Files
openclaw-control-plane/tasks/T10-G2-VPS-pairing-approve.md
2026-05-21 16:54:31 +08:00

3.9 KiB

T10 - G2 VPS Pairing Approval

Status

blocked

Owner

VPS_EXECUTOR

Dependencies

  • T9 produces a non-secret pairing request ID or pending node ID
  • Fresh user authorization after role-misdirection correction
  • CORRECTION confirms sync-health is not blocked

Scope

Approve the intended PC node/device pairing on the VPS Gateway side.

This task does not authorize service restarts, reloads, token rotation, Gateway configuration changes, Nginx changes, Docker compose edits, bind mount changes, image changes, or public website changes.

Planning Status

  • G2 pre-execution plan is documented in docs/G2_RUNBOOK.md.
  • Sync-health has been confirmed healthy and T7 sync-health blocked state is cleared.
  • Fresh second G2 authorization was recorded by ORCHESTRATOR on 2026-05-19 for target window ORCHESTRATOR in D:\openclaw-control-plane.
  • This task remains blocked until T9 produces a matching non-secret request/node ID.
  • Authorization covers only the corresponding VPS pairing approval after T9 evidence exists; it does not authorize service restarts/reloads, token rotation, Gateway config mutation, Nginx changes, Docker changes, or frozen website changes.

Blocker Update - 2026-05-21

  • T9 is done and evidence/pc-g2-node-run-20260521.md reports the PC node connected to openclaw.smartmotor.cloud.
  • T9 evidence does not provide a pairing request ID or pending node ID.
  • T10 remains blocked because there is no specific non-secret approval target.
  • ORCHESTRATOR opened tasks/T10A-G2-VPS-pending-status-check.md for VPS_EXECUTOR to perform a read-only Gateway pending/online status check.
  • Do not approve until ORCHESTRATOR opens T10 with one matching non-secret request/node ID, unless T10A proves the intended PC node is already online/approved and ORCHESTRATOR routes to G2 verification instead.

Required Evidence

  • rollback/vps-g2-approve-YYYYMMDD.md written before approval action.
  • Confirmation that request identity matched the PC evidence and display name.
  • Exact command shape used, without secrets.
  • Approval result summary.
  • Confirmation that no restart, reload, token rotation, Nginx route edit, Docker compose edit, bind mount change, image change, service-state mutation, or frozen website output change was performed.
  • Evidence written to evidence/vps-g2-approve-YYYYMMDD.md.
  • handoff/VPS_EXECUTOR.md updated.

Command Drafts

Do not run these until T9 evidence provides a matching non-secret request/node ID. Approval must target only the intended PC pairing.

docker exec openclaw-gateway node openclaw.mjs nodes pending
docker exec openclaw-gateway node openclaw.mjs devices approve <requestId>
docker exec openclaw-gateway node openclaw.mjs nodes approve <nodeId>

Expected Output

  • The intended PC device/node is approved.
  • Gateway shows the PC node online or approved.
  • Evidence contains only non-secret request IDs or node IDs.

Stop Conditions

  • Fresh user authorization after the role-misdirection correction is absent or ambiguous.
  • docs/G2_RUNBOOK.md has not been read by VPS_EXECUTOR.
  • Request identity is ambiguous or multiple indistinguishable pending requests exist.
  • A command asks for or prints a token/password.
  • Approval would require restart, reload, token rotation, config mutation, Nginx changes, Docker changes, or any action that could affect frozen smartmotor.cloud website output.

Acceptance

VPS_VERIFIER must review this evidence before ORCHESTRATOR can count the VPS half of G2 as accepted.

Session Freeze - 2026-05-19 14:46 UTC+8

  • Status at freeze: blocked.
  • Blocker: waiting for T9 evidence with one matching non-secret pairing request ID or pending node ID.
  • Next owner after unblock: VPS_EXECUTOR.
  • Do not run nodes pending, devices approve, or nodes approve until ORCHESTRATOR opens T10 after T9 evidence exists.
  • Do not restart/reload services, change Gateway config, edit Nginx/Docker/website state, or record secrets.