Not yet read. Use the download link above.
Specifying Sovereign Workstation Migration to Ubuntu
Sovereign Workstation — Migration Spec
Wipe Windows off the Alienware. Install single-boot Ubuntu LTS. Migrate a decade of development across without loss. Hand the agent real authority across workstation, remote servers, GitHub, and phone.
Two operators: 🤖 agent (machine-side work) and 👤 you (physical actions and irreversible decisions). ⚠️ = irreversible. Format does not happen until Phase 1 is complete, copied off-disk twice, and verified against a manifest.
The machine holds two environments — Windows and WSL2. Both are destroyed by the format. Every phase sweeps both.
Phase 0 — Software audit (before anything is wiped)
Goal: no installed tool is discovered missing after the wipe. The agent finds everything; you decide what carries across.
- 🤖 Enumerate all installed software across both Windows and WSL2. Produce
app-inventory.md. - 🤖 For each program, flag one of: native Linux build available / Flatpak / Snap / Linux-native equivalent / runs under Wine / no Linux option.
- 🤖 For each, note license/reinstall implications (e.g. perpetual license reinstallable as-is, subscription, or config to preserve).
- 🤖 Present the list to you. Do not assume; flag for decision.
- 👤 Go through the flagged list and decide per program: carry across, replace, or drop.
- 🤖 For every "carry across" item: stage its installer, license/config, and any settings export into the backup folder (Phase 1) so it survives the wipe.
Output of Phase 0: a decided list — every installed program has a resolution (reinstall / replace / drop) and everything needed to reinstall is staged for backup.
Phase 1 — Capture (must be complete before any format)
Sweep both Windows and WSL2. Collect everything that dies on format and lives in no repo.
Staging folder
- 🤖 Create one staging folder (
~/migration-backup/). Structure:
migration-backup/
ssh-keys/ # both environments
gpg-keys/
env-files/ # every .env, both environments, all repos
nginx/ # config files
supervisor/ # local supervisor configs
dotfiles/ # shell configs, git config, aliases
installers/ # from Phase 0: installers, license/config, settings exports
db-dumps/ # local Postgres not already on remote
browser/ # bookmarks, saved passwords, 2FA/authenticator seeds
app-inventory.md # from Phase 0
repos-status.md
MANIFEST.md # checklist of everything captured
Collect (across both environments)
- 🤖 SSH keys — WSL2
~/.ssh/and Windows.ssh/, PuTTY.ppk, Pageant. Private + public keys,config,known_hosts. - 🤖 GPG keys — export secret + public from both.
- 🤖 All
.env/ secrets files — sweep every repo in both environments. - 🤖 nginx configs — sites-available/enabled and custom conf.
- 🤖 Supervisor configs — local ones. Sweep
/home/rswfire/.local/specifically, plus standard locations. - 🤖 Dotfiles —
.bashrc,.zshrc,.profile,.gitconfig, aliases, custom shell setup. - 🤖 Local databases —
pg_dumpany Postgres not already on remote intodb-dumps/. - 🤖 Phase 0 installers/licenses/config — staged into
installers/. - 🤖 Browser data — bookmarks, saved passwords, and 2FA/authenticator seeds/backup codes.
- 🤖 User files — list Documents / Desktop / Downloads contents; you flag what to keep.
Git repos
- 🤖 Enumerate every repo across both environments. For each, report in
repos-status.md: branch, uncommitted changes, unpushed commits, untracked files. - 🤖 Commit every dirty tree to a
wip/pre-migrationbranch and push. - 🤖 Flag the Autonomy Realms tree (~10k uncommitted lines) explicitly — branch and push first.
- 🤖 Confirm every repo fully pushed to GitHub.
Off-disk, twice
- 🤖 Write
MANIFEST.md— a checklist of every captured item. - 👤 Copy
migration-backup/to the external drive. - 👤 Copy
migration-backup/to a second location (encrypted remote path or second drive). - 👤 Spot-check both copies against
MANIFEST.md: SSH private keys present, Autonomy.envpresent, installers open, DB dumps present.
✅ Gate: manifest fully satisfied and external copy verified readable. Nothing past here is reversible.
