docs: defer DWH client cutover before Project B

This commit is contained in:
User
2026-08-21 14:35:37 +02:00
parent 7118950416
commit 9974fb4bc0
12 changed files with 244 additions and 86 deletions
+17 -5
View File
@@ -7,9 +7,10 @@
> ThothII per il repository (app + CLI `tht`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-20 (PSD server replacement and Authentik-integration program designed;
> executable survey, two gated project plans, human-test guides, and evidence templates prepared;
> no server mutation has been executed).
> Last updated: 2026-08-21 (DWH per-installation authentication is active in dual-key mode;
> the owner deferred Mac acceptance and legacy revocation to the mandatory pre-Project-B gate,
> authorized the read-only survey and Project A private preparation, and did not authorize either
> stopping the legacy stack or starting the new stack).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### PSD server deployment program — design approved, execution PENDING (2026-08-20)
@@ -38,8 +39,19 @@
balancer can prove an operator-only temporary endpoint. Project B preserves the real user flow
`Aritmolab homepage -> sidebar -> load balancer -> Nginx -> ThothII`, with direct ThothII-managed
OIDC and no second Nginx `auth_request`.
- **State:** survey `PENDING`; Project A `PENDING`; Project B `BLOCKED_BY_PROJECT_A`; server and
external repositories/services unchanged by this planning work.
- **State:** survey `SURVEY_NO_GO` for Project A private; Project A
`BLOCKED_BY_SURVEY_AND_MUTATION_GATE`; Project B `BLOCKED_BY_PROJECT_A_AND_PRE_B_GATE`.
Remaining private-scope blockers are legacy rollback/backup, approved installation paths and UID
strategy, dedicated read-only workspace access, a dedicated direct-DWH role/route, and Pi/LLM
metadata. The catalog-only survey proved the currently available `postgres` identity owns
`datawarehouse` and has full write/DDL privileges, so it must not be reused by the new core.
Pi metadata resolves to 0.80.3, `deepseek/deepseek-v4-pro`, thinking `high`, but the bounded
no-session/no-tool reachability probe is FAIL and must be diagnosed without exposing auth data.
- **Sequencing amendment (owner, 2026-08-21):** use two survey decisions. Project A private may
proceed only after `SURVEY_GO_PROJECT_A_PRIVATE` and a separate stop/start authorization. Mac
`rest_api` acceptance, the 48-hour/two-ETL observation, and revocation of `legacy-shared` are
mandatory before `SURVEY_GO_PROJECT_B`. Current authorization covers read-only survey and
preparation only; old-stack stop and new-stack start remain forbidden.
### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18)
+8 -4
View File
@@ -1,6 +1,6 @@
# PSD — rollout controllato DWH REST
Questo runbook rispecchia i Task 9–10 del [piano](../superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md). È descrittivo: non autorizza mutazioni ora. Activity 1 PSD resta `IN_DISCUSSION` fino a due consensi espliciti separati.
Questo runbook rispecchia i Task 9–10 del [piano](../superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md). Gate A e la parte dual-key di Gate B sono stati eseguiti con autorizzazioni separate. L'emendamento del proprietario del 2026-08-21 rinvia collaudo Mac, osservazione e revoca a prima di Project B; non autorizza ulteriori mutazioni.
## Invarianti
@@ -29,11 +29,15 @@ Serve un secondo consenso: presentare file, backup, canale consegna Mac, osserva
2. Aggiungere solo `/etc/nginx/conf.d/dwh-auth-rate-limit.conf` e route DWH; preservare upstream `http://127.0.0.1:3001/`, mantenere byte-identiche le location vector e rimuovere la chiave prima di PostgREST.
3. Eseguire checker strutturale, scansione segreti con solo `PASS/FAIL` e metadati, installare candidati e `sudo nginx -t`. No raw diff: non eseguire o conservare raw diff, `nginx -T` o dump: il file legacy può contenere la chiave. Se uno fallisce, ripristinare backup prima di reload e registrare FAIL sanitizzato.
4. Dopo consenso fare reload, poi HTTPS `.it` con CA e file header curl protetti 0600: v1=2xx, legacy=2xx, casuale=401, assente=401 su `/dwh/rpc/ping`; guasto autenticatore=503, mai accesso permissivo.
5. Consegnare al Mac chiave e CA separatamente, verificare fingerprint fuori banda, configurare vault GUI o `API_KEY_FILE`, poi **Validate workspace source** e **Test workspace connections**.
6. Dopo osservazione revocare `legacy-shared` con ragione `shared-credential-rotation`; v1=2xx post-revoca, legacy=401 post-revoca e journal limitato senza chiavi/digest.
5. **Deferred pre-Project-B:** consegnare al Mac chiave e CA separatamente, verificare fingerprint fuori banda, configurare vault GUI o `API_KEY_FILE`, poi **Validate workspace source** e **Test workspace connections**.
6. **Deferred pre-Project-B:** completare 48 ore di osservazione comprendenti due cicli ETL delle 03:00, quindi revocare `legacy-shared` con ragione `shared-credential-rotation`; v1=2xx post-revoca, legacy=401 post-revoca e journal limitato senza chiavi/digest.
## Rollback e chiusura
Durante dual-key il rollback ripristina solo route/servizio revisionati, verifica `nginx -t` e fa reload autorizzato. Non ripristina chiavi revocate, PostgreSQL, dati legacy o stack. Scatta per TLS, risposte inattese, salute degradata o assenza di consenso.
Activity 1 diventa `PASS` solo con v1=2xx post-revoca, legacy=401 post-revoca, servizio/Nginx validi, log sanitizzati, rollback leggibile e accettazione owner; poi avanza a Activity 2, con programma ancora `SURVEY_NO_GO`. Compilare [evidenza](../testing/evidence/psd-dwh-auth-rollout-report-template.md) e [collaudo](../testing/dwh-auth-manual-acceptance.md).
Activity 1 resta `DEFERRED_PRE_PROJECT_B`: dual-key è attivo, ma PASS richiede ancora v1=2xx
post-revoca, legacy=401 post-revoca, servizio/Nginx validi, log sanitizzati, rollback leggibile e
accettazione owner. Il rinvio non blocca il survey e Project A privato; blocca Project B. Compilare
[evidenza](../testing/evidence/psd-dwh-auth-rollout-report-template.md) e
[collaudo](../testing/dwh-auth-manual-acceptance.md).
@@ -22,16 +22,17 @@ Authentik, Aritmolab o repository esterni.
- Survey report: `/var/tmp/thothii-psd-survey.fJh7DS/survey-report.md`
- Survey report SHA-256: `36461b6c7d1e44d055f24d6919e892b7017352ac9eb99ac67b9ae62f0614f8e7`
- Legacy stack: deve restare acceso e invariato durante la discussione di questa lista
- Project A remains forbidden fino a un nuovo `SURVEY_GO` e all'approvazione esplicita del proprietario
- La preparazione statica di Project A privato è autorizzata; stop del legacy e start del nuovo
restano vietati fino a `SURVEY_GO_PROJECT_A_PRIVATE` e a un consenso di mutazione separato
- Project B remains forbidden fino ai PASS automatico, umano e del proprietario per Project A
## Current activity and resume point
- Current activity: `1`
- Title: Rotate or revoke the exposed DWH credential safely
- Resume from: Activity 1, review the approved implementation plan and choose its execution mode
- Current activity: `2`
- Title: Identify accountable owners for the private Project A scope
- Resume from: Activity 2, assign owner/authority for legacy rollback, direct DWH, workspace and Pi/LLM
- Discussion rule: una sola attività può essere `IN_DISCUSSION`
- Allowed states: `PENDING`, `IN_DISCUSSION`, `BLOCKED`, `PASS`
- Allowed states: `PENDING`, `IN_DISCUSSION`, `DEFERRED_PRE_PROJECT_B`, `BLOCKED`, `PASS`
## How to use this checklist
@@ -51,20 +52,20 @@ Authentik, Aritmolab o repository esterni.
