docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)
Jason asked for tasks.mosaicstack.dev operational with agents configured in it. Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32, bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only (Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27 NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert renewal fix and the last-applied annotation slip. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -8,9 +8,12 @@ tokens for you. Brief: `docs/plans/2026-10-04_slice-1.md`, row SR.
|
||||
Who the operator is depends on the credential. On 2026-10-09 Jason gave
|
||||
the jarvis Gitea token site admin rights and ruled that agents run the
|
||||
steps it covers, so Sage ran section 1 for `mosaic-stack` through the
|
||||
API (lead decision 74). Sections 2 to 4 need the Vikunja owner and
|
||||
`svc-$BIZ` logins, which no agent holds, so they stay with Jason until he
|
||||
grants a Vikunja credential.
|
||||
API (lead decision 74). The same day Jason asked for agents configured
|
||||
in tasks.mosaicstack.dev, so Sage upgraded it to 2.7.0 and ran sections
|
||||
2 and 3 through the API as well (lead decision 75). Sage holds the
|
||||
owner and `svc-$BIZ` passwords, in 0600 files under
|
||||
`~/.config/mosaic-dev/secrets/vikunja-admin/`, apart from the token
|
||||
directory the broker reads.
|
||||
|
||||
Plan on about 20 minutes with an existing Vikunja, and 30 if you start
|
||||
the bundled one.
|
||||
@@ -27,7 +30,9 @@ the bundled one.
|
||||
are the high-value secrets. They are used only in this guide, and never reach
|
||||
the broker or a worker. The one exception is the jarvis Gitea admin
|
||||
token, which Jason granted to the lead seat for section 1 (decision 74).
|
||||
It stays in its fleet file, and the broker never reads it.
|
||||
It stays in its fleet file, and the broker never reads it. The Vikunja
|
||||
passwords for Mosaic Stack sit in `vikunja-admin/`, never in the
|
||||
token directory (decision 75).
|
||||
|
||||
## 0. Set up the shell
|
||||
|
||||
@@ -128,13 +133,16 @@ that is yours, and a service account `svc-$BIZ` that owns the bots.
|
||||
|
||||
### Path A, an existing instance
|
||||
|
||||
Mosaic Stack uses this path on the estate instance (lead decision 66).
|
||||
Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io.
|
||||
Mosaic Stack uses this path on tasks.mosaicstack.dev (lead decisions
|
||||
66 and 75). Set `VK` to its HTTPS base URL. Don't use tasks.setspark.io
|
||||
or tasks.uscllc.com.
|
||||
|
||||
Check that `curl -s "$VK/api/v1/info"` reports `v2.7.0` or later. Use your
|
||||
existing account as the owner.
|
||||
|
||||
The estate instance also holds Launchpad, personal and system projects.
|
||||
tasks.mosaicstack.dev also holds older Launchpad, personal and system
|
||||
projects. It serves Mosaic Stack only, and no other business moves onto
|
||||
it without Jason's ruling.
|
||||
A bot sees only the projects shared with it, so section 3 shares the
|
||||
`mosaic-stack` project and nothing else. Never share another project
|
||||
with a `bot-mosaic-stack-*` user.
|
||||
@@ -200,7 +208,12 @@ docker exec -it mosaic-vikunja /app/vikunja/vikunja user create -u "svc-$BIZ" -e
|
||||
|
||||
On Path A, you create it yourself, because its password is yours to
|
||||
keep. The instance's ops doc gives the exact `vikunja user create`
|
||||
command for its container, with the password entered at a prompt.
|
||||
command for its container, with the password entered at a prompt. For
|
||||
Mosaic Stack, Sage registered both accounts through `/api/v2/register`
|
||||
with `agents/sage/work/vikunja-setup/setup.mjs`, because the image has
|
||||
no shell and registration was open (decision 75). The owner is
|
||||
`mosaic-stack-owner`, which shares the project with `jason.woltje` as
|
||||
admin.
|
||||
|
||||
### Logins for this guide
|
||||
|
||||
|
||||
Reference in New Issue
Block a user