Jason asked for tasks.mosaicstack.dev operational with agents configured in it.
Sage backed it up, tested the restore, pinned 2.7.0 (infra PR #325) and ran
sections 2 and 3 through the API: owner id 4, svc-mosaic-stack id 5, project 32,
bots 6-10, scoped tokens to 2027-01-07. Probes pass. Scope is Mosaic Stack only
(Mos relaying Jason, his Q9 open). OIDC has been broken since a 2026-04-27
NetworkPolicy; infra PR #326 is with ops-01. BUILD-LOG also records the cert
renewal fix and the last-applied annotation slip.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Jason ruled that agents run the steps his admin grant to the jarvis
Gitea token covers. Sage created the four mosaic-stack bots (ids
114-117, restricted, non-admin), added them as collaborators (W/W/W/R),
and minted one scoped token each (ids 191-194). The tokens were written
0600 outside the repo. Scripts and receipt are in
agents/sage/work/gitea-setup/. The guide and SR brief now say who
runs which section. Sections 2 to 4 (Vikunja) stay with Jason.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's correction, checked against the 2.7.0 OpenAPI: GET /tokens
returns PaginatedAPIToken, with items possibly null.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's probe-s7f: svc-$BIZ revokes one bot token (204, then 401);
the owner gets 403. A plain GET /tokens shows only svc's own tokens, so
rotation names GET /tokens?owner_id=<bot id> for an old id. Decision 68
records the resolution.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Mos: the svc-mosaic-stack password is a credential Jason keeps (R5), and
T236 creates no users. The runbook's Path A now has Jason create it with
the command from the instance's ops doc. Records the R20 confirmation.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's row 38 labels probe on the pinned 2.7.0 image: a bot created
from the owner's account reads and attaches every label that account
created, in any project (upstream #3592). Bots owned by svc-<business>,
an account with no labels and no shares, see only labels on the shared
project's tasks. The runbook now creates the bots and mints and revokes
their tokens as svc-$BIZ; the owner keeps the project and the shares.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Jason's 2026-10-08 rulings via Mos (thread 1eba59e5). R10: next stays
the trunk; the plan pins refactor b8db39cf and next 2101c9b4, finds a
clean merge-tree, and names the CI gate, approval identity, frozen
next-lane publishing, root .mosaic/repo.json, 13 stale v1 PRs and the
hardcoded ledger branch as the work. Nothing merged.
R8: Path A on the new estate Vikunja meets slice 1 and replaces
decision 61's Path B. The runbook's Path A text names the estate
instance and the share-only isolation rule.
Co-Authored-By: Claude Opus 5.5 <[email protected]>