docs(prd): PRD draft 0.3; slice 1 addendum A; lead decision 49

Darkwing's addendum as a record. Broker verbs enforce field ownership,
broker push from a bare repo, polling without webhooks, Vikunja probes
before the adapter interface is fixed.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-04 14:56:14 -05:00
co-authored by Claude Opus 5.5
parent c57998772d
commit d7723e2237
4 changed files with 508 additions and 9 deletions
+12 -9
View File
@@ -1,13 +1,13 @@
# PRD: Mosaic Stack
- Status: draft, version 0.2. Jason approves it, and once approved it is
- Status: draft, version 0.3. Jason approves it, and once approved it is
never edited in place. Changes after approval are a new version.
- Owner: Jason. Sage writes it from the PRDY interview.
- Template: PRDY "software" (`v1/packages/prdy/src/templates.ts`), filled
by hand until PRDY is ported.
- Interview record: Sage's thread 1ef1e4f8. Round 1 is lead decision 45.
Round 2 is lead decision 48. Design inputs are lead decisions 43, 44,
46 and 47.
46, 47 and 49.
## Introduction
@@ -111,9 +111,10 @@ parent requirement is refused.
allowed in.
- **REQ-VAR-2.** `~/.config/mosaic-dev/config.json` stays the only system
config, and nothing writes it automatically. A secret appears only as a
reference, either a file path or an environment variable name. The
stack checks a referenced file with `stat` and never reads its
contents.
reference, either a file path or an environment variable name. Only
the broker reads a secret's contents. It holds them in memory and
never logs or writes them. Everything else checks a referenced file
with `stat`.
### Credentials
@@ -153,11 +154,13 @@ parent requirement is refused.
### Tasks
- **REQ-TASK-1.** Tasks live in Vikunja, reached through `/api/v2` with a
bot token for each role. Each task cites a requirement id. Only the
assigned role writes a task's mutable fields. A person's edits come in
as events.
bot token for each role. Each task cites a requirement id. Each task
field has one writing role, listed in the slice 1 brief's field table,
and the assigned role writes the task's state. Vikunja's token scopes
cover whole route groups, so the broker's verbs enforce this, not the
tokens. A person's edits come in as events.
- **REQ-TASK-2.** Polling for changes since the last check is the source
of truth, and webhooks only trigger a check sooner.
of truth, with an hourly full reconcile. Slice 1 uses no webhooks.
- **REQ-TASK-3.** The installer offers two choices: point at an existing
Vikunja, or deploy the bundled one. The bundled one is the unmodified
upstream image. No Vikunja code enters the repository.