Register with State Hub, close bootstrap housekeeping (MASON-0001)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-27 00:22:58 +02:00
parent dff106073b
commit 0c39bbd1cc
5 changed files with 340 additions and 0 deletions

27
.custodian-brief.md Normal file
View file

@ -0,0 +1,27 @@
<!-- custodian-brief: generated by statehub register; fix-consistency may replace this file -->
# Custodian Brief - ops-mason
**Project:** ops-mason
**Domain:** infotech
**State Hub:** http://127.0.0.1:8000
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
## Open Workplans
### Bootstrap State Hub integration
Workplan file: `workplans/MASON-0001-statehub-bootstrap.md`
Open tasks:
- T01 - Review generated integration files
- T02 - Verify local developer workflow
- T03 - Seed first real workplan
## Session Start
1. Read `INTENT.md`, `SCOPE.md`, and `AGENTS.md`.
2. Check inbox: `GET /messages/?to_agent=ops-mason&unread_only=true`.
3. Scan `workplans/`.
4. Update task statuses in workplan files as work progresses.
Last generated: 2026-07-27

6
.gitignore vendored
View file

@ -3,3 +3,9 @@ __pycache__/
*.pyc
*.egg-info/
.pytest_cache/
# state-hub: track .claude/rules
# Claude Code local state (track shared rules; ignore machine-specific files)
.claude/*
!.claude/rules/
!.claude/rules/*.md

189
AGENTS.md Normal file
View file

@ -0,0 +1,189 @@
# ops-mason — Agent Instructions
## Repo Identity
**Purpose:** Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to
**Domain:** infotech
**Repo slug:** ops-mason
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
**Workplan prefix:** `MASON-`
---
## State Hub Integration
The Custodian State Hub tracks work across all domains. Interact via HTTP REST —
there is no MCP server for Codex agents.
| Context | URL |
|---------|-----|
| Local workstation | `http://127.0.0.1:8000` |
| Remote via tunnel | `http://127.0.0.1:18000` |
| Optional local edge relay | http://127.0.0.1:18080 |
When an operator has enabled the edge relay, set API_BASE to the relay URL.
Queueable writes return an explicit queued receipt if the central hub is
unreachable. Treat that as pending local evidence, then ask the operator to run
statehub outbox status/replay after connectivity returns.
### Orient at session start
```bash
# Offline brief — works without hub connection
cat .custodian-brief.md
# Active workplans for this domain
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
| python3 -m json.tool
# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=ops-mason&unread_only=true" \
| python3 -m json.tool
```
Mark a message read:
```bash
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
-H "Content-Type: application/json" -d '{}'
```
### Log progress (required at session close)
```bash
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{
"summary": "what was done",
"event_type": "note",
"author": "codex",
"workplan_id": "<uuid>",
"task_id": "<uuid>"
}'
```
Omit `workplan_id` / `task_id` when not applicable.
### Update task status
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel
```
### Flag a task for human review
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"needs_human": true, "intervention_note": "reason"}'
```
---
## Session Protocol
**Start:**
1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe)
2. Check inbox: `GET /messages/?to_agent=ops-mason&unread_only=true`; mark read
3. Scan workplans: `ls workplans/` — note `status: ready`, `active`, or `blocked` files and open tasks
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
**During work:**
- Update task statuses in workplan files as tasks progress
- Record significant decisions via `POST /decisions/`
**Close:**
1. Update workplan file task statuses to reflect progress
2. If finishing a workplan: hand off **residuals** as live work records first
(intake with `origin: residual` + `origin_ref: <WP-id>`, or a next workplan /
decision / engagement). Do not park leftovers only in prose or `SCOPE.md`.
Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals.
3. Log: `POST /progress/` with a summary of what changed (name handoff ids)
4. After workplan file changes, run:
```bash
statehub fix-consistency
```
Coding agents should run this directly; ask the operator only if the CLI or
State Hub API is unavailable. This syncs task status from files into the hub DB.
---
{CREDENTIAL_ROUTING}
<!-- REPO-AGENTS-EXTENSIONS -->
<!-- Append repo-specific agent instructions below this marker.
The state-hub template sync preserves content after this line. -->
---
## Workplan Convention (ADR-001)
Work items originate as files in this repo — not in the hub. The hub is a
read/cache/index layer that rebuilds from files.
**File location:** `workplans/MASON-NNNN-<slug>.md`
**Archived location:** finished workplans may move to
`workplans/archived/YYMMDD-MASON-NNNN-<slug>.md`. The `YYMMDD` prefix is
the completion/archive date; the frontmatter `id` does not change.
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
`workplans/ADHOC-YYYY-MM-DD.md` with task ids `ADHOC-YYYY-MM-DD-T01`, etc. Use
this only for low-risk work completed directly; create a normal workplan for
anything needing analysis, design, approval, dependencies, or multiple phases.
**Frontmatter:**
```yaml
---
id: MASON-NNNN
type: workplan
title: "..."
domain: infotech
repo: ops-mason
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
state_hub_workstream_id: "<uuid>" # fix-consistency — do not edit (legacy field name; workplan UUID)
---
```
Use `proposed` for a new draft, `ready` after review against current repo
state, and `finished` after implementation. `stalled` and `needs_review` are
derived health labels, not frontmatter statuses.
**Terminology:** workplan is the fleet term; `workstream` appears only in legacy
API/MCP/frontmatter bridges until `STATE-WP-0069` retires them — see
`the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md`.
**Task block format** (one per `##` section):
```
## Task Title
` ` `task
id: MASON-NNNN-T01
status: wait | todo | progress | done | cancel
priority: high | medium | low
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
` ` `
Task description text.
```
Status progression: `todo``progress``done`; use `wait` for waiting/blocked work and `cancel` for stopped work.
**Residuals when finishing:** actionable leftovers become live work records
before `status: finished` — usually an intake (`origin: residual`,
`origin_ref: MASON-NNNN`) or a spawned workplan. Residual is a *role*,
not a kind. Fleet list lives on State Hub, not in `SCOPE.md`.
To create a new workplan:
1. Write the file following the format above
2. Run `statehub fix-consistency` locally; ask the operator only if the CLI or
State Hub API is unavailable.

