2026-10-03 15:47:19 +00:00
|
|
|
# NetVM Infrastructure Layout
|
|
|
|
|
|
|
|
|
|
## bl (100.123.153.75) — Main Compute
|
|
|
|
|
- 16 cores, 28GB RAM
|
|
|
|
|
- Roles: Browser automation, NetVM nodes
|
|
|
|
|
- Access: VM -> bl via SSH
|
|
|
|
|
- WARP: Per-node identities in /etc/netvm/
|
|
|
|
|
- Browsers: Headless Chromium via chrome-box
|
|
|
|
|
- API: muse-chat-api.py via netvm-exec (CDP)
|
2026-10-03 15:58:06 +00:00
|
|
|
- Sign-in: muse-signin.py --email <addr> [--otp <code>]
|
2026-10-03 15:47:19 +00:00
|
|
|
- Hygiene: netvm-reaper.sh
|
2026-10-03 15:58:06 +00:00
|
|
|
- Approvals: In-browser via chat (see below)
|
2026-10-03 15:47:19 +00:00
|
|
|
|
|
|
|
|
## VM (34.139.37.135) — Gateway + Vault
|
|
|
|
|
- E2 micro (2 vCPU, 1GB RAM)
|
|
|
|
|
- Roles: Jump host to bl, credential store
|
|
|
|
|
- Credential store: /etc/netvm/meta-credentials/ (age-encrypted)
|
|
|
|
|
- No browser automation (resource constraints)
|
|
|
|
|
|
|
|
|
|
## Laptop — Dev
|
|
|
|
|
- Roles: Iteration, visible browser debugging
|
|
|
|
|
- Nothing production
|
|
|
|
|
|
|
|
|
|
## Credential Flow
|
|
|
|
|
- Meta accounts: /etc/netvm/meta-credentials/store.age (VM)
|
|
|
|
|
- WARP identities: /etc/netvm/node.conf (per-machine, root 600)
|
|
|
|
|
- Operators handle transiently; never log values.
|
2026-10-03 15:58:06 +00:00
|
|
|
|
|
|
|
|
## In-Browser Approvals
|
|
|
|
|
When automation needs human input (OTP, confirmation):
|
|
|
|
|
1. Script exits with code 2 and prints "APPROVAL_NEEDED: <details>"
|
|
|
|
|
2. Operator sees this and asks user via chat
|
|
|
|
|
3. User provides input (e.g., OTP code)
|
|
|
|
|
4. Operator re-runs script with --otp <code>
|
|
|
|
|
5. Script completes the flow
|
|
|
|
|
|
|
|
|
|
No file-based queue needed — the chat IS the approval interface.
|
|
|
|
|
The human is already in the chat; the automation just needs to
|
|
|
|
|
signal when it's stuck.
|
|
|
|
|
|
|
|
|
|
## Sign-In Flow (muse-signin.py)
|
|
|
|
|
Automated login for muse.ai accounts:
|
|
|
|
|
- Step 1: Check if already logged in (skip if yes)
|
|
|
|
|
- Step 2: Click "Log in"
|
|
|
|
|
- Step 3: Enter email
|
|
|
|
|
- Step 4: Click "Continue"
|
|
|
|
|
- Step 5: Detect OTP prompt
|
|
|
|
|
- If --otp provided: enter it, click Next, verify
|
|
|
|
|
- If not: exit 2 with APPROVAL_NEEDED
|
|
|
|
|
- Credentials never stored; OTP is transient.
|