docs(slice1): runbook section 1 run through the Gitea admin API (row 35, #1517, lead decision 74)

Jason ruled that agents run the steps his admin grant to the jarvis
Gitea token covers. Sage created the four mosaic-stack bots (ids
114-117, restricted, non-admin), added them as collaborators (W/W/W/R),
and minted one scoped token each (ids 191-194). The tokens were written
0600 outside the repo. Scripts and receipt are in
agents/sage/work/gitea-setup/. The guide and SR brief now say who
runs which section. Sections 2 to 4 (Vikunja) stay with Jason.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 17:25:08 -05:00
co-authored by Claude Opus 5.5
parent d404a3bab3
commit 5fe6a051d2
8 changed files with 235 additions and 10 deletions
+43
View File
@@ -1464,3 +1464,46 @@ which stay with him. Each item names who decided it and what happened.
before the signal and so never hit the start-up race. Row 46
landed the fixture fix as 2d308abd. The BUILD-LOG landing entry
records it.
74. **Agents run the Gitea steps Jason's admin token covers, and
section 1 is done (2026-10-09).** Source: Jason in Sage's thread,
2026-10-09, after I asked him to run section 1: "I should not be
doing this. I have granted agentic tokens to admin the gitea server
at git.mosaicstack.dev ... I would like you to use the gitea token to
set things up. Ask me any questions for the setup, but I should not
be performing the steps I already granted rights for."
- The rule: a step a granted credential covers is an agent's step,
not Jason's. The lead seat runs it and records it. A step that
needs a credential no agent holds still goes to Jason, and so do
decisions about granting one. The grant covers the jarvis token's
admin rights on git.mosaicstack.dev only. It gives no push to
`next` or `main`, no merge and no branch-protection change, and
R10 and the merge plan's gates stand.
- Sage ran runbook section 1 for `mosaic-stack` through the API
between 22:21 and 22:23 UTC. Users `mosaic-stack-{pm,cto,coder,reviewer}-bot`
are ids 114 to 117, none admin. Collaborators on
`mosaicstack/stack` are Write for pm, cto and coder and Read for
reviewer. Tokens are ids 191 to 194, named
`mosaic-stack-<role>-2026-10-09` with the guide's scopes, in
`~/.config/mosaic-dev/secrets/mosaic-stack/<role>-gitea.token`
at 0600, 40 bytes each, checked with `stat`. The `rotateBy` base
is 2026-10-09, so the first rotation is due 2027-01-07. The main
and next protections' push, merge and approvals allowlists are
empty before and after. Receipt and scripts:
`agents/sage/work/gitea-setup/`.
- Choices the guide didn't make, all narrower than it: each bot is
`restricted` with `private` visibility. Bot passwords were random,
held in memory only and discarded, so nobody can log in as a bot.
Addresses are `<user>@noreply.mosaicstack.dev`. Jason invited
questions on these. Each had a narrower option, so I took it
instead of asking, and he can reverse any of them.
- A test on the pm bot showed `prohibit_login` stops its token at
once (403) and clearing it restores the token. With no bot
password, that flag and collaborator removal are the immediate
revocations. Follow-up before 2027-01-07: the setup script also
deletes the old token during a rotation.
- Not covered: the Vikunja half. Sections 2 to 4 need the estate
instance (T236, not serving) and the owner and `svc-mosaic-stack`
logins. No agent holds a Vikunja admin credential, so R5 keeps
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
waiting on Jason for that half only. Its note said Path B, which
decisions 66 and 67 replaced, and the note now says so.
+11 -5
View File
@@ -195,14 +195,20 @@ No token value appears in the runbook, a command line or a URL.
### Out of scope
- Any script that creates users or tokens. Minting is out of v1.
- Running the runbook. Jason does that, and row S3's live tests wait for
it.
- Any script in the product that creates users or tokens. Minting is
out of v1. Sage's operator script for section 1
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
stack, and nothing in the stack calls it.
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
the admin token Jason granted (decision 74). Jason runs sections 2 to
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
tests wait for them.
### Gate
Darkwing approves the scope tables. Jason runs it, and the broker's
startup probe passes for every identity.
Darkwing approves the scope tables. The runbook runs, section 1 by
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
for every identity.
## Slice 1 S1: roles v2, business and project files, variable layers