# Perintah untuk Agen di Mesin Baru — v3 (API gateway, tanpa webhook)

Tempel pesan berikut ke chat TUI mesin baru.
**Sumber file = S3 provisioning** (`https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision`) —
semua curl di bawah sudah menunjuk ke S3. Fallback kalau S3 bermasalah: web root mesin utama
(`https://hermes-3s1llz-6080.jkt3.sumopod.my.id`).

---

TUGAS: Siapkan mesin ini agar identik dengan mesin utama:
noVNC (JWT auth, 1600×900) + API server 8642 + tooling jobseeker + skill.
Kerjakan SEMUA dengan tool TERMINAL — JANGAN pakai tool browser.

LANGKAH 1 — Unduh 2 skrip (sumber: S3 provisioning):
  curl -fsSL https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision/bootstrap-mesin.sh -o /tmp/bootstrap-mesin.sh
  curl -fsSL https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision/jobseeker-platform.sh -o /tmp/jobseeker-platform.sh
  chmod +x /tmp/bootstrap-mesin.sh /tmp/jobseeker-platform.sh

LANGKAH 2 — Bootstrap dasar (TANPA argumen — webhook sudah tidak dipakai):
  bash /tmp/bootstrap-mesin.sh

LANGKAH 3 — Platform jobseeker (API server 8642 + tooling + venv-cdp + 6 skill + config).
  Tooling diunduh dari SRC_BASE — pakai S3 provisioning:
  SRC_BASE=https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision bash /tmp/jobseeker-platform.sh
  (Instal 6 skill: jobseeker-agent + 5 portal [jobstreet/glints/linkedin/indeed/kalibrr];
   tooling termasuk report-application.py v2 [pick/update] & portal-check.py v3 [CDP langsung];
   venv-cdp + websocket-client dibuat otomatis.)

LANGKAH 4 — Isi agent-config.env dengan nilai yang DIBERIKAN operator:
  Tulis file /opt/data/jobseeker/agent-config.env berisi:
  BE_API_URL=<alamat BE>  ·  BE_INTERNAL_TOKEN=<token internal>  ·  USER_ID=<user_id>
  (Kalau nilainya belum diberikan, laporkan ke operator bahwa mesin menunggu
  konfigurasi ini — LANGKAH 6 tetap jalan, item "koneksi BE" ditandai menunggu.)

LANGKAH 5 — Attach sesi TUI ini ke Chromium lokal: ketik di kolom chat TUI
  (bukan terminal tool): /browser connect, lalu cek /browser status.
  (Sesi baru otomatis attach — browser.cdp_url sudah diset bootstrap.)

  CATATAN: kalau skill TIDAK muncul di /opt/data/skills/jobseeker/ ATAU tooling
  tidak ada di /opt/data/jobseeker/ (gejala bug path lama) → jalankan:
    curl -fsSL https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision/fix-platform-paths.sh -o /tmp/fix.sh
    bash /tmp/fix.sh

LANGKAH 6 — Verifikasi (semua harus OK):
  curl -s http://localhost:9222/json | head -5                    # CDP aktif
  curl -s -o /dev/null -w "noVNC: %{http_code}\n" http://localhost:6080/vnc.html   # 200
  curl -s http://localhost:8642/health                            # API server OK
  ls /opt/data/jobseeker/                                         # tooling ada (portal-check.py, report-application.py)
  ls /opt/data/skills/jobseeker/jobseeker-agent/SKILL.md          # skill base ada
  ls /opt/data/skills/jobseeker/ | grep portal                    # 5 skill portal (jobstreet, glints, linkedin, indeed, kalibrr)
  ls /opt/data/venv-cdp/bin/python                                # venv-cdp ada (untuk portal-check v3)
  hermes config get platforms.api_server.enabled                  # true
  ls /opt/data/jobseeker/portal-check.py                          # watchdog portal status (daftar portal dari BE)
  hermes cron list                                                 # cron 'vnc-stack-watchdog' terdaftar (every 10m)
  python3 /opt/data/jobseeker/check-quota.py                       # koneksi BE: exit 0 = terhubung (jika agent-config.env sudah terisi)
  python3 /opt/data/jobseeker/sync-profile.py                      # profil user ter-pull dari BE → user-profile.json (jika config terisi)
  python3 /opt/data/jobseeker/report-application.py pick --limit 1 # ambil 1 dari antrian queued (alur baru; ANTRIAN KOSONG = wajar bila BE belum isi)

LANGKAH 7 — Kumpulkan 2 secret, laporkan LANGSUNG ke operator
  (jangan tempel ke chat publik):
  cat /opt/data/home/vncsetup/run/vnc-jwt-secret                  # secret VNC JWT
  grep '^API_SERVER_KEY=' /opt/data/.env                          # API key Hermes (default: hasil generate di .env)
  Laporan ke operator: hasil verifikasi per item (OK/gagal/menunggu),
  hostname mesin (untuk tunnel), dan 2 secret di atas.
  (Tunnel publik 6080 & 8642 dibuat OPERATOR di panel SumoPod — mesin
  cukup melaporkan hostname-nya; URL publik pola https://<hostname>-6080/8642.)

LANGKAH 8 — Restart gateway (agar API server memakai config & key yang benar):
  /opt/hermes/bin/hermes gateway restart
  Setelah restart, verifikasi sekali lagi:
  curl -s http://localhost:8642/health    → {"status":"ok",...}
  # UJI key .env benar-benar dipakai (200 = OK · 401 = env container menimpa):
  KEY=$(grep '^API_SERVER_KEY=' /opt/data/.env | cut -d= -f2-)
  curl -s -o /dev/null -w "key .env → HTTP %{http_code}\n" http://localhost:8642/v1/chat/completions \
    -H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \
    -d '{"model":"hermes-agent","messages":[{"role":"user","content":"hi"}],"max_tokens":5}'
  # Kalau hasilnya 401 → API_SERVER_KEY di env container MENIMPA → HAPUS dari
  # container settings (panel SumoPod) lalu restart lagi.
  (Platform script sudah menjadwalkan restart +180 dtk bila config berubah —
  langkah ini memastikan restart bersih SETELAH semua langkah selesai.)

Catatan: gateway restart otomatis (bootstrap +60 dtk, platform +180 dtk bila
config berubah) — sesi mungkin terputus sebentar, itu normal, tidak perlu tindakan.

---
UPDATE MESIN EXISTING (sudah ter-config sebelumnya) — 1 perintah:
  bash <(curl -fsSL https://s3-autoapply-public.s3.ap-southeast-1.amazonaws.com/provision/update-mesin.sh)
  lalu: /opt/hermes/bin/hermes gateway restart
  (Refresh tooling v2, venv-cdp, 6 skill, cron — idempotent, secret tidak disentuh.)
---
