The AI's console X server takes the AI's clicks
LightDM's Xorg on :0, the AI workstation's desktop, adds udev input devices only through an input driver, and the golden image had none. It logged 'No input dri...
Register with FreePBX under the names the image reads; one owner; health probes; host-only ingress
AI extensions route to LiveKit; one recording path on every call; outside-calls list comes from Kamo
The host patch refuses until kamo-asterisk-support's recording subroutine and managed allow-list are on the node (and the list covers the hand-edited one), veri...
Svc_kamoai_voice follows the org pause and the kill switch (KamoAI SP13)
LiveKit server, SIP and Redis on k3m1 for KamoAI voice; signalling route; ports and secrets
The signalling EndpointSlice uses k3m1's node address 10.0.50.1 (k1m1's eno49 corrupts TCP payloads), the TURN secret volume is 0400 (livekit-server refuses a s...
Widen svc_kamoai for the KamoAI runtime (SP10)
kamoai-service creates and pulls its own KAMOAI_WORK work queue, runs up to four notify shards (kamoai-notify, kamoai-notify-1..3) on EMAIL_NOTIFICATIONS, publi...
Golden image AI layer — Chrome, x11vnc, computer-use-linux, ydotool
Chrome's source is kamo-google-chrome.list, not google-chrome.list: Chrome's postinst (154.0.8037.57) migrates a google-chrome.list into its own google-chrome.s...
The agent runs the AI workstation profile when cloud-init asks for it
The agent loads kamo_hc_ai only for KAMO_HC_PROFILE=AI_WORKSTATION: the AI's paths on 9810 behind the agent bearer, the MCP bridge on 9811, the AI's activity re...
AI workstation profile applier, screen guard, software kit and runtime
MCP bridge from the Tool Plane to computer-use-linux
Streamable HTTP on 9811 (JSON answers only, GET 405, Origin 403, per-wake bearer 401, take-over 409) in front of one stdio computer-use-linux child per session....
AI workstation agent module — renderers, MCP token, lease, VNC passwords
The guest half of SP11's AI profile: the files the profile writes (LightDM autologin at 1280x800, kiosk, x11vnc and ydotoold units, Chrome wrapper and managed p...
The PBX speaks through Kamo Speech — kamo_tts.agi, Piper norman at 8 kHz, key from a secret volume
Six Whisper workers and six requested CPUs, so a batch chunk never queues a realtime turn
The acceptance run on k3m1 (4 realtime streams + 1 batch) measured p95 17.9 s: the batch held one of the 4 workers, so one turn waited behind a whole turn. Six ...
Size the reranker's TEI thread pools to its 1-CPU limit
The reranker runs embedding-model's TEI 1.9.4 under the same 1-CPU limit, so it takes the same sizing (KamoAI SP00 final review I-1): one tokenization worker, a...
Mirror GitHub kamouniverse main to Forgejo so a merge deploys
The KamoUniverse marketing site is now edited on GitHub GitHub, and PRs merge there. But the site deploys from Forgejo (kamo/kamouniverse-marketing), whose work...
Record live kontak.kamocrm.com, desktop-1 sizing and the Docs host list
A .forgejo/ change makes the next deploy a full reconcile, which applies every manifest over live state. Four had drifted from live by hand or by another repo's...
Certificate and disruption budget for dev.kamouniverse.com
dev.kamouniverse.com is the new KamoUniverse marketing site (repo kamouniverse-marketing; it carries its own Host() IngressRoute in namespace kamo). The kamouni...
Dovecot pushes mail events to EmailService (Lua push_notification); stop logging secrets
Size every TEI thread pool to the 1-CPU limit, and let probes outlast a batch
TEI 1.5's ONNX backend starts one inference thread per physical host core (24 on k1m1) and reads no thread setting, so under the pod's 1-CPU quota the CFS throt...
The default user may only PING
SP00 stage R3. Persists the runtime rule for a future start of redis-0: default keeps nopass for the unauthenticated readiness probe and may run PING and nothin...
