This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/systemd/sea-haven-checkers.timer
Adam Moussa 17ef4de415
feat(security-review): schedule the Plane-1 checker coordinator nightly + role-skip (#36)
- checker_coordinator.sh: add COORDINATOR_SKIP_ROLES env (comma-separated) to drop
  roles whose credentials are not provisioned from the registry entirely (never
  canaried/run/ALARMed). Fail-safe: empty/unset = run all.
- systemd: sea-haven-checkers.{service,timer} run the coordinator nightly at ~03:30
  UTC (90 min after the secrev sweep so they don't contend on $MIRROR_DIR / the
  Claude pool). The unit sets COORDINATOR_SKIP_ROLES=aws-posture,confluence-doc
  (aws-posture needs IAM Roles Anywhere; confluence-doc needs the confluence-bot
  token — both intentionally unprovisioned).

Deployed + enabled on the box (deploy-before-merge): canary 4/4 with the skip,
timer scheduled for 2026-06-23 03:35 UTC.
2026-06-22 19:05:02 -04:00

20 lines
658 B
SYSTEMD

# sea-haven-checkers.timer — fires the Plane-1 checker coordinator nightly.
#
# 03:30 UTC — ~90 min after the sea-haven-secrev sweep (02:00) so the two do not
# contend on $MIRROR_DIR or the shared Claude subscription pool at the same instant.
# Persistent=true → if the VM was off, it runs at next boot. RandomizedDelaySec
# spreads load off an exact-minute spike.
#
# Install: see the header of sea-haven-checkers.service.
[Unit]
Description=Run the Sea Haven Plane-1 checker coordinator nightly (~03:30 UTC)
[Timer]
OnCalendar=*-*-* 03:30:00
Persistent=true
RandomizedDelaySec=600
Unit=sea-haven-checkers.service
[Install]
WantedBy=timers.target