Sanitized anonymous distribution of the Infrastructure Ops Codex plugin
  • Python 97.1%
  • PowerShell 2.2%
  • Shell 0.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-08-10 18:16:20 +08:00
.agents/plugins release: infrastructure-ops v0.4.0 2026-08-09 06:57:25 +00:00
config release: infrastructure ops v0.7.0 2026-08-10 17:37:16 +08:00
plugins/infrastructure-ops release: infrastructure ops v0.7.1 2026-08-10 18:16:20 +08:00
scripts release: infrastructure ops v0.7.1 2026-08-10 18:16:20 +08:00
.gitattributes Release infrastructure-ops v0.6.1 2026-08-09 22:00:51 +08:00
DISTRIBUTION-MANIFEST.json release: infrastructure ops v0.7.1 2026-08-10 18:16:20 +08:00
README.md release: infrastructure ops v0.7.1 2026-08-10 18:16:20 +08:00
requirements.txt release: infrastructure-ops v0.4.0 2026-08-09 06:57:25 +00:00

Infrastructure Ops Codex Plugin

This is the sanitized, credential-free distribution of the Infrastructure Ops Codex plugin, release v0.7.1.

It contains seven Codex workflows and a standalone proxy-fleet controller:

  • infrastructure-registry
  • frp-gateway
  • aliyun-dns
  • public-app-release
  • operator-profile-sync
  • developer-machine-bootstrap
  • proxy-fleet

The standalone controller does not require Codex:

.\scripts\proxy_fleet.ps1 --registry <registry.json> --profile-manifest <profiles.json> plan --policy <policy-id>
./scripts/proxy_fleet.sh --registry <registry.json> --profile-manifest <profiles.json> plan --policy <policy-id>

Run it on a trusted management machine. Managed Ubuntu targets do not install this repository, Codex or a Skill and do not download the proxy client. The controller pushes pinned artifacts over SSH/Ansible.

It deliberately does not contain the private source repository, infrastructure topology, deployment records, live registries, credentials, private keys, tokens or server configuration.

Install

Clone the exact reviewed tag without an account:

git clone --branch v0.7.1 --depth 1 https://git.sivita.xyz/infra-admin/infrastructure-ops-dist.git
Set-Location infrastructure-ops-dist
.\scripts\bootstrap.ps1
git clone --branch v0.7.1 --depth 1 https://git.sivita.xyz/infra-admin/infrastructure-ops-dist.git
cd infrastructure-ops-dist
./scripts/bootstrap.sh

The bootstrap validates the distribution, creates an empty non-secret Registry v2 and empty proxy-profile manifest only when their runtime paths do not exist, registers the local Marketplace and installs infrastructure-ops@infrastructure-ops-local.

Start a new Codex task after plugin installation. Live operations require the management node to have its own reviewed Registry v2 and local credential references. Never paste passwords, access keys, FRP tokens or private keys into a Codex prompt.

To restore an existing operator environment, invoke operator-profile-sync after installation. It anonymously downloads a separate age-encrypted profile, then asks for the master password directly in the local terminal. Review its import plan before allowing --apply.

For a completely new developer machine, use the read-only planner and then repeat with explicit apply:

.\scripts\setup_machine.ps1
.\scripts\setup_machine.ps1 -Apply -RestoreProfile
./scripts/setup_machine.sh
./scripts/setup_machine.sh --apply --restore-profile

This installs the pinned developer CLI toolchain, installs the plugin, then optionally restores the encrypted operator profile in one ordered flow. Domestic Node/npm mirrors are tried first and official sources are retained as automatic fallbacks. Existing HTTPS_PROXY, HTTP_PROXY and NO_PROXY settings are inherited without being stored by the installer.

Verify

.\scripts\bootstrap.ps1 -VerifyOnly -SkipConfig
./scripts/bootstrap.sh --verify-only --skip-config

DISTRIBUTION-MANIFEST.json records the SHA-256 digest of every distributed file. Pin both the tag and exact commit supplied by the release operator.