docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)

Jason asked for tasks.mosaicstack.dev operational with agents configured in it.
Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran
sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32,
bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only
(Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27
NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert
renewal fix and the last-applied annotation slip.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 17:49:40 -05:00
co-authored by Claude Opus 5.5
parent ecbf59e555
commit a6382f7bdf
10 changed files with 314 additions and 17 deletions
+21 -8
View File
@@ -8,9 +8,12 @@ tokens for you. Brief: `docs/plans/2026-10-04_slice-1.md`, row SR.
Who the operator is depends on the credential. On 2026-10-09 Jason gave
the jarvis Gitea token site admin rights and ruled that agents run the
steps it covers, so Sage ran section 1 for `mosaic-stack` through the
API (lead decision 74). Sections 2 to 4 need the Vikunja owner and
`svc-$BIZ` logins, which no agent holds, so they stay with Jason until he
grants a Vikunja credential.
API (lead decision 74). The same day Jason asked for agents configured
in tasks.mosaicstack.dev, so Sage upgraded it to 2.7.0 and ran sections
2 and 3 through the API as well (lead decision 75). Sage holds the
owner and `svc-$BIZ` passwords, in 0600 files under
`~/.config/mosaic-dev/secrets/vikunja-admin/`, apart from the token
directory the broker reads.
Plan on about 20 minutes with an existing Vikunja, and 30 if you start
the bundled one.
@@ -27,7 +30,9 @@ the bundled one.
are the high-value secrets. They are used only in this guide, and never reach
the broker or a worker. The one exception is the jarvis Gitea admin
token, which Jason granted to the lead seat for section 1 (decision 74).
It stays in its fleet file, and the broker never reads it.
It stays in its fleet file, and the broker never reads it. The Vikunja
passwords for Mosaic Stack sit in `vikunja-admin/`, never in the
token directory (decision 75).
## 0. Set up the shell
@@ -128,13 +133,16 @@ that is yours, and a service account `svc-$BIZ` that owns the bots.
### Path A, an existing instance
Mosaic Stack uses this path on the estate instance (lead decision 66).
Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io.
Mosaic Stack uses this path on tasks.mosaicstack.dev (lead decisions
66 and 75). Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io
or tasks.uscllc.com.
Check that `curl -s "$VK/api/v1/info"` reports `v2.7.0` or later. Use your
existing account as the owner.
The estate instance also holds Launchpad, personal and system projects.
tasks.mosaicstack.dev also holds older Launchpad, personal and system
projects. It serves Mosaic Stack only, and no other business moves onto
it without Jason's ruling.
A bot sees only the projects shared with it, so section 3 shares the
`mosaic-stack` project and nothing else. Never share another project
with a `bot-mosaic-stack-*` user.
@@ -200,7 +208,12 @@ docker exec -it mosaic-vikunja /app/vikunja/vikunja user create -u "svc-$BIZ" -e
On Path A, you create it yourself, because its password is yours to
keep. The instance's ops doc gives the exact `vikunja user create`
command for its container, with the password entered at a prompt.
command for its container, with the password entered at a prompt. For
Mosaic Stack, Sage registered both accounts through `/api/v2/register`
with `agents/sage/work/vikunja-setup/setup.mjs`, because the image has
no shell and registration was open (decision 75). The owner is
`mosaic-stack-owner`, which shares the project with `jason.woltje` as
admin.
### Logins for this guide