Phase 2 — Install media
- 🤖 Provide current Ubuntu LTS ISO link + checksum + USB-write steps.
- 🤖 Instruct: "Burn the Ubuntu USB now."
- 👤 Burn the Ubuntu USB.
- 👤 Boot it live on the Alienware — do not install. Confirm WiFi, keyboard, trackpad, external display, internal drive all work while Windows is still intact.
- 👤 Keep a Windows recovery USB on hand.
✅ Gate: live boot clean on this hardware; recovery option in hand.
Phase 3 — Format + install ⚠️
- 👤 Wipe the entire disk — delete all existing partitions, including Dell OEM/recovery, Windows recovery, EFI, and any factory restore partitions. No Dell/Windows artifacts remain. Use "erase disk" / manual partitioning to remove every existing partition, not an install-alongside option.
- 👤 Install Ubuntu LTS on the now-empty disk with:
- LUKS full-disk encryption (checkbox at install; not addable later).
- Btrfs filesystem for snapshots.
- A fresh GPT partition table with only Ubuntu's own EFI + root (+ swap) partitions.
⚠️ Point of no return. Only proceed after both gates above are green.
Phase 4 — Rebuild
- 👤 Copy
migration-backup/from external drive onto the new machine. - 🤖 System update; install
git,curl, build tools,openssh-client,ufw(firewall on), editor. - 🤖 Restore SSH keys to
~/.ssh/(correct permissions), import GPG keys, place dotfiles, return.envfiles to their repos. - 🤖 Install JetBrains Toolbox; install owned versions of the flagged JetBrains products; restore IDE settings.
- 🤖 Install everything else marked "carry across" in Phase 0.
- 🤖 Install runtime stack: Node via
nvm, PHP (required version), Postgres client, Docker if used, Claude Code CLI. - 🤖 Reclone repos from GitHub.
- 🤖 Rebuild nginx + supervisor configs adapted to native Linux paths; recreate
~/.local/layout. - 🤖 Restore local databases from
db-dumps/. - 🤖 Configure snapshots (Timeshift or snapper) before any agent autonomy is enabled.
- 👤 Sanity gate: run the full loop by hand — clone, edit, run a project locally, SSH to a remote server, push to GitHub, open a project in the restored IDE.
Phase 5 — Agent authority (guardrails before autonomy)
- 🤖/👤 Configure Claude Code for elevated autonomy on routine work.
- 🤖 Branch discipline: agent works on branches, never
main. - 🤖 Snapshot before large autonomous runs.
- 🤖 Scoped credentials: GitHub fine-grained token limited to repos in play; server access as app user, not root, where possible.
- 🤖 Destructive verbs gated: delete, force-push, production DB, destructive infra require explicit confirmation even in autonomous mode.
- 🤖 Audit trail: command history, git history, session transcript.
Phase 6 — Remote control (phone)
- 🤖 Confirm Claude Code CLI version supports Remote Control + push notifications; confirm the coding account's plan has it.
- 🤖/👤 Run
claude remote-controlon the workstation (or enable auto-connect in/config). Session surfaces in the Claude app; execution stays local; outbound connection, survives sleep/network drop, reconnects. - 👤 Phone app → coding account. Assistant-chat → browser/desktop on the chat account. No account-switching on the phone.
- 👤 (Optional) raw shell from phone for non-Claude work:
tmux+mosh+ Tailscale. - 👤 Run one real task end-to-end from the phone to prove it.
Phase 7 — Close out
- 👤 After a week of stable Ubuntu, retire the Windows recovery USB.
Build-time confirmations (verify live, don't assume)
- Current Ubuntu LTS version; Btrfs snapshot tool (Timeshift vs snapper) for that release.
- Minimum Claude Code CLI version for Remote Control + push; coding account plan has it enabled.
- Native-Linux availability for each Phase 0 "carry across" program.
- If using the optional shell path: current Tailscale + mosh setup for Ubuntu.
