Complete PQRST-WP-0001: bootstrap State Hub integration
T01 — Reviewed the generated integration files. Resolved the
{CREDENTIAL_ROUTING} placeholder in AGENTS.md from the fleet canon, refreshed
the SCOPE.md repository layout (stale after registration), and replaced the
README stub with orientation and entry points.
T02 — Documented the developer workflow in AGENTS.md. This is a Markdown-only
spec repository: nothing to install, build, or run, and no test suite. In place
of a toolchain, added a six-point verification checklist covering prompt/spec
coupling, the closed 5-tuple, example-record arithmetic, cross-references,
version discipline, and the append-only rule for history/. The signature
validation command is verified working — all nine example signatures sum to 100.
T03 — Seeded PQRST-WP-0002 "Validate spec v0.1 against real sessions and cut
v0.2": pilot the closing prompt unassisted on at least eight real sessions,
decide the record-storage boundary SCOPE.md leaves open, then revise. v0.1 was
consolidated from two drafts neither of which had been applied to a session, so
the open questions are empirical rather than editorial.
WP-0001 marked finished with DoR/DoD assessments (clears C-34). No open
residuals — the follow-on work is carried by PQRST-WP-0002.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SQ6oF1DtVDKcD1FCpvRVLx
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 272883@bnt-lap001
Assistant-Session: f40c8f53-fb65-4980-9d29-bcdb3dd946f7
This commit is contained in:
parent
14d53264fa
commit
2b36fc187d
5 changed files with 333 additions and 7 deletions
129
AGENTS.md
129
AGENTS.md
|
|
@ -123,7 +123,56 @@ curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
|
|||
|
||||
---
|
||||
|
||||
{CREDENTIAL_ROUTING}
|
||||
## Credential and access routing
|
||||
|
||||
**Audience:** Codex, Claude Code, Grok, and custodian agents that call **llm-connect**
|
||||
for inference. Run this check **before** requesting secrets, API keys, SSH access,
|
||||
login tokens, or database passwords — in any repo, not only `ops-warden`.
|
||||
|
||||
ops-warden **issues SSH certificates only** (`warden sign`, `cert_command`). Every
|
||||
other credential need belongs to another subsystem. **Do not** message
|
||||
`ops-warden` on State Hub expecting a secret value; the reply is a pointer, not a key.
|
||||
|
||||
### Lookup (do this first)
|
||||
|
||||
```bash
|
||||
warden route find "<describe your need>" --json
|
||||
warden route show <catalog-id> --json
|
||||
```
|
||||
|
||||
Requires the `warden` CLI from `~/ops-warden` (`uv tool install .` or `uv run warden`).
|
||||
|
||||
| Agent runtime | How to orient |
|
||||
| --- | --- |
|
||||
| **Codex / Grok** (shell, HTTP State Hub) | `warden route` commands above; inbox `to_agent=pqrst-practice` is for coordination, not secret vending |
|
||||
| **Claude Code** (MCP when available) | `get_domain_summary("custodian")` for workplans; **still** use `warden route` for credential ownership |
|
||||
| **llm-connect** (inference service) | Never put secret retrieval in prompts; route custody to OpenBao/operator paths surfaced by `warden route` |
|
||||
|
||||
### Quick routing table
|
||||
|
||||
| I need… | Owner | ops-warden executes? |
|
||||
| --- | --- | --- |
|
||||
| SSH cert (`adm`/`agt`/`atm`) | ops-warden | **Yes** — `warden sign` |
|
||||
| API key, DB password, provider token | OpenBao (`railiance-platform`) | No — route only |
|
||||
| Login / OIDC / MFA | key-cape / Keycloak | No — route only |
|
||||
| Authorization decision | flex-auth | No — route only |
|
||||
| activity-core → issue-core emission | activity-core + issue-core | No — `warden route show activity-core-issue-sink` |
|
||||
| SSH tunnel | ops-bridge (+ `cert_command` from warden) | No — route only |
|
||||
|
||||
### Anti-patterns (do not do these)
|
||||
|
||||
- `POST /messages/` to `ops-warden` asking for `ISSUE_CORE_API_KEY`, `OPENROUTER_API_KEY`, etc.
|
||||
- Inventing `warden secret`, `warden login`, `warden bao`, `warden tunnel` — they do not exist
|
||||
- Pasting secrets into Git, State Hub, workplans, logs, or chat
|
||||
|
||||
### Other capabilities (reuse-surface)
|
||||
|
||||
Non-credential capabilities are usually discovered through **reuse-surface** federation
|
||||
(`reuse-surface` registry / `capability.*` indexes). Credential routing is inlined in
|
||||
every repo's agent instructions because it is high-frequency, high-risk, and easy to
|
||||
get wrong.
