diff --git a/.custodian-brief.md b/.custodian-brief.md new file mode 100644 index 0000000..9eb4cf2 --- /dev/null +++ b/.custodian-brief.md @@ -0,0 +1,27 @@ + +# Custodian Brief - ops-mason + +**Project:** ops-mason +**Domain:** infotech +**State Hub:** http://127.0.0.1:8000 +**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a` + +## Open Workplans + +### Bootstrap State Hub integration + +Workplan file: `workplans/MASON-0001-statehub-bootstrap.md` + +Open tasks: +- T01 - Review generated integration files +- T02 - Verify local developer workflow +- T03 - Seed first real workplan + +## Session Start + +1. Read `INTENT.md`, `SCOPE.md`, and `AGENTS.md`. +2. Check inbox: `GET /messages/?to_agent=ops-mason&unread_only=true`. +3. Scan `workplans/`. +4. Update task statuses in workplan files as work progresses. + +Last generated: 2026-07-27 diff --git a/.gitignore b/.gitignore index e1736e9..5361415 100644 --- a/.gitignore +++ b/.gitignore @@ -3,3 +3,9 @@ __pycache__/ *.pyc *.egg-info/ .pytest_cache/ + +# state-hub: track .claude/rules +# Claude Code local state (track shared rules; ignore machine-specific files) +.claude/* +!.claude/rules/ +!.claude/rules/*.md diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..9db0c67 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,189 @@ +# ops-mason — Agent Instructions + +## Repo Identity + +**Purpose:** Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to + +**Domain:** infotech +**Repo slug:** ops-mason +**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a` +**Workplan prefix:** `MASON-` + +--- + +## State Hub Integration + +The Custodian State Hub tracks work across all domains. Interact via HTTP REST — +there is no MCP server for Codex agents. + +| Context | URL | +|---------|-----| +| Local workstation | `http://127.0.0.1:8000` | +| Remote via tunnel | `http://127.0.0.1:18000` | +| Optional local edge relay | http://127.0.0.1:18080 | + +When an operator has enabled the edge relay, set API_BASE to the relay URL. +Queueable writes return an explicit queued receipt if the central hub is +unreachable. Treat that as pending local evidence, then ask the operator to run +statehub outbox status/replay after connectivity returns. + +### Orient at session start + +```bash +# Offline brief — works without hub connection +cat .custodian-brief.md + +# Active workplans for this domain +curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \ + | python3 -m json.tool + +# Check inbox +curl -s "http://127.0.0.1:8000/messages/?to_agent=ops-mason&unread_only=true" \ + | python3 -m json.tool +``` + +Mark a message read: +```bash +curl -s -X PATCH "http://127.0.0.1:8000/messages//read" \ + -H "Content-Type: application/json" -d '{}' +``` + +### Log progress (required at session close) + +```bash +curl -s -X POST http://127.0.0.1:8000/progress/ \ + -H "Content-Type: application/json" \ + -d '{ + "summary": "what was done", + "event_type": "note", + "author": "codex", + "workplan_id": "", + "task_id": "" + }' +``` + +Omit `workplan_id` / `task_id` when not applicable. + +### Update task status + +```bash +curl -s -X PATCH "http://127.0.0.1:8000/tasks/" \ + -H "Content-Type: application/json" \ + -d '{"status": "progress"}' +# values: wait | todo | progress | done | cancel +``` + +### Flag a task for human review + +```bash +curl -s -X PATCH "http://127.0.0.1:8000/tasks/" \ + -H "Content-Type: application/json" \ + -d '{"needs_human": true, "intervention_note": "reason"}' +``` + +--- + +## Session Protocol + +**Start:** +1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe) +2. Check inbox: `GET /messages/?to_agent=ops-mason&unread_only=true`; mark read +3. Scan workplans: `ls workplans/` — note `status: ready`, `active`, or `blocked` files and open tasks +4. Check human-needed tasks: `GET /tasks/?needs_human=true` + +**During work:** +- Update task statuses in workplan files as tasks progress +- Record significant decisions via `POST /decisions/` + +**Close:** +1. Update workplan file task statuses to reflect progress +2. If finishing a workplan: hand off **residuals** as live work records first + (intake with `origin: residual` + `origin_ref: `, or a next workplan / + decision / engagement). Do not park leftovers only in prose or `SCOPE.md`. + Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals. +3. Log: `POST /progress/` with a summary of what changed (name handoff ids) +4. After workplan file changes, run: + ```bash + statehub fix-consistency + ``` + Coding agents should run this directly; ask the operator only if the CLI or + State Hub API is unavailable. This syncs task status from files into the hub DB. + +--- + +{CREDENTIAL_ROUTING} + + + + +--- + +## Workplan Convention (ADR-001) + +Work items originate as files in this repo — not in the hub. The hub is a +read/cache/index layer that rebuilds from files. + +**File location:** `workplans/MASON-NNNN-.md` + +**Archived location:** finished workplans may move to +`workplans/archived/YYMMDD-MASON-NNNN-.md`. The `YYMMDD` prefix is +the completion/archive date; the frontmatter `id` does not change. + +**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use +`workplans/ADHOC-YYYY-MM-DD.md` with task ids `ADHOC-YYYY-MM-DD-T01`, etc. Use +this only for low-risk work completed directly; create a normal workplan for +anything needing analysis, design, approval, dependencies, or