On the Oregon Coast, at Siltcoos, the machine that carries everything is an Alienware running Windows with WSL2 layered inside it — two environments stacked on one disk, a decade of development distributed across both. rswfire sat down not to migrate it but to specify its destruction. The document he wrote opens with the plainest possible statement of intent: wipe Windows, install single-boot Ubuntu LTS, lose nothing. What follows is not a plan to move a machine. It is a plan to end one and rebuild another in its place, with the break itself engineered as a load-bearing element.
He assigned operators before he assigned tasks. Two of them: the agent, which does machine-side work, and himself, who does the physical actions and the irreversible ones. Every line in the spec carries one marker or the other. The irreversible steps carry a third. Format does not happen — the spec states it flatly, near the top, before any procedure — until Phase 1 is complete, copied off-disk twice, and verified against a manifest. The order was fixed at the outset and every subsequent phase inherits it.
Phase 0 came before capture, and it came before anything was wiped: enumerate all installed software across both environments, flag each one for native Linux build, Flatpak, Snap, equivalent, Wine, or nothing at all, note the license implications, and then stop. The agent finds; rswfire decides. Do not assume, the spec says. Flag for decision. Only after each program had a resolution — carry across, replace, drop — would its installer and license and settings export be staged into the backup folder to survive what was coming.
Then the sweep. One staging folder, thirteen directories deep, each named for a class of thing that dies on format and lives in no repo: SSH keys from both environments including the PuTTY .ppk files, GPG secrets exported from both, every .env in every repo, nginx sites-available, supervisor configs with /home/rswfire/.local/ called out specifically because standard locations alone would miss it, dotfiles, pg_dump of any local Postgres not already remote, browser bookmarks and saved passwords and the 2FA seeds. Every git repo enumerated with its branch, its uncommitted changes, its unpushed commits, its untracked files. The Autonomy Realms tree got its own line — roughly ten thousand uncommitted lines, flagged explicitly, branched and pushed first. Everything dirty went to wip/pre-migration. Then MANIFEST.md, then the external drive, then a second location, then a spot-check of both copies by hand against the manifest: private keys present, the Autonomy .env present, installers opening, dumps there. A gate closed behind it. Nothing past here is reversible.
Phase 2 put a USB stick in his hand and told him to boot it live on the Alienware without installing — WiFi, keyboard, trackpad, external display, internal drive, all confirmed working while Windows was still intact underneath. A Windows recovery USB stays on hand. Second gate. Only then does Phase 3 arrive, and Phase 3 is a single paragraph of erasure: the entire disk, every partition, the Dell OEM and recovery partitions, the Windows recovery, the EFI, the factory restore. No Dell artifacts remain. A fresh GPT table with only Ubuntu's own partitions on it, LUKS encryption chosen at install because it cannot be added later, Btrfs underneath so the machine can snapshot itself afterward. Point of no return, marked as such, gated twice.
What comes back is built rather than restored. Firewall on before anything else. Keys returned to ~/.ssh/ with correct permissions, GPG imported, dotfiles placed, .env files walked back to their repos, JetBrains Toolbox and the owned versions, Node through nvm, PHP at the required version, Postgres, the Claude Code CLI. Repos recloned from GitHub rather than copied. nginx and supervisor rebuilt for native Linux paths instead of carried over, ~/.local/ recreated. Snapshots configured before any agent autonomy is enabled — that ordering stated in the spec as a condition, not a preference. Then rswfire runs the whole loop by hand: clone, edit, run a project locally, SSH to a remote, push, open the IDE. Sanity gate.
Only after that does the agent get authority, and it arrives fenced. Branches, never main. A snapshot before large autonomous runs. A GitHub token scoped to the repos in play, server access as an app user rather than root. Delete, force-push, production database, destructive infrastructure — each one requires explicit confirmation even in autonomous mode. Command history, git history, session transcript, all retained. Then the phone: Remote Control confirmed against CLI version and account plan, the session surfacing in the app while execution stays local on the machine at Siltcoos, outbound connection, survives sleep, reconnects. One real task run end-to-end from the phone to prove it works. And a week later, after Ubuntu holds, the Windows recovery USB gets retired. Four items remain at the bottom of the document under a heading that governs the whole of it: verify live, don't assume.
