# sea-haven-checkers.service — Plane-1 nightly checker coordinator (sh-secrev VM, user adam). # # Runs security-review/checker_coordinator.sh: the read-only Plane-1 checkers # (compliance-drift, dependency-cve, doc-drift, plan-groomer) under ONE shared # budget ledger + versioned rotation/coverage, ALARM-only to Slack. Reuses the # secrev sweep's substrate ($MIRROR_DIR clones, budget discipline) — no re-clone. # # Install (on the VM, as root): # sudo cp sea-haven-checkers.service /etc/systemd/system/ # sudo cp sea-haven-checkers.timer /etc/systemd/system/ # sudo systemctl daemon-reload # sudo systemctl enable --now sea-haven-checkers.timer # the timer drives it # systemctl list-timers sea-haven-checkers.timer # # Secrets/config come from the EnvironmentFiles (leading '-' = optional): # ~/secrev.env -> CLAUDE_CODE_OAUTH_TOKEN, GH_TOKEN, SLACK_WEBHOOK_URL # ~/orchestrator/.env -> OPENAI/etc. (only if a checker shells the cross-model run.py) # # COORDINATOR_SKIP_ROLES excludes roles whose creds are NOT provisioned: # - aws-posture needs IAM Roles Anywhere / step-ca (not provisioned) # confluence-doc is ONLINE (2026-06-22): authenticates via the OAuth 2.0 # client-credentials service account in ~/secrev.env (CONFLUENCE_BASE_URL + # CONFLUENCE_OAUTH_CLIENT_ID/_SECRET); PAGE_MAP_FILE points at the IT page-ID map # generated from the live space. Remove a name from the skip list once its # credential is provisioned to bring that checker online. [Unit] Description=Sea Haven agent-team Plane-1 nightly checker coordinator After=network-online.target Wants=network-online.target [Service] Type=oneshot User=adam WorkingDirectory=/home/adam/orchestrator/security-review EnvironmentFile=-/home/adam/secrev.env EnvironmentFile=-/home/adam/orchestrator/.env Environment=GH_ORG=Sea-Haven-Industries Environment=COORDINATOR_SKIP_ROLES=aws-posture # IT page-ID map for confluence-doc (generated from the live space; regenerate # periodically as pages change). Environment=PAGE_MAP_FILE=/home/adam/confluence-page-map.json # Tune the shared ceiling without editing the script (uncomment to override): # Environment=TOTAL_BUDGET_USD=120 # Environment=MAX_CYCLE_NIGHTS=4 ExecStart=/home/adam/orchestrator/security-review/checker_coordinator.sh # Bounded so a hung checker cannot run forever; spend is capped by TOTAL_BUDGET_USD. TimeoutStartSec=10800 Nice=10 [Install] WantedBy=multi-user.target