Found during hydragon reconnaissance (#615) on 2026-08-31.
hydraperforcewatcher has a single global perforce.port in its configuration. The Watches struct carries no per-watch port and no per-watch user (internal/cli/serve.go).
So one watcher process can only ever serve one p4d server.
We now run one Perforce scale for each organization. galloromeinsmuseum is on port 1666, p4scale-visitflanders is on 1667, and hydragon will be on 1668. Adding a //hydragon/main entry to the running watcher's watches: list does not work. Worse, editing that live configuration repoints Cyborn's watcher, because the port is global.
The workaround today is a second watcher instance for each scale: its own configuration file, its own state directory, its own systemd unit and its own agent identifier. That is one more process for every organization we onboard, and each one is a separate thing to monitor, update and get wrong.
Move port and user from the global perforce block onto each watch entry, and keep the global as the default when a watch omits them. One process then serves every scale on the node.
Until that lands, the runbook must say plainly that a new scale needs a new watcher instance, and must never say "add a watch".
Related: #615, #623 hydragon Phase 1, #543 ensure-server hardening.