From bd8f02b785032dd7ee2553e5c9d7bd2b8bb20f64 Mon Sep 17 00:00:00 2001 From: codex Date: Mon, 24 Aug 2026 22:24:01 +0200 Subject: [PATCH] feat(workplan): rescope CUST-WP-0067 to retire the local hub instance Operator decision 2026-08-24: rather than making two hub instances coexist safely, retire the second one. The local postgres+uvicorn instance is what impersonates central and is redundant with ADR-010 decision 3 plus Repo Manager's file-derived index. With it gone, state-hub-primary binds 127.0.0.1:8000 unchanged and every existing default becomes correct with no call-site edits. Adds the cache-only recovery export (44 records) as the T05 source. Co-Authored-By: Claude Opus 5 --- .../recovery/cache-only-repos-2026-08-24.json | 1077 +++++++++++++++++ ...WP-0067-hub-authority-target-resolution.md | 138 ++- 2 files changed, 1157 insertions(+), 58 deletions(-) create mode 100644 docs/recovery/cache-only-repos-2026-08-24.json diff --git a/docs/recovery/cache-only-repos-2026-08-24.json b/docs/recovery/cache-only-repos-2026-08-24.json new file mode 100644 index 0000000..e8a6f5c --- /dev/null +++ b/docs/recovery/cache-only-repos-2026-08-24.json @@ -0,0 +1,1077 @@ +{ + "schema": "custodian.cache-only-repo-recovery.v1", + "captured_at": "2026-08-24T20:23:07.189810+00:00", + "workplan": "CUST-WP-0067", + "task": "CUST-WP-0067-T02", + "note": "Repo records present on the local cache and absent from central at capture time. Recovery source for T05 onboarding; the cache may be retired once every entry here exists on central.", + "cache_total": 122, + "central_total": 78, + "cache_only_total": 44, + "records": [ + { + "slug": "agent-harness", + "name": "agent-harness", + "domain_slug": "agents", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/agent-harness", + "remote_url": "forgejo-remote:coulomb/agent-harness.git", + "description": "Single shared runtime for unattended agent instances (ADR-001 / DEC-2026-002): consumes activity-core tasks, binds kaizen blueprints to declarative per-repo instances, executes via llm-connect under named tool profiles, reports to the State Hub.", + "created_at": "2026-07-17T21:35:48.180596Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": false, + "has_classification_file": false + }, + { + "slug": "binky-control", + "name": "binky-control", + "domain_slug": "infotech", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/binky-control", + "remote_url": "ssh://forgejo-remote/coulomb/binky-control.git", + "description": "binky-control is the company control plane (\"company brain\") for Binky Hedgehog GmbH's transformation into Operational Knowledge GmbH, holding the canon (intent, policies, plans), work queues, and registries that give agents and the solo founder shared situational awareness with executable next steps.", + "created_at": "2026-07-16T00:33:34.138738Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "c540edeede3d0c7bd1f04d3b6b2a72d6c5d037a7" + }, + { + "slug": "clay-borg", + "name": "clay-borg", + "domain_slug": "consumer", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/clay-borg", + "remote_url": null, + "description": "Simulation and games engine framework: assimilates optimized libraries behind canonical Clay-Borg interfaces, built agentic-coding-first, with GROUND (a tabletop game) as its first vertical slice.", + "created_at": "2026-07-30T21:41:01.572752Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "18c57f2e9dce0589c1f0e24dd4d939aea50cee86" + }, + { + "slug": "coulomb-social", + "name": "coulomb-social", + "domain_slug": "communication", + "secondary_domains": null, + "category": "experimental", + "status": "active", + "local_path": "/home/worsch/coulomb-social", + "remote_url": "forgejo-remote:coulomb/coulomb-social.git", + "description": "Reimplementation of the coulomb.social co-creation platform on Railiance/NetKingdom/HelixForge, exiting stalled bubble.io.", + "created_at": "2026-08-08T22:33:22.430445Z", + "classified_at": "2026-08-09", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "marketplace", + "collaboration", + "tenancy", + "user-management" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "688215f831e41dcc0372198e32cc4680eec4f4c7" + }, + { + "slug": "direkt-vermittlung-de", + "name": "direkt-vermittlung-de", + "domain_slug": "government", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/direkt-vermittlung-de", + "remote_url": "forgejo-remote:coulomb/direkt-vermittlung-de.git", + "description": "DirektVermittlungDe is a document-centric platform that routes citizens' documents or reference numbers (Aktenzeichen) directly to the responsible German authority caseworker and opens a communication thread, replacing manual phone-routing hunts.", + "created_at": "2026-07-08T11:40:49.345955Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "184e2f5b1108058688421786bc9885b3b0d7e86b" + }, + { + "slug": "freedom-intelligence", + "name": "Freedom