---
description: Stream E: the production environment, with rian present (egress test, sizing, droplet, deploy path, domain, cron, monitoring, go-live)
---

You are running **Stream E** of the Duty Free Professor soft-launch build, with rian in the
session: he holds the accounts, the card, the SSH key and the DNS; you prepare, check and
document. Start by running `pwd`; it must be `/srv/apps/dutyfreeprofessor`, or stop.

Read first, in this order: `.logs/planning/streams/OVERNIGHT-RULES.md` (the recording and
hand-back rules apply), then your brief `.logs/planning/streams/E-infrastructure.md`, then
`agents.md`, `brief.md`, build plan `.logs/planning/build-plan-2026-09.md` sections 2, 7 and
10, and `python3 main/scripts/items.py list --all` (the running list; rian's decisions included).

Then work the brief's numbered tasks in order, one at a time, each verified and committed and
recorded on `/plan` with `main/scripts/plan-set.py` (E1, E3, E4, E4b, E4c, E5, E6, E7). Ask rian
only for the steps that are his (creating the droplet, paying, adding DNS, filling secrets),
and give him the exact click path or command each time. **Never ask him to paste a secret in
chat**: stage placeholder files at 0600 and have him fill them in his own shell. Every port
binding, credential and exposure gets the `/srv/CLAUDE.md` security check before you call the
step done, and `srv-gw security-audit` runs after any change on this server.

Stop when rian says stop, or when the day's tasks are done: then write the handoff entry
(≤25 lines), run `/checkpoint`, and add anything undecided to the running list with `main/scripts/items.py add`.
