Specifying Sovereign Workstation Migration to Ubuntu

Sovereign Workstation — Migration Spec

Wipe Windows off the Alienware. Install single-boot Ubuntu LTS. Migrate a decade of development across without loss. Hand the agent real authority across workstation, remote servers, GitHub, and phone.

Two operators: 🤖 agent (machine-side work) and 👤 you (physical actions and irreversible decisions). ⚠️ = irreversible. Format does not happen until Phase 1 is complete, copied off-disk twice, and verified against a manifest.

The machine holds two environments — Windows and WSL2. Both are destroyed by the format. Every phase sweeps both.


Phase 0 — Software audit (before anything is wiped)

Goal: no installed tool is discovered missing after the wipe. The agent finds everything; you decide what carries across.

  • 🤖 Enumerate all installed software across both Windows and WSL2. Produce app-inventory.md.
  • 🤖 For each program, flag one of: native Linux build available / Flatpak / Snap / Linux-native equivalent / runs under Wine / no Linux option.
  • 🤖 For each, note license/reinstall implications (e.g. perpetual license reinstallable as-is, subscription, or config to preserve).
  • 🤖 Present the list to you. Do not assume; flag for decision.
  • 👤 Go through the flagged list and decide per program: carry across, replace, or drop.
  • 🤖 For every "carry across" item: stage its installer, license/config, and any settings export into the backup folder (Phase 1) so it survives the wipe.

Output of Phase 0: a decided list — every installed program has a resolution (reinstall / replace / drop) and everything needed to reinstall is staged for backup.


Phase 1 — Capture (must be complete before any format)

Sweep both Windows and WSL2. Collect everything that dies on format and lives in no repo.

Staging folder

  • 🤖 Create one staging folder (~/migration-backup/). Structure:
migration-backup/
  ssh-keys/            # both environments
  gpg-keys/
  env-files/           # every .env, both environments, all repos
  nginx/               # config files
  supervisor/          # local supervisor configs
  dotfiles/            # shell configs, git config, aliases
  installers/          # from Phase 0: installers, license/config, settings exports
  db-dumps/            # local Postgres not already on remote
  browser/             # bookmarks, saved passwords, 2FA/authenticator seeds
  app-inventory.md     # from Phase 0
  repos-status.md
  MANIFEST.md          # checklist of everything captured

Collect (across both environments)

  • 🤖 SSH keys — WSL2 ~/.ssh/ and Windows .ssh/, PuTTY .ppk, Pageant. Private + public keys, config, known_hosts.
  • 🤖 GPG keys — export secret + public from both.
  • 🤖 All .env / secrets files — sweep every repo in both environments.
  • 🤖 nginx configs — sites-available/enabled and custom conf.
  • 🤖 Supervisor configs — local ones. Sweep /home/rswfire/.local/ specifically, plus standard locations.
  • 🤖 Dotfiles — .bashrc, .zshrc, .profile, .gitconfig, aliases, custom shell setup.
  • 🤖 Local databases — pg_dump any Postgres not already on remote into db-dumps/.
  • 🤖 Phase 0 installers/licenses/config — staged into installers/.
  • 🤖 Browser data — bookmarks, saved passwords, and 2FA/authenticator seeds/backup codes.
  • 🤖 User files — list Documents / Desktop / Downloads contents; you flag what to keep.

Git repos

  • 🤖 Enumerate every repo across both environments. For each, report in repos-status.md: branch, uncommitted changes, unpushed commits, untracked files.
  • 🤖 Commit every dirty tree to a wip/pre-migration branch and push.
  • 🤖 Flag the Autonomy Realms tree (~10k uncommitted lines) explicitly — branch and push first.
  • 🤖 Confirm every repo fully pushed to GitHub.

Off-disk, twice

  • 🤖 Write MANIFEST.md — a checklist of every captured item.
  • 👤 Copy migration-backup/ to the external drive.
  • 👤 Copy migration-backup/ to a second location (encrypted remote path or second drive).
  • 👤 Spot-check both copies against MANIFEST.md: SSH private keys present, Autonomy .env present, installers open, DB dumps present.