Intelligence", + "domain_slug": "agents", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/freedom-intelligence", + "remote_url": "forgejo-remote:coulomb/freedom-intelligence.git", + "description": null, + "created_at": "2026-07-27T22:22:16.994060Z", + "classified_at": "2026-07-28", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "knowledge", + "documentation", + "orchestration", + "automation", + "model-routing" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "8832652ad36f441dc89dfd9ab8ded7fad4563e83" + }, + { + "slug": "glas-harness", + "name": "glas-harness", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/glas-harness", + "remote_url": "forgejo-remote:coulomb/glas-harness.git", + "description": "Meta-framework routing between concrete agent-harness backends (reins)", + "created_at": "2026-07-26T10:31:03.312239Z", + "classified_at": "2026-06-22", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "configuration", + "documentation" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "6bd2e10e6b19f1ef30231a101d933b3327726b36" + }, + { + "slug": "ground-game", + "name": "ground-game", + "domain_slug": "consumer", + "secondary_domains": [ + "health" + ], + "category": "product", + "status": "active", + "local_path": "/home/worsch/ground-game", + "remote_url": "forgejo-remote:coulomb/ground-game.git", + "description": "Product repo for GROUND \u2014 A Game of Bonds and Rivalry (DARVO Edition): playtest edition datasets, rules content, and design history for a semi-cooperative conflict card game.", + "created_at": "2026-07-30T22:19:54.460181Z", + "classified_at": "2026-07-31", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "game", + "entertainment", + "documentation", + "product-development" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "3872ddc01405201979cd10db0be8c8acd5e8a7e1" + }, + { + "slug": "kings-guard", + "name": "kings-guard", + "domain_slug": "infotech", + "secondary_domains": [ + "government" + ], + "category": "product", + "status": "active", + "local_path": "/home/worsch/kings-guard", + "remote_url": "forgejo-remote:coulomb/kings-guard.git", + "description": "Adaptive immune security control plane for complex multi-tenant cloud environments.", + "created_at": "2026-07-23T20:45:46.635693Z", + "classified_at": "2026-07-23", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "access-control", + "policy", + "governance", + "risk", + "platform", + "operations" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "2784e4e1b67905342260078513249e4b6a9139e5" + }, + { + "slug": "ops-mason", + "name": "ops-mason", + "domain_slug": "infotech", + "secondary_domains": [ + "agents" + ], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/ops-mason", + "remote_url": "forgejo-remote:coulomb/ops-mason.git", + "description": "Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to", + "created_at": "2026-07-26T22:21:51.576970Z", + "classified_at": "2026-08-22", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "access-control", + "audit", + "authorization", + "configuration", + "deployment", + "governance", + "orchestration", + "policy" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "7a45e5f2498fa70ccc41793415049047cd6f8933" + }, + { + "slug": "policy-nexus", + "name": "Policy Nexus", + "domain_slug": "infotech", + "secondary_domains": [ + "government" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/policy-nexus", + "remote_url": "forgejo-remote:coulomb/policy-nexus.git", + "description": "Permanent, provenance-bearing publication surface for estate canon and architecture decisions.", + "created_at": "2026-08-18T10:03:51.869199Z", + "classified_at": "2026-08-18", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "governance", + "knowledge", + "documentation" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "32cea111ebfd8b686906a8e2ca1748bfe9955b45" + }, + { + "slug": "polycode-sim", + "name": "polycode-sim", + "domain_slug": "infotech", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/polycode-sim", + "remote_url": "forgejo-remote:coulomb/polycode-sim.git", + "description": "PolyCode Simulator is a Python-based agent simulation modeling investor and voter strategies to study governance/allocation dynamics, with parameter sweeps and KPI aggregation.", + "created_at": "2026-07-08T11:53:34.002632Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "7296a822ba954e8e42c595561082524ba688a011" + }, + { + "slug": "prj-canon-federation", + "name": "prj-canon-federation", + "domain_slug": "infotech", + "secondary_domains": [ + "financials", + "government" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/prj-canon-federation", + "remote_url": "forgejo-remote:coulomb/prj-canon-federation.git", + "description": "This repository owns the cross-repository goal, concept-ownership boundary, sequencing, dependency map, migration ledger, risks, acceptance gates, and consolidated evidence for the canon federation effort.", + "created_at": "2026-08-16T00:40:42.560038Z", + "classified_at": "2026-08-16", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "canon", + "terminology", + "governance", + "identity", + "documentation" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "2b6980bea9022bc16c5efa6ec87984842ae4d626" + }, + { + "slug": "prj-forgejo-org-refactor", + "name": "prj-forgejo-org-refactor", + "domain_slug": "infotech", + "secondary_domains": [ + "agents" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/prj-forgejo-org-refactor", + "remote_url": "forgejo-remote:coulomb/prj-forgejo-org-refactor.git", + "description": "Temporary coordination repo for splitting the single `coulomb/` Forgejo organization into stewardship organizations without breaking GitOps, image pulls, or clones.", + "created_at": "2026-08-11T11:40:43.310384Z", + "classified_at": "2026-08-11", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "governance", + "operations", + "coordination", + "migration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "847ee07c5c0ae791d53ec8d00107e6b1b16717cc" + }, + { + "slug": "prj-state-hub-retirement", + "name": "prj-state-hub-retirement", + "domain_slug": "infotech", + "secondary_domains": [ + "agents" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/prj-state-hub-retirement", + "remote_url": "forgejo-remote:coulomb/prj-state-hub-retirement.git", + "description": null, + "created_at": "2026-08-09T14:25:59.044067Z", + "classified_at": "2026-08-09", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "orchestration", + "coordination", + "governance" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "54f9706b294681964253e7991ff9876cf853cd7e" + }, + { + "slug": "prj-unattended-progress-company", + "name": "Prj Unattended Progress Company", + "domain_slug": "infotech", + "secondary_domains": [ + "agents", + "financials" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/prj-unattended-progress-company", + "remote_url": "forgejo-remote:coulomb/prj-unattended-progress-company.git", + "description": "Temporary project: make Binky Hedgehog GmbH a profitable self-organizing company with minimal CEO time and governance. Authoritative outcome in GOAL.md.", + "created_at": "2026-08-09T20:53:13.905978Z", + "classified_at": "2026-08-09", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "governance", + "orchestration", + "automation", + "operations", + "coordination" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "7e547b3eb2b733d98a9085b36f7d82d84d69f04d" + }, + { + "slug": "python-snake", + "name": "Python Snake", + "domain_slug": "consumer", + "secondary_domains": null, + "category": "experimental", + "status": "active", + "local_path": "/home/worsch/python-snake", + "remote_url": "forgejo-remote:coulomb/python-snake.git", + "description": null, + "created_at": "2026-07-08T12:25:49.522702Z", + "classified_at": "2026-07-08", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "game", + "entertainment" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "0f743b3a83cd1e5650299ebd0cd48f9d3052f348" + }, + { + "slug": "qonto-assistant", + "name": "qonto-assistant", + "domain_slug": "infotech", + "secondary_domains": [ + "financials", + "agents" + ], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/qonto-assistant", + "remote_url": "forgejo-remote:coulomb/qonto-assistant.git", + "description": "Policy-governed Qonto domain REST+MCP assistant: sole bank-key consumer, default-deny no-spend/no-volume-cost policy for multi-harness finance awareness.", + "created_at": "2026-07-21T21:30:28.591700Z", + "classified_at": "2026-07-21", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "finance", + "governance", + "automation", + "api", + "observability" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "efdf00352ae4f34ca85e5d74ffe9db63a04fda60" + }, + { + "slug": "rail-knative", + "name": "Rail Knative", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rail-knative", + "remote_url": "forgejo-remote:coulomb/rail-knative.git", + "description": "Derived Railiance execution rail for Knative activation and revision semantics.", + "created_at": "2026-07-26T11:24:07.459731Z", + "classified_at": "2026-07-26", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "3b2d23092310bf1bf4710067e8d55c4e72a3cb45" + }, + { + "slug": "railiance-master", + "name": "Railiance Master", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/railiance-master", + "remote_url": "forgejo-remote:coulomb/railiance-master.git", + "description": null, + "created_at": "2026-07-25T06:59:58.286289Z", + "classified_at": "2026-07-25", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "governance", + "documentation", + "coordination" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "256034346c299f2188ce70c983166fe710b566a6" + }, + { + "slug": "railiance-telemetry", + "name": "railiance-telemetry", + "domain_slug": "financials", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/railiance-telemetry", + "remote_url": "forgejo-remote:coulomb/railiance-telemetry.git", + "description": "Observability for Railiance \u2014 monitoring, metrics, logs, traces, and alerting that turn running behaviour into evidence and give the self-organizing control loop a signal to close