rdmbair13m5-changelog-20260823-0350-local-llm-fleet-maintenance
Updated the six-host LLM configuration baseline, installed and benchmarked privacy-safe local models, and published a protected fleet dashboard without synchronizing any provider identity or personal benchmark data.
Scope
- Acting host:
rdmbair13m5; fleet scope: all six Macs. - Canonical development source remained
rdmsm4x:/Users/richh/dev. - Provider authentication, browser state, native histories, Tosh signing keys, and Ollama identities remained host-local.
Changes on this host
- Reconciled the managed fleet path blocks in
~/.claude/CLAUDE.md,~/.codex/AGENTS.md,~/.gemini/GEMINI.md, and~/.agent-coordination/FLEET.mdto the canonicalrdmsm4x:/Users/richh/dev/apps/{RTTy,LogTTY}roots. - Completed
/Users/richh/dev_update.zsh; verified no outdated formulae or greedy casks remained andbrew doctorwas clean. - Reinstalled the Antigravity CLI cask receipt collision safely;
backup:
/Users/richh/.agent-coordination/backups/antigravity-cli-reinstall-20260823T020553. - Verified Claude Code 2.1.241, Codex CLI 0.149.0, agy 1.1.19, Antigravity 2.9.1, Antigravity IDE 2.5.5, and Ollama 0.32.15.
- Installed Ollama models
qwen3.8:27b-mlxandqwen3.5:35b-mlxand generated sanitized benchmark artifacts using/Users/richh/Documents/Codex/2026-08-23/fi/work/benchmark_ollama_synthetic_v1.0.py. - Kept the local System Settings Automation state least-privileged: Terminal-to-Finder/System Events and zsh-to-Notes remain enabled; the SSH wrapper's Notes/Terminal/System Events controls remain disabled because SSH is not an Aqua GUI session and does not need broad AppleEvent authority.
Fleet commands and verification
- Ran the six-host topology audit; result:
FLEET_TOPOLOGY_AUDIT_PASS checked=6 failures=0 canonical=rdmsm4x account_stores=separate. - Ran the bounded TCC audit with
/Users/richh/scripts/audit_tcc_llm_permissions_v1.0.py; this host has no explicit denied or limited LLM/terminal records in the audited system scopes. - Ran deterministic loopback-only Ollama workloads; no prompt, response, hostname, path, username, serial, IP, or account data was serialized.
- Verified the dashboard's internal container response and exact
deployed SHA-256
c68266538815f8c56ee77c6b21779c495d94f7aa3655666b0d1819bb442c52c4; the public route correctly returns HTTP 401 without its existing Basic-auth credentials.
Undo
- Restore the Antigravity receipt from the dated backup above only if the current verified CLI becomes unusable.
- Remove downloaded models with
ollama rm <model>only after an explicit owner decision; no automatic model deletion is scheduled. - Path blocks can be restored from the pre-change backups recorded in the earlier per-host path-refresh changelog, but doing so would reintroduce stale roots.
Outstanding owner actions
- Complete each host's Ollama browser sign-in in the correct iCloud/Gmail account lane if cloud-library features are desired; the sign-in pages are ready, but no email/account identity was transmitted by this run.
- No local permission switch is recommended solely for SSH automation.
notes_changelog.zshwaited 600 seconds in the documented large-store cold-start path, then reported that Notes never became responsive. The Markdown file copy is complete; the Apple Notes entry remains pending and must be retried from this Aqua session later.