/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half
the RAM goes, then every temp-file creation fails with ENOSPC and shells
break. Swap does not lift the cap, so the fix is /tmp on disk.
End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent):
- offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at
boot, 10-day purge, /var/tmp rule kept). Effective at next reboot.
- offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in
(OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and
--prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard.
install_cloudpex deploys the NAS mount helper in the Linux block.
Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
cloudpex/cloudpex mounts //192.168.1.111/CloudPex on /mnt/cloudpex on demand
(password prompted, nothing stored, noexec/nosuid/nodev, dir_mode 0750).
cloudpex/install.sh reproduces the live deployment: /usr/local/bin/cloudpex
root:root 0755, /mnt/cloudpex, cifs-utils if mount.cifs is missing.
README (FR) explains why on-demand and not fstab (RECOVERY doc 04).