on.", + "created_at": "2026-08-11T19:52:16.001975Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "773f4822c37f4c9786cb129425b9086d2d6adf70" + }, + { + "slug": "ralph-workplan", + "name": "ralph-workplan", + "domain_slug": "agents", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/ralph-workplan", + "remote_url": "forgejo-remote:coulomb/ralph-workplan.git", + "description": "ralph-workplan is a Claude Code skill/plugin that runs a Ralph Loop scoped to a Markdown workplan file, automatically stopping once every task in the workplan is marked done.", + "created_at": "2026-07-08T12:07:08.940795Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "a295ed3d0af605d18e92af071a866e36450e26fb" + }, + { + "slug": "rapp-core-hub", + "name": "Rapp Core Hub", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-core-hub", + "remote_url": "forgejo-remote:coulomb/rapp-core-hub.git", + "description": "Managed Railiance runtime package for Core Hub", + "created_at": "2026-08-20T09:16:03.880762Z", + "classified_at": "2026-08-20", + "classified_by": "repo-manager", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "b322bf1531650a09a9ef0669d3c63091532ab078" + }, + { + "slug": "rapp-issue-core", + "name": "Rapp Issue Core", + "domain_slug": "infotech", + "secondary_domains": [ + "agents" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-issue-core", + "remote_url": "forgejo-remote:coulomb/rapp-issue-core.git", + "description": null, + "created_at": "2026-08-19T19:42:59.724908Z", + "classified_at": "2026-08-19", + "classified_by": "repo-manager", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration", + "integration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "a78f38cfd8afb29ed23d150a4ea3e3dcd1f35381" + }, + { + "slug": "rapp-openbao", + "name": "rapp-openbao", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-openbao", + "remote_url": "forgejo-remote:coulomb/rapp-openbao.git", + "description": "First Railiance managed OpenBao workload package.", + "created_at": "2026-07-25T23:12:16.035040Z", + "classified_at": "2026-07-25", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration", + "governance" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "8e5347b157813d19a8a29509a983cb8f9474a6c6" + }, + { + "slug": "rapp-policy-nexus", + "name": "Rapp Policy Nexus", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-policy-nexus", + "remote_url": "forgejo-remote:coulomb/rapp-policy-nexus.git", + "description": "Managed Kubernetes runtime package for the canonical Policy Nexus publication artifact.", + "created_at": "2026-08-18T10:03:52.187039Z", + "classified_at": "2026-08-18", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration", + "governance" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "41c42e8d1a653af666da2e5e7e008a27464d9b87" + }, + { + "slug": "rapp-postgres", + "name": "rapp-postgres", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-postgres", + "remote_url": "forgejo-remote:coulomb/rapp-postgres.git", + "description": "Railiance managed PostgreSQL platform and multi-tenant relational storage.", + "created_at": "2026-08-10T10:41:48.811909Z", + "classified_at": "2026-08-10", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "tenancy", + "configuration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "cfc252630c53e87d01eb38b91e1d5b692e72a4b2" + }, + { + "slug": "rapp-qonto", + "name": "Rapp Qonto", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-qonto", + "remote_url": "forgejo-remote:coulomb/rapp-qonto.git", + "description": "Managed runtime package for the Qonto assistant domain service.", + "created_at": "2026-07-26T11:24:07.680014Z", + "classified_at": "2026-07-26", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "f57e60ad2a41c18f55dd9ee4ec24a56a4e0d9ff2" + }, + { + "slug": "rapp-sbom-nexus", + "name": "rapp-sbom-nexus", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "project", + "status": "active", + "local_path": "/home/worsch/rapp-sbom-nexus", + "remote_url": "forgejo-remote:coulomb/rapp-sbom-nexus.git", + "description": "Managed private runtime package for the SBOM Nexus authority on Railiance.", + "created_at": "2026-08-22T13:17:53.750516Z", + "classified_at": null, + "classified_by": "repo-manager", + "standard_version": "1.0", + "capability_tags": [], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "1566bcf69fc0757db5efc67f78b14af10d944c1b" + }, + { + "slug": "reef-railiance", + "name": "Reef Railiance", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/reef-railiance", + "remote_url": "forgejo-remote:coulomb/reef-railiance.git", + "description": null, + "created_at": "2026-07-26T00:40:07.793983Z", + "classified_at": "2026-07-26", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "operations", + "configuration", + "governance" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "3e98b10d81990c45465f3f620441d97347670b52" + }, + { + "slug": "rein-aharness", + "name": "rein-aharness", + "domain_slug": "agents", + "secondary_domains": [ + "infotech" + ], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/rein-aharness", + "remote_url": "forgejo-remote:coulomb/rein-aharness.git", + "description": "Claude-Code-CLI-driven rein: governed, unattended/scheduled agent