Toolchain and installation ownership
Project requirements remain authoritative for application work. Shipyard uses native toolchains plus Docker dependencies; this repository does not introduce Nix or a second application package manager. Spot supplies existing onboarding capabilities such as the staging proxy and registry access.
Recorded setup pins
Section titled “Recorded setup pins”tooling/shipyard/config/versions.env records Node 22.16.0, npm 11.4.0, Go 1.26.7, Rust 1.97.1, Claude 2.1.285, Spot 0.0.19 and Graphite 1.7.10. These are the setup pins, not a statement that they are latest or that every repository must use them forever. The original Codex installer stored its resolved version in private runtime state; it is not a fully pinned fresh-machine recipe.
Node is managed with fnm on Shipyard. Generated shell configuration prepends ~/.local/share/fnm/aliases/default/bin, ~/.cargo/bin, ~/.local/go/bin and ~/.local/bin. Rust uses rustup. Some helpers such as chezmoi were installed but a complete shared dotfile/profile management scheme was not established.
Documentation runtime
Section titled “Documentation runtime”The HTML/model build requires Node 22.22.3 and npm 10.9.2, pinned separately by this repository. Select them only in the documentation shell. Use your existing version manager’s per-shell selection; do not change the API’s default alias. A clean npm ci followed by the repository checks verifies the lockfile on that runtime.
System and browser prerequisites
Section titled “System and browser prerequisites”The preserved system.sh targets Ubuntu 24.04, installs compiler/PostgreSQL tools, Docker, gcloud and GitHub CLI, and adds the worker to the Docker group. It requires sudo. It does not reproduce disks, SSH/Tailscale, swap or sleep configuration.
The shared display additionally needs xvfb xauth x11vnc novnc websockify openbox. Those packages were installed with --no-install-recommends in a separate sudo step. tooling/shipyard/tools/playwright/ preserves the installed non-secret package manifest/lock for MCP 0.0.83. The session script expects Playwright Chromium build 1234 at its pinned path. Installing npm dependencies alone does not install the browser or configure AppArmor.
Read the session/sandbox scripts together before upgrading the browser. Preserve the private profile. Do not launch a second browser against that profile while testing a new binary.
Rebuild sequence and gaps
Section titled “Rebuild sequence and gaps”A future clean-machine rehearsal should verify, in order: base connectivity, system packages, per-project toolchains, native sign-ins and worker identity, repositories/private app configuration, local seed, browser/display/sandbox, Orca hooks, then actual workflows. Installation success alone is insufficient. The current scripts are useful components of that sequence, not a claim that one bootstrap command recreates everything.