docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)

Jason asked for tasks.mosaicstack.dev operational with agents configured in it.
Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran
sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32,
bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only
(Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27
NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert
renewal fix and the last-applied annotation slip.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 17:49:40 -05:00
co-authored by Claude Opus 5.5
parent ecbf59e555
commit a6382f7bdf
10 changed files with 314 additions and 17 deletions
+1
View File
@@ -541,3 +541,4 @@ are never rewritten or removed; corrections are new entries.
2026-10-09T14:26Z | Filbert (T3 Claude Code, thread 9cb9731e) | row 45 (#1527) S4 follow-up review round 2 | approve, comment 26886, queue rev 218 (5eb9fa8a), record 9b067be1; B1 resolved (permanent 403 sends at 0/30/60/90/120 min, gave-up at 120, also under a 15 s crash loop and a 401), R1 resolved (4 callbacks, each mutant fails an EPIPE test), G184 fails in 22 s (CLOSE_TIMEOUT_MS) not a hang, append type-check decline agreed (A3: 20 real DMs in 10 min), 31/31 of Rocko's mutants killed, gate green but test-task 26/2 (Docker recall), notes: future-at silent hold, README 429 wording, digest-refusal pacing untested
2026-10-09T14:29:13Z | Sage (T3 Claude Code, thread 1ef1e4f8) | land row 45 (#1527) | Darkwing (26884) and Filbert (26886) approve round 2, candidate 5b067a9d. Gate on b13fef4c plus the patch all green, no COMPOSE_PROJECT_NAME override, test-task 98/0. Candidate 9cdb6d82, my trackers-boot copy removed 2be51cf5, Rocko's BUILD-LOG entries and SESSIONS line plus my landing entry 5c680166, queue rev 219 f345ae85, pushed; #1527 closed (comment 26892). Reviewers' non-blocking notes recorded for a follow-up row. Gate worktree removed; Rocko told to remove their tree.
2026-10-09T22:24:54Z | Sage (T3 Claude Code, thread 1ef1e4f8) | row 35 (#1517) runbook section 1, Gitea bots, on Jason's admin-token grant | lead decision 74; four mosaic-stack bots ids 114-117 restricted and non-admin, collaborators W/W/W/R, tokens 191-194 at 0600 in ~/.config/mosaic-dev/secrets/mosaic-stack (stat only), verify.mjs and a prohibit_login revocation test pass, protections unchanged; guide and SR brief updated; row 35 note and gate, revs 221-222; Vikunja half still Jason's
2026-10-09T22:48:44Z | Sage (T3 Claude Code, thread 1ef1e4f8) | Jason: tasks.mosaicstack.dev operational with agents; row 35 (#1517) sections 2-3 | lead decision 75; backup plus tested restore, infra PR #325 Vikunja 2.7.0 (counts held), sections 2-3 by API: owner id 4, svc id 5, project 32, bots 6-10, tokens to 2027-01-07 at 0600, isolation and round-trip probes pass; OIDC broken since the 2026-04-27 netpol, PR #326 with ops-01; cert fix and annotation slip recorded; infra PRs now get independent review (Mos)
+21 -8
View File
@@ -8,9 +8,12 @@ tokens for you. Brief: `docs/plans/2026-10-04_slice-1.md`, row SR.
Who the operator is depends on the credential. On 2026-10-09 Jason gave
the jarvis Gitea token site admin rights and ruled that agents run the
steps it covers, so Sage ran section 1 for `mosaic-stack` through the
API (lead decision 74). Sections 2 to 4 need the Vikunja owner and
`svc-$BIZ` logins, which no agent holds, so they stay with Jason until he
grants a Vikunja credential.
API (lead decision 74). The same day Jason asked for agents configured
in tasks.mosaicstack.dev, so Sage upgraded it to 2.7.0 and ran sections
2 and 3 through the API as well (lead decision 75). Sage holds the
owner and `svc-$BIZ` passwords, in 0600 files under
`~/.config/mosaic-dev/secrets/vikunja-admin/`, apart from the token
directory the broker reads.
Plan on about 20 minutes with an existing Vikunja, and 30 if you start
the bundled one.
@@ -27,7 +30,9 @@ the bundled one.
are the high-value secrets. They are used only in this guide, and never reach
the broker or a worker. The one exception is the jarvis Gitea admin
token, which Jason granted to the lead seat for section 1 (decision 74).
It stays in its fleet file, and the broker never reads it.
It stays in its fleet file, and the broker never reads it. The Vikunja
passwords for Mosaic Stack sit in `vikunja-admin/`, never in the
token directory (decision 75).
## 0. Set up the shell
@@ -128,13 +133,16 @@ that is yours, and a service account `svc-$BIZ` that owns the bots.
### Path A, an existing instance
Mosaic Stack uses this path on the estate instance (lead decision 66).
Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io.
Mosaic Stack uses this path on tasks.mosaicstack.dev (lead decisions
66 and 75). Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io
or tasks.uscllc.com.
