3e85e37b63
- CFG_SITE_NAME in setup.env (below CFG_DOMAIN, default "local") names the directory site; slug site_<name> matches ldap-client's parentSlug convention so joined Linux hosts land under the same site. Wired through sso-secrets.js stack.siteName. - setup.sh collects host facts ON THE HOST (hostname, IP, default-route MAC, OS pretty-name, kernel — same collection as ldap-client/index.sh) and passes them into the bootstrap exec env; the stack host is now registered as host_<hostname> with that metadata (subType linux). - Services carry their internal port and git repo in metadata (sso-manager 3001, proxy 3000, openldap 389/ext 636, openresty 443), using the metadata keys the directory UI natively displays. - ensure() now adopts resources from the earlier seed layout (alt slugs 'stack-host' / domain-slug site) and back-fills missing seed metadata via a metadata-only PUT — operator-set values are never overwritten. Verified against a live app: old-layout resources are adopted and back-filled (no duplicates), fresh seed creates the full graph, and a second pass changes nothing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>