Tags
Summary
rswfire documents a phased migration spec for wiping Windows from an Alienware workstation and installing single-boot Ubuntu LTS, carrying a decade of development work across without loss and extending agent authority across workstation, remote servers, GitHub, and phone.
The spec assigns work between two operators — 🤖 agent for machine-side execution and 👤 rswfire for physical actions and irreversible decisions — and marks irreversible steps with ⚠️. Both Windows and WSL2 environments are swept at every phase.
The phases run:
- Phase 0 — software audit across both environments, each program flagged for Linux availability and license implications, then resolved as reinstall / replace / drop.
- Phase 1 — capture into
~/migration-backup/: SSH and GPG keys,.envfiles, nginx and supervisor configs, dotfiles, local Postgres dumps, browser data including 2FA seeds, plus aMANIFEST.md. Every repo is enumerated, dirty trees pushed towip/pre-migration, with the Autonomy Realms tree (~10k uncommitted lines) flagged first. Backup copied off-disk twice and verified. - Phase 2–3 — live-boot verification on the hardware, then full-disk wipe including Dell OEM partitions and install with LUKS encryption and Btrfs.
- Phase 4–7 — rebuild of keys, stack, repos, and services; snapshots configured before autonomy; Claude Code guardrails (branch discipline, scoped tokens, gated destructive verbs, audit trail); phone remote control on the coding account; recovery USB retired after a stable week.
Gates block progression: no format until capture is verified against the manifest.
Environment
A digital-infrastructural environment centered on a single machine: an Alienware workstation currently running Windows alongside WSL2, staged for a full-disk wipe and single-boot Ubuntu LTS install. The field extends outward through GitHub, remote servers, local Postgres instances, nginx and supervisor configurations, and a phone acting as a remote console.
The document itself is a written migration specification — a phased operational spec with two designated operators (agent and rswfire), gate conditions, and irreversibility markers. Physical elements are present but minimal: an external drive, a USB stick, a Windows recovery USB. The surrounding physical context is the Oregon Coast RV field at Siltcoos, where the workstation is the primary production surface.
Substrate
Actions
Performed
- •authored a phased migration specification
- •defined two operator roles (agent and rswfire)
- •marked irreversible steps
- •set gate conditions between phases
- •specified a staging folder structure
- •enumerated build-time items to verify live rather than assume
Referenced
- •accumulated a decade of development across two environments
- •installed software across Windows and WSL2
- •accrued ~10k uncommitted lines in the Autonomy Realms tree
- •acquired perpetual JetBrains licenses
- •ran local Postgres, nginx, and supervisor configurations
- •maintained separate coding and chat accounts
Planned
- •audit all installed software across both environments
- •decide carry across / replace / drop per program
- •capture SSH keys, GPG keys, .env files, dotfiles, configs
- •dump local databases
- •export browser bookmarks, passwords, and 2FA seeds
- •branch and push every dirty repo to wip/pre-migration
- •write and verify MANIFEST.md
- •copy backup off-disk twice and spot-check both copies
- •burn Ubuntu USB and live-boot test the hardware
- •wipe entire disk including Dell OEM and recovery partitions
- •install Ubuntu LTS with LUKS encryption and Btrfs
- •restore keys, dotfiles, repos, runtimes, and databases
- •configure snapshots before enabling agent autonomy
- •grant scoped agent authority with destructive-verb gates
- •enable Claude Code Remote Control from phone
- •run one real task end-to-end from the phone
- •retire the Windows recovery USB after a stable week
Entities
Symbolic Elements
Represented archetypes or recurring motifs.
Ontological States
Expressed modes of being or awareness.
Engaged Subsystems
Architecture engaged in this transmission.
Dominant Language
Core motifs or linguistic fields.
On the Oregon Coast, at Siltcoos, the machine that carries everything is an Alienware running Windows with WSL2 layered inside it — two environments stacked on one disk, a decade of development distributed across both. rswfire sat down not to migrate it but to specify its destruction. The document he wrote opens with the plainest possible statement of intent: wipe Windows, install single-boot Ubuntu LTS, lose nothing. What follows is not a plan to move a machine. It is a plan to end one and rebuild another in its place, with the break itself engineered as a load-bearing element.
