Files
operator adfcd2e602 feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
  (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
  probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
  surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
  never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
  engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
2026-10-05 20:18:47 +00:00

1.3 KiB

Fleet Topology & Agent Identities

Box is the main surface. All operator work goes through Box (box.muse-dev.online). The web UI, box CLI, and agents share the same API endpoints. No UI-only powers.

NetVM manages four primary autonomous browser agents and two development/staging nodes isolated inside Linux network namespaces (warp-*) on compute host bl (100.123.153.75).


1. Node Inventory

Node NetNS CDP Port Peer IP Default Sidechat Primary Role
muse warp-muse 9410 10.201.35.2 muse tasks General assistant, UI testing
pip warp-pip 9411 10.201.35.3 646-pip-coord Pipeline execution & driver
646 warp-646 9412 10.201.35.4 646 tasks Operator-646, code & bridge
opm warp-opm 9413 10.201.35.5 heartbeat Operator-main supervisor
dev warp-dev 9414 10.201.35.6 dev tasks Development sandbox
def warp-def 9415 10.201.35.7 default Fallback routing node

2. Headless Gateway & CLI Access

Each node has its own isolated Cloudflare WARP egress. To interact with a node:

# Gateway REPL
muse -a 646 chat

# Direct headless status
box muse 646 status

# Bounce node
box fleet restart 646