docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)
Jason asked for tasks.mosaicstack.dev operational with agents configured in it. Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32, bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only (Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27 NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert renewal fix and the last-applied annotation slip. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -541,3 +541,4 @@ are never rewritten or removed; corrections are new entries.
|
||||
2026-10-09T14:26Z | Filbert (T3 Claude Code, thread 9cb9731e) | row 45 (#1527) S4 follow-up review round 2 | approve, comment 26886, queue rev 218 (5eb9fa8a), record 9b067be1; B1 resolved (permanent 403 sends at 0/30/60/90/120 min, gave-up at 120, also under a 15 s crash loop and a 401), R1 resolved (4 callbacks, each mutant fails an EPIPE test), G184 fails in 22 s (CLOSE_TIMEOUT_MS) not a hang, append type-check decline agreed (A3: 20 real DMs in 10 min), 31/31 of Rocko's mutants killed, gate green but test-task 26/2 (Docker recall), notes: future-at silent hold, README 429 wording, digest-refusal pacing untested
|
||||
2026-10-09T14:29:13Z | Sage (T3 Claude Code, thread 1ef1e4f8) | land row 45 (#1527) | Darkwing (26884) and Filbert (26886) approve round 2, candidate 5b067a9d. Gate on b13fef4c plus the patch all green, no COMPOSE_PROJECT_NAME override, test-task 98/0. Candidate 9cdb6d82, my trackers-boot copy removed 2be51cf5, Rocko's BUILD-LOG entries and SESSIONS line plus my landing entry 5c680166, queue rev 219 f345ae85, pushed; #1527 closed (comment 26892). Reviewers' non-blocking notes recorded for a follow-up row. Gate worktree removed; Rocko told to remove their tree.
|
||||
2026-10-09T22:24:54Z | Sage (T3 Claude Code, thread 1ef1e4f8) | row 35 (#1517) runbook section 1, Gitea bots, on Jason's admin-token grant | lead decision 74; four mosaic-stack bots ids 114-117 restricted and non-admin, collaborators W/W/W/R, tokens 191-194 at 0600 in ~/.config/mosaic-dev/secrets/mosaic-stack (stat only), verify.mjs and a prohibit_login revocation test pass, protections unchanged; guide and SR brief updated; row 35 note and gate, revs 221-222; Vikunja half still Jason's
|
||||
2026-10-09T22:48:44Z | Sage (T3 Claude Code, thread 1ef1e4f8) | Jason: tasks.mosaicstack.dev operational with agents; row 35 (#1517) sections 2-3 | lead decision 75; backup plus tested restore, infra PR #325 Vikunja 2.7.0 (counts held), sections 2-3 by API: owner id 4, svc id 5, project 32, bots 6-10, tokens to 2027-01-07 at 0600, isolation and round-trip probes pass; OIDC broken since the 2026-04-27 netpol, PR #326 with ops-01; cert fix and annotation slip recorded; infra PRs now get independent review (Mos)
|
||||
|
||||
@@ -8,9 +8,12 @@ tokens for you. Brief: `docs/plans/2026-10-04_slice-1.md`, row SR.
|
||||
Who the operator is depends on the credential. On 2026-10-09 Jason gave
|
||||
the jarvis Gitea token site admin rights and ruled that agents run the
|
||||
steps it covers, so Sage ran section 1 for `mosaic-stack` through the
|
||||
API (lead decision 74). Sections 2 to 4 need the Vikunja owner and
|
||||
`svc-$BIZ` logins, which no agent holds, so they stay with Jason until he
|
||||
grants a Vikunja credential.
|
||||
API (lead decision 74). The same day Jason asked for agents configured
|
||||
in tasks.mosaicstack.dev, so Sage upgraded it to 2.7.0 and ran sections
|
||||
2 and 3 through the API as well (lead decision 75). Sage holds the
|
||||
owner and `svc-$BIZ` passwords, in 0600 files under
|
||||
`~/.config/mosaic-dev/secrets/vikunja-admin/`, apart from the token
|
||||
directory the broker reads.
|
||||
|
||||
Plan on about 20 minutes with an existing Vikunja, and 30 if you start
|
||||
the bundled one.
|
||||
@@ -27,7 +30,9 @@ the bundled one.
|
||||
are the high-value secrets. They are used only in this guide, and never reach
|
||||
the broker or a worker. The one exception is the jarvis Gitea admin
|
||||
token, which Jason granted to the lead seat for section 1 (decision 74).
|
||||
It stays in its fleet file, and the broker never reads it.
|
||||
It stays in its fleet file, and the broker never reads it. The Vikunja
|
||||
passwords for Mosaic Stack sit in `vikunja-admin/`, never in the
|
||||
token directory (decision 75).
|
||||
|
||||
## 0. Set up the shell
|
||||
|
||||
@@ -128,13 +133,16 @@ that is yours, and a service account `svc-$BIZ` that owns the bots.
|
||||
|
||||
### Path A, an existing instance
|
||||
|
||||
Mosaic Stack uses this path on the estate instance (lead decision 66).
|
||||
Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io.
|
||||
Mosaic Stack uses this path on tasks.mosaicstack.dev (lead decisions
|
||||
66 and 75). Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io
|
||||
or tasks.uscllc.com.
|
||||
|
||||
Check that `curl -s "$VK/api/v1/info"` reports `v2.7.0` or later. Use your
|
||||
existing account as the owner.
|
||||
|
||||
The estate instance also holds Launchpad, personal and system projects.
|
||||
tasks.mosaicstack.dev also holds older Launchpad, personal and system
|
||||
projects. It serves Mosaic Stack only, and no other business moves onto
|
||||
it without Jason's ruling.