multiple phases. + +**Frontmatter:** + +```yaml +--- +id: MASON-NNNN +type: workplan +title: "..." +domain: infotech +repo: ops-mason +status: proposed | ready | active | blocked | backlog | finished | archived +owner: codex +topic_slug: ... +created: "YYYY-MM-DD" +updated: "YYYY-MM-DD" +state_hub_workstream_id: "" # fix-consistency — do not edit (legacy field name; workplan UUID) +--- +``` + +Use `proposed` for a new draft, `ready` after review against current repo +state, and `finished` after implementation. `stalled` and `needs_review` are +derived health labels, not frontmatter statuses. + +**Terminology:** workplan is the fleet term; `workstream` appears only in legacy +API/MCP/frontmatter bridges until `STATE-WP-0069` retires them — see +`the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md`. + +**Task block format** (one per `##` section): + +``` +## Task Title + +` ` `task +id: MASON-NNNN-T01 +status: wait | todo | progress | done | cancel +priority: high | medium | low +state_hub_task_id: "" # written by fix-consistency — do not edit +` ` ` + +Task description text. +``` + +Status progression: `todo` → `progress` → `done`; use `wait` for waiting/blocked work and `cancel` for stopped work. + +**Residuals when finishing:** actionable leftovers become live work records +before `status: finished` — usually an intake (`origin: residual`, +`origin_ref: MASON-NNNN`) or a spawned workplan. Residual is a *role*, +not a kind. Fleet list lives on State Hub, not in `SCOPE.md`. + +To create a new workplan: +1. Write the file following the format above +2. Run `statehub fix-consistency` locally; ask the operator only if the CLI or + State Hub API is unavailable. diff --git a/SCOPE.md b/SCOPE.md new file mode 100644 index 0000000..de4f817 --- /dev/null +++ b/SCOPE.md @@ -0,0 +1,46 @@ +# SCOPE + +## One-liner + +Builder of NetKingdom security infrastructure — creates, changes, +maintains, and tears down OpenBao AppRoles, policies, and KV secret paths +so ops-warden always has something real to route to. + +## Core Idea + +Four-phase process: (1) construction plan — respect/extend/compact +existing structure before proposing new; (2) review/optimize against +what already exists; (3) executive summary — the one mandatory human +decision gate, in plain terms; (4) build, only after approval. + +## In Scope + +- Construction plans for new/changed/retired OpenBao AppRoles, policies, + KV secret paths +- Consistency review — reuse over duplication, compaction over sprawl +- The executive-summary format that makes a plan decidable at a glance +- Registering what it builds into ops-warden's routing catalog +- Its own audit trail of what it built, under which approved plan + +## Out of Scope + +- Deciding *whether* access should exist — that's architecture/founder, + ops-mason builds what's already decided +- Runtime authorization decisions — flex-auth +- Identity/MFA — key-cape/Keycloak +- Routing consumers to lanes once built — ops-warden +- SSH certificate issuance — ops-warden +- OpenBao cluster init/unseal, platform deploy — railiance-platform +- Holding or logging secret values, ever + +## Current State + +Charter only (`INTENT.md`). `MASON-WP-0001` scopes the four-phase +pipeline and its first real exercise: the `rein-openweights` OpenBao +AppRole that `glas-harness/GLAS-WP-0002-T02` is blocked on. No code yet. + +## Getting Oriented + +- Start with: `INTENT.md` +- Agent instructions: `AGENTS.md` +- Workplans: `workplans/` diff --git a/workplans/MASON-0001-statehub-bootstrap.md b/workplans/MASON-0001-statehub-bootstrap.md new file mode 100644 index 0000000..8c7f972 --- /dev/null +++ b/workplans/MASON-0001-statehub-bootstrap.md @@ -0,0 +1,72 @@ +--- +id: MASON-0001 +type: workplan +title: "Bootstrap State Hub integration" +domain: infotech +repo: ops-mason +status: active +owner: codex +topic_slug: custodian +created: "2026-07-27" +updated: "2026-07-27" +--- + +# Bootstrap State Hub integration + +Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to + +## Review Generated Integration Files + +```task +id: MASON-0001-T01 +status: todo +priority: high +``` + +Review `INTENT.md`, `SCOPE.md`, `AGENTS.md`, and `.custodian-brief.md`. +Replace generated placeholders with repo-specific facts where needed. + +**Done (2026-07-27).** `SCOPE.md` refined from generic template to real +specifics. + +```task +id: MASON-0001-T01 +status: done +priority: high +``` + +## Verify Local Developer Workflow + +Identify the repo's install, test, lint, build, and run commands. Add or refine +those commands in the agent instructions so future coding sessions can verify +changes confidently. + +**Not applicable yet.** No code exists — `MASON-WP-0001-T01` +(construction-plan format) is the first task that will produce anything +to install/test/run. Revisit once that lands. + +```task +id: MASON-0001-T02 +status: done +priority: high +``` + +## Seed First Real Workplan + +Create the first implementation workplan for the repository's most important +next change. After workplan file updates, run the sync locally from this repo +checkout: + +```bash +statehub fix-consistency +``` + +**Done (2026-07-27).** `MASON-WP-0001-foundation.md` — the four-phase +pipeline, exercised on the real, already-waiting rein-openweights AppRole +demand. + +```task +id: MASON-0001-T03 +status: done +priority: medium +```