docs: plan PSD server deployment program

This commit is contained in:
2026-08-20 00:57:47 +02:00
parent 3fd177b6c4
commit 21caaa22e3
11 changed files with 2154 additions and 2 deletions
+32 -2
View File
@@ -7,10 +7,40 @@
> ThothII per il repository (app + CLI `tht`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (final-review fix round 2 recorded; native Windows authentication gate
> passed, remediation is complete, and unrelated release gates remain open).
> Last updated: 2026-08-20 (PSD server replacement and Authentik-integration program designed;
> executable survey, two gated project plans, human-test guides, and evidence templates prepared;
> no server mutation has been executed).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### PSD server deployment program — design approved, execution PENDING (2026-08-20)
- **Approved design:** `docs/plans/2026-08-20-psd-server-deployment-program-design.md`; design
commit `3fd177b`. The owner approved a common read-only survey followed by two independently
accepted projects: A installs/proves a private local-auth stack through F1-F8; B starts only
after A PASS and integrates Supabase schema storage, Authentik OIDC, Nginx, the load balancer,
and the existing Aritmolab sidebar journey.
- **Executable entrypoint:** `docs/plans/2026-08-20-psd-server-deployment-program.md`, with separate
plans for the survey, Project A, and Project B. The server-local Sol agent must execute them with
`superpowers:executing-plans`, checkpointing every verified step and stopping on the documented
owner/secret/rollback boundaries.
- **Human gates:** `docs/testing/psd-server-project-a-manual.md` and
`docs/testing/psd-server-project-b-manual.md`; survey and Project A/B report templates are under
`docs/testing/evidence/`. Automated evidence never substitutes for the two explicit human PASS
decisions.
- **Workspace decision:** keep one `psd-clinical` descriptor in `tht-workspace-psd`; publish
`supported_transports: [rest_api, postgres_direct]`. Mac selects REST, server selects direct;
all installation bindings/secrets remain outside Git.
- **Data/runtime decision:** migrate configuration only. Legacy work sessions, Qdrant indexes, and
Ollama cache are not imported. Project A rebuilds internal Qdrant/Ollama and uses filesystem work
sessions. Project B uses the existing Supabase PostgreSQL database with isolated schema
`thoth_sessions`, dedicated migrator/runtime roles, forced RLS, and no PostgREST exposure.
- **Network/auth decision:** no SSH tunnel. Project A is loopback-only unless the surveyed load
balancer can prove an operator-only temporary endpoint. Project B preserves the real user flow
`Aritmolab homepage -> sidebar -> load balancer -> Nginx -> ThothII`, with direct ThothII-managed
OIDC and no second Nginx `auth_request`.
- **State:** survey `PENDING`; Project A `PENDING`; Project B `BLOCKED_BY_PROJECT_A`; server and
external repositories/services unchanged by this planning work.
### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18)
- Frozen source is `2a9359071257f9b8a71d36ec2bbb25b161003f81` on `feat/thoth-auth`.