age key at /home/claude-runner/.age/p24-infra-keys.txt
Yes � claude-runner has the age key (verified 2026-06-24)
On-server plaintext fallback
/opt/p24-infra/bms-4/.env (deployed by CI)
N/A � already plaintext
GitHub Actions secrets
Not accessible from VPS directly
N/A
bms-4 / AI-Dev-BMS4-1 does hold the SOPS age key and can decrypt all SOPS files directly.
Resource Budget (32 GB RAM)
Component
Expected RAM
Notes
MongoDB arbiter (mongod)
~200 MB
Arbiter holds no data � minimal footprint
n8n main instance
~400 MB
Queue-mode coordinator only
n8n worker � 3
~800 MB each = ~2.4 GB
Rises to ~1.2 GB/worker under Playwright load
Redis
~100 MB
n8n queue backend
Traefik
~50 MB
TLS proxy
node_exporter + cAdvisor
~100 MB combined
Metrics exporters
Claude Code agents � 4
~700 MB each = ~2.8 GB
Per-agent process + git worktree I/O
OS + buffers
~2 GB
Ubuntu 22.04 baseline
Total (light n8n load)
~8 GB
Comfortable headroom
Total (heavy n8n Playwright load)
~14�16 GB
Safe, monitor
Total (heavy n8n + 4 Claude agents)
~16�18 GB
Watch � OOM risk if n8n spikes
OOM risk flag: Running 4 Claude agents simultaneously while n8n executes Playwright-heavy workflows (browser automation) can push total RAM to 18�20 GB. Monitor via node_exporter / Grafana node_memory_MemAvailable_bytes. If available RAM drops below 4 GB, reduce Claude agent concurrency to 2.