docs(slice1): tasks.mosaicstack.dev on Vikunja 2.7.0, runbook sections 2-3 by Sage (row 35, #1517, lead decision 75)

Jason asked for tasks.mosaicstack.dev operational with agents configured in it.
Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran
sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32,
bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only
(Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27
NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert
renewal fix and the last-applied annotation slip.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 17:49:40 -05:00
co-authored by Claude Opus 5.5
parent ecbf59e555
commit a6382f7bdf
10 changed files with 314 additions and 17 deletions
+39
View File
@@ -1507,3 +1507,42 @@ which stay with him. Each item names who decided it and what happened.
`svc-mosaic-stack` with Jason until he grants one. Row 35 stays
waiting on Jason for that half only. Its note said Path B, which
decisions 66 and 67 replaced, and the note now says so.
75. **tasks.mosaicstack.dev runs Vikunja 2.7.0 and holds the Mosaic
Stack agents (2026-10-09).** Source: Jason in Sage's thread,
2026-10-09: "I want tasks.mosaicstack.dev operational. I want agents
configured within tasks.mosaicstack.dev. I want to see this get
done." Decision 74's rule applies: Sage holds cluster-admin through
kubectl and the jarvis Gitea token, so these were Sage's steps.
- Scope, per Mos relaying Jason (his Q9 is open): the instance serves
Mosaic Stack work and its agent accounts only. No other business,
project set or team moves onto it. SetSpark stays on
tasks.setspark.io and USC on tasks.uscllc.com. Don't call it the
estate instance. This replaces decision 66's "estate instance"
wording and T236's separate new instance, which Mos stopped.
- Upgrade: infra PR #325 pinned `vikunja/vikunja:2.7.0@sha256:e2204a1c…`
in place of `latest` (2.1.0). Backup and a tested restore came
first; migrations ran clean and the counts held (tasks 142,
projects 29, users 3). Rollback is a revert plus a restore of the
dump. Sage merged #325 as author. Mos accepted it and set the rule
that I follow from now on: the infrastructure repo is prod, and a
PR there gets an independent review (ops-01 or Mos) before merge,
even when I wrote it. Cert, DNS, Cloudflare and edge work goes to
ops-01 through Mos.
- Runbook sections 2 and 3 ran through the API at 22:45Z.
`mosaic-stack-owner` (id 4) owns project `mosaic-stack` (32) and
shares it with `jason.woltje` as admin. `svc-mosaic-stack` (5) owns
the five bots (6 to 10) and nothing else. Tokens expire
2027-01-07. Both account passwords are agent-held, in
`~/.config/mosaic-dev/secrets/vikunja-admin/`, outside the token
directory. I chose an agent-held owner over Jason's account
because his is OIDC-only and can't log in with a password, and
sharing as admin keeps the project his to manage.
- The probes passed: no bot reads a task outside project 32, workers
can't delete, sync can't write. The instance has no labels yet,
so decision 68's label leak has nothing to show until someone
creates one. Receipt: `agents/sage/work/vikunja-setup/`.
- Open, owned elsewhere: OIDC has been broken since the 2026-04-27
NetworkPolicy, so Jason can't log in to the web UI yet. PR #326
and turning registration off are with ops-01. The broker's startup
probe (row S3) closes row SR's gate.
+9 -9
View File
@@ -196,19 +196,19 @@ No token value appears in the runbook, a command line or a URL.
### Out of scope
- Any script in the product that creates users or tokens. Minting is
out of v1. Sage's operator script for section 1
(`agents/sage/work/gitea-setup/`, decision 74) isn't part of the
stack, and nothing in the stack calls it.
out of v1. Sage's operator scripts for sections 1 to 3
(`agents/sage/work/gitea-setup/` and `agents/sage/work/vikunja-setup/`,
decisions 74 and 75) aren't part of the stack, and nothing in the
stack calls them.
- Running the runbook. Sage ran section 1 (Gitea) on 2026-10-09 with
the admin token Jason granted (decision 74). Jason runs sections 2 to
4 (Vikunja) until he grants a Vikunja credential, and row S3's live
tests wait for them.
the admin token Jason granted (decision 74), and sections 2 and 3
(Vikunja) the same day on tasks.mosaicstack.dev (decision 75).
### Gate
Darkwing approves the scope tables. The runbook runs, section 1 by
Sage and sections 2 to 4 by Jason, and the broker's startup probe passes
for every identity.
Darkwing approves the scope tables. The runbook runs (sections 1 to 3
done by Sage on 2026-10-09), and the broker's startup probe from row S3
passes for every identity.
## Slice 1 S1: roles v2, business and project files, variable layers