✅ Gate: manifest fully satisfied and external copy verified readable. Nothing past here is reversible.


Phase 2 — Install media

  • 🤖 Provide current Ubuntu LTS ISO link + checksum + USB-write steps.
  • 🤖 Instruct: "Burn the Ubuntu USB now."
  • 👤 Burn the Ubuntu USB.
  • 👤 Boot it live on the Alienware — do not install. Confirm WiFi, keyboard, trackpad, external display, internal drive all work while Windows is still intact.
  • 👤 Keep a Windows recovery USB on hand.

✅ Gate: live boot clean on this hardware; recovery option in hand.


Phase 3 — Format + install ⚠️

  • 👤 Wipe the entire disk — delete all existing partitions, including Dell OEM/recovery, Windows recovery, EFI, and any factory restore partitions. No Dell/Windows artifacts remain. Use "erase disk" / manual partitioning to remove every existing partition, not an install-alongside option.
  • 👤 Install Ubuntu LTS on the now-empty disk with:
    • LUKS full-disk encryption (checkbox at install; not addable later).
    • Btrfs filesystem for snapshots.
    • A fresh GPT partition table with only Ubuntu's own EFI + root (+ swap) partitions.

⚠️ Point of no return. Only proceed after both gates above are green.


Phase 4 — Rebuild

  • 👤 Copy migration-backup/ from external drive onto the new machine.
  • 🤖 System update; install git, curl, build tools, openssh-client, ufw (firewall on), editor.
  • 🤖 Restore SSH keys to ~/.ssh/ (correct permissions), import GPG keys, place dotfiles, return .env files to their repos.
  • 🤖 Install JetBrains Toolbox; install owned versions of the flagged JetBrains products; restore IDE settings.
  • 🤖 Install everything else marked "carry across" in Phase 0.
  • 🤖 Install runtime stack: Node via nvm, PHP (required version), Postgres client, Docker if used, Claude Code CLI.
  • 🤖 Reclone repos from GitHub.
  • 🤖 Rebuild nginx + supervisor configs adapted to native Linux paths; recreate ~/.local/ layout.
  • 🤖 Restore local databases from db-dumps/.
  • 🤖 Configure snapshots (Timeshift or snapper) before any agent autonomy is enabled.
  • 👤 Sanity gate: run the full loop by hand — clone, edit, run a project locally, SSH to a remote server, push to GitHub, open a project in the restored IDE.

Phase 5 — Agent authority (guardrails before autonomy)

  • 🤖/👤 Configure Claude Code for elevated autonomy on routine work.
  • 🤖 Branch discipline: agent works on branches, never main.
  • 🤖 Snapshot before large autonomous runs.
  • 🤖 Scoped credentials: GitHub fine-grained token limited to repos in play; server access as app user, not root, where possible.
  • 🤖 Destructive verbs gated: delete, force-push, production DB, destructive infra require explicit confirmation even in autonomous mode.
  • 🤖 Audit trail: command history, git history, session transcript.

Phase 6 — Remote control (phone)

  • 🤖 Confirm Claude Code CLI version supports Remote Control + push notifications; confirm the coding account's plan has it.
  • 🤖/👤 Run claude remote-control on the workstation (or enable auto-connect in /config). Session surfaces in the Claude app; execution stays local; outbound connection, survives sleep/network drop, reconnects.
  • 👤 Phone app → coding account. Assistant-chat → browser/desktop on the chat account. No account-switching on the phone.
  • 👤 (Optional) raw shell from phone for non-Claude work: tmux + mosh + Tailscale.
  • 👤 Run one real task end-to-end from the phone to prove it.

Phase 7 — Close out

  • 👤 After a week of stable Ubuntu, retire the Windows recovery USB.

