# AGENTS.md — netinfra Point of truth for fleet-wide agent policy: the workspace AGENTS.md in KNEL/PFVCluster (loaded globally). This file holds repo-specific notes only. - Ticket gate: `echo '#NNN' > .crush/active-ticket` before any modification; reference [\#694] + [#769]. - Remote access: SSH chokepoints only — tests/remote.sh (PFVCluster) or netinfra/dns-cluster-setup/remote-dns.sh in THIS repo; DNS names only, never IP literals. - Docs: Discourse topic https://community.turnsys.com/t/306 — keep README pointer current. - shellcheck zero-warning (incl. info) via `bash tests/shellcheck.sh`.