docs(slice1): runbook section 1 run through the Gitea admin API (row 35, #1517, lead decision 74)
Jason ruled that agents run the steps his admin grant to the jarvis Gitea token covers. Sage created the four mosaic-stack bots (ids 114-117, restricted, non-admin), added them as collaborators (W/W/W/R), and minted one scoped token each (ids 191-194). The tokens were written 0600 outside the repo. Scripts and receipt are in agents/sage/work/gitea-setup/. The guide and SR brief now say who runs which section. Sections 2 to 4 (Vikunja) stay with Jason. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -1464,3 +1464,46 @@ which stay with him. Each item names who decided it and what happened.
|
||||
before the signal and so never hit the start-up race. Row 46
|
||||
landed the fixture fix as 2d308abd. The BUILD-LOG landing entry
|
||||
records it.
|
||||
74. **Agents run the Gitea steps Jason's admin token covers, and
|
||||
section 1 is done (2026-10-09).** Source: Jason in Sage's thread,
|
||||
2026-10-09, after I asked him to run section 1: "I should not be
|
||||
doing this. I have granted agentic tokens to admin the gitea server
|
||||
at git.mosaicstack.dev ... I would like you to use the gitea token to
|
||||
set things up. Ask me any questions for the setup, but I should not
|
||||
be performing the steps I already granted rights for."
|
||||
- The rule: a step a granted credential covers is an agent's step,
|
||||
not Jason's. The lead seat runs it and records it. A step that
|
||||
needs a credential no agent holds still goes to Jason, and so do
|
||||
decisions about granting one. The grant covers the jarvis token's
|
||||
admin rights on git.mosaicstack.dev only. It gives no push to
|
||||
`next` or `main`, no merge and no branch-protection change, and
|
||||
R10 and the merge plan's gates stand.
|
||||
- Sage ran runbook section 1 for `mosaic-stack` through the API
|
||||
between 22:21 and 22:23 UTC. Users `mosaic-stack-{pm,cto,coder,reviewer}-bot`
|
||||
are ids 114 to 117, none admin. Collaborators on
|
||||
`mosaicstack/stack` are Write for pm, cto and coder and Read for
|
||||
reviewer. Tokens are ids 191 to 194, named
|
||||
`mosaic-stack-<role>-2026-10-09` with the guide's scopes, in
|
||||
`~/.config/mosaic-dev/secrets/mosaic-stack/<role>-gitea.token`
|
||||
at 0600, 40 bytes each, checked with `stat`. The `rotateBy` base
|
||||
is 2026-10-09, so the first rotation is due 2027-01-07. The main
|
||||
and next protections' push, merge and approvals allowlists are
|
||||
empty before and after. Receipt and scripts:
|
||||
`agents/sage/work/gitea-setup/`.
|
||||
- Choices the guide didn't make, all narrower than it: each bot is
|
||||
`restricted` with `private` visibility. Bot passwords were random,
|
||||
held in memory only and discarded, so nobody can log in as a bot.
|
||||
Addresses are `<user>@noreply.mosaicstack.dev`. Jason invited
|
||||
questions on these. Each had a narrower option, so I took it
|
||||
instead of asking, and he can reverse any of them.
|
||||
- A test on the pm bot showed `prohibit_login` stops its token at
|
||||
once (403) and clearing it restores the token. With no bot
|
||||
password, that flag and collaborator removal are the immediate
|
||||
revocations. Follow-up before 2027-01-07: the setup script also
|
||||
deletes the old token during a rotation.
|
||||
- Not covered: the Vikunja half. Sections 2 to 4 need the estate
|
||||
instance (T236, not serving) and the owner and `svc-mosaic-stack`
|
||||
logins. No agent holds a Vikunja admin credential, so R5 keeps
|
||||
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
|
||||
waiting on Jason for that half only. Its note said Path B, which
|
||||
decisions 66 and 67 replaced, and the note now says so.
|
||||
|
||||
@@ -195,14 +195,20 @@ No token value appears in the runbook, a command line or a URL.
|
||||
|
||||
### Out of scope
|
||||
|
||||
- Any script that creates users or tokens. Minting is out of v1.
|
||||
- Running the runbook. Jason does that, and row S3's live tests wait for
|
||||
it.
|
||||
- Any script in the product that creates users or tokens. Minting is
|
||||
out of v1. Sage's operator script for section 1
|
||||
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
|
||||
stack, and nothing in the stack calls it.
|
||||
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
|
||||
the admin token Jason granted (decision 74). Jason runs sections 2 to
|
||||
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
|
||||
tests wait for them.
|
||||
|
||||
### Gate
|
||||
|
||||
Darkwing approves the scope tables. Jason runs it, and the broker's
|
||||
startup probe passes for every identity.
|
||||
Darkwing approves the scope tables. The runbook runs, section 1 by
|
||||
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
|
||||
for every identity.
|
||||
|
||||
## Slice 1 S1: roles v2, business and project files, variable layers
|
||||
|
||||
|
||||
Reference in New Issue
Block a user