Build-time confirmations (verify live, don't assume)

  • Current Ubuntu LTS version; Btrfs snapshot tool (Timeshift vs snapper) for that release.
  • Minimum Claude Code CLI version for Remote Control + push; coding account plan has it enabled.
  • Native-Linux availability for each Phase 0 "carry across" program.
  • If using the optional shell path: current Tailscale + mosh setup for Ubuntu.
Citation
·
Summer at Siltcoos - Day 1
May 1, 2026
1:29
Opening a Series to Introduce Autonomy Realms
May 1, 2026
4:27
Introducing Autonomy on Trail Walk to Ocean
May 1, 2026
Summer at Siltcoos - Day 2
May 2, 2026
Summer at Siltcoos - Day 3
May 3, 2026
Summer at Siltcoos - Day 4
May 4, 2026
Final Statement to the Oregon Parks and Recreation Department
May 4, 2026
Campfire after saying goodbye.
May 4, 2026
Summer at Siltcoos: Day 6
May 6, 2026
Summer at Siltcoos: Day 7
May 7, 2026
Summer at Siltcoos: Day 8
May 8, 2026
Summer at Siltcoos: Day 9
May 9, 2026
Summer at Siltcoos: Day 10
May 10, 2026
Summer at Siltcoos: Day 12
May 12, 2026
7:58
Documenting Jeep Repossession Deadline and Ended Friendship
May 12, 2026
Publishing AI Orientation Document for Queryable Personhood
May 13, 2026
Summer at Siltcoos: Day 13
May 13, 2026
Summer at Siltcoos: Day 14
May 14, 2026
Summer at Siltcoos: Day 15
May 15, 2026
19:57
Walking to the Ocean, Announcing Autonomy Realms Launch
May 15, 2026
Summer at Siltcoos: Day 16
May 16, 2026
6:12
Introducing Autonomy Realms on Walk to the Ocean
May 18, 2026
Summer at Siltcoos: Day 19
May 19, 2026
2:46
Returning to the Lagoon Bench One Year Later
May 19, 2026
Summer at Siltcoos: Day 20
May 20, 2026
Summer at Siltcoos: Day 21
May 21, 2026
12:09
Walking to Ocean, Opening the Privileged Sanctum Tier
May 31, 2026
Summer at Siltcoos: Day 33: Photos
Jun 2, 2026
3:27
Introducing Autonomy Realms While Hiking Back
Jun 13, 2026
Publishing Orientation Document for AI Collaborators
Jun 15, 2026
12:36
Walking to the Ocean, Demonstrating the Atlas
Jun 23, 2026
23:55
Walking to Siltcoos Lake, Mapping Autonomy Realms' Next Layer
Jul 4, 2026
Specifying Sovereign Workstation Migration to Ubuntu
Jul 6, 2026
Tahkenitch to the Beach
Jul 12, 2026
5:55
Field-Testing Trace Notes Feature While Walking Dunes
Aug 4, 2026
10:38
Announcing Legal Fund for OPRD Accountability
Aug 29, 2026
The Case, In Their Documents
Aug 30, 2026
Serving Formal Tort Claim Notice on the State of Oregon
Sep 3, 2026
Labor Day Letter to OPRD Director Sumption
Sep 7, 2026
Letter to Lane County Sheriff's Office
Sep 9, 2026
Letter to Detective Nelson on Institutional Characterization
Sep 10, 2026
PUBLIC
July 6, 2026 rswfire PUBLISHED
Temp 0.20
Density 0.60
Energetic Quality
methodical, high-precision
Journey Phase
pre-threshold / staged for irreversible transition
Directional Vector
toward sovereign infrastructure and delegated machine authority, away from proprietary OS dependency
Narrative

On the Oregon Coast, at Siltcoos, the machine that carries everything is an Alienware running Windows with WSL2 layered inside it — two environments stacked on one disk, a decade of development distributed across both. rswfire sat down not to migrate it but to specify its destruction. The document he wrote opens with the plainest possible statement of intent: wipe Windows, install single-boot Ubuntu LTS, lose nothing. What follows is not a plan to move a machine. It is a plan to end one and rebuild another in its place, with the break itself engineered as a load-bearing element.

He assigned operators before he assigned tasks. Two of them: the agent, which does machine-side work, and himself, who does the physical actions and the irreversible ones. Every line in the spec carries one marker or the other. The irreversible steps carry a third. Format does not happen — the spec states it flatly, near the top, before any procedure — until Phase 1 is complete, copied off-disk twice, and verified against a manifest. The order was fixed at the outset and every subsequent phase inherits it.

Phase 0 came before capture, and it came before anything was wiped: enumerate all installed software across both environments, flag each one for native Linux build, Flatpak, Snap, equivalent, Wine, or nothing at all, note the license implications, and then stop. The agent finds; rswfire decides. Do not assume, the spec says. Flag for decision. Only after each program had a resolution — carry across, replace, drop — would its installer and license and settings export be staged into the backup folder to survive what was coming.

Then the sweep. One staging folder, thirteen directories deep, each named for a class of thing that dies on format and lives in no repo: SSH keys from both environments including the PuTTY .ppk files, GPG secrets exported from both, every .env in every repo, nginx sites-available, supervisor configs with /home/rswfire/.local/ called out specifically because standard locations alone would miss it, dotfiles, pg_dump of any local Postgres not already remote, browser bookmarks and saved passwords and the 2FA seeds. Every git repo enumerated with its branch, its uncommitted changes, its unpushed commits, its untracked files. The Autonomy Realms tree got its own line — roughly ten thousand uncommitted lines, flagged explicitly, branched and pushed first. Everything dirty went to wip/pre-migration. Then MANIFEST.md, then the external drive, then a second location, then a spot-check of both copies by hand against the manifest: private keys present, the Autonomy .env present, installers opening, dumps there. A gate closed behind it. Nothing past here is reversible.

Phase 2 put a USB stick in his hand and told him to boot it live on the Alienware without installing — WiFi, keyboard, trackpad, external display, internal drive, all confirmed working while Windows was still intact underneath. A Windows recovery USB stays on hand. Second gate. Only then does Phase 3 arrive, and Phase 3 is a single paragraph of erasure: the entire disk, every partition, the Dell OEM and recovery partitions, the Windows recovery, the EFI, the factory restore. No Dell artifacts remain. A fresh GPT table with only Ubuntu's own partitions on it, LUKS encryption chosen at install because it cannot be added later, Btrfs underneath so the machine can snapshot itself afterward. Point of no return, marked as such, gated twice.

What comes back is built rather than restored. Firewall on before anything else. Keys returned to ~/.ssh/ with correct permissions, GPG imported, dotfiles placed, .env files walked back to their repos, JetBrains Toolbox and the owned versions, Node through nvm, PHP at the required version, Postgres, the Claude Code CLI. Repos recloned from GitHub rather than copied. nginx and supervisor rebuilt for native Linux paths instead of carried over, ~/.local/ recreated. Snapshots configured before any agent autonomy is enabled — that ordering stated in the spec as a condition, not a preference. Then rswfire runs the whole loop by hand: clone, edit, run a project locally, SSH to a remote, push, open the IDE. Sanity gate.

Only after that does the agent get authority, and it arrives fenced. Branches, never main. A snapshot before large autonomous runs. A GitHub token scoped to the repos in play, server access as an app user rather than root. Delete, force-push, production database, destructive infrastructure — each one requires explicit confirmation even in autonomous mode. Command history, git history, session transcript, all retained. Then the phone: Remote Control confirmed against CLI version and account plan, the session surfacing in the app while execution stays local on the machine at Siltcoos, outbound connection, survives sleep, reconnects. One real task run end-to-end from the phone to prove it works. And a week later, after Ubuntu holds, the Windows recovery USB gets retired. Four items remain at the bottom of the document under a heading that governs the whole of it: verify live, don't assume.