runtime", + "created_at": "2026-07-26T10:30:41.463658Z", + "classified_at": "2026-08-23", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "orchestration", + "governance", + "policy", + "observability", + "control", + "coordination" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "84b4089f8acfc92241e77e34e6ef4cc2a1f91df7" + }, + { + "slug": "rein-openweights", + "name": "rein-openweights", + "domain_slug": "infotech", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/rein-openweights", + "remote_url": "forgejo-remote:coulomb/rein-openweights.git", + "description": "Agentic tool-use harness driving open-weight models via OpenRouter", + "created_at": "2026-07-26T12:12:40.191614Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "a9071245b23d7870ea200899013b6840195d5057" + }, + { + "slug": "resource-control", + "name": "resource-control", + "domain_slug": "financials", + "secondary_domains": [ + "infotech" + ], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/resource-control", + "remote_url": "forgejo-remote:coulomb/resource-control.git", + "description": "Provider-neutral infrastructure resource inventory, procurement, cost, utilization, and optimization control plane.", + "created_at": "2026-08-10T15:38:53.719470Z", + "classified_at": "2026-08-10", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "platform", + "observability", + "decision-support", + "pricing", + "control" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "7a196b62655cfebc4c5e600f3a083d340a6e0ef1" + }, + { + "slug": "risk-nexus", + "name": "Risk Nexus", + "domain_slug": "infotech", + "secondary_domains": [ + "government" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/risk-nexus", + "remote_url": "forgejo-remote:coulomb/risk-nexus.git", + "description": "Risk register and regulatory intake for the estate; serves risk.coulomb.social. Owned by the-custodian, alongside policy-nexus. Holds security/architecture/operational/compliance findings with severity, owner and date; decides disclosure timing; holds regulatory intake; carries the escalation duty (what must reach the operator personally). Does not fix defects (routes to the owning repo) and does not publish (policy-nexus is the publication surface). Governance in INTENT.md; findings in findings/.", + "created_at": "2026-08-19T21:14:28.123149Z", + "classified_at": "2026-08-19", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "risk", + "governance", + "compliance", + "audit", + "knowledge" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "cad7adf85146970616558cc1198900828cd20921" + }, + { + "slug": "sbom-nexus", + "name": "sbom-nexus", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/sbom-nexus", + "remote_url": "forgejo-remote:coulomb/sbom-nexus.git", + "description": "Dedicated SBOM capture, history, evaluation, and bounded catch-up service.", + "created_at": "2026-08-22T10:40:42.011116Z", + "classified_at": "2026-08-22", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "traceability", + "compliance", + "risk", + "audit", + "operations" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "503bebcb0bd7be60d3f15e11e8dd974dbc5af1eb" + }, + { + "slug": "soul-frame", + "name": "Soul Frame", + "domain_slug": "agents", + "secondary_domains": [ + "infotech" + ], + "category": "research", + "status": "active", + "local_path": "/home/worsch/soul-frame", + "remote_url": "forgejo-remote:coulomb/soul-frame.git", + "description": "Systems-theoretic research program for person-like informational beings (Body=Action, Mind=Model, Soul=Relation).", + "created_at": "2026-08-09T19:37:31.944268Z", + "classified_at": "2026-08-09", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "knowledge", + "documentation", + "orchestration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "6ccd5e2a6a523125eaba8798fb8fb317368170a3" + }, + { + "slug": "target-revenue", + "name": "target-revenue", + "domain_slug": "infotech", + "secondary_domains": [ + "financials" + ], + "category": "project", + "status": "active", + "local_path": "/home/worsch/target-revenue", + "remote_url": "forgejo-remote:coulomb/target-revenue.git", + "description": "Target Revenue Framework (TRF): a Target Revenue Source License + Trust Service for financing exploratory product development, converting to a permissive license once a declared revenue target is satisfied.", + "created_at": "2026-07-28T15:58:59.084695Z", + "classified_at": "2026-07-28", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "f1109d54eeda9f187daa215cf1c7163610d35d0a" + }, + { + "slug": "tenant-engine", + "name": "tenant-engine", + "domain_slug": "infotech", + "secondary_domains": [ + "financials" + ], + "category": "product", + "status": "active", + "local_path": "/home/worsch/tenant-engine", + "remote_url": "forgejo-remote:coulomb/tenant-engine.git", + "description": "Canonical owner of tenant-as-an-entity facts for NetKingdom: existence, onboarding grouping, capability roles, and plan/subscription assignment.", + "created_at": "2026-07-23T19:52:04.885950Z", + "classified_at": "2026-07-23", + "classified_by": "agent", + "standard_version": "1.0", + "capability_tags": [ + "identity", + "access-control", + "tenancy", + "platform", + "operations" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "0c0b40f510ba745fe6652f40832b9d491e37d3fb" + }, + { + "slug": "test-driver", + "name": "test-driver", + "domain_slug": "infotech", + "secondary_domains": [ + "agents" + ], + "category": "research", + "status": "active", + "local_path": "/home/worsch/test-driver", + "remote_url": "forgejo-remote:coulomb/test-driver.git", + "description": "Use-case-driven verification framework for integration, end-to-end, multi-user, authorization and security testing that matures tests from agentic exploration into deterministic regression.", + "created_at": "2026-08-22T20:38:15.850357Z", + "classified_at": "2026-08-22", + "classified_by": "human", + "standard_version": "1.0", + "capability_tags": [ + "testing", + "verification", + "quality-assurance", + "authorization", + "security", + "evidence", + "orchestration" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "4575a6c2383cd529c7d630c7cbff0e505546042d" + }, + { + "slug": "testdrive-jsui", + "name": "testdrive-jsui", + "domain_slug": "infotech", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/testdrive-jsui", + "remote_url": "forgejo-remote:coulomb/testdrive-jsui.git", + "description": "TestDrive-JSUI is a standalone, JavaScript-first markdown editor and UI library (with an optional Python integration adapter) that is being packaged for npm distribution.", + "created_at": "2026-07-08T12:09:35.301634Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "f69fd6568b733d1e00cdadede22184682eb78b78" + }, + { + "slug": "timeline-svg", + "name": "timeline-svg", + "domain_slug": "infotech", + "secondary_domains": null, + "category": null, + "status": "active", + "local_path": "/home/worsch/timeline-svg", + "remote_url": "forgejo-remote:coulomb/timeline-svg.git", + "description": "TimelineSvg is a client-side, browser-based tool that generates multi-lane SVG timeline graphics from CSV data using an Inkscape-editable SVG template system with no backend or build pipeline.", + "created_at": "2026-07-08T12:11:08.331627Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": null, + "working_copy_present": true, + "has_classification_file": false, + "head_sha": "efa97f2230a72aea25f3fe18da26e3e180168a16" + }, + { + "slug": "tmux-amq", + "name": "tmux-amq", + "domain_slug": "communication", + "secondary_domains": [ + "agents", + "infotech" + ], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/tmux-amq", + "remote_url": "forgejo-remote:coulomb/tmux-amq.git", + "description": "Local durable message queue and tmux endpoint runtime for coordinating agent workers across gita-registered repositories.", + "created_at": "2026-08-24T12:12:29.848269Z", + "classified_at": "2026-08-24", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "collaboration", + "coordination", + "orchestration", + "operations", + "platform" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "c9a162c2d94230bfaaa9064731b6e5401b519078" + }, + { + "slug": "whitehat-security", + "name": "Whitehat Security", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "tooling", + "status": "active", + "local_path": "/home/worsch/whitehat-security", + "remote_url": "forgejo-remote:coulomb/whitehat-security.git", + "description": "NetKingdom authorization-bound offensive-security tooling for adversarial security evidence and risk-nexus findings delivery.", + "created_at": "2026-08-21T20:51:12.956538Z", + "classified_at": "2026-08-21", + "classified_by": "codex", + "standard_version": "1.0", + "capability_tags": [ + "access-control", + "evidence", + "traceability", + "compliance", + "risk", + "audit", + "observability", + "operations" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "4c1e0db718f045fbc933acab7f6b4849bb26af60" + }, + { + "slug": "zone-engine", + "name": "zone-engine", + "domain_slug": "infotech", + "secondary_domains": [], + "category": "project", + "status": "active", + "local_path": "/home/worsch/zone-engine", + "remote_url": "forgejo-remote:coulomb/zone-engine.git", + "description": "Authority for security zone identity, workload admission, and time-boxed enforcement exceptions.", + "created_at": "2026-08-19T19:19:13.305844Z", + "classified_at": null, + "classified_by": null, + "standard_version": null, + "capability_tags": [ + "governance", + "policy" + ], + "working_copy_present": true, + "has_classification_file": true, + "head_sha": "6f667d20c26cd731d5c299940848cc01e9ed2847" + } + ] +} diff --git a/workplans/CUST-WP-0067-hub-authority-target-resolution.md b/workplans/CUST-WP-0067-hub-authority-target-resolution.md index c0554a6..a0d3ade 100644 --- a/workplans/CUST-WP-0067-hub-authority-target-resolution.md +++ b/workplans/CUST-WP-0067-hub-authority-target-resolution.md @@ -100,29 +100,46 @@ and print the resolved API base so the operator can see which instance answered. defaults throughout, and prints `API base:` as its second line. Verified against the live API. -## Eliminate the port