|
||||
|
||||
**Canon:** `~/ops-warden/wiki/CredentialRouting.md` · catalog `~/ops-warden/registry/routing/catalog.yaml`
|
||||
|
||||
<!-- REPO-AGENTS-EXTENSIONS -->
|
||||
<!-- Append repo-specific agent instructions below this marker.
|
||||
|
|
@ -203,3 +252,81 @@ To create a new workplan:
|
|||
1. Write the file following the format above
|
||||
2. Run `uv run --project ~/repo-manager rmgr sync --path . --push`.
|
||||
3. Run `statehub fix-consistency` only when a separate deep audit is needed.
|
||||
|
||||
---
|
||||
|
||||
## Repo-Specific Working Notes
|
||||
|
||||
### What this repo is
|
||||
|
||||
A **specification-and-prompt repository**. Every tracked file is Markdown except
|
||||
`.repo-classification.yaml`. There is no application code, no package manifest,
|
||||
and no runtime. Read [`INTENT.md`](INTENT.md) and [`SCOPE.md`](SCOPE.md) before
|
||||
changing anything — SCOPE.md is normative about what must *not* be added here.
|
||||
|
||||
The deliverables are:
|
||||
|
||||
| File | Role |
|
||||
| --- | --- |
|
||||
| `spec/PqrstEstimationPractice.md` | The normative specification. Versioned. |
|
||||
| `PqrstPrompt.md` | The canonical end-of-session prompt operators paste. |
|
||||
| `INTENT.md` / `SCOPE.md` | Why the practice exists; what belongs here. |
|
||||
| `history/` | Source drafts. **Append-only — never edit an existing file.** |
|
||||
|
||||
### Developer workflow
|
||||
|
||||
There is nothing to install, build, or run.
|
||||
|
||||
| Step | Command | Notes |
|
||||
| --- | --- | --- |
|
||||
| Install | — | No dependencies. |
|
||||
| Build | — | No build step. |
|
||||
| Run | — | Nothing executes; the prompt is pasted into a session by an operator. |
|
||||
| Test | — | No test suite. Verification is the checklist below. |
|
||||
| Lint | — | No linter is configured. Match surrounding Markdown style. |
|
||||
| Sync | `uv run --project ~/repo-manager rmgr sync --path . --push` | After workplan file changes. |
|
||||
| Audit | `statehub fix-consistency` | Deep audit; also regenerates `WORK-RECORDS.md`. |
|
||||
|
||||
Do not add a toolchain to make this table look fuller. A validator, collector,
|
||||
or CI harness for PQRST records is explicitly out of scope (`SCOPE.md`) and
|
||||
belongs in a consuming repository.
|
||||
|
||||
### Verification checklist
|
||||
|
||||
Run this before committing a change to the spec or the prompt. It is a reading
|
||||
task, not a command — the coupling between the two files is the thing that
|
||||
breaks.
|
||||
|
||||
1. **Prompt matches spec.** Every rule in the prompt's `Rules:` list has a
|
||||
corresponding rule in spec §3, and the prompt's output block matches the
|
||||
stored-record format in spec §5.1 field for field.
|
||||
2. **The 5-tuple is closed.** No change introduces a sixth dimension, and
|
||||
confidence stays outside P/Q/R/S/T (spec R9, R10).
|
||||
3. **Examples validate.** Every example record in the repo satisfies spec §5.5.
|
||||
The arithmetic can be checked mechanically:
|
||||
|
||||
```bash
|
||||
grep -rhoE 'P[0-9]+ Q[0-9]+ R[0-9]+ S[0-9]+ T[0-9]+' --include='*.md' . \
|
||||
| sort -u \
|
||||
| awk '{sig=$0; s=0; for(i=1;i<=NF;i++){gsub(/[PQRST]/,"",$i); s+=$i}
|
||||
printf "%-28s %s\n", sig, (s==100 ? "ok" : "SUM=" s)}'
|
||||
```
|
||||
|
||||
Every line must report `ok`.
|
||||
4. **Cross-references resolve.** Relative links between `INTENT.md`,
|
||||
`SCOPE.md`, `PqrstPrompt.md`, and `spec/` still point at existing files and
|
||||
sections.
|
||||
5. **Version discipline.** A change to a dimension's meaning, the validation
|
||||
rules, or the stored record format is **breaking**: bump the spec version,
|
||||
add a row to its Appendix B, and say plainly that older records are less
|
||||
comparable. Editorial changes need no bump.
|
||||
6. **`history/` untouched.** `git diff --stat history/` is empty.
|
||||
|
||||
### Conventions
|
||||
|
||||
- The specification is the source of truth; `PqrstPrompt.md` follows it, never
|
||||
the reverse.
|
||||
- Prefer prose the operator can act on at 11pm at the end of a long session.
|
||||
Terse beats thorough in `PqrstPrompt.md`; thorough beats terse in `spec/`.
|
||||
- Keep the anti-goals in `INTENT.md` intact when editing. They are the load-
|
||||
bearing part of the practice, not framing.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue