diff --git a/install/nexus-install.sh b/install/nexus-install.sh index a71518a..ce83cf1 100644 --- a/install/nexus-install.sh +++ b/install/nexus-install.sh @@ -57,11 +57,12 @@ else msg_warn "Node $(node -v) already present, skipping" fi -# ── RUNTIME (extended by the stack-introducing SDD card in nexus-hub) ───────── -# The nexus tech stack is not yet decided (nexus-hub Project Brief, open point 2). -# When the stack card lands, it adds the runtime here (e.g. Python/uv, DB client -# libs) AND documents the change in nexus-hub docs/agent-rules.md → Projekt-Kommandos. -msg_warn "RUNTIME section is a placeholder until the nexus stack decision (see nexus-hub)" +# ── RUNTIME ─────────────────────────────────────────────────────────────────── +# Stack decided (nexus-hub ADR-0002, card K-101): Python 3.12 via uv, tesseract +# deu+eng, nexus-worker.service + sudoers extension. Provisioned by +# install/nexus-runtime.sh, invoked at the END of this script (it extends the +# sudoers rule and systemd units written below, so order matters). Commands are +# documented in nexus-hub docs/05_AGENT_RULES.md → Projekt-Kommandos. # ── act_runner binary ───────────────────────────────────────────────────────── if [[ ! -x /usr/local/bin/act_runner ]]; then @@ -121,6 +122,9 @@ cat >/etc/systemd/system/nexus.service </dev/null 2>&1 systemctl enable --now nexus-runner.service msg_ok "systemd units installed (runner started; nexus.service enabled, starts on first deploy)" +# ── RUNTIME provisioning (K-101): uv/Python 3.12, tesseract, worker unit ────── +# Runs LAST on purpose: it extends the sudoers rule and unit set from above. +# Idempotent — the same script retrofits an existing LXC: +# curl -fsSL .../install/nexus-runtime.sh | bash +bash <(curl -fsSL "${LIB_URL%/lib}/install/nexus-runtime.sh") + # ── notes / summary file ────────────────────────────────────────────────────── CRED_FILE="/root/nexus.credentials" cat >"$CRED_FILE" </dev/null 2>&1 || { msg_err "user $APP_USER missing — run nexus-install.sh first"; exit 1; } + +# ── OCR stack (ING-3: tesseract deu+eng) ────────────────────────────────────── +msg_info "Installing tesseract (deu+eng)..." +apt-get install -y -qq tesseract-ocr tesseract-ocr-deu tesseract-ocr-eng >/dev/null +msg_ok "tesseract $(tesseract --version 2>/dev/null | head -n1 | awk '{print $2}')" + +# ── uv for the nexus user (provides Python 3.12 via pyproject/uv.lock) ──────── +if [[ ! -x "$APP_HOME/.local/bin/uv" ]]; then + msg_info "Installing uv for $APP_USER..." + run_user bash -c "curl -LsSf https://astral.sh/uv/install.sh | sh" >/dev/null + msg_ok "uv $(run_user "$APP_HOME/.local/bin/uv" --version | awk '{print $2}') installed" +else + msg_warn "uv already present ($(run_user "$APP_HOME/.local/bin/uv" --version | awk '{print $2}')), skipping" +fi +run_user "$APP_HOME/.local/bin/uv" python install 3.12 >/dev/null 2>&1 || true +msg_ok "Python 3.12 toolchain available via uv" + +# ── nexus-worker.service ────────────────────────────────────────────────────── +cat >/etc/systemd/system/nexus-worker.service </etc/sudoers.d/nexus-deploy </dev/null + +systemctl daemon-reload +systemctl enable nexus-worker.service >/dev/null 2>&1 +msg_ok "nexus-worker.service installed + enabled (starts once a deploy ships start-worker.sh)" + +msg_ok "nexus runtime provisioning finished (idempotent — safe to re-run)"