collision +## Retire the local hub instance and the reverse-tunnel relay ```task id: CUST-WP-0067-T02 -status: todo +status: progress priority: high state_hub_task_id: "4093e928-d752-5a91-96c3-2e80f0e1dac5" ``` -Move `state-hub-primary` off `local_port: 8000` to `18000`, matching the port -map already reserved for the primary in the global agent instructions. Leave the -local cache on 8000 so nothing that currently resolves to it changes behaviour — -this step is deliberately non-breaking and must stay that way. +Decision, 2026-08-24: rather than making two hub instances coexist safely, +retire the second one. The local `postgres:16-alpine` + uvicorn instance is what +impersonates central, and it is redundant — `ADR-010` decision 3 already states +that local work requires no hub at all, and Repo Manager already maintains a +file-derived local index (`index_store.py`, `rmgr cache status` / `cache +rebuild`). Two caching layers exist and one of them is a database pretending to +be the primary. -Extend the `ops-bridge` duplicate-port guard so it rejects a `direction: local` -tunnel whose `local_port` is already bound by any listener, not only by another -bridge tunnel. The current guard could not have caught this. +With the local instance gone, `state-hub-primary` binds `127.0.0.1:8000` +unchanged and every existing `http://127.0.0.1:8000` default becomes correct +without editing a single call site. The port collision cannot recur because only +one process binds the port. -Acceptance: `state-hub-primary` binds `127.0.0.1:18000`; `[::1]:8000` no longer -serves a hub; `curl 127.0.0.1:18000/state/health` reports the central instance -and `curl 127.0.0.1:8000/state/health` reports the cache; the two return -different repo counts; the guard fails a synthetic config that reintroduces the -collision. +Retire the reverse tunnels too. `state-hub-railiance01` forwards a remote box's +`:18000` back to this workstation's `:8000`, so a remote agent following the +documented port map reaches the workstation rather than the primary — which on +railiance01 is its own machine. That topology assumed the workstation was the +hub; it has not been since the primary moved. + +Sequence matters: export the cache-only records first, stop serving second, +discard the cache data only after T05 proves central holds everything. + +Acceptance: no local hub process listening; `127.0.0.1:8000` answers from +central; MCP `dev-hub` resolves to central; reverse `state-hub-*` tunnels removed +or repointed; the cache-only recovery export is committed. + +**Done (2026-08-24):** `docs/recovery/cache-only-repos-2026-08-24.json` captures +all 44 cache-only repository records with working-copy presence, classification +file presence, and HEAD sha — the recovery source for T05. +`ops-bridge` now pins local forwards to `127.0.0.1` (commit `2213847`), so a +contested port fails loudly instead of silently landing on `[::1]`. ## Make the hub target explicit and unspoofable @@ -133,19 +150,19 @@ priority: high state_hub_task_id: "29977448-1a74-5a4d-b729-974c15b6bbde" ``` -Remove the `http://127.0.0.1:8000` default from every call site that claims to -reach the primary: `custodian_cli.py:28`, `statehub_register.py:22`, -`repo_manager/cli.py:56,405`, `repo_manager/commands/registrar_reconcile.py:410`. +Retiring the local instance removes today's impersonator but not the ability for +a future one to appear. Give the hub an instance identity it can assert — role +served from the health or summary endpoint — and make +`registrar-reconcile --confirm-primary` refuse anything that does not assert +`primary`. -A default that silently resolves to a cache is worse than a missing one. Give -the hub an identity it can assert — instance role served from the health or -summary endpoint — and make `registrar-reconcile --confirm-primary` refuse to -run against anything that does not assert `primary`. Confirming against a cache -is a false green and is the specific failure that let this run for seven weeks. +`_check_primary` currently asserts only `status == ok` and `db == connected`. +Both instances passed it. It is a liveness check wearing an authority check's +name, and it is what allowed a cache to certify itself as the registrar. -Acceptance: `--confirm-primary` against the cache exits non-zero with a message -naming the instance it reached; against central it succeeds; no code path -reaches a hub without an explicitly resolved target. +Acceptance: `--confirm-primary` fails against a non-primary instance and names +what it reached; a hub reports its role; `statehub status` shows role alongside +the API base. ## Give Repo Manager a real onboarding write path @@ -156,21 +173,21 @@ priority: high state_hub_task_id: "ffa141d5-331d-543d-8b87-516f27973a22" ``` -Repo Manager owns `managed_repos` as `file-derived` and has no command for it. -Add onboarding that follows ADR-010 decision 5: write `.repo-classification.yaml` -in the target repository, commit, push, and have central derive the record. -Central must not accept a push of derived state, so the