|
||||
A bot sees only the projects shared with it, so section 3 shares the
|
||||
`mosaic-stack` project and nothing else. Never share another project
|
||||
with a `bot-mosaic-stack-*` user.
|
||||
@@ -200,7 +208,12 @@ docker exec -it mosaic-vikunja /app/vikunja/vikunja user create -u "svc-$BIZ" -e
|
||||
|
||||
On Path A, you create it yourself, because its password is yours to
|
||||
keep. The instance's ops doc gives the exact `vikunja user create`
|
||||
command for its container, with the password entered at a prompt.
|
||||
command for its container, with the password entered at a prompt. For
|
||||
Mosaic Stack, Sage registered both accounts through `/api/v2/register`
|
||||
with `agents/sage/work/vikunja-setup/setup.mjs`, because the image has
|
||||
no shell and registration was open (decision 75). The owner is
|
||||
`mosaic-stack-owner`, which shares the project with `jason.woltje` as
|
||||
admin.
|
||||
|
||||
### Logins for this guide
|
||||
|
||||
|
||||
@@ -1507,3 +1507,42 @@ which stay with him. Each item names who decided it and what happened.
|
||||
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
|
||||
waiting on Jason for that half only. Its note said Path B, which
|
||||
decisions 66 and 67 replaced, and the note now says so.
|
||||
|
||||
75. **tasks.mosaicstack.dev runs Vikunja 2.7.0 and holds the Mosaic
|
||||
Stack agents (2026-10-09).** Source: Jason in Sage's thread,
|
||||
2026-10-09: "I want tasks.mosaicstack.dev operational. I want agents
|
||||
configured within tasks.mosaicstack.dev. I want to see this get
|
||||
done." Decision 74's rule applies: Sage holds cluster-admin through
|
||||
kubectl and the jarvis Gitea token, so these were Sage's steps.
|
||||
- Scope, per Mos relaying Jason (his Q9 is open): the instance serves
|
||||
Mosaic Stack work and its agent accounts only. No other business,
|
||||
project set or team moves onto it. SetSpark stays on
|
||||
tasks.setspark.io and USC on tasks.uscllc.com. Don't call it the
|
||||
estate instance. This replaces decision 66's "estate instance"
|
||||
wording and T236's separate new instance, which Mos stopped.
|
||||
- Upgrade: infra PR #325 pinned `vikunja/vikunja:2.7.0@sha256:e2204a1c…`
|
||||
in place of `latest` (2.1.0). Backup and a tested restore came
|
||||
first; migrations ran clean and the counts held (tasks 142,
|
||||
projects 29, users 3). Rollback is a revert plus a restore of the
|
||||
dump. Sage merged #325 as author. Mos accepted it and set the rule
|
||||
that I follow from now on: the infrastructure repo is prod, and a
|
||||
PR there gets an independent review (ops-01 or Mos) before merge,
|
||||
even when I wrote it. Cert, DNS, Cloudflare and edge work goes to
|
||||
ops-01 through Mos.
|
||||
- Runbook sections 2 and 3 ran through the API at 22:45Z.
|
||||
`mosaic-stack-owner` (id 4) owns project `mosaic-stack` (32) and
|
||||
shares it with `jason.woltje` as admin. `svc-mosaic-stack` (5) owns
|
||||
the five bots (6 to 10) and nothing else. Tokens expire
|
||||
2027-01-07. Both account passwords are agent-held, in
|
||||
`~/.config/mosaic-dev/secrets/vikunja-admin/`, outside the token
|
||||
directory. I chose an agent-held owner over Jason's account
|
||||
because his is OIDC-only and can't log in with a password, and
|
||||
sharing as admin keeps the project his to manage.
|
||||
- The probes passed: no bot reads a task outside project 32, workers
|
||||
can't delete, sync can't write. The instance has no labels yet,
|
||||
so decision 68's label leak has nothing to show until someone
|
||||
creates one. Receipt: `agents/sage/work/vikunja-setup/`.
|
||||
- Open, owned elsewhere: OIDC has been broken since the 2026-04-27
|
||||
NetworkPolicy, so Jason can't log in to the web UI yet. PR #326
|
||||
and turning registration off are with ops-01. The broker's startup
|
||||
probe (row S3) closes row SR's gate.
|
||||
|
||||
@@ -196,19 +196,19 @@ No token value appears in the runbook, a command line or a URL.
|
||||
### Out of scope
|
||||
|
||||
- Any script in the product that creates users or tokens. Minting is
|
||||
out of v1. Sage's operator script for section 1
|
||||
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
|
||||
stack, and nothing in the stack calls it.
|
||||
out of v1. Sage's operator scripts for sections 1 to 3
|
||||
(`agents/sage/work/gitea-setup/` and `agents/sage/work/vikunja-setup/`,
|
||||
decisions 74 and 75) aren't part of the stack, and nothing in the
|
||||
stack calls them.
|
||||
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
|
||||
the admin token Jason granted (decision 74). Jason runs sections 2 to
|
||||
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
|
||||
tests wait for them.
|
||||
the admin token Jason granted (decision 74), and sections 2 and 3
|
||||
(Vikunja) the same day on tasks.mosaicstack.dev (decision 75).
|
||||
|
||||
### Gate
|
||||
|
||||
Darkwing approves the scope tables. The runbook runs, section 1 by
|
||||
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
|
||||
for every identity.
|
||||
Darkwing approves the scope tables. The runbook runs (sections 1 to 3
|
||||
done by Sage on 2026-10-09), and the broker's startup probe from row S3
|
||||
passes for every identity.
|
||||
|
||||
## Slice 1 S1: roles v2, business and project files, variable layers
|
||||
|
||||
|
||||
Reference in New Issue
Block a user