Automation go-live checklist¶
Use this to bring the Automation tab into use on the lab
network: the agent, its runner, approvals and device control. Work through
it in order. Each step links to the full instructions. Here the runner runs
in Docker inside WSL on central_server_pc. The steps for a dedicated Linux
runner PC are the same from step 5 on (see
In the lab: the runner PC).
Before you start, the network itself must already be deployed and verified (Production deployment): Central, Caddy, the Control Center and every Lab PC.
1. Decide first¶
- [ ] Which instruments may ever be automated, and the safe range of every number the agent may set on them. These become site limits in step 3. An instrument with no limit for a number can't be automated ("no limit, no automation").
- [ ] Who approves. Any signed-in lab member can approve a protocol. Agree who should, and that approvers read the review card's numbers, not the agent's description.
- [ ] The Claude account the runner signs in with is the lab's, and its plan allows automated use by the whole lab.
- [ ] IT agrees to WSL 2 and Docker Engine on
central_server_pc, and virtualization is enabled in its firmware. - [ ] The first instrument is one where a wrong value is harmless.
2. Control Center: logins and settings¶
On central_server_pc:
- [ ] Update the Control Center to this release (
labnet update --role control-center; see Operations and upgrades). -
[ ] In
C:\ProgramData\LabNet\control-center.env, check:LABNET_AUTOMATION_DIR, and that the folder is backed up;LABNET_AGENT_LITERATURE_DIR(the lab library).
The run limits keep their defaults unless you have a reason to change them (Control Center settings table). - [ ] Logins: 1. List the lab members in
C:\ProgramData\LabNet\logins.txt. 2. Runscripts/lab/setup_logins.ps1and hand out the passwords it prints (Logins). - [ ] The Caddyfile starts with{ admin off }, imports the logins snippet, and the Control Center's site block usesimport labnet_control_center(sites/pqt/Caddyfile.example). - [ ] Restart Caddy, then the Control Center. - [ ] Check: - opening the Control Center from another computer asks for a login, and the top bar shows the signed-in name; -curl.exe http://127.0.0.1:8080/statuson the server is refused (403).
3. Lab PCs: site limits¶
On each Lab PC whose instruments may be automated:
- [ ] In its inventory (
sites/pqt/inventories/<lab-pc>.py), wrap each such device insite_limits(...)with the ranges from step 1 (Site limits). Narrow the driver's limits; never copy them unexamined. - [ ] Restart the Lab PC. It refuses to start if a site limit is wider than what the driver allows, or names an unknown argument; fix the inventory and restart.
- [ ] Check:
- on the Network page, the device's ranges show "(site limit)";
- a client call just outside a limit is refused with
ARGUMENT_OUTSIDE_LIMITS.
4. The safe-state watchdog¶
On central_server_pc, following
The safe-state watchdog:
- [ ] Create its Central user (
labnet-central-admin setup --user automation-watchdog …). - [ ] Put its settings in
C:\ProgramData\LabNet\watchdog.env, as insites/pqt/watchdog.env.example. - [ ] Start it next to the Control Center. Then register its Task Scheduler task, so it also starts at logon.
- [ ] Check:
http://127.0.0.1:8081/health/readyanswers 200 on the server.
5. The runner: Docker in WSL on the Central PC¶
The detailed steps are in The Automation runner.
On central_server_pc:
- [ ] Install WSL 2 with Ubuntu 24.04 (
wsl --install -d Ubuntu-24.04). Then install Docker Engine in it (docs.docker.com/engine/install/ubuntu). Don't add people to thedockergroup: it is root-equivalent. - [ ] Turn on mirrored networking, so the runner reaches the Control
Center through Caddy at the Central PC's own address:
- Put
networkingMode=mirroredunder[wsl2]in%UserProfile%\.wslconfig. - Run
wsl --shutdown.
- Put
-
[ ] Keep WSL running. Windows stops WSL, and with it Docker and the runner, about a minute after the last Windows program using WSL closes. Register a task that keeps one hidden WSL process open from logon:
$action = New-ScheduledTaskAction -Execute "wsl.exe" ` -Argument '-d Ubuntu-24.04 -e bash -c "exec -a labnet-runner-keepalive sleep infinity"' $trigger = New-ScheduledTaskTrigger -AtLogOn Register-ScheduledTask -TaskName "LabNet runner keep-alive" -Action $action -Trigger $trigger -
[ ] Inside WSL:
- Copy the repository to
/opt/labnet-src. - Copy
labnet-ca.pemto/etc/labnet/labnet-ca.pem. - Check that
lab-control-centerresolves. WSL copies the Windows hosts file unless it has been told not to.
- Copy the repository to
- [ ] A runner token:
labnet-control-center-admin … runner add central-runner(Runners and their tokens). - [ ] Write
/etc/labnet/runner.env, owned by root with mode 600. It needs the HTTPS address, the token and the CA file (In the lab: the runner PC, step 6). Don't setLABNET_RUNNER_DEV. - [ ] Build, sign in, check, start. Run each in
/opt/labnet-src, withsudo docker compose -f packages/labnet-automation/docker/compose.yaml …in front:build--profile login run --rm login: in Claude,/loginwith the lab account, then/exit.run --rm --no-deps runner labnet-runner self-check: every line must sayok.up -d egress runner
- [ ] Optional: limit the runner API to the runner's address with
setup_logins.ps1 -RunnerAddress <address>(Logins). Check the address Caddy's log shows for runner requests first. - [ ] Check:
sudo docker compose -f packages/labnet-automation/docker/compose.yaml logs runnershows the self-check passing, then "polling".
6. A first supervised run¶
- [ ] On the Automation tab, press Index library and wait for the count. Note any papers flagged without a text layer (Literature search).
- [ ] Create a test project:
- link an experiment canvas that holds the harmless instrument;
- tick it under Allowed devices;
- add a short task in
Tasks/.
- [ ] Press Run. Watch the run's log on the project page while the agent plans and submits a protocol.
- [ ] Review the protocol on the approval card
(Protocols and approval):
- every device, method, range, step, rate and call limit, the duration and the safe state;
- Edit… to narrow anything; Reject with a note if it's wrong.
- [ ] Approve. Then check:
- the Network page shows the device as held by Automation, with a countdown and Stop;
- Play on that device is refused.
- [ ] After the run:
- check the results in
Analysis/; - check the audit trail (
state/<project>/audit/<run>/): every call is listed, the safe state was applied, and the leases were released.
- check the results in
- [ ] Practise Stop: start another run, approve it, and press Stop on the Network page mid-experiment. The device should go to its safe state at once.
- [ ] Optional, the watchdog drill: during a third approved run, end the
Control Center's process in Task Manager. Within about two minutes the
watchdog log (
C:\ProgramData\LabNet\logs\watchdog.log) shows it applying the safe state. Then restart the Control Center.
7. Keep it running¶
- [ ] Back up these folders with the rest of LabNet's data:
C:\ProgramData\LabNet\automation(projects, runs, approvals, audit trails);experiments;literature.
- [ ] After an update: rebuild and restart the runner (
build, thenup -d egress runner), and restart the watchdog with the Control Center. - [ ] When an instrument is added or changed: set its site limits before ticking it under Allowed devices.
- [ ] When someone joins or leaves: run
setup_logins.ps1again, and restart Caddy. - [ ] If the lab's Claude login changes: run the runner's
loginstep again.