# VPS_EXECUTOR Handoff ## Role Operate only on the VPS side: `/opt/services`, OpenClaw Gateway, Docker stack, Nginx, Gitea, Confluence, Postgres, and Gateway-side approval workflows. ## Allowed Work - Read VPS service state. - Run harmless diagnostic commands. - Capture evidence under `evidence/vps-*`. - Prepare rollback notes under `rollback/vps-*` before service or config changes. ## Not Allowed - Do not request or store plaintext VPS passwords. - Do not rotate or print secrets unless explicitly authorized by the user. - Do not change the `smartmotor.cloud` website during filing review: homepage content, linked content reachable from the homepage, static assets, routes, bind mounts, container images, Nginx rules, `/opt/services/docker-compose.openclaw.yml`, or any equivalent compose/service entries that affect public website output are frozen. - Do not restart production-facing services without an approved rollback note. - Do not mark VPS work as accepted without verifier review. ## Current State - VPS public IP: `114.132.222.127`. - OpenClaw Gateway is already deployed and coexists with the existing Docker stack. - The VPS service workspace path is `/opt/services`. - The VPS control-plane path is `/home/ubuntu/openclaw-control-plane`. - Gitea control-plane repository: `https://git.smartmotor.cloud/wangzhendong/openclaw-control-plane.git`. ## Next Read-Only Task After the Gitea control plane is synchronized, collect current VPS baseline evidence: - Git/Gitea repository availability for the control plane. - OpenClaw Gateway process or container status. - Nginx route for `openclaw.smartmotor.cloud`. - Whether `openclaw devices approve`, `openclaw nodes pending`, and `openclaw nodes approve` are available. ## Last Update 2026-05-19 G2 authorized for corresponding VPS pairing approval only after PC evidence exists. - Read `docs/G2_RUNBOOK.md` before acting. - T10 remains draft until T9 provides a matching non-secret pairing request ID or pending node ID. - Before approval action, write `rollback/vps-g2-approve-YYYYMMDD.md`. - Approve only the intended PC request/node that matches T9 evidence and display name. - Do not run approval commands if multiple pending requests are indistinguishable. - Do not request, print, record, rotate, or store any token/password/secret. - Do not restart/reload services, change Gateway config, edit Nginx, edit Docker/compose/bind mounts/images, change service state, or alter frozen `smartmotor.cloud` website output. - Evidence should go to `evidence/vps-g2-approve-YYYYMMDD.md` and must include no secrets.