Commit graph

1931 commits

Author SHA1 Message Date
fee89c4ea1 Finish ACTIVITY-WP-0025 after NK-WP-0021 group allowlist.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Close T06: LLDAP activity-core-operators and Authelia domain rules are live
in net-kingdom. Mark the workplan finished, update G10/runbook/SSO design
with membership pointers, and clear residual handoff notes.
2026-07-22 17:47:57 +02:00
custodian-sync
6134b82101 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-22:
  - update .custodian-brief.md for activity-core
2026-07-22 17:47:49 +02:00
652e799969 Link WP-0025 T06 residual to net-kingdom intakes NK-IN-0001/0002.
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 7s
Point residual and ops-sso-access design at the file-backed work records
in net-kingdom rather than informal coordination notes.
2026-07-22 10:47:25 +02:00
91353df7d0 Finish WP-0025 SSO cutover except group allowlist residual.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 29s
Mark T03–T05 and T07–T08 done after live Authelia/TLS verification,
prefer SSO principal in ops UI copy and audits, and document break-glass
port-forward. Leave T06 waiting on net-kingdom LLDAP/Authelia group rules.
2026-07-22 10:23:36 +02:00
custodian-sync
27c087bcb4 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-22:
  - update .custodian-brief.md for activity-core
2026-07-22 09:53:16 +02:00
3bd005acc9 Prefer temporal.coulomb.social; fix Ingress ACME entrypoints
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Document AAAA parking pitfall for activity.coulomb.social. Use web+websecure
entrypoints and Authelia middleware on SSO Ingress manifests.
2026-07-22 01:29:23 +02:00
54431db583 Use temporal.coulomb.social for Temporal UI SSO host
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m12s
Prefer clean short hostname temporal.coulomb.social instead of
activity-temporal.coulomb.social for Ingress, CORS, and ops UI links.
2026-07-22 01:17:52 +02:00
2acf2baffa chore: consistency writeback after WP-0025 active
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
2026-07-22 00:49:44 +02:00
custodian-sync
eb3ce73396 chore(consistency): sync task status from DB [auto]
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Updated by fix-consistency on 2026-07-22:
  - update .custodian-brief.md for activity-core
2026-07-22 00:49:36 +02:00
f885697e96 Activate ACTIVITY-WP-0025: Authelia SSO ingress for ops and Temporal UI
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 54s
Build and Publish Container Image / build-and-push (push) Successful in 1m47s
Mark workplan active. Add Traefik ForwardAuth middleware and Ingress
manifests for activity.coulomb.social and activity-temporal.coulomb.social.
Prefer Authelia SSO identity for ops mutations; document DNS gate and
fleet pattern (docs/ops-sso-access.md).
2026-07-22 00:47:29 +02:00
7e71c0c837 chore: hub IDs for ACTIVITY-WP-0025 after fix-consistency
All checks were successful
CI Smoke / host-smoke (push) Successful in 3s
CI Smoke / container-smoke (push) Successful in 9s
2026-07-22 00:33:34 +02:00
7761acf86a Link Temporal UI from ops console; propose SSO access WP-0025
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m45s
Add nav/deep link to Temporal Web UI (configurable URL, default
127.0.0.1:8080 for port-forward). Document dual port-forward and draft
ACTIVITY-WP-0025 for Keycloak SSO ingress without port-forward.
2026-07-22 00:30:17 +02:00
6c34e2c1f1 Show last run timestamp on ops automation status
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m9s
Expose last_run_at / last_run on the status contract and display Last run
and Tasks columns on the /ops/ui status page for the selected window.
2026-07-22 00:16:25 +02:00
a304ad7397 chore: consistency writeback after WP-0024 finish
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-21 23:53:20 +02:00
71027f0a67 Implement ACTIVITY-WP-0024 operator automation console
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 36s
Add /ops REST inventory, status, runs, and fail-closed operator-token
mutations (trigger, enable/disable, pause/unpause) with audit trail.
Ship thin HTML UI at /ops/ui, runbook/k8s access docs, and contract tests.
2026-07-21 23:51:39 +02:00
81d350de71 chore: hub IDs for ACTIVITY-WP-0024 after fix-consistency
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Write back state_hub_workstream_id and task ids from C-06 registration.