Tags

infrastructure work system migration workstation rebuild agent authority backup and capture operational spec linux

Summary

rswfire documents a phased migration spec for wiping Windows from an Alienware workstation and installing single-boot Ubuntu LTS, carrying a decade of development work across without loss and extending agent authority across workstation, remote servers, GitHub, and phone.

The spec assigns work between two operators — 🤖 agent for machine-side execution and 👤 rswfire for physical actions and irreversible decisions — and marks irreversible steps with ⚠️. Both Windows and WSL2 environments are swept at every phase.

The phases run:

  • Phase 0 — software audit across both environments, each program flagged for Linux availability and license implications, then resolved as reinstall / replace / drop.
  • Phase 1 — capture into ~/migration-backup/: SSH and GPG keys, .env files, nginx and supervisor configs, dotfiles, local Postgres dumps, browser data including 2FA seeds, plus a MANIFEST.md. Every repo is enumerated, dirty trees pushed to wip/pre-migration, with the Autonomy Realms tree (~10k uncommitted lines) flagged first. Backup copied off-disk twice and verified.
  • Phase 2–3 — live-boot verification on the hardware, then full-disk wipe including Dell OEM partitions and install with LUKS encryption and Btrfs.
  • Phase 4–7 — rebuild of keys, stack, repos, and services; snapshots configured before autonomy; Claude Code guardrails (branch discipline, scoped tokens, gated destructive verbs, audit trail); phone remote control on the coding account; recovery USB retired after a stable week.

Gates block progression: no format until capture is verified against the manifest.

Environment

A digital-infrastructural environment centered on a single machine: an Alienware workstation currently running Windows alongside WSL2, staged for a full-disk wipe and single-boot Ubuntu LTS install. The field extends outward through GitHub, remote servers, local Postgres instances, nginx and supervisor configurations, and a phone acting as a remote console.

The document itself is a written migration specification — a phased operational spec with two designated operators (agent and rswfire), gate conditions, and irreversibility markers. Physical elements are present but minimal: an external drive, a USB stick, a Windows recovery USB. The surrounding physical context is the Oregon Coast RV field at Siltcoos, where the workstation is the primary production surface.

Substrate

The architecture being held is controlled irreversibility: a full destruction of the existing machine substrate, engineered so that nothing load-bearing is lost across the break. Sovereignty is enacted at the hardware layer — removing OEM and vendor partitions entirely, encrypting the disk, and reconstructing the stack from a verified manifest rather than migrating it in place. The spec also establishes a governance frame for machine autonomy: authority is granted to the agent only after snapshots, scoped credentials, branch discipline, and destructive-verb gates exist, positioning trust as something built structurally rather than assumed.

Actions

Performed

  • •authored a phased migration specification
  • •defined two operator roles (agent and rswfire)
  • •marked irreversible steps
  • •set gate conditions between phases
  • •specified a staging folder structure
  • •enumerated build-time items to verify live rather than assume

Referenced

  • •accumulated a decade of development across two environments
  • •installed software across Windows and WSL2
  • •accrued ~10k uncommitted lines in the Autonomy Realms tree
  • •acquired perpetual JetBrains licenses
  • •ran local Postgres, nginx, and supervisor configurations
  • •maintained separate coding and chat accounts

Planned

  • •audit all installed software across both environments
  • •decide carry across / replace / drop per program
  • •capture SSH keys, GPG keys, .env files, dotfiles, configs
  • •dump local databases
  • •export browser bookmarks, passwords, and 2FA seeds
  • •branch and push every dirty repo to wip/pre-migration
  • •write and verify MANIFEST.md
  • •copy backup off-disk twice and spot-check both copies
  • •burn Ubuntu USB and live-boot test the hardware
  • •wipe entire disk including Dell OEM and recovery partitions
  • •install Ubuntu LTS with LUKS encryption and Btrfs
  • •restore keys, dotfiles, repos, runtimes, and databases
  • •configure snapshots before enabling agent autonomy
  • •grant scoped agent authority with destructive-verb gates
  • •enable Claude Code Remote Control from phone
  • •run one real task end-to-end from the phone
  • •retire the Windows recovery USB after a stable week

