feat(install): offer /tmp on disk + SSH memory guard, deploy cloudpex helper
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half the RAM goes, then every temp-file creation fails with ENOSPC and shells break. Swap does not lift the cap, so the fix is /tmp on disk. End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent): - offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at boot, 10-day purge, /var/tmp rule kept). Effective at next reboot. - offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in (OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and --prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard. install_cloudpex deploys the NAS mount helper in the Linux block. Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
This commit is contained in:
@@ -23,9 +23,16 @@ vim/colors/ molokai colorscheme (committed)
|
||||
bash/bashrc-{linux,osx} OS-detected bashrc
|
||||
bin/{dt,dtach-router,claude-provider} CLI scripts deployed to ~/.local/bin
|
||||
etc/profile.d/disk-usage-warning.sh login-time low-disk warning → /etc/profile.d (Linux only)
|
||||
etc/tmpfiles.d/tmp.conf disk-backed /tmp cleanup rules (offer: /tmp on disk)
|
||||
etc/systemd/ssh.service.d/override.conf sshd OOM-exempt drop-in (offer: SSH memory guard)
|
||||
etc/default/earlyoom earlyoom args, spare sshd / kill node first (same offer)
|
||||
cloudpex/{cloudpex,install.sh,README.md} on-demand CloudPex SMB mount helper → /usr/local/bin (FR docs)
|
||||
.claude/{tasks,memory,audits}/ Claude working state
|
||||
```
|
||||
|
||||
`/tmp` is a RAM-backed tmpfs on Ubuntu (50% of RAM): agent runs fill it, which is why
|
||||
install.sh offers to mask `tmp.mount`. Swap is not the fix (the cap and ENOSPC stay).
|
||||
|
||||
`pymupdf`/`markdown_py` are NOT tracked — they are pipx entry-point shims,
|
||||
recreated by `pipx install PyMuPDF Markdown` in install.sh.
|
||||
`claude-provider` reads `$OPENROUTER_API_KEY` from the env — never hardcode it (the
|
||||
@@ -35,8 +42,8 @@ original had a live key; it was scrubbed — see decisions/blockers).
|
||||
|
||||
| Task | Command |
|
||||
| ----- | ---------------------------------------- |
|
||||
| Lint | `shellcheck *.sh bash/bashrc-*` |
|
||||
| Syntax check | `bash -n install.sh remote-install.sh` |
|
||||
| Lint | `shellcheck *.sh cloudpex/install.sh cloudpex/cloudpex bash/bashrc-*` |
|
||||
| Syntax check | `bash -n install.sh remote-install.sh cloudpex/install.sh` |
|
||||
| Install | `./install.sh` (OS auto-detected) |
|
||||
| Remote install | `curl -fsSL <raw>/remote-install.sh \| bash` |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user