security-review/systemd/sea-haven-checkers.timer
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

20 lines
658 B
SYSTEMD

# sea-haven-checkers.timer — fires the Plane-1 checker coordinator nightly.
#
# 03:30 UTC — ~90 min after the sea-haven-secrev sweep (02:00) so the two do not
# contend on $MIRROR_DIR or the shared Claude subscription pool at the same instant.
# Persistent=true → if the VM was off, it runs at next boot. RandomizedDelaySec
# spreads load off an exact-minute spike.
#
# Install: see the header of sea-haven-checkers.service.
[Unit]
Description=Run the Sea Haven Plane-1 checker coordinator nightly (~03:30 UTC)
[Timer]
OnCalendar=*-*-* 03:30:00
Persistent=true
RandomizedDelaySec=600
Unit=sea-haven-checkers.service
[Install]
WantedBy=timers.target