skills: sanitize operator-identity tokens from folded ops skills
Four folded skills carried operator identity tokens that the sanitization gate (verify-sanitized.sh) forbids in the public framework package: - kickstart: template path pointed at a private brain checkout; now uses the framework-shipped $MOSAIC_HOME/templates/docs/TASKS.md.template - mosaic-deploy: dropped one estate-specific stack-name row from the example table - mosaic-portainer, mosaic-woodpecker: credentials now name the framework credentials store (load_credentials <service>) instead of a private checkout path Estate-specific values can live in a skills-local override, which the linker applies with precedence over canonical skills.
This commit is contained in:
@@ -166,13 +166,13 @@ Always load these orchestrator-relevant skills:
|
|||||||
Create tracking files using templates:
|
Create tracking files using templates:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
TEMPLATES=~/src/jarvis-brain/docs/templates
|
MOSAIC_HOME="${MOSAIC_HOME:-$HOME/.config/mosaic}"
|
||||||
|
|
||||||
# Create tasks.md scaffold
|
# Create tasks.md scaffold from the framework-shipped template
|
||||||
envsubst < $TEMPLATES/orchestrator/tasks.md.template > docs/tasks.md
|
cp "$MOSAIC_HOME/templates/docs/TASKS.md.template" docs/tasks.md
|
||||||
|
|
||||||
# Create learnings tracking
|
# Create learnings tracking (scaffold — adapt to your estate's template)
|
||||||
envsubst < $TEMPLATES/orchestrator/orchestrator-learnings.json.template > docs/orchestrator-learnings.json
|
echo '{}' > docs/orchestrator-learnings.json
|
||||||
```
|
```
|
||||||
|
|
||||||
Then populate `docs/tasks.md` with tasks derived from the issues:
|
Then populate `docs/tasks.md` with tasks derived from the issues:
|
||||||
|
|||||||
@@ -69,7 +69,6 @@ Check deployment:
|
|||||||
| mosaic-stack | `mosaic-stack` |
|
| mosaic-stack | `mosaic-stack` |
|
||||||
| sage-phr | `sage-phr` |
|
| sage-phr | `sage-phr` |
|
||||||
| openbrain | `openbrain` |
|
| openbrain | `openbrain` |
|
||||||
| jarvis-crypto | `jarvis-crypto` |
|
|
||||||
| firefly | `firefly` |
|
| firefly | `firefly` |
|
||||||
|
|
||||||
## Notes
|
## Notes
|
||||||
|
|||||||
@@ -56,4 +56,4 @@ source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials portainer
|
|||||||
- Portainer URL: `https://10.1.1.43:9443`
|
- Portainer URL: `https://10.1.1.43:9443`
|
||||||
- Primary Docker host: `w-docker0` (10.1.1.45) managed via Portainer agent
|
- Primary Docker host: `w-docker0` (10.1.1.45) managed via Portainer agent
|
||||||
- Docker Swarm image updates: `stack-redeploy.sh -p` does NOT guarantee new image pull if digest is pinned; SSH to node and `docker pull` first if needed
|
- Docker Swarm image updates: `stack-redeploy.sh -p` does NOT guarantee new image pull if digest is pinned; SSH to node and `docker pull` first if needed
|
||||||
- Credentials source: `~/src/jarvis-brain/credentials.json` (must be cloned)
|
- Credentials: `load_credentials portainer` (framework credentials store)
|
||||||
|
|||||||
@@ -65,6 +65,6 @@ cd ~/src/<repo>
|
|||||||
## Notes
|
## Notes
|
||||||
|
|
||||||
- CI URL: `https://ci.mosaicstack.dev`
|
- CI URL: `https://ci.mosaicstack.dev`
|
||||||
- Credentials: `load_credentials woodpecker` (from `~/src/jarvis-brain/credentials.json`)
|
- Credentials: `load_credentials woodpecker` (framework credentials store)
|
||||||
- `ci-queue-wait.sh` is automatically called by `pr-merge.sh` unless `--skip-queue-guard` is passed
|
- `ci-queue-wait.sh` is automatically called by `pr-merge.sh` unless `--skip-queue-guard` is passed
|
||||||
- Pipeline output shows step-level status: OK / FAIL / RUN / SKIP / WAIT
|
- Pipeline output shows step-level status: OK / FAIL / RUN / SKIP / WAIT
|
||||||
|
|||||||
Reference in New Issue
Block a user