## 1. Pre-flight

- [x] 1.1 Read `.reversa/reversa-config.json` and confirm edits to `.gitlab-ci.yml`, `.gitattributes`, `README.md` are allowed (currently `allowLegacyEdits: true`, unrestricted — warn once); do not modify the config
- [x] 1.2 On the dev server run `sudo -l -U gitlab-runner` and record whether `install` (or `ALL`) is already granted — result: only `rm -rf /var/www/html/tnx_pos_2026/*` is granted; `install` rule (3.2) is required

## 2. Repository files

- [x] 2.1 Add `deploy/cron.d/*  text eol=lf` to `.gitattributes`
- [x] 2.2 Create `deploy/cron.d/tnx-pos-dev` containing the single line `* * * * * www-data cd /var/www/html/tnx_pos_2026/dev/pos/src && /usr/bin/php artisan schedule:run >> /dev/null 2>&1` with LF endings and a trailing newline (verify with `file` / `od -c | tail`)
- [x] 2.3 In `.gitlab-ci.yml` job `pos-dev`, after `cd $DEV_DIR/src`, add `sudo install -m 644 -o root -g root deploy/cron.d/tnx-pos-dev /etc/cron.d/tnx-pos-dev`
- [x] 2.4 In `.gitlab-ci.yml` `after_script`, add `cat /etc/cron.d/tnx-pos-dev` so the installed entry is visible in the job log

## 3. Documentation

- [x] 3.1 Add a "Dev scheduler (cron)" section to `README.md`: mechanism (cron → `schedule:run` every minute as `www-data`), why `www-data`, file locations (repo vs `/etc/cron.d`), and that CI overwrites the server file on every deploy
- [x] 3.2 Document the exact scoped sudoers rule from design D5 for `/etc/sudoers.d/gitlab-runner-tnxpos` (one-time manual server step — required, per 1.2)
- [x] 3.3 Document verification: `cat /etc/cron.d/tnx-pos-dev`, `journalctl -u cron -n 5` (expect `(www-data) CMD (...)`), and `sudo -u www-data /usr/bin/php artisan schedule:run` in `src` (expect "No scheduled commands are ready to run.")

## 4. Deploy and verify on dev server

> 4.1–4.5 skipped at the user's request on 2026-09-15 (not performed in this change); they are tracked as the open checklist in GitLab issue #18.

- [x] 4.0 On the server, add the sudoers rule from 3.2 to `/etc/sudoers.d/gitlab-runner-tnxpos` (alongside the existing `rm -rf` rule) (mode 440), validate with `sudo visudo -c`, and confirm `sudo -l -U gitlab-runner` lists the `install` command
- [x] 4.1 (skipped → issue #18) Commit, merge, tag `dev-<10 digits>` and confirm the `pos-dev` job passes
- [x] 4.2 (skipped → issue #18) On the server: `stat -c '%U:%G %a' /etc/cron.d/tnx-pos-dev` → `root:root 644`; `diff /etc/cron.d/tnx-pos-dev /var/www/html/tnx_pos_2026/dev/pos/src/deploy/cron.d/tnx-pos-dev` → no output
- [x] 4.3 (skipped → issue #18) Wait ≥1 minute, then `journalctl -u cron -n 5` (or `grep CRON /var/log/syslog | tail`) shows `(www-data) CMD (cd /var/www/html/... schedule:run ...)` and no `WRONG FILE OWNER` / `bad minute` lines
- [x] 4.4 (skipped → issue #18) Run `sudo -u www-data /usr/bin/php artisan schedule:run` in `src`; expect "No scheduled commands are ready to run." with no permission errors
- [x] 4.5 (skipped → issue #18) Next day (after 17:00 UTC): confirm `customer_order_summary` received new rows and `storage/logs/laravel-<date>.log` is owned by `www-data`
