Bootstrap OpenClaw agent control plane
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
71
AGENT_BOARD.md
Normal file
71
AGENT_BOARD.md
Normal file
@@ -0,0 +1,71 @@
|
||||
# OpenClaw Agent Control Board
|
||||
|
||||
> Source of truth for multi-agent work across the Windows PC workspace and the VPS `/opt/service` workspace.
|
||||
|
||||
## Mission
|
||||
|
||||
Bring the Windows 11 always-on PC, Tencent Cloud VPS OpenClaw Gateway, phone Control UI, optional Tailscale path, and later channels such as QQ into a controlled multi-device OpenClaw workflow.
|
||||
|
||||
## Current Decision
|
||||
|
||||
- Shared mechanism: use the VPS Gitea repository as the durable sync point.
|
||||
- Repository mode: standalone Gitea repository `openclaw-control-plane`.
|
||||
- Repository URL: `https://git.smartmotor.cloud/wangzhendong/openclaw-control-plane.git`.
|
||||
- Authentication mode: HTTPS access from both the Windows PC and VPS.
|
||||
- Default branch: `main`.
|
||||
- PC control-plane path: `D:\openclaw-control-plane`.
|
||||
- VPS control-plane path: `/opt/openclaw-control-plane`.
|
||||
- Secrets policy: no password, token, API key, or `OPENCLAW_GATEWAY_TOKEN` may be written into repo files, handoffs, evidence, or chat.
|
||||
- Frozen website policy: strict freeze during ICP/public-security filing review. Agents must not change the `smartmotor.cloud` homepage, content reachable from homepage links, static assets, Nginx routing, bind mounts, container images, or `/opt/services/docker-composite.yml` entries that could alter public website output.
|
||||
|
||||
## Agent Roles
|
||||
|
||||
| Role | Scope | May Write |
|
||||
|---|---|---|
|
||||
| ORCHESTRATOR | Requirements alignment, task split, dependency tracking, final acceptance | `AGENT_BOARD.md`, `handoff/ORCHESTRATOR.md` |
|
||||
| PC_EXECUTOR | Windows PC, Tailscale, OpenClaw CLI/node, local service install | `handoff/PC_EXECUTOR.md`, `evidence/pc-*`, `rollback/pc-*` |
|
||||
| VPS_EXECUTOR | VPS `/opt/service`, Gateway, Docker stack, Nginx, Gitea, approvals | `handoff/VPS_EXECUTOR.md`, `evidence/vps-*`, `rollback/vps-*` |
|
||||
| PC_VERIFIER | Independent read-only validation of PC executor results | `handoff/PC_VERIFIER.md`, `evidence/verify-pc-*` |
|
||||
| VPS_VERIFIER | Independent read-only validation of VPS executor results | `handoff/VPS_VERIFIER.md`, `evidence/verify-vps-*` |
|
||||
| CORRECTION | Detect drift, conflicts, unsafe changes, missing evidence, and rollback needs | `handoff/CORRECTION.md` |
|
||||
|
||||
## Quality Gates
|
||||
|
||||
| Gate | Required Evidence | Owner | Status |
|
||||
|---|---|---|---|
|
||||
| G0 Requirements aligned | User-approved mission, roles, and acceptance criteria | ORCHESTRATOR | Pending |
|
||||
| G1 Baseline discovered | PC and VPS read-only status snapshots | PC_EXECUTOR, VPS_EXECUTOR, verifiers | Pending |
|
||||
| G2 Gateway/node pairing ready | PC `node run` evidence and VPS approval evidence | PC_EXECUTOR, VPS_EXECUTOR | Pending |
|
||||
| G3 Execution smoke test | Harmless command result proves execution came from the PC node | PC_VERIFIER | Pending |
|
||||
| G4 Persistent service verified | `node install/start/status` and reboot survival evidence | PC_VERIFIER, CORRECTION | Pending |
|
||||
| G5 Security posture reviewed | Secrets absent, public exposure avoided, least-privilege notes captured | VPS_VERIFIER, CORRECTION | Pending |
|
||||
|
||||
## Active Tasks
|
||||
|
||||
| ID | Task | Owner | Depends On | Status |
|
||||
|---|---|---|---|---|
|
||||
| T0 | Create local control-plane scaffold | ORCHESTRATOR | None | Done |
|
||||
| T1 | Create standalone Gitea repo for this control plane | User + ORCHESTRATOR | T0 | Done |
|
||||
| T2 | Sync this scaffold to Gitea and clone/pull on VPS | ORCHESTRATOR + VPS_EXECUTOR | T1 | In Progress |
|
||||
| T3 | Run read-only PC baseline discovery | PC_EXECUTOR | T2 | Pending |
|
||||
| T4 | Run read-only VPS baseline discovery | VPS_EXECUTOR | T2 | Pending |
|
||||
| T5 | Verify both baselines before any config change | PC_VERIFIER + VPS_VERIFIER | T3, T4 | Pending |
|
||||
|
||||
## Acceptance Criteria Draft
|
||||
|
||||
- The PC can act as an OpenClaw execution node connected to the existing Gateway.
|
||||
- The Gateway continues to coexist with Nginx, Gitea, Confluence, and Postgres on the VPS.
|
||||
- The existing `smartmotor.cloud` website content remains unchanged during filing review, including homepage content and linked content reachable from the homepage.
|
||||
- No PC service port is exposed directly to the public internet.
|
||||
- Tailscale is optional for the OpenClaw public Gateway path, but available for safer device-to-device operations.
|
||||
- Phone can be used as a control client after the execution path is stable.
|
||||
- Later QQ or other channels are added only after the Gateway/node path is verified.
|
||||
|
||||
## Operating Rules
|
||||
|
||||
- Agents must read this file before doing work.
|
||||
- Executors must not accept work outside their named scope.
|
||||
- Executors must not validate their own work as complete.
|
||||
- VPS-related agents must treat the `smartmotor.cloud` website defined by `/opt/services/docker-composite.yml` as frozen: no edits to homepage content, linked page content, routing, static assets, bind mounts, container images, or Nginx rules that could alter what public visitors see.
|
||||
- Any system-level change requires a rollback note before execution.
|
||||
- Any blocking issue must be recorded in the relevant handoff file and surfaced to ORCHESTRATOR.
|
||||
Reference in New Issue
Block a user