Workspace — memory/, a git repository of its own beside the
Hostwarden checkout that holds everything Hostwarden learned and
everything you told it. The workspace
Operations checkout — a checkout whose memory/ is the
workspace. It administers servers; Hostwarden's own files are
read-only there. The operations checkout
Development checkout — a checkout without a workspace, and every
git worktree. It works on Hostwarden itself and reaches no server.
Working on Hostwarden
Shared workspace — a workspace with a private git remote, shared
by a team or by one person on several machines.
A shared workspace
Operator handle — the short name, such as alice, that opens
every journal line you cause and every decision you record.
A shared workspace
Operations host — an always-on machine that runs the fleet's
housekeeping unattended and reads your servers only through fleet
read. An operations host
First-connection pipeline — the ordered steps before the first
command on any host: access lists, DNS aliases, SSH user, host key,
OS detection, machine memory, activity check, Heinzel legacy.
Your first session
Onboarding — a full, read-only first probe of a host, on
request, ending with what it lacks against the baseline.
Onboarding a host
Local mode — administration of the machine Hostwarden runs on,
without SSH, as your own user.
Local administration
Unprivileged mode — work as the current user where neither sudo
nor root SSH is available, with a report of what needs root.
Access control
Via-host mode — reaching a guest that has no SSH server of its
own through its hypervisor's manager.
Hypervisors and their guests
Appliance — a system with its own updater, configuration and
firewall, such as Proxmox VE or OPNsense, which gets a rule file of
its own. Appliances
Platform — what the OS runs inside when something outside owns
part of the machine; WSL is one.
WSL and workstations
Role — what a machine is expected to have. A Mac, a WSL instance
and the machine Hostwarden runs on are workstations, held to other
expectations than a server.
WSL and workstations
Baseline — what every server is expected to have, written down
in rules/baseline.md, plus your own additions.
Server baseline
Housekeeping — the routine health inspection of a host; it
changes nothing. Housekeeping checks
Security audit — findings on SSH, firewall, accounts, services
and hardening, by severity.
Security audit
Fleet audit — a side-by-side comparison of key policies across
every host, to show drift.
Fleet audit
Fleet read — the way an operations host reads a server: its key
may run a bundle of read-only checks you signed and write one
journal line, nothing else. Fleet read
Override — a file you write under memory/custom-rules/ or in a
host's rules.md to add to, replace or remove part of a shipped rule
or skill. Overrides
Taboo — a command Hostwarden never runs without your explicit
request, such as writing a partition table or touching a running
sshd's configuration. Hard guardrails
Taboo guard — the Claude Code hook that blocks the taboos in
every permission mode. Hard guardrails
SSH safety net — the automatic undo a firewall or network change
arms first; it reverts the change unless a new SSH login succeeds.
What it asks first
Canary — on a change to several hosts, the one host that runs it
alone first; the others follow only when its result matches what was
expected. One task on many hosts
Radius — the hosts a disruptive step reaches beyond its own: its
guests, the hosts behind it, the hosts using its services, its
cluster peers. What a reboot would hit
Maintenance window — a planned time for a disruptive step, with
who to notify by when.
Planning a maintenance window
Coordinator — a background session per operations checkout that
keeps track of which session works on which host and passes
announced steps on. It never reaches a server.
Parallel sessions