
✅ No issues found.
--tools sentrux --resolveoutput: sentrux and sentrux-grammars both v0.5.7, with sha256 valuessentrux gate --save .thensentrux gate .gaveQuality: 3981 -> 3981, 'No degradation detected', exit 0ansible-playbookandansibleare not on PATH.dockeris installed but the daemon is unreachable (permission denied on /var/run/docker.sock), sotests/container-smoke.shcannot build or run the…python3 scripts/install_tools.py --home <tmp> --tools sentrux --resolveagainst live GitHubpython3 scripts/install_tools.py --home <tmp> --tools sentrux, run twice, into a disposable homesentrux --version,sentrux gate --save .andsentrux gate .in a throwaway git repoinstall with a tampered sha256 passed through--resolvedpytest tests/test_install_tools.pyin a temporary venv✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.