| ID | Attività | Stato | Responsabile | Prossimo gate |
|---|---|---|---|---|
| 1 | Rotazione controllata della credenziale DWH esposta | `IN_DISCUSSION` | Proprietario del progetto | Revisionare il piano eseguibile e scegliere l’esecuzione |
| 2 | Assegnazione dei responsabili dei componenti condivisi | `PENDING` | Unassigned | Elenco owner confermato |
| 3 | Risoluzione del dominio pubblico `.it` oppure `.com` | `PENDING` | Unassigned | Origine autorevole documentata |
| 4 | Topologia e responsabilità del load balancer | `PENDING` | Unassigned | Route, health, TLS, rollback e allowlist verificati |
| 5 | Accesso read-only protetto ad Authentik | `PENDING` | Unassigned | Inventario API autorizzato e redatto |
| 6 | Accesso catalog-only protetto a PostgreSQL | `PENDING` | Unassigned | Catalogo, grant e PostgREST verificati |
| 7 | Backup e rollback del vecchio ThothII | `PENDING` | Unassigned | Backup verificabile e restart recipe completa |
| 8 | Accesso Git read-only al workspace PSD | `PENDING` | Unassigned | SHA, descriptor e deploy key verificati |
| 9 | Metadati Pi e LLM verificabili | `PENDING` | Unassigned | Versione, policy e reachability redatte |
| 1 | Rotazione controllata della credenziale DWH esposta | `DEFERRED_PRE_PROJECT_B` | Proprietario del progetto | Chiusura obbligatoria prima di Project B |
| 2 | Assegnazione dei responsabili dei componenti condivisi | `IN_DISCUSSION` | Proprietario del progetto | Owner privati A e shared B distinti |
| 3 | Risoluzione del dominio pubblico `.it` oppure `.com` | `BLOCKED` | Unassigned | Necessario per Project B, non per A privato |
| 4 | Topologia e responsabilità del load balancer | `BLOCKED` | Unassigned | Necessario per Project B/route opzionale |
| 5 | Accesso read-only protetto ad Authentik | `BLOCKED` | Unassigned | Necessario per Project B, non per A privato |
| 6 | Accesso catalog-only protetto a PostgreSQL | `BLOCKED` | Unassigned | DWH direct read-only ancora da provare |
| 7 | Backup e rollback del vecchio ThothII | `BLOCKED` | Proprietario del progetto | Procedura e destinazione da approvare |
| 8 | Accesso Git read-only al workspace PSD | `BLOCKED` | Curator da confermare | Checkout/deploy key server mancanti |
| 9 | Metadati Pi e LLM verificabili | `BLOCKED` | Unassigned | Policy e reachability redatte mancanti |
| 10 | Conservazione evidenze e nuovo survey bounded | `PENDING` | Unassigned | Nuovo report e decisione proprietario |
## Activity 1: Rotate or revoke the exposed DWH credential safely
- Status: `IN_DISCUSSION`
- Status: `DEFERRED_PRE_PROJECT_B`
- Accountable owner: Proprietario del progetto (confermato dall'utente)
- Objective: sostituire o revocare in modo controllato la credenziale DWH comparsa nell'output
interno del survey, senza interrompere consumer legittimi e senza esporne nuovamente il valore.
@@ -161,16 +162,17 @@ Authentik, Aritmolab o repository esterni.
trasporto. Il proprietario del progetto è accountable per coordinare la rotazione. Il meccanismo
target è il servizio server-only `dwh-auth`, indipendente dallo stack ThothII, con registro a file
e una chiave revocabile per installazione.
- Blockers: il piano eseguibile attende la revisione del proprietario; mancano ancora la
sorgente protetta per importare la chiave legacy, la procedura realizzata di aggiornamento e
verifica del Mac, la documentazione TLS implementata, l'autorizzazione ai due gate di mutazione
e la revoca provata della vecchia chiave.
- Next step: revisionare il piano eseguibile e scegliere tra esecuzione subagent-driven o inline.
Le Task 1–8 non mutano il server; le Task 9–10 richiedono due autorizzazioni esplicite separate.
- Owner amendment 2026-08-21: Gate A e dual-key Gate B sono eseguiti; il Mac live test, le 48 ore
comprendenti due cicli ETL delle 03:00 e la revoca di `legacy-shared` sono rinviati al gate
obbligatorio prima di Project B. Il rinvio non equivale a PASS.
- Blockers: per chiudere Activity 1 restano il collaudo Mac, l'osservazione completa, la revoca,
v1 positivo post-revoca e legacy `401`.