He assigned operators before he assigned tasks. Two of them: the agent, which does machine-side work, and himself, who does the physical actions and the irreversible ones. Every line in the spec carries one marker or the other. The irreversible steps carry a third. Format does not happen — the spec states it flatly, near the top, before any procedure — until Phase 1 is complete, copied off-disk twice, and verified against a manifest. The order was fixed at the outset and every subsequent phase inherits it.
Phase 0 came before capture, and it came before anything was wiped: enumerate all installed software across both environments, flag each one for native Linux build, Flatpak, Snap, equivalent, Wine, or nothing at all, note the license implications, and then stop. The agent finds; rswfire decides. Do not assume, the spec says. Flag for decision. Only after each program had a resolution — carry across, replace, drop — would its installer and license and settings export be staged into the backup folder to survive what was coming.
Then the sweep. One staging folder, thirteen directories deep, each named for a class of thing that dies on format and lives in no repo: SSH keys from both environments including the PuTTY .ppk files, GPG secrets exported from both, every .env in every repo, nginx sites-available, supervisor configs with /home/rswfire/.local/ called out specifically because standard locations alone would miss it, dotfiles, pg_dump of any local Postgres not already remote, browser bookmarks and saved passwords and the 2FA seeds. Every git repo enumerated with its branch, its uncommitted changes, its unpushed commits, its untracked files. The Autonomy Realms tree got its own line — roughly ten thousand uncommitted lines, flagged explicitly, branched and pushed first. Everything dirty went to wip/pre-migration. Then MANIFEST.md, then the external drive, then a second location, then a spot-check of both copies by hand against the manifest: private keys present, the Autonomy .env present, installers opening, dumps there. A gate closed behind it. Nothing past here is reversible.
Phase 2 put a USB stick in his hand and told him to boot it live on the Alienware without installing — WiFi, keyboard, trackpad, external display, internal drive, all confirmed working while Windows was still intact underneath. A Windows recovery USB stays on hand. Second gate. Only then does Phase 3 arrive, and Phase 3 is a single paragraph of erasure: the entire disk, every partition, the Dell OEM and recovery partitions, the Windows recovery, the EFI, the factory restore. No Dell artifacts remain. A fresh GPT table with only Ubuntu's own partitions on it, LUKS encryption chosen at install because it cannot be added later, Btrfs underneath so the machine can snapshot itself afterward. Point of no return, marked as such, gated twice.
What comes back is built rather than restored. Firewall on before anything else. Keys returned to ~/.ssh/ with correct permissions, GPG imported, dotfiles placed, .env files walked back to their repos, JetBrains Toolbox and the owned versions, Node through nvm, PHP at the required version, Postgres, the Claude Code CLI. Repos recloned from GitHub rather than copied. nginx and supervisor rebuilt for native Linux paths instead of carried over, ~/.local/ recreated. Snapshots configured before any agent autonomy is enabled — that ordering stated in the spec as a condition, not a preference. Then rswfire runs the whole loop by hand: clone, edit, run a project locally, SSH to a remote, push, open the IDE. Sanity gate.
Only after that does the agent get authority, and it arrives fenced. Branches, never main. A snapshot before large autonomous runs. A GitHub token scoped to the repos in play, server access as an app user rather than root. Delete, force-push, production database, destructive infrastructure — each one requires explicit confirmation even in autonomous mode. Command history, git history, session transcript, all retained. Then the phone: Remote Control confirmed against CLI version and account plan, the session surfacing in the app while execution stays local on the machine at Siltcoos, outbound connection, survives sleep, reconnects. One real task run end-to-end from the phone to prove it works. And a week later, after Ubuntu holds, the Windows recovery USB gets retired. Four items remain at the bottom of the document under a heading that governs the whole of it: verify live, don't assume.
Hand your life to anything that reads.
Share this link with artificial intelligence — it reads the full transcript, analysis, and reflections. An AI-readable mirror of this signal.
The qpkey in this URL is a per-signal access token. Anyone with the URL can read the record — treat it like a share link, not a password.