Deploy Kamo Speech, and pre-add the livekit/ hook so SP13 needs no second full reconcile
Kamo Speech's registry facts and its registration through AIService's internal registry
The last wait needs VERIFIED to hold for 120 s. An attestation itself writes VERIFIED and #36 carries no probe time, so a first VERIFIED read cannot tell SP01's...
Transcribe realtime turns over the pod's own loopback
Speaches 0.9.0-rc.3 posts every realtime turn to /v1/audio/transcriptions. With LOOPBACK_HOST_URL unset it makes that call in-process through httpx's ASGITransp...
A live probe of every Kamo Speech capability, with a four-stream load check
The probe runs inside the pod and prints one JSON document for register.py: a TTS round trip per voice and language (recall >= 0.8), the batch STT row, a realti...
Kamo Speech on k3m1 — pinned Speaches, read-only models, DNS-only egress
Keys and NetworkPolicies on in-cluster inference; Kamo reranker and Kamo Local LLM
TEI embeddings and the new cross-encoder reranker require TEI_API_KEY; bergamot, LibreTranslate and the new Kamo-owned Ollama (qwen3:4b) sit behind the Kamo aut...
Pinned, hash-verified model fetch and a warm-up that holds the pod until every model is resident
The warm-up also drops a model whose load failed: Speaches 0.9.0-rc.3 keeps the entry of a failed load, so the next startupProbe would get 409 and /api/ps would...
Svc_ai publishes ai.registry.changed.> (KamoAI SP01 registry events)
Svc_security publishes kamoai.platform.state, svc_kamoai subscribes to it (KamoAI SP02)
SecurityService announces the platform AI kill switch on kamoai.platform.state and KamoAI Service listens for it. rt.org.<org>.ai-workforce needs no new grant: ...
Reserve 768M for the OS so --memory 3G fits in the 4Gi pod
Seastar keeps max(1.5 GiB, 7%) of the cgroup limit plus ~94 MiB per shard back for the OS and refuses to start when --memory does not fit in what is left. With ...
Scylla to 2 CPU / 4Gi, libretranslate request to 10Gi (32 GiB, 6 CPU released)
Scylla: --smp 2 --memory 3G in a Guaranteed 2 CPU / 4Gi pod (14-day peak 0.66 GiB, 0.05 CPU; the database is 2.93 MB). The init container now has requests == li...
Log in to Redis as mail_rspamd
rspamd reads its password from Secret mail/rspamd-redis-auth, included into local.d/redis.conf. The pod gains fsGroup 11333: the image runs as 11333:11333 and a...
ACL users for the platform, rspamd and operators (default still open)
X keeps counting through a sleep, so every resumed computer went straight back to sleep
A member opening their computer got a black tab. The launch was fine, the wake was fine, the resume was fine — and then the machine powered itself off before th...
A cloud session asks for its task in the terminal
description") unless the account has the interactive cloud backend, which this one does not; given one, it creates the session, prints its task for the cloud se...
Start a coder session in the cloud from a local checkout
repository. The bundle is forced because our remotes are Forgejo, not GitHub, and the point is the checkout on this disk. No --permission-mode (the CLI drops by...
ASCII in finalize.sh's log lines — jibri's logger printed the em dash as ???
Xrdp was told its session backend was itself, so nothing ever rendered
Opening a computer gave a black screen that never became a desktop. The cause is one unanchored sed in this file: sed -i 's/^port=.*/port=3389/' /etc/xrdp/...
Recording had never worked — jicofo never looked for jibri, and jibri never arrived
Four separate faults, each enough on its own to stop every recording: - jicofo had no ENABLE_RECORDING, so the image wrote no `jibri {}` block: it never watc...
Recreate, and probe the XMPP session — a surge left meetings with no focus for 18h
Every jicofo logs in to prosody as the same full JID, focus@auth.meet.Meet/focus. The maxSurge rollout from 9da0998 runs two of them at once, and prosody answer...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