- Next step: continuare Activity 2–10 per lo scope Project A privato; riaprire Activity 1 prima di
congelare il candidato Project B.
## Activity 2: Identify accountable owners for shared components
- Status: `PENDING`
- Status: `IN_DISCUSSION`
- Accountable owner: Unassigned
- Objective: associare ogni componente condiviso a una persona o a un team con autorità di lettura,
modifica, approvazione e rollback.
@@ -185,11 +187,12 @@ Authentik, Aritmolab o repository esterni.
- Discussion notes: Not discussed
- Decision: No decision recorded
- Blockers: nessun owner condiviso è stato ancora formalmente confermato.
- Next step: compilare la matrice owner/componente dopo la chiusura dell'Activity 1.
- Next step: compilare ora la matrice distinguendo componenti necessari a Project A privato e
componenti shared/pubblici rinviabili a Project B.
## Activity 3: Resolve the authoritative public origin
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: scegliere sulla base di evidenze l'unica origine pubblica finale tra il dominio `.it`
osservato e il dominio `.com` riportato nel piano.
@@ -209,7 +212,7 @@ Authentik, Aritmolab o repository esterni.
## Activity 4: Establish the load-balancer contract
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: documentare il confine effettivo del load balancer e la procedura reversibile per le
route temporanea e finale.
@@ -230,7 +233,7 @@ Authentik, Aritmolab o repository esterni.
## Activity 5: Provide protected read-only Authentik survey access
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: permettere un inventario Authentik bounded e read-only della versione installata.
- Why this is required: applicazioni, provider, flow, mapping, gruppi, service account, permessi API
@@ -250,7 +253,7 @@ Authentik, Aritmolab o repository esterni.
## Activity 6: Provide protected catalog-only PostgreSQL survey access
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: verificare database, schemi, ruoli, grant, migrazioni e PostgREST con sole query di
catalogo.
@@ -265,14 +268,22 @@ Authentik, Aritmolab o repository esterni.
6. registrare TLS/CA, backup e convenzioni per ruoli migrator/runtime.
- Required redacted evidence: risultati catalogici bounded, nomi dei ruoli, attributi e grant,
schemi PostgREST, riferimento a backup e TLS; nessuna stringa di connessione.
- Discussion notes: Not discussed
- Decision: No decision recorded
- Blockers: non esiste ancora un meccanismo psql approvato post-rotazione.
- Next step: far predisporre dal DBA l'accesso catalog-only.
- Discussion notes: il wrapper ETL `ConnectionFactory` ha aperto una sessione dichiarata
read-only e ha eseguito sole query aggregate a `pg_catalog`. Il database è PostgreSQL 15.8;
l'identità disponibile è `postgres`, owner dello schema `datawarehouse`, con `USAGE` e
`CREATE`. Su tutte le 163 relazioni catalogate possiede SELECT e anche tutti i privilegi di
scrittura/DDL tabellari verificati. Nessun nome tabella o dato clinico è stato raccolto.
- Decision: il meccanismo esistente è valido per il survey catalogico, ma è vietato come identità
runtime del nuovo core perché non è least-privilege né read-only.
- Blockers: il DBA deve fornire un ruolo dedicato con soli USAGE/SELECT e una route diretta
certificabile dal nuovo core. Il PostgREST DWH è loopback host su 127.0.0.1:3001 e non prova il
percorso PostgreSQL diretto richiesto da Project A.
- Next step: definire con il DBA ruolo, secret-file protetto, TLS/rete e query di grant da ripetere;
non creare il ruolo durante il survey.
## Activity 7: Prove legacy backup and rollback
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: dimostrare che il vecchio ThothII possa essere preservato e ripristinato prima di
qualsiasi stop.
@@ -287,14 +298,26 @@ Authentik, Aritmolab o repository esterni.
6. eseguire il backup soltanto nella successiva fase autorizzata, prima dello stop.
- Required redacted evidence: inventario, percorso backup, checksum, owner, restart recipe e
rollback route; nessun contenuto di secret.
- Discussion notes: il legacy stack è ancora attivo e invariato.
