agent-ops
OPS-103
· child of OPS-97 Scheduled security-scan ownership (rkhunter/clamav) + fleet-wide systemd/cron job registry with heartbeat monitoring on venus Backlog
Full inventory + sense-check sweep of all current venus systemd timers/cron.d
Done normal
nvnw-venus-cc
Initial sweep 2026-07-12 found 15 system-scope + 19 user-scope timers plus /etc/cron.d (e2scrub_all, php, sysstat) on venus -- many outside nw-venus-cc's documented ownership list (memory-sweep.timer, llmmsg-purge-ghosts.timer, dropbox-orphan-sweep.timer, journal-digest.timer, applog-pull@{mars,pluto,venus}.timer, evolutiva-dbperf@{venus,mars,pluto}.timer, llmmsg-kpi-report.timer, db-size-monitor.timer, system-update.timer, etc). For each: confirm current owner, confirm purpose still valid, flag orphans/duplicates/stale-doc-vs-live drift (rkhunter's dup timer is the pattern to hunt for elsewhere). Feed findings into OPS-103's registry as the seed data.
Questions
No questions.
Activity
-
parent=#1880
-
First-pass sense-check sweep 2026-07-12 (system+user timers + /etc/cron.d): CONFIRMED nw-venus-cc owned (fine as-is): scan-rkhunter-venus.timer (fixed today), rclone-health.timer, self-ssh-monitor.timer, llmmsg-reconcile.timer, sys-check.timer, venus-state-backup-daily/weekly.timer, mars-uxpain-relay.timer. FIXED today (were broken/duplicated): rkhunter-scan.timer (dup, removed), clamav-scan.timer (orphaned since script deletion 2026-07-06, removed pending OPS-99 decision). OS-default, no agent ownership needed (Debian stock, leave alone): phpsessionclean, e2scrub_all, xfs_scrub_all, man-db, systemd-tmpfiles-clean, dpkg-db-backup, logrotate, fstrim, apt-daily, apt-daily-upgrade timers; /etc/cron.d/{e2scrub_all,php,sysstat}. bin-venus-cc/host-infra lane (script authorship confirmed elsewhere, not re-verified here): cc-context-monitor.timer, system-update.timer. UNCONFIRMED OWNER -- need a ping, this is exactly the drift the registry should catch: db-size-monitor.timer, llmmsg-purge-ghosts.timer, applog-pull@{mars,pluto,venus}.timer, memory-sweep.timer, llmmsg-kpi-report.timer, dropbox-orphan-sweep.timer, evolutiva-dbperf@{venus,mars,pluto}.timer, journal-digest.timer. 9 timers, likely owned by pm-llmmsgsrv-cc/db-venus-cc/evolutiva-app lanes respectively but not verified against a canonical source -- this is the seed-data gap OPS-101's registry needs to close permanently instead of relying on tribal memory.
-
status=inProgress
-
Ownership resolved (verified live via systemctl cat description/exec, not guessed) 2026-07-12: nw-venus-cc: scan-rkhunter-venus.timer, rclone-health.timer, self-ssh-monitor.timer, llmmsg-reconcile.timer, sys-check.timer, venus-state-backup-daily/weekly.timer, mars-uxpain-relay.timer, memory-sweep.timer, journal-digest.timer, db-size-monitor.timer. bin-venus-cc: cc-context-monitor.timer, system-update.timer, dropbox-orphan-sweep.timer. pm-llmmsgsrv-cc: llmmsg-purge-ghosts.timer, llmmsg-kpi-report.timer (both under /opt/llmmsg-srv, hub maintenance boundary). evolutiva app-lane (db-venus-cc/coder-venus, not nw): evolutiva-dbperf@{venus,mars,pluto}.timer, applog-pull@{mars,pluto,venus}.timer. OS-default (sense=os-default, no agent owner): phpsessionclean, e2scrub_all, xfs_scrub_all, man-db, systemd-tmpfiles-clean, dpkg-db-backup, logrotate, fstrim, apt-daily, apt-daily-upgrade + cron.d/{e2scrub_all,php,sysstat}. REMOVED this session: clamav-scan.timer (orphaned), rkhunter-scan.timer (duplicate). All 34 originally-flagged timers now have a confirmed owner. Handed to bin-venus-cc as OPS-101's seed data.
-
status=inProgress
-
Sweep complete: 34 timers inventoried, all owners confirmed (verified live, not guessed) and handed to bin-venus-cc as OPS-101 seed data. First jobreg watch run validated the sweep by catching 2 real silent failures the manual pass had missed (OPS-104 db-size-monitor, OPS-105 mars-uxpain-relay) -- both now fixed. Ownership table also recorded as an event on this WI for reference.
task
5w ago by wi-cli-venus
5w ago
2026-07-12 02:53