docs: adopt clean PSD replacement model
This commit is contained in:
+13
-4
@@ -9,8 +9,9 @@
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-21 (DWH per-installation authentication is active in dual-key mode;
|
||||
> the owner deferred Mac acceptance and legacy revocation to the mandatory pre-Project-B gate,
|
||||
> authorized the read-only survey and Project A private preparation, and did not authorize either
|
||||
> stopping the legacy stack or starting the new stack).
|
||||
> approved a clean replacement with no legacy-state migration and no new host account, authorized
|
||||
> the read-only survey and Project A private preparation, and did not authorize either stopping the
|
||||
> legacy stack or starting the new stack).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### PSD server deployment program — design approved, execution PENDING (2026-08-20)
|
||||
@@ -39,10 +40,18 @@
|
||||
balancer can prove an operator-only temporary endpoint. Project B preserves the real user flow
|
||||
`Aritmolab homepage -> sidebar -> load balancer -> Nginx -> ThothII`, with direct ThothII-managed
|
||||
OIDC and no second Nginx `auth_request`.
|
||||
- **Clean-replacement amendment (owner, 2026-08-21):** no host `thothii` user or group is created.
|
||||
The image retains its internal numeric UID/GID `10001:10001`; only its dedicated writable bind
|
||||
trees may carry that unmapped numeric ownership. Old ThothII sessions/configuration are
|
||||
disposable, but the exact legacy containers, images, source, and data remain intact until the
|
||||
new Aritmolab journey passes Project B. Shared Omics/LocalLLM networks, ETL Evidence, DWH,
|
||||
`dwh-auth`, Supabase, Authentik, Superset, and Aritmolab are never cleanup targets. Approved
|
||||
design and executable amendment: `docs/superpowers/specs/2026-08-21-psd-clean-replacement-design.md`
|
||||
and `docs/superpowers/plans/2026-08-21-psd-clean-replacement.md`.
|
||||
- **State:** survey `SURVEY_NO_GO` for Project A private; Project A
|
||||
`BLOCKED_BY_SURVEY_AND_MUTATION_GATE`; Project B `BLOCKED_BY_PROJECT_A_AND_PRE_B_GATE`.
|
||||
Remaining private-scope blockers are legacy rollback/backup, approved installation paths and UID
|
||||
strategy, dedicated read-only workspace access, a dedicated direct-DWH role/route, and Pi/LLM
|
||||
Legacy retention and UID strategy are resolved. Remaining private-scope blockers are dedicated
|
||||
read-only workspace access, a dedicated direct-DWH role/route, and sanitized Pi/LLM
|
||||
metadata. The catalog-only survey proved the currently available `postgres` identity owns
|
||||
`datawarehouse` and has full write/DDL privileges, so it must not be reused by the new core.
|
||||
Pi metadata resolves to 0.80.3, `deepseek/deepseek-v4-pro`, thinking `high`, but the bounded
|
||||
|
||||
Reference in New Issue
Block a user