command's job is to make -the source file correct and reachable, then trigger and verify derivation. +Repo Manager owns `managed_repos` as `file-derived` in +`hub-record-authority.yaml` and exposes no command for it. Add onboarding that +follows `ADR-010` decision 5: write `.repo-classification.yaml` in the target +repository, commit, push, and have central derive the record. Central must not +accept a push of derived state, so the command makes the source file correct and +reachable, then triggers and verifies derivation. Resolve the bootstrap gap explicitly — central derives from repositories it already knows about, so a never-registered repository is never scanned. The onboarding path must be able to introduce a repository central has not seen. -Acceptance: onboarding a fresh repository from the workstation produces a -central record with no manual step; re-running is idempotent; the cache is not -written directly. +Acceptance: onboarding a fresh repository from the workstation produces a central +record with no manual step; re-running is idempotent. -## Backfill the 44 cache-only registrations +## Onboard the 44 cache-only repositories to central ```task id: CUST-WP-0067-T05 @@ -179,22 +196,21 @@ priority: medium state_hub_task_id: "078159e6-5ecd-5f9d-b3ec-1fabf60955f7" ``` -Runs only after T02–T04; backfilling before the target is unambiguous refills -the cache. Drive the 43 on-disk repositories through the T04 path. Nine lack -`.repo-classification.yaml` (`binky-control`, `clay-borg`, -`direkt-vermittlung-de`, `polycode-sim`, `railiance-telemetry`, `ralph-workplan`, -`rein-openweights`, `testdrive-jsui`, `timeline-svg`) and need one authored with -the owner rather than guessed — classification is not mechanical, per -`CUST-WP-0065-T01`. Push `soul-frame` and `rein-openweights` first. +Runs after T04. With the cache retired this is no longer a convergence of two +hubs — it is onboarding 44 repositories to central from their files, which is +T04 applied to the recovery export. -`agent-harness` has no working copy: decide restore-from-remote or drop, and -record the decision. Do not preserve it as a hub-only record — that is the -ADR-001 violation ADR-010 calls out. +Ten of the 44 lack `.repo-classification.yaml` and need one authored with the +owner rather than guessed; classification is not mechanical, per +`CUST-WP-0065-T01`. Push `soul-frame` and `rein-openweights` first — both are +ahead of their remote, and central derives from what it can fetch. +`agent-harness` has no working copy: decide restore-from-remote or drop and +record it. Do not preserve it as a hub-only record. -Acceptance: central and cache repo counts converge; the cache-only set is empty -or every remainder has a written disposition. +Acceptance: every record in the recovery export exists on central or carries a +written disposition; only then may the local cache database be discarded. -## Correct the ADR-010 repo-record framing +## Correct the ADR-010 framing and record the retirement ```task id: CUST-WP-0067-T06 @@ -203,16 +219,22 @@ priority: medium state_hub_task_id: "007bfcf1-3b17-5d4a-b16a-b80ebf273934" ``` -ADR-010 decision 2 says a divergent database is a merge problem and a stale -cache is a refresh problem. For `managed_repos` neither holds: the gap is a -strict subset in the cache's favour, and refreshing destroys rather than -reconciles. Record the third shape — cache-only records whose authoritative -source exists but was never introduced to central — and state that its remedy is -re-derivation from source, not refresh and not merge. +`ADR-010` decision 2 says a divergent database is a merge problem and a stale +cache is a refresh problem. For `managed_repos` neither held: the gap was a +strict subset in the cache's favour, and refreshing would have destroyed rather +than reconciled. Record that third shape — cache-only records whose +authoritative source exists but was never introduced to central — with +re-derivation from source as its remedy. -Also correct the implicit assumption that the ADR's own remediation happened. -The measurement stands; the fix did not land, and the ADR reads as though it did. +Record the mechanical cause, which the ADR observed but did not diagnose: an +unbound `ssh -L` binds every loopback family, so the IPv4 bind losing to a local +listener still leaves a working `[::1]` forward and `ExitOnForwardFailure` never +fires. The ADR treated the shared port as the hazard; the missing bind address +was what made it silent. -Acceptance: ADR-010 revised with a superseding note dated and linked to this -workplan; the port-collision remediation recorded as an outcome rather than an -observation. +Note also that ADR-010 reads as though its remediation landed. It did not — the +condition it measured was still live seven weeks later. Supersede decision 2 for +this record class and record the local-instance retirement as the outcome. + +Acceptance: ADR-010 revised with a dated superseding note linked to this +workplan; `ops-bridge` and the port map documented as the structural fix.