diff --git a/CLAUDE.md b/CLAUDE.md index 0d3e534..68931a9 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -31,6 +31,33 @@ machines when deployed. the auto-installer (see `docs/auto-installer.md`). Never commit its contents; if `git status` ever shows it as trackable, something is wrong. +### `pve.sweet.home` (the Proxmox node) + +`pve.sweet.home` (`PROXMOX_HOST` in `scripts/env.sh`) is a real, live Proxmox +node hosting production VMs/containers — not a sandbox. + +- **Read-only for existing state.** You may SSH in (or use `pvesm`, `qm + list`, `pct list`, `qm config`, `pct config`, the Proxmox API, etc.) to + inspect the node's config, storage, and any existing VM/container — + including ones this repo didn't create. Never modify, stop, restart, + delete, or reconfigure anything that already exists there (`qm set`, + `pct set`, `qm destroy`, `pct destroy`, `qm stop`, `pct stop`, snapshot + operations, storage changes, etc.) without the operator's explicit + go-ahead. +- **Test VMs/containers are allowed, but must be torn down.** You may create + a scratch VM or container on the node (e.g. via + `scripts/proxmox/create-proxmox-resource.sh` or raw `qm`/`pct create`) to + validate something. Anything you create this way must be destroyed again + in the same session, before ending the task — never leave a test + resource running on the node. Use a VMID/name that's obviously scratch + (and doesn't collide with a real flake target) so it's unambiguous what's + safe to remove. +- **No changes to production, ever, from an agent session** — this covers + both the node itself (Proxmox host config, storage pools, networking) and + any pre-existing guest. Anything beyond inspecting and tearing down your + own scratch resources is the operator's call to make manually, same as + the deploy commands above. + ## Commands ```bash