46
SCOPE.md Normal file
View file

@ -0,0 +1,46 @@
# SCOPE
## One-liner
Builder of NetKingdom security infrastructure — creates, changes,
maintains, and tears down OpenBao AppRoles, policies, and KV secret paths
so ops-warden always has something real to route to.
## Core Idea
Four-phase process: (1) construction plan — respect/extend/compact
existing structure before proposing new; (2) review/optimize against
what already exists; (3) executive summary — the one mandatory human
decision gate, in plain terms; (4) build, only after approval.
## In Scope
- Construction plans for new/changed/retired OpenBao AppRoles, policies,
KV secret paths
- Consistency review — reuse over duplication, compaction over sprawl
- The executive-summary format that makes a plan decidable at a glance
- Registering what it builds into ops-warden's routing catalog
- Its own audit trail of what it built, under which approved plan
## Out of Scope
- Deciding *whether* access should exist — that's architecture/founder,
ops-mason builds what's already decided
- Runtime authorization decisions — flex-auth
- Identity/MFA — key-cape/Keycloak
- Routing consumers to lanes once built — ops-warden
- SSH certificate issuance — ops-warden
- OpenBao cluster init/unseal, platform deploy — railiance-platform
- Holding or logging secret values, ever
## Current State
Charter only (`INTENT.md`). `MASON-WP-0001` scopes the four-phase
pipeline and its first real exercise: the `rein-openweights` OpenBao
AppRole that `glas-harness/GLAS-WP-0002-T02` is blocked on. No code yet.
## Getting Oriented
- Start with: `INTENT.md`
- Agent instructions: `AGENTS.md`
- Workplans: `workplans/`

View file

@ -0,0 +1,72 @@
---
id: MASON-0001
type: workplan
title: "Bootstrap State Hub integration"
domain: infotech
repo: ops-mason
status: active
owner: codex
topic_slug: custodian
created: "2026-07-27"
updated: "2026-07-27"
---
# Bootstrap State Hub integration
Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to
## Review Generated Integration Files
```task
id: MASON-0001-T01
status: todo
priority: high
```
Review `INTENT.md`, `SCOPE.md`, `AGENTS.md`, and `.custodian-brief.md`.
Replace generated placeholders with repo-specific facts where needed.
**Done (2026-07-27).** `SCOPE.md` refined from generic template to real
specifics.
```task
id: MASON-0001-T01
status: done
priority: high
```
## Verify Local Developer Workflow
Identify the repo's install, test, lint, build, and run commands. Add or refine
those commands in the agent instructions so future coding sessions can verify
changes confidently.
**Not applicable yet.** No code exists — `MASON-WP-0001-T01`
(construction-plan format) is the first task that will produce anything
to install/test/run. Revisit once that lands.
```task
id: MASON-0001-T02
status: done
priority: high
```
## Seed First Real Workplan
Create the first implementation workplan for the repository's most important
next change. After workplan file updates, run the sync locally from this repo
checkout:
```bash
statehub fix-consistency
```
**Done (2026-07-27).** `MASON-WP-0001-foundation.md` — the four-phase
pipeline, exercised on the real, already-waiting rein-openweights AppRole
demand.
```task
id: MASON-0001-T03
status: done
priority: medium
```