Check that `curl -s "$VK/api/v1/info"` reports `v2.7.0` or later. Use your
existing account as the owner.
The estate instance also holds Launchpad, personal and system projects.
tasks.mosaicstack.dev also holds older Launchpad, personal and system
projects. It serves Mosaic Stack only, and no other business moves onto
it without Jason's ruling.
A bot sees only the projects shared with it, so section 3 shares the
`mosaic-stack` project and nothing else. Never share another project
with a `bot-mosaic-stack-*` user.
@@ -200,7 +208,12 @@ docker exec -it mosaic-vikunja /app/vikunja/vikunja user create -u "svc-$BIZ" -e
On Path A, you create it yourself, because its password is yours to
keep. The instance's ops doc gives the exact `vikunja user create`
command for its container, with the password entered at a prompt.
command for its container, with the password entered at a prompt. For
Mosaic Stack, Sage registered both accounts through `/api/v2/register`
with `agents/sage/work/vikunja-setup/setup.mjs`, because the image has
no shell and registration was open (decision 75). The owner is
`mosaic-stack-owner`, which shares the project with `jason.woltje` as
admin.
### Logins for this guide
+39
View File
@@ -1507,3 +1507,42 @@ which stay with him. Each item names who decided it and what happened.
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
waiting on Jason for that half only. Its note said Path B, which
decisions 66 and 67 replaced, and the note now says so.
75. **tasks.mosaicstack.dev runs Vikunja 2.7.0 and holds the Mosaic
Stack agents (2026-10-09).** Source: Jason in Sage's thread,
2026-10-09: "I want tasks.mosaicstack.dev operational. I want agents
configured within tasks.mosaicstack.dev. I want to see this get
done." Decision 74's rule applies: Sage holds cluster-admin through
kubectl and the jarvis Gitea token, so these were Sage's steps.
- Scope, per Mos relaying Jason (his Q9 is open): the instance serves
Mosaic Stack work and its agent accounts only. No other business,
project set or team moves onto it. SetSpark stays on
tasks.setspark.io and USC on tasks.uscllc.com. Don't call it the
estate instance. This replaces decision 66's "estate instance"
wording and T236's separate new instance, which Mos stopped.
- Upgrade: infra PR #325 pinned `vikunja/vikunja:2.7.0@sha256:e2204a1c…`
in place of `latest` (2.1.0). Backup and a tested restore came
first; migrations ran clean and the counts held (tasks 142,
projects 29, users 3). Rollback is a revert plus a restore of the
dump. Sage merged #325 as author. Mos accepted it and set the rule
that I follow from now on: the infrastructure repo is prod, and a
PR there gets an independent review (ops-01 or Mos) before merge,
even when I wrote it. Cert, DNS, Cloudflare and edge work goes to
ops-01 through Mos.
- Runbook sections 2 and 3 ran through the API at 22:45Z.
`mosaic-stack-owner` (id 4) owns project `mosaic-stack` (32) and
shares it with `jason.woltje` as admin. `svc-mosaic-stack` (5) owns
the five bots (6 to 10) and nothing else. Tokens expire
2027-01-07. Both account passwords are agent-held, in
`~/.config/mosaic-dev/secrets/vikunja-admin/`, outside the token
directory. I chose an agent-held owner over Jason's account
because his is OIDC-only and can't log in with a password, and
sharing as admin keeps the project his to manage.
- The probes passed: no bot reads a task outside project 32, workers
can't delete, sync can't write. The instance has no labels yet,
so decision 68's label leak has nothing to show until someone
creates one. Receipt: `agents/sage/work/vikunja-setup/`.
- Open, owned elsewhere: OIDC has been broken since the 2026-04-27
NetworkPolicy, so Jason can't log in to the web UI yet. PR #326
and turning registration off are with ops-01. The broker's startup
probe (row S3) closes row SR's gate.
+9 -9
View File
@@ -196,19 +196,19 @@ No token value appears in the runbook, a command line or a URL.
### Out of scope
- Any script in the product that creates users or tokens. Minting is
out of v1. Sage's operator script for section 1
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
stack, and nothing in the stack calls it.
out of v1. Sage's operator scripts for sections 1 to 3
(`agents/sage/work/gitea-setup/` and `agents/sage/work/vikunja-setup/`,
decisions 74 and 75) aren't part of the stack, and nothing in the
stack calls them.
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
the admin token Jason granted (decision 74). Jason runs sections 2 to
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
tests wait for them.
the admin token Jason granted (decision 74), and sections 2 and 3
(Vikunja) the same day on tasks.mosaicstack.dev (decision 75).
### Gate
Darkwing approves the scope tables. The runbook runs, section 1 by
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
for every identity.
Darkwing approves the scope tables. The runbook runs (sections 1 to 3
done by Sage on 2026-10-09), and the broker's startup probe from row S3
passes for every identity.
## Slice 1 S1: roles v2, business and project files, variable layers