# VPS_EXECUTOR Handoff ## Role Operate only on the VPS side: `/opt/services`, OpenClaw Gateway, Docker stack, Nginx, Gitea, Confluence, Postgres, and Gateway-side approval workflows. ## Allowed Work - Read VPS service state. - Run harmless diagnostic commands. - Capture evidence under `evidence/vps-*`. - Prepare rollback notes under `rollback/vps-*` before service or config changes. ## Not Allowed - Do not request or store plaintext VPS passwords. - Do not rotate or print secrets unless explicitly authorized by the user. - Do not change the `smartmotor.cloud` website during filing review: homepage content, linked content reachable from the homepage, static assets, routes, bind mounts, container images, Nginx rules, `/opt/services/docker-compose.openclaw.yml`, or any equivalent compose/service entries that affect public website output are frozen. - Do not restart production-facing services without an approved rollback note. - Do not mark VPS work as accepted without verifier review. ## Current State - VPS public IP: `114.132.222.127`. - OpenClaw Gateway is already deployed and coexists with the existing Docker stack. - The VPS service workspace path is `/opt/services`. - The VPS control-plane path is `/home/ubuntu/openclaw-control-plane`. - Gitea control-plane repository: `https://git.smartmotor.cloud/wangzhendong/openclaw-control-plane.git`. ## Next Read-Only Task After the Gitea control plane is synchronized, collect current VPS baseline evidence: - Git/Gitea repository availability for the control plane. - OpenClaw Gateway process or container status. - Nginx route for `openclaw.smartmotor.cloud`. - Whether `openclaw devices approve`, `openclaw nodes pending`, and `openclaw nodes approve` are available. ## Last Update 2026-05-19 G2 execution paused after role-misdirection correction. - T10 is blocked and must not be claimed or executed. - Do not run `openclaw devices approve`, `openclaw nodes pending`, or `openclaw nodes approve` for G2. - Do not approve any pairing request. - Do not request, print, record, rotate, or store any token/password/secret. - Do not restart/reload services, change Gateway config, edit Nginx, edit Docker/compose/bind mounts/images, change service state, or alter frozen `smartmotor.cloud` website output. - Wait for ORCHESTRATOR to record fresh explicit user authorization after the role-misdirection correction and for T9 to produce matching non-secret evidence before any VPS-side G2 action.