51 yes/no prompts and ~20 free-text ones, of which about six actually need a human.
The line drawn is "a question with a default answers itself; a question with no
possible default still asks", so it stays attended without being a conversation.
Half of it already existed: ASSUME_YES=1 was implemented and honoured by confirm()
in both scripts, returning each question's OWN default — so a "do the thing you
asked for" question goes yes and a genuine extra goes no. --unattended sets it.
The new part is menu_answer(), for the eight numbered menus. It sets the variable
EMPTY rather than passing a default in, because every menu already consumes its
choice as `${CHOICE:-<n>}` — the default lives next to the options it selects
between, which is the right place, and a second copy in the helper could drift from
the one the prompt advertises. Verified all eight consume that way before touching
them. `read <<<''` rather than eval or `declare -g`, which is bash 4.2+ and rules
out the bash 3.2 macOS still ships.
officer-setup's ask_required takes its default too, except where there is none — the
owning account on a machine machine-setup never ran on, where a guess would install
as the wrong user.
STILL ASKS, deliberately: the username; the Tailscale control plane, login server
and auth key; the git identity; and an SSH public key when the account has none.
That last one is a trap I nearly walked into — on a fresh VPS KEY_COUNT==0 forces
ADD_KEY=true with no confirm, and the menu's default is "[1] paste a public key",
which then prompts with no default at all. Auto-answering that menu would hang or
fail, so it is excluded by name. adduser also still asks for a password; that is
the tool, not us.
Two pre-existing bugs fixed on the way: machine-setup's sudo re-exec passed "$@"
after `shift` had emptied it, so --only and --reask stopped existing the moment it
escalated — same bug as officer-setup had. And UNATTENDED/ASSUME_YES are named in
all three sudo lists, because env_reset would otherwise drop the flag at
escalation, which is now the fourth variable lost that way.
Verified: bash -n on five files, --help on all three, and menu_answer + confirm
under the flag showing a menu resolving to its default and a no-default confirm
correctly answering no.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The documentation, triaged
2026-08-13. A map of what is in here, what it is for, and what should happen to it. Made because there are 42 documents and 13,000 lines, and no way to tell from the filenames which describe the system as it is and which are a record of an afternoon in July.
How much I verified: the classifications below are from filenames, status lines, and greps for things that changed on 2026-08-13. Where I actually read the document or checked the code, it says so. The rest is a starting point for a conversation, not a verdict.
Living — these describe the system and must stay true
| doc | state |
|---|---|
working-on-officer.md |
updated 2026-08-13. Operational guide. |
secret-store.md |
updated 2026-08-13. Built; rotation still open. |
install-variants.md |
new. The branch tree, for discussion. |
http-secure-context-audit.md |
new. What breaks over plain http. |
install-container-testing.md |
new. First container pass and its findings. |
per-user-linux-accounts.md |
partly updated. OFFICER_OS_USERS is gone; check the rest. |
navigation-audit.md |
authoritative on routing. Unverified against tonight's route removals. |
workspace-panels.md + workspace-panel-todo.md |
the panel framework. 1,300 lines combined — likely the biggest cleanup here. |
agent-coordination.md |
the north star for panel work. |
deprovision-os-account.md |
implemented; the 'disabled' stage it may mention was deleted tonight. |
Stale — describe things that changed on 2026-08-13
Each of these references something that no longer exists. Not yet corrected.
sidecar-topology.md— "ecosystem.config.cjs is the source of truth". It is generated now, and holds six processes.sidecar-app-store.md— derives the catalogue fromfull − light. Those files are gone, andcatalogue.test.tswas rewritten.sidecar-bootstrapping.md— "20 PM2 entries, 18 sidecar dirs". Six entries now.mobile-api-keys.md— partly corrected; recheck the origin-checking claims.wallet-key-custody.md—VAULT_STORE_KEYis now the per-purposewalletkey.push-notifications.md— "agreed design, 2026-07-31". Notify is a plugin and unmounted.chat-session-lifetime.md,chat-ui-walkthrough.md— referenceofficer-agent, renamed.
Historical — a record of a moment, and should stay one
Do not rewrite these to match today's code. They document how a decision was reached, and editing them destroys the reasoning. If they mislead, add a dated header pointing forward.
sidecar-audit-2026-07.md(1,377 lines)claude-sidecar-isolation.md— records theofficer-claude→officer-agentrename that preceded tonight'sofficer-agent→officer-claude-codeopen-threads-after-per-user-claude.mdtwo-agent-field-report-2026-08-12.mdapi-method-changes-2026-08-06.md
The opencode cluster — nine documents for one migration
opencode-fork-decision · -parity · -api-2-assessment · -phase0-review · -phase1-report ·
-phase1-review · -serve-migration-plan · -serve-path · -testing-checklist
The migration landed — opencode serve is in the sidecar, verified. So
opencode-serve-migration-plan.md saying "Nothing here is implemented" is false.
This is the clearest consolidation candidate in the whole directory: one document recording what was decided and what shipped, replacing nine that describe stages of getting there. I did not do it because it needs reading all nine, and deleting documents unread is not a thing to do at 4am.
The mobile-dav thread — three documents, one conversation
mobile-dav-provisioning · -feedback · -reply. A correspondence. Almost certainly one document.
Unclassified — I have not looked
design-language-interface · file-sync · jobs-unification · mobile-photo-sync-api ·
nextcloud-replacement · agent-git-identity
The plugin split, which affects most of the above
A core install is six processes. Everything else is a plugin, switched off tonight but present on disk. Most documents here were written when the estate was twenty processes and every one of them was simply "there", so they describe availability that no longer holds.
The useful rewrite is usually one line, not a rewrite: say whether the thing described is core or a plugin, and if a plugin, that it is not mounted on a fresh install.