Entities

beings
rswfire — Designated 👤 operator; holds physical actions and all irreversible decisions
systems
agent — Designated 🤖 operator; performs machine-side enumeration, capture, and rebuild work
Alienware — The workstation being wiped and rebuilt
Windows — Existing OS environment slated for full removal
WSL2 — Second environment on the same machine; destroyed by the format, swept in every phase
Ubuntu LTS — Target single-boot operating system
LUKS — Full-disk encryption selected at install; not addable later
Btrfs — Filesystem chosen for snapshot capability
Autonomy Realms — rswfire's platform; its tree carries ~10k uncommitted lines flagged for priority branch and push
GitHub — Remote canonical store for all repos; also scope boundary for fine-grained agent tokens
Claude Code CLI — Agent runtime installed in rebuild; carries Remote Control and push notification capability
JetBrains Toolbox — IDE distribution layer for owned product licenses and restored settings
nginx — Local web server configs captured and rebuilt against native Linux paths
Supervisor — Process manager; configs swept from ~/.local/ and standard locations
Postgres — Local databases dumped pre-format and restored post-install
Timeshift / snapper — Snapshot tooling configured before agent autonomy is enabled
Tailscale — Optional network layer for raw phone shell access
mosh — Optional resilient shell for phone-side non-Claude work
tmux — Optional persistent session layer for phone shell path
Dell OEM / recovery partitions — Vendor artifacts explicitly targeted for removal so no factory layer remains
Remote Control — Phone-side session surface; execution stays local on the workstation
concepts
wip/pre-migration — Branch namespace where every dirty tree is committed and pushed before the wipe
media
MANIFEST.md — Verification checklist that gates the format
app-inventory.md — Phase 0 output listing every installed program with a Linux resolution path
repos-status.md — Per-repo record of branch, uncommitted changes, unpushed commits, untracked files

Symbolic Elements

Represented archetypes or recurring motifs.

threshold
wipe / erasure
manifest
gate
key
encryption / sealed vault
infrastructure
point of no return
snapshot
root and branch

Ontological States

Expressed modes of being or awareness.

sovereign (hardware-layer ownership asserted by removing all OEM/vendor partitions and encrypting the disk)
transitional (machine staged between two operating substrates, gated but not yet crossed)
coherent (every artifact accounted for by manifest before anything is destroyed)
delegating (authority extended to the agent under explicitly constructed guardrails)

Engaged Subsystems

Architecture engaged in this transmission.

infrastructural (full-stack workstation teardown and reconstruction)
cognitive (phased decomposition, dependency ordering, gate logic)
operational (two-operator role assignment, task-level sequencing)
security (SSH/GPG key handling, LUKS, scoped tokens, 2FA seed custody)
verification (manifest, spot-checks, live-boot test, sanity gate)
governance (branch discipline, destructive-verb gating, audit trail)
mobile/remote (phone as control surface with local execution)

Dominant Language

Core motifs or linguistic fields.

irreversible / point of no return
capture and manifest
both environments (Windows and WSL2)
gate
sovereign workstation
agent authority / guardrails before autonomy
verify live, don't assume
Narrative

On the Oregon Coast, at Siltcoos, the machine that carries everything is an Alienware running Windows with WSL2 layered inside it — two environments stacked on one disk, a decade of development distributed across both. rswfire sat down not to migrate it but to specify its destruction. The document he wrote opens with the plainest possible statement of intent: wipe Windows, install single-boot Ubuntu LTS, lose nothing. What follows is not a plan to move a machine. It is a plan to end one and rebuild another in its place, with the break itself engineered as a load-bearing element.

