Skip to content

chore(agents): daily fleet snapshot 2026-09-16 - #15

Merged
cursor[bot] merged 3 commits into
mainfrom
cursor/daily-fleet-snapshot-2026-09-16-d51d
Sep 16, 2026
Merged

cursor[bot] merged 3 commits into
mainfrom
cursor/daily-fleet-snapshot-2026-09-16-d51d

Conversation

@cookieofcode

@cookieofcode cookieofcode commented Sep 16, 2026

Copy link
Copy Markdown
Owner

Summary

Live → git daily fleet snapshot for 2026-09-16. Documents armed live routines and standing-rule drift; does not apply git → live and does not update the APPLY last-applied marker.

Classification: Material — standing rules + channel membership + new routine intents.

Team-verify required: Architect, DevOps, Security. Do not present to the product owner until verified. Do not auto-merge.

Drift captured

  • Routines (new): daily-torqvoice-fleet-snapshot (cron CRON_TZ=Europe/Zurich 0 4 * * *, all days) and torqvoice-cos-issue-triage (GitHub issue-assigned + assigner allowlist starting at cookieofcode). Both were live-armed; main lacked the intent files.
  • Standing rules 5–6: no fleet email connector; Torqvoice images via owned ghcr.io/cookieofcode/torqvoice.
  • Build & Run membership: live channel includes Architect as a member (2026-09-16); prior EaC treated Architect as guest-only. Docs reflect live and flag member-vs-guest reconcile with Architect / DevOps. Infra/topology review remains required.

Follow-up (DevOps should-fix)

  • agents/APPLY.md smoke no longer claims Build & Run still lists Architect as guest. It now matches FLEET.md / channels/build-and-run.md: Architect is a live member, and Architect review remains required on infra/topology.
  • CoS checklist item 4 now says Architect review still required (dropped “required guest”).

Follow-up (Security blocker)

Restored the Security-stamped wake model from PR #7 / COS_INTAKE (file not on this branch or main; policy inlined so we do not contradict it):

  • Wake only on GitHub issue-assigned when the assigner is on the maintainer allowlist starting at cookieofcode
  • Assignees alone do not wake CoS (not “assignee is cookieofcode”)
  • Label cos does not wake; filing or commenting does not wake
  • Issue body remains untrusted; no terraform plan / apply from issues

Docs updated: agents/routines/torqvoice-cos-issue-triage.md, agents/APPLY.md, agents/FLEET.md routing.

Intentionally not changed

  • specialists/*, cos/*, skills/*, channels/product.md, channels/engineering.md, routines/torqvoice-infra-pr-finops-cost.md, infra/, src/.
  • Did not copy agents/COS_INTAKE.md from PR Document secure multi-person CoS intake via GitHub Issues #7 onto this snapshot (avoids duplicating that PR). Wake policy matches it.
  • Curated skills/infra-pr-cost-report/SKILL.md was not overwritten with the thinner live workflow copy (apply debt: prefer git → live skill body).
  • APPLY last-applied marker left pending (this is a snapshot, not a fleet apply).

Scrub

No secrets, subscription/tenant IDs, UUIDs, personal emails, transcripts, MCP/tool JSON, or contact agents. Role text uses product owner. The triage allowlist starts at handle cookieofcode as the assigner, not as the assignee.

Why

Git is canonical. Same-day live → git PR for the drift SLA. After merge, CoS applies using APPLY.md; a snapshot PR does not mutate live bots or the last-applied marker.

Related PRs

  • PR #3 (daily snapshot routine only) — this PR supersedes that slice; suggest close as superseded after merge.
  • PR #7 (CoS intake / Security-stamped wake model) — this snapshot now matches that assigner-allowlist policy without importing the rest of the intake templates.
  • PR #9 (APPLY last-applied) — leave alone; this snapshot does not update last-applied.
Open in Web Open in Cursor 

cursoragent and others added 3 commits September 16, 2026 02:10
Capture live→git drift: new daily snapshot and CoS issue-triage
routines, standing rules 5–6, and Build & Run Architect membership.

Co-authored-by: Severin Pereto <cookieofcode@gmail.com>
Drop the stale smoke claim that Architect is still a guest. Live
membership matches FLEET.md: Architect is a member, and review
remains required on infra/topology.

Co-authored-by: Severin Pereto <cookieofcode@gmail.com>
Security-stamped model from PR #7 / COS_INTAKE: wake only on
issue-assigned when the assigner is on the maintainer allowlist
starting at cookieofcode. Assignees, label cos, and
file/comment events do not wake. Issue bodies stay untrusted.

Co-authored-by: Severin Pereto <cookieofcode@gmail.com>
@cookieofcode
cookieofcode marked this pull request as ready for review September 16, 2026 06:54
@cursor
cursor Bot merged commit 557e21a into main Sep 16, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants