Adds a manifest-driven "Install CircuitForge Apps" menu to install.sh,
alongside the existing extras-menu pattern.
- cf-apps/*.manifest: one file per product (circuitforge-core, peregrine,
kiwi, snipe, turnstone, pagepiper, linnet - the beta/alpha menagerie
products), declaring repo URLs, supported install types, conda env,
.env template, and per-install-type setup hooks. Hooks prefer shelling
out to each product's own install.sh/Makefile/docker-compose rather
than reimplementing their setup logic.
- lib/cf-apps.functions: registry loader, provisioning-profile prompt
(oem/collaborator/orchard), app multiselect menu, and the install
dispatcher (clone, .env bootstrap, install-type selection, hook
dispatch). circuitforge-core installs automatically as a dependency
for apps that declare app_needs_core=true.
Provisioning profiles gate both which apps are offered and which remote
credentials are used:
- oem: public CircuitForgeLLC GitHub mirrors only, no Forgejo access,
no circuitforge-orch (product install menu only)
- collaborator: private Circuit-Forge Forgejo, same product menu
- orchard: narrow flow, not the product menu - clones circuitforge-orch
(Forgejo-only, no public mirror exists) and hands off interactively to
its own install.sh, which gathers agent/coordinator topology itself
(it has no --topology/--coordinator-url flags to script around).
NOTE: circuitforge-orch has no model-sync/cache-sync mechanism today
(checked its install.sh and README); this wrapper doesn't invent one.
Design rationale and survey of each product's real install story:
circuitforge-plans/cf-node-bootstrap/superpowers/plans/2026-07-17-cf-apps-install-menu.md
- get_top_processes: use 'comm' instead of 'args' so the actual binary
name is shown instead of a path truncated before reaching it; also
exclude the ps invocation itself, which was always appearing with an
inflated %cpu artifact from its own brief runtime.
- Network Information: interfaces matching grouped_adapter_patterns
(Docker br-*/veth*/docker0 by default) are now tallied into a single
summary line instead of printed individually. On a host running many
containers this cut the section from 100+ lines to a handful.
- get_security_info: failed-login count used `journalctl -u sshd`, but
the systemd unit is named ssh.service on Debian/Ubuntu, so the query
silently matched zero entries there. Filter by `_COMM=sshd` instead,
which matches the actual binary name regardless of unit naming, and
add /var/log/secure as a fallback alongside /var/log/auth.log.
- Pin LC_ALL=C on free/uptime/sensors calls parsed by grep/awk on
English words and fixed column positions; these broke under
non-English locales. Uptime's token-position parsing is still
format-fragile across procps versions/distros; noted as a follow-up
for a /proc/uptime-based rewrite.
- Replace hardcoded '°C' with a deg_symbol variable that collapses to
plain "C" when PRbL/functions reports unicode_supported=false, so
temperature readouts stay pure ASCII on terminals/locales that can't
render the degree sign.
- Bump PRbL submodule for the ANSI-code and box-border fallback fixes.