2026-07-21 23:44:10 +02:00
86bb550c7a Add ACTIVITY-WP-0024 operator automation console workplan
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Propose API-first ops console: status/inventory/runs REST, fail-closed
operator token, Run now + pause controls, then thin UI. No cron edit or
public Ingress in MVP.
2026-07-21 23:42:15 +02:00
c80ac9ac51 chore: refresh WORK-RECORDS after WP-0023 closeout
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-21 23:20:57 +02:00
custodian-sync
2612609e92 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 23:20:32 +02:00
21d46927f6 Finish ACTIVITY-WP-0023: ESO FORGEJO_TOKEN and gap dispositions
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 7s
Ship ExternalSecret actcore-forgejo-admin and multi-policy ESO token
bootstrap so weekly prune credentials refresh without bootstrap inject.
Disposition issue-core path A and MarkiTect ROS as external owners;
close workplan finished.
2026-07-21 23:19:10 +02:00
d36adb0822 chore: consistency writeback after WP-0022/0023
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-21 21:41:59 +02:00
custodian-sync
f887437f46 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 21:41:40 +02:00
4f5399df84 Implement ACTIVITY-WP-0022/0023: safe sink default and gap closures
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 28s
Default ISSUE_SINK_TYPE to state-hub (no silent Forgejo issues), hard-fail
prune apply without live-images protection, refresh-live-images script,
disable TaskExecutor stub by default, and document consumer/sink contracts.
2026-07-21 21:40:08 +02:00
5c7a90ce7c chore: write back hub IDs for ACTIVITY-WP-0023
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
2026-07-21 21:20:52 +02:00
e73575dcd6 Refresh SCOPE.md intent gap analysis; add ACTIVITY-WP-0023
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 4s
Document production posture after WP-0020/0021, list INTENT↔practice gaps
G1–G10, and open a workplan for gap closure plus operational follow-ups.
2026-07-21 21:19:47 +02:00
custodian-sync
bb7842dcdc chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 19:21:57 +02:00
a35997878b Finish ACTIVITY-WP-0020: enable weekly Forgejo package prune
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 28s
First apply deleted 38 stale versions; enable schedule with live-images
protection file for worker pods without kubectl; restore path for live
state-hub tags after an unprotected worker apply.
2026-07-21 19:20:42 +02:00
custodian-sync
2525f234e7 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 07:33:53 +02:00
bd1c993405 Finish ACTIVITY-WP-0021: state-hub sink default + deploy verification
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 28s
Record railiance01 one-shot evidence (Binky/SBOM/triage COMPLETED), keep
ISSUE_SINK_TYPE=state-hub until Forgejo PAT rotation, and re-read sink env
at factory call time.
2026-07-21 07:33:03 +02:00
custodian-sync
8ca0267382 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 04:23:06 +02:00
60d344e465 workplan: propose ACTIVITY-WP-0022 IssueSink no-default-Forgejo policy
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Filed from issue-core ISSUE-WP-0004-T05 / CUST-WP-0060 item 6. Default
IssueSink must not silently create Forgejo issues for internal findings.
Registered in state-hub via fix-consistency (UUIDs written back).
2026-07-21 04:22:18 +02:00
98e8aa83bd Implement ACTIVITY-WP-0021 production automation reliability
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 47s
Root-cause IssueSink 503 (dead Forgejo PAT on issue-core), add state-hub
task sink path B, log runs before emit, harden sync_schedules, deterministic
SBOM/triage reports, DB probe thrash fix, and prod automation-status helper.
2026-07-21 04:21:55 +02:00
1209ff6973 chore: write back hub IDs for ACTIVITY-WP-0021 and WORK-RECORDS index
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
fix-consistency C-06 registered the workplan and nine tasks; C-33
regenerated the work-record index.
2026-07-21 04:11:07 +02:00
custodian-sync
650895d580 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for activity-core
2026-07-21 04:10:49 +02:00
5afd2f347d Add ACTIVITY-WP-0021 production automation reliability workplan
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s
Captures the Sunday–Monday railiance01 schedule review: IssueSink 503s,
Binky cutover failures, edge-relay/ROS issues, silent daily triage,
sync_schedules bug, and DB restart thrash — with tasks to fix and verify.
