Compare commits

..

2 Commits

Author SHA1 Message Date
d278d18bb3 Correct system-architect specs from live 2026-10-05 inspection
- .13: KDE Plasma 6 (not Niri); RAM 15GB; disk letters corrected
  (root is /dev/sda2, storage sdb2, data sdc2, ubuntu_storage sdd1);
  add sda3 swap (81% full)
- .13 GPU: GTX 760 dead, no driver bound, software rendering
- .27: 4 cores/8 threads, Quadro P620 + HD 630, add swap + NTFS disk
- add Resource Pressure on .13 section and must-stay-on list
- note dead stacks (airflow 24GB logs, engram container) and caveats
2026-10-05 14:47:54 +11:00
8111abea38 image-maker: don't hardcode a per-machine secrets path
The previous version pointed at /home/sam/.secrets, which exists on .13 but
NOT on .27 — so the subagent would work on one machine and fail on another.
It had the same bug before in reverse (pointed at environment.d/10-secrets.conf,
which was missing the key on .13).

Now: require the OPENROUTER_API_KEY environment variable, document
~/.config/environment.d/10-secrets.conf as the canonical source (the only one
systemd user services read, which is what Paperclip workers get), and fall back
to ~/.secrets only if it exists.
2026-09-27 18:43:45 +10:00
2 changed files with 81 additions and 23 deletions

View File

@@ -68,13 +68,22 @@ The image comes back as base64 in `choices[0].message.images[0].image_url.url`.
## API Key ## API Key
`OPENROUTER_API_KEY` lives in **`/home/sam/.secrets`** (a plain `KEY=value` file). Load it with: `OPENROUTER_API_KEY` must be present as an **environment variable**. Do not assume a fixed file path — the canonical location differs per machine.
**Canonical source on all machines:** `~/.config/environment.d/10-secrets.conf` (plain `KEY=value`, no `export`). This is the only location that **systemd user services read**, which is what matters when this subagent runs under Paperclip rather than in an interactive shell.
Check availability first:
```bash ```bash
set -a; . /home/sam/.secrets; set +a
echo "${OPENROUTER_API_KEY:+key loaded}" echo "${OPENROUTER_API_KEY:+key loaded}"
``` ```
It is NOT in `~/.config/environment.d/10-secrets.conf` — older versions of this file claimed that and the call failed. If it is empty, source it for the current shell:
```bash
set -a; . ~/.config/environment.d/10-secrets.conf; set +a
```
**Do not hardcode other paths.** `.13` additionally keeps keys in `~/.secrets` (an `export`-style file), but `.27` has no `~/.secrets` at all — anything that sources that path fails there. Prefer the environment variable; fall back to `~/.secrets` only if the variable is unset *and* the file exists.
Write detailed, specific prompts. Save images to the user's current working directory or a specified path. Tell the user where you saved the file. Write detailed, specific prompts. Save images to the user's current working directory or a specified path. Tell the user where you saved the file.