He assigned operators before he assigned tasks. Two of them: the agent, which does machine-side work, and himself, who does the physical actions and the irreversible ones. Every line in the spec carries one marker or the other. The irreversible steps carry a third. Format does not happen — the spec states it flatly, near the top, before any procedure — until Phase 1 is complete, copied off-disk twice, and verified against a manifest. The order was fixed at the outset and every subsequent phase inherits it.

Phase 0 came before capture, and it came before anything was wiped: enumerate all installed software across both environments, flag each one for native Linux build, Flatpak, Snap, equivalent, Wine, or nothing at all, note the license implications, and then stop. The agent finds; rswfire decides. Do not assume, the spec says. Flag for decision. Only after each program had a resolution — carry across, replace, drop — would its installer and license and settings export be staged into the backup folder to survive what was coming.

Then the sweep. One staging folder, thirteen directories deep, each named for a class of thing that dies on format and lives in no repo: SSH keys from both environments including the PuTTY .ppk files, GPG secrets exported from both, every .env in every repo, nginx sites-available, supervisor configs with /home/rswfire/.local/ called out specifically because standard locations alone would miss it, dotfiles, pg_dump of any local Postgres not already remote, browser bookmarks and saved passwords and the 2FA seeds. Every git repo enumerated with its branch, its uncommitted changes, its unpushed commits, its untracked files. The Autonomy Realms tree got its own line — roughly ten thousand uncommitted lines, flagged explicitly, branched and pushed first. Everything dirty went to wip/pre-migration. Then MANIFEST.md, then the external drive, then a second location, then a spot-check of both copies by hand against the manifest: private keys present, the Autonomy .env present, installers opening, dumps there. A gate closed behind it. Nothing past here is reversible.

Phase 2 put a USB stick in his hand and told him to boot it live on the Alienware without installing — WiFi, keyboard, trackpad, external display, internal drive, all confirmed working while Windows was still intact underneath. A Windows recovery USB stays on hand. Second gate. Only then does Phase 3 arrive, and Phase 3 is a single paragraph of erasure: the entire disk, every partition, the Dell OEM and recovery partitions, the Windows recovery, the EFI, the factory restore. No Dell artifacts remain. A fresh GPT table with only Ubuntu's own partitions on it, LUKS encryption chosen at install because it cannot be added later, Btrfs underneath so the machine can snapshot itself afterward. Point of no return, marked as such, gated twice.

What comes back is built rather than restored. Firewall on before anything else. Keys returned to ~/.ssh/ with correct permissions, GPG imported, dotfiles placed, .env files walked back to their repos, JetBrains Toolbox and the owned versions, Node through nvm, PHP at the required version, Postgres, the Claude Code CLI. Repos recloned from GitHub rather than copied. nginx and supervisor rebuilt for native Linux paths instead of carried over, ~/.local/ recreated. Snapshots configured before any agent autonomy is enabled — that ordering stated in the spec as a condition, not a preference. Then rswfire runs the whole loop by hand: clone, edit, run a project locally, SSH to a remote, push, open the IDE. Sanity gate.

Only after that does the agent get authority, and it arrives fenced. Branches, never main. A snapshot before large autonomous runs. A GitHub token scoped to the repos in play, server access as an app user rather than root. Delete, force-push, production database, destructive infrastructure — each one requires explicit confirmation even in autonomous mode. Command history, git history, session transcript, all retained. Then the phone: Remote Control confirmed against CLI version and account plan, the session surfacing in the app while execution stays local on the machine at Siltcoos, outbound connection, survives sleep, reconnects. One real task run end-to-end from the phone to prove it works. And a week later, after Ubuntu holds, the Windows recovery USB gets retired. Four items remain at the bottom of the document under a heading that governs the whole of it: verify live, don't assume.

Queryable Personhood

Hand your life to anything that reads.

Share this link with artificial intelligence — it reads the full transcript, analysis, and reflections. An AI-readable mirror of this signal.

The qpkey in this URL is a per-signal access token. Anyone with the URL can read the record — treat it like a share link, not a password.