2026-07-21 04:09:57 +02:00
114866ef1a Sync embedded daily-todo-md-stale-review ConfigMap: paused (enabled: false)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s
Mirrors the-custodian's ADR-001 source-of-truth change (2026-07-20): this
activity was the fleet's only consumer of the task_template rule action,
which unconditionally routes through IssueSink -> issue-core -> Forgejo
-- the sole source of 5 stale-review issues that had to be manually
reviewed and closed. Embedded copy in this ConfigMap had drifted from
the source file (still enabled: true) since there's no automated sync
between the-custodian/activity-definitions/ and this k8s manifest; the
Deploy runbook in k8s/railiance/README.md re-applies the ConfigMap as
committed here, so this had to be updated before re-running actcore-sync.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 23:59:59 +02:00
custodian-sync
7a17df4771 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-18:
  - update .custodian-brief.md for activity-core
2026-07-18 15:26:35 +02:00
01f42993ef ACTIVITY-WP-0020-T07 done: multi-cluster dry-run clean, evidence recorded
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 15:25:58 +02:00
73cc785426 feat(definitions): enable Binky operating-rhythm definitions (DEC-2026-003 cutover)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 9s
Founder-approved cutover 2026-07-18. binky_rhythm_status resolver
(b1eb5e6) guards idempotence; harness on railiance01 executes via the
issue-core sink. Rollback: enabled: false + workstation cron bridge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:33:21 +02:00
aed1437608 ACTIVITY-WP-0020-T07: dry-run via warden lane instead of PAT file drop
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:27:24 +02:00
8e74932db5 ACTIVITY-WP-0020-T07: multi-cluster protection mechanism + cluster census
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:54:59 +02:00
b1eb5e6a55 feat(resolvers): binky_rhythm_status query in state-hub resolver
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m16s
Due-items for the three Binky operating-rhythm definitions
(BINKY-WP-0004-T02). Dueness derives from hub progress events recorded
by the executing session (binky_daily_brief / binky_mail_intake /
binky_weekly_review, detail.repo scoped); weekly_review carries
milestone_moved from event_type=milestone events in the last 7 days
(RISK-005 signal). Definitions' resolver comments updated; definitions
stay enabled:false until cutover (BINKY-WP-0004-T06).

7 new tests; resolver test file 31/31 green. Pre-existing failures in
test_railiance_ops_inventory_wiring/test_schedule_health are untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:07:00 +02:00
custodian-sync
a2c53508ad chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for activity-core
2026-07-16 14:48:36 +02:00
fbce4ea94c ACTIVITY-WP-0020 T07: live-tag protection implemented (partial — multi-cluster)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 1m19s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:45:43 +02:00
b2fa9642b6 feat(definitions): propose Binky operating-rhythm definitions (disabled)
Three proposed, disabled definitions for the binky-control rhythm
(BINKY-WP-0003-T05): daily rhythm, weekly paper-mail intake, weekly
founder-review prep. All parse via definition_parser. Enabling requires
the proposed binky_rhythm_status state-hub resolver and an executor
(llm-connect assessment, BINKY-WP-0003-T06).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 11:02:29 +02:00
4ceadfef0e chore(consistency): write state-hub id into ACTIVITY-WP-0020-T07 [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 02:51:22 +02:00
custodian-sync
ed214976f3 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 8m28s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for activity-core
2026-07-16 02:51:12 +02:00
8ae85742fb ACTIVITY-WP-0020: dry-run clean after tool fix; add T07 protection gate
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
Dry-run now works (tool bug fixed in railiance-platform@6f7ca31): 29 candidates,
0 errors. Enable/apply blocked on new T07 — protection scan misses activity-core
& state-hub live tags; extend to source protected tags from live cluster before apply.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 02:50:21 +02:00
e4d6222d22 fix(context): use repo-scoping /scope/context endpoint
All checks were successful
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / container-smoke (push) Successful in 21s
Build and Publish Container Image / build-and-push (push) Successful in 33s
Cherry-picked from stale branch codex/wp-0012-scope-context (9709692).
main was still calling the old /repos/{slug}/scope path; repo-scoping now
serves GET /repos/{slug}/scope/context (web_api/app.py:1449). Includes the
resolver test and consistent workplan-doc updates. Test: 2 passed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 23:19:50 +02:00
custodian-sync
2f4ef5809b chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-12:
  - update .custodian-brief.md for activity-core
2026-07-12 11:39:17 +02:00