docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)
Jason asked for tasks.mosaicstack.dev operational with agents configured in it. Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32, bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only (Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27 NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert renewal fix and the last-applied annotation slip. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -1507,3 +1507,42 @@ which stay with him. Each item names who decided it and what happened.
|
||||
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
|
||||
waiting on Jason for that half only. Its note said Path B, which
|
||||
decisions 66 and 67 replaced, and the note now says so.
|
||||
|
||||
75. **tasks.mosaicstack.dev runs Vikunja 2.7.0 and holds the Mosaic
|
||||
Stack agents (2026-10-09).** Source: Jason in Sage's thread,
|
||||
2026-10-09: "I want tasks.mosaicstack.dev operational. I want agents
|
||||
configured within tasks.mosaicstack.dev. I want to see this get
|
||||
done." Decision 74's rule applies: Sage holds cluster-admin through
|
||||
kubectl and the jarvis Gitea token, so these were Sage's steps.
|
||||
- Scope, per Mos relaying Jason (his Q9 is open): the instance serves
|
||||
Mosaic Stack work and its agent accounts only. No other business,
|
||||
project set or team moves onto it. SetSpark stays on
|
||||
tasks.setspark.io and USC on tasks.uscllc.com. Don't call it the
|
||||
estate instance. This replaces decision 66's "estate instance"
|
||||
wording and T236's separate new instance, which Mos stopped.
|
||||
- Upgrade: infra PR #325 pinned `vikunja/vikunja:2.7.0@sha256:e2204a1c…`
|
||||
in place of `latest` (2.1.0). Backup and a tested restore came
|
||||
first; migrations ran clean and the counts held (tasks 142,
|
||||
projects 29, users 3). Rollback is a revert plus a restore of the
|
||||
dump. Sage merged #325 as author. Mos accepted it and set the rule
|
||||
that I follow from now on: the infrastructure repo is prod, and a
|
||||
PR there gets an independent review (ops-01 or Mos) before merge,
|
||||
even when I wrote it. Cert, DNS, Cloudflare and edge work goes to
|
||||
ops-01 through Mos.
|
||||
- Runbook sections 2 and 3 ran through the API at 22:45Z.
|
||||
`mosaic-stack-owner` (id 4) owns project `mosaic-stack` (32) and
|
||||
shares it with `jason.woltje` as admin. `svc-mosaic-stack` (5) owns
|
||||
the five bots (6 to 10) and nothing else. Tokens expire
|
||||
2027-01-07. Both account passwords are agent-held, in
|
||||
`~/.config/mosaic-dev/secrets/vikunja-admin/`, outside the token
|
||||
directory. I chose an agent-held owner over Jason's account
|
||||
because his is OIDC-only and can't log in with a password, and
|
||||
sharing as admin keeps the project his to manage.
|
||||
- The probes passed: no bot reads a task outside project 32, workers
|
||||
can't delete, sync can't write. The instance has no labels yet,
|
||||
so decision 68's label leak has nothing to show until someone
|
||||
creates one. Receipt: `agents/sage/work/vikunja-setup/`.
|
||||
- Open, owned elsewhere: OIDC has been broken since the 2026-04-27
|
||||
NetworkPolicy, so Jason can't log in to the web UI yet. PR #326
|
||||
and turning registration off are with ops-01. The broker's startup
|
||||
probe (row S3) closes row SR's gate.
|
||||
|
||||
@@ -196,19 +196,19 @@ No token value appears in the runbook, a command line or a URL.
|
||||
### Out of scope
|
||||
|
||||
- Any script in the product that creates users or tokens. Minting is
|
||||
out of v1. Sage's operator script for section 1
|
||||
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
|
||||
stack, and nothing in the stack calls it.
|
||||
out of v1. Sage's operator scripts for sections 1 to 3
|
||||
(`agents/sage/work/gitea-setup/` and `agents/sage/work/vikunja-setup/`,
|
||||
decisions 74 and 75) aren't part of the stack, and nothing in the
|
||||
stack calls them.
|
||||
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
|
||||
the admin token Jason granted (decision 74). Jason runs sections 2 to
|
||||
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
|
||||
tests wait for them.
|
||||
the admin token Jason granted (decision 74), and sections 2 and 3
|
||||
(Vikunja) the same day on tasks.mosaicstack.dev (decision 75).
|
||||
|
||||
### Gate
|
||||
|
||||
Darkwing approves the scope tables. The runbook runs, section 1 by
|
||||
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
|
||||
for every identity.
|
||||
Darkwing approves the scope tables. The runbook runs (sections 1 to 3
|
||||
done by Sage on 2026-10-09), and the broker's startup probe from row S3
|
||||
passes for every identity.
|
||||
|
||||
## Slice 1 S1: roles v2, business and project files, variable layers
|
||||
|
||||
|
||||
Reference in New Issue
Block a user