View File

@@ -13,56 +13,83 @@ metadata:
hardware: hardware:
cpu: cpu:
model: "Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz" model: "Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz"
cores: 8 cores: 4
threads: 8 threads: 8
ram: ram:
total_gb: 62.7 total_gb: 62
gpu: gpu:
- i915 - Intel HD Graphics 630 (i915) — drives the 4 display outputs
- nvidia - NVIDIA Quadro P620 2GB (nvidia 580.173.02)
disks: disks:
- device: /dev/nvme0n1p2 - device: /dev/nvme0n1p2
size: 869G size: 869G
mountpoint: / mountpoint: /
note: "ext4, 66% used (2026-10-05)"
- device: /dev/nvme0n1p3
size: 69G
mountpoint: "[SWAP]"
- device: efivarfs - device: efivarfs
size: 256K size: 256K
mountpoint: /sys/firmware/efi/efivars mountpoint: /sys/firmware/efi/efivars
- device: /dev/nvme0n1p1 - device: /dev/nvme0n1p1
size: 1022M size: 1022M
mountpoint: /boot mountpoint: /boot
- device: /dev/sda2
size: 224G
mountpoint: "(not mounted)"
note: NTFS
verified: 2026-10-05
- name: nixos-desktop - name: nixos-desktop
type: Desktop type: Desktop
ip: 192.168.20.13 ip: 192.168.20.13
os: "NixOS, Niri" os: "NixOS 26.11 (Zokor), KDE Plasma 6 / KWin Wayland (SDDM)"
role: NixOS with Niri. Second dev. Web facing. Network scripts. role: Always-on web-facing server. Docker host + native services. Memory-bound — do not treat as CPU-bound.
tech: Docker (Mosquitto, N8N, Pi Hole back up with nebulasync from sam-ubuntu1 pihole, pocketbase, speech_piper, voice_bridge), websites at /var/www/, snapcast, gstreamer, librespot, mopidy tech: Docker (OmniRoute, Outline, n8n, Pi-hole replica + nebulasync, Mosquitto, voice_bridge/voice_whisper, speech_piper, pocketbase, family-home-lab, dsh, worldmonitor, prefect, litellm, headroom/JEV), Caddy :8000 serving /var/www, snapcast, librespot, mopidy, native PostgreSQL :5433 (paperclip), paperclipai, Paseo Daemon, where-woof
hardware: hardware:
cpu: cpu:
model: "AMD Ryzen 5 5600 6-Core Processor" model: "AMD Ryzen 5 5600 6-Core Processor"
cores: 12 cores: 6
threads: 12 threads: 12
ram: ram:
total_gb: 15.5 total_gb: 15
note: "6.8 GiB used; swap 7.1 GiB of 8.8 GiB used (81%) - 2026-10-05"
gpu: gpu:
- "NVIDIA GTX 760 (Kepler, PCI 10de:11c2) - DEAD. No driver bound; only /dev/dri/card0 simple-framebuffer. /proc/driver/nvidia absent. Desktop renders via software (llvmpipe). hardware.nvidia.open=true can never work on Kepler (open modules need Turing+). Recommended replacement: AMD RX 6600 (in-kernel amdgpu)."
disks: disks:
- device: /dev/sdb2 - device: /dev/sda2
size: 907G size: 907G
mountpoint: / mountpoint: /
- device: efivarfs note: "ext4, 459G used (54%) - 2026-10-05"
size: 128K - device: /dev/sda3
mountpoint: /sys/firmware/efi/efivars size: 8.8G
- device: /dev/sdb1 mountpoint: "[SWAP]"
note: "81% full - the main resource problem on this machine"
- device: /dev/sda1
size: 1022M size: 1022M
mountpoint: /boot mountpoint: /boot
- device: /dev/sdb2
size: 916G
mountpoint: /mnt/storage
note: empty spare
- device: /dev/sdc2
size: 1.8T
mountpoint: /mnt/data
note: "21% used"
- device: /dev/sdd1 - device: /dev/sdd1
size: 2.7T size: 2.7T
mountpoint: /mnt/ubuntu_storage_3TB mountpoint: /mnt/ubuntu_storage_3TB
- device: /dev/sda2 note: "USB drive - photo master + Borg backup target for .27 and .13. Letter shifts on replug (has been sdd1/sde1)."
size: 1.9T - device: /dev/sde1
mountpoint: /mnt/data size: 1.4T
- device: /dev/sdc2 mountpoint: "(not mounted)"
size: 932G note: MaxtorBackup, old migration tarballs
mountpoint: /mnt/storage caveats:
- "Device letters are NOT stable - NixOS mounts by UUID. Always check lsblk/df before using a device path."
- "GPU is dead: no hardware acceleration. KDE session costs ~2.4 GB because of software rendering plus 28-day uptime."
- "litellm and headroom are idle and almost entirely swapped out (~1.05 GB of swap combined)."
- "Dead stacks to ignore: airflow (7 containers exited, 24 GB of logs in /home/sam/deployment/airflow/logs), engram container (never started - the live engram is a user systemd service on :7437 and its DB is empty), trigger_dev, t3_stack_react, sams-home-network."
- "There is a SECOND airflow install at /home/sam/deployment/ai-resume/airflow/ - also not running."
verified: 2026-10-05
- name: sam-ubuntu1 - name: sam-ubuntu1
type: virtual machine type: virtual machine
ip: 192.168.20.35 ip: 192.168.20.35
@@ -184,6 +211,28 @@ Sam's NixOS multi-machine infrastructure reference.
Full hardware specs are in the frontmatter metadata. Full hardware specs are in the frontmatter metadata.
## Resource Pressure on .13 (verified 2026-10-05)
`.13` is **memory-bound, not CPU-bound**. Load average is ~0.27 on 12 threads, but the
8.8 GB swap partition is **81% full**. Before proposing anything that adds load to `.13`,
check the swap. Full detail: Obsidian → `300 areas/360 Dev-Ops Network Computers/Resource Use — .13 CPU & RAM.md`.
| Consumer | RAM + swap | Notes |
|---|---|---|
| KDE Plasma session (~30 processes) | ~2.4 GB | Software rendering (GPU dead) + 28-day uptime |
| Docker containers (all) | ~3.5 GB RSS | `voice_whisper` 877 MB is the largest |
| `litellm` + `headroom` | ~1.05 GB *swap* | Idle; both fully paged out; redundant with OmniRoute |
| Dead Airflow logs | 24 GB *disk* | `/home/sam/deployment/airflow/logs` — nothing depends on it |
**Must stay on `.13`:** Pi-hole `:53`, OmniRoute `:20128/20129` (all pi LLM traffic),
Mosquitto `:1883` (Home Assistant on `.30`), the Borg backup target on `/mnt/ubuntu_storage_3TB`
(`.27` pushes daily at 04:00), Caddy `:8000` + `/var/www`.
**Corrections applied 2026-10-05:** `.13` runs **KDE Plasma 6**, not Niri. `.13` disk device
letters were wrong (root is `/dev/sda2`). Home Assistant is on **`.30`, not `.35`** (`.35` is
`sam-ubuntu1`, the Caddy/docker app host). Pi-hole primary is **`.35`**; `.13` is the replica
(confirmed from `nebulasync`: `PRIMARY=http://192.168.20.35`, `REPLICAS=http://192.168.20.13`).
## Pi Agent (uniform across machines) ## Pi Agent (uniform across machines)
- **Binary**: nixpkgs `pi-coding-agent` 0.82.1 in `home.packages` on .27/.13/.51 (Nix-managed; npx wrapper + npm-global install removed 2026-08-05). Updates = nixpkgs flake bump + rebuild. - **Binary**: nixpkgs `pi-coding-agent` 0.82.1 in `home.packages` on .27/.13/.51 (Nix-managed; npx wrapper + npm-global install removed 2026-08-05). Updates = nixpkgs flake bump + rebuild.