Ruling 2: every tracked text mention of the login's pre-rename spelling becomes igneum-labs (29 files); the commit identity in the scripts becomes igneum-labs <337424239+igneum-labs@users.noreply.github.com> (the same noreply id); the three scripts that hand the stored gh keyring name to gh (register.sh, fetch-ci-artifacts.sh, ship-app.mjs) read it from ~/.config/igneum/gh-user (never in the repository), default igneum-labs; fresh-repo.sh reads the login to rewrite from the encoded list's row 10; the old spelling joins the founder-strings list, so no tracked file may spell it; CLAUDE.md's GitHub paragraph rewritten. The red watcher's self-test fixtures use a neutral author. Ruling 4: docs/ledger-public.md, one row per ledger item (id, the claim in one line, status, what was done in one line, the evidence link or the evidence in words), generated by tools/ledger/export-public.mjs from docs/fud-ledger.md: no round or status-update sections, no commit ids, no time of day, no lane, agent or branch names. 190 items. The gate runs its self-test (a fixture with a commit id, a time, a lane and a branch name comes out clean; --check fails on drift) and its --check on every merge; the founder check reads the output like every tracked file. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| capacity | ||
| ci-red | ||
| devnet3 | ||
| discord-hooks | ||
| hands | ||
| night | ||
| prover | ||
| repro | ||
| runner | ||
| workers | ||
| lease.sh | ||
| lib.sh | ||
| overlap-browser.sh | ||
| provision.sh | ||
| README.md | ||
| remote-run.sh | ||
| run-from-mac.sh | ||
| wave1-0320.sh | ||
The build boxes (infra/build-server)
Three Hetzner dedicated servers in Falkenstein run everything the Mac must not: builds, test suites, benchmarks, CPU proving, the devnet hands and the observer. The Mac keeps macOS binaries, the DMG and Metal tests (CLAUDE.md, "Running agents on this Mac").
No mining on any Hetzner box, ever
The founder's rule through main, 7 October 2026: Hetzner's policies forbid crypto mining. The boxes run nodes, builds, tests, benchmarks and
CPU proving only. The pool's fast-time network runs its miners on rented GPU pods (tools/fleet), never on a box; a box may run the
network's nodes. The capacity layer refuses a job that would start igneum-miner mine or a GPU worker (capacity/run.sh), and no
hands unit carries a miner. A node started with --enable-unsynced-mining is a node flag, not a miner; nothing feeds it blocks here.
The boxes and the kind map
| Box | Host file on the Mac | Takes | Never |
|---|---|---|---|
| igneum-build-1 (188.40.146.49, AX162-1-LTD) | ~/.config/igneum/build-server |
release gates (--priority gate), builds and cross-builds, checks, the GPU workers' host side, the devnet hands (node 1, the observer node, the observer), the Devnet 2 seed, the CI runner, the dashboard feed |
suites and benches once box 2 exists |
| igneum-build-2 (AX162-1, on order) | ~/.config/igneum/build-server-2 |
suites (cargo test), benches (cargo bench), the attack rows (--box 2) |
gates, hands |
| igneum-build-3 (AX102-1, on order) | ~/.config/igneum/build-server-3 |
proving and aggregation CPU work (proving/igneum-prove builds and suites), the second prover's shadow runner, the pool's fast-time NETWORK (nodes only, --box 3) |
miners of any kind |
tools/build-remote.sh routes by class (lib.sh bs_route): suite and bench to box 2, the proving crate to box 3, everything else
to box 1; --box N overrides; a class whose box has no host file yet falls back to box 1 and says so. --priority gate always runs
on box 1. Each box has its own mirrors, slots, locks and JSONL log under /srv; run-from-mac.sh --box N <ip> provisions a box and
writes its host file; the dashboard collector reads every box it is told about.
Files
| File | What |
|---|---|
provision.sh |
the box itself: install mode (rescue system, Ubuntu 24.04, RAID 1, no swap) and provision mode (user build, toolchains, the pin, sccache, zig, CUDA headers, docker, Caddy, mirrors, slots, sshd, ufw) |
run-from-mac.sh |
ships provision.sh, writes the host file, wires the build remotes and pushes every branch |
lib.sh, remote-run.sh |
the Mac and box halves of a remote run: sync, checkout, slots, scheduling classes, the JSONL line |
hands/ |
the devnet hands' units, the mover and the restart read-backs |
capacity/ |
the capacity layer (the box-work lane's): background jobs under the build slots, never a miner |
repro/, night/, prover/, runner/, workers/ |
other lanes' pieces that live on the boxes |
Plan, numbers and the gotchas: docs/plans/build-server.md; the hands: docs/plans/hands-on-build-1.md.