3.5 KiB
Final housekeeping quantum — existing proven procedure, GPT-5.5 lab role
User confirmed passwords should be stashed. Previous Terra session found provisioning ISO password and proved VM146 console autologon after reboot using LSA path. Read its checkpoint PLUS last section of /tmp/opencode/sots-housekeeping-followup.log (completion details after stale checkpoint). Preserve source of credential privately, never print secret or command args. No password reset.
Use role lab / model openai/gpt-5.5, actor housekeeping-completion for NEW leases. Previous worker acquired vm140/vm144/vm146 and spicy-autounattend-credential leases under housekeeping-worker / verifier / Terra; inspect lease JSON and completed processes before proceeding. You may ask lead to release those stale worker leases; do not impersonate its role/model. Lead is authorizing release after confirming previous worker process stopped, outstanding mount cleaned and SSH/access validated. Record which resources still held when ending. No delegates/commits or codebase architecture edits.
Astra corrections/decisions
- VM141 canonical address is 192.168.10.143. Previous 'No route' check incorrectly used .141. Do not diagnose guest outage until checking its verified .143 identity/MAC. Other addresses: VM140=.139, VM144=.144, VM145=.145, VM146=.146. Confirm actual identities from hypervisor.
- Protected-secret presence alone was insufficient (VM144 failed); use existing PROVEN provisioned password via secure stream, validate LogonUser, set LSA, then reboot free guest to prove login.
- VM146 succeeded. Its current consumer M365Copilot/OfficeHub process appeared after login and Remove-AppxPackage -AllUsers failed. Prefer targeted per-user removal or disabling its documented startup entry and stopping this identified consumer process; do not remove generic webview or system packages indiscriminately. Record any package removal blocked; don't hide it as compliant.
- Active console/passive VNC is not itself a test. Non-disruptive cleanup is allowed if actual test/tool activity absent. Reboot only known free guests. VM140 already had a logged-in console; keep its session unless user/test activity demonstrably absent and a reboot is necessary.
Finish
- Verify current vm146 SSH+console result, cleanup any temporary credential ISO mount, release stale leases through lead as noted. Persist last session's actual outcomes to checkpoint.
- VM144 and VM145: apply proven protected autologon with ISO credential, reboot if free, verify console re + keySSH + intended debloat policies/startups. VM141 use CORRECT .143 address and perform same. VM140 verify existing login/config, apply missing non-disruptive cleanup.
- Ensure all five have targeted consumer startups disabled, update auto-restart/task interference controls set, no currently identified consumer nag process; preserve SOTS/graphics/runtime/access.
- Update guides/windows-lab-housekeeping.md and per-VM verify/results/housekeeping/*.json with exact current result, including actual reboot proof vs config-only. Record model/role accurately.
- At quantum end update campaign/rollout/housekeeping-worker-state.md and release YOUR leases; explicitly report any blocked guest/subtask. Stop at 40 steps with exact next action if needed.
Owned files: same tools/windows-housekeeping/, guides/windows-lab-housekeeping.md, verify/results/housekeeping/, housekeeping-worker-state.md. Routine execution only; Astra handles any new plan-changing surprise. Existing script mutation bugs may be fixed in own scope.