- Decision: No decision recorded
- Blockers: lifecycle supportato, backup owner e comandi esatti non stabiliti.
- Next step: approvare la procedura senza eseguirla durante la discussione.
- Discussion notes: il legacy stack è ancora attivo e invariato. Compose project `thothii` usa
`/home/chirone/ThothII/compose.yaml`; i servizi sono `core` e `frontend`, senza named volume.
Il solo bind applicativo RW è `/home/chirone/thothii-data` (con i bind Pi annidati); Evidence è
un bind RO esterno. Una lettura tar verso `/dev/null` di source e data ha dato
`legacy_backup_readability=PASS`. Il source è circa 1.05 GB e il data bind circa 1.9 MB.
I dry-run Compose passano solo fornendo il path non segreto
`PI_AUTH_FILE=/home/chirone/thothii-data/pi-config/agent/auth.json` insieme a
`--env-file deploy/thothii.env -p thothii -f compose.yaml`; stop individua entrambi i container
e start è sintatticamente valido (non trova container arrestati mentre lo stack è ancora attivo).
- Decision: il controller e le radici da archiviare sono identificati; nessun backup o stop è stato
eseguito. Per un rollback normale i container restano esistenti e il controller usa `start`.
- Blockers: scegliere/approvare la destinazione protetta, creare il backup con manifest/checksum,
verificare la leggibilità dell'archivio, definire la gestione della route durante lo stop e
ottenere il consenso separato prima di eseguire stop/start.
- Next step: approvare manifest, destinazione e comandi; eseguire backup e checksum soltanto nel
successivo gate di mutazione.
## Activity 8: Provide read-only PSD workspace Git access
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: verificare il repository remoto condiviso e il suo stato corrente dal server senza
capacità di push.
@@ -315,7 +338,7 @@ Authentik, Aritmolab o repository esterni.
## Activity 9: Make Pi and LLM metadata verifiable
- Status: `PENDING`
- Status: `BLOCKED`
- Accountable owner: Unassigned
- Objective: verificare versione Pi, provider, modello, thinking level, riferimento credenziale e
reachability LLM senza esporre il secret.
@@ -330,10 +353,51 @@ Authentik, Aritmolab o repository esterni.
- Required redacted evidence: versione, provider, model ID, thinking level, endpoint sanitizzato,
percorso/mode della credenziale e risultato di reachability.
- Discussion notes: host `x86_64`; due GPU NVIDIA osservate, ma `nvidia-smi` non è utilizzabile per
mismatch driver/libreria NVML. Il deployment CPU resta da valutare con le immagini pinned.
- Decision: No decision recorded
- Blockers: configurazione Pi protetta non leggibile e nessun endpoint LLM credential-free noto.
- Next step: ottenere un controllo assistito o permessi read-only mirati.
mismatch driver/libreria NVML. Una lettura whitelist di `settings.json` ha rilevato Pi 0.80.3,
provider `deepseek`, modello `deepseek-v4-pro` e thinking `high`, senza leggere
`auth.json`. Un singolo probe senza tool, contesto o sessione ha prodotto solo
`pi_reachability=FAIL`. Il catalogo custom dichiara inoltre il solo provider `local-qwen`.
- Decision: i metadati sono verificati, ma reachability e coerenza default/catalogo non passano.
- Blockers: diagnosticare il FAIL senza esporre la credenziale e confermare il provider/modello
approvato per Project A; il mismatch NVML/GPU resta rischio separato, non un motivo per assumere
che il percorso CPU funzioni.
- Next step: eseguire un controllo assistito e sanitizzato della configurazione provider, quindi
ripetere una sola reachability probe bounded.
## Read-only resume — 2026-08-21
- Host/source: Linux x86_64, Docker 29.1.1, Compose 2.40.3, application worktree clean at
`7118950416b3008a8182825de027c7f8b235de57`; Qdrant/Ollama images are local, while the required
embedding image/model is not yet proved local.
- Capacity: approximately 1.1 TB free on `/home` and 36 GB on `/`; several loopback candidate
ports are currently free. These facts do not reserve a path or port.
- Legacy: project `thothii` is still running and unchanged. Source is
`/home/chirone/ThothII` at `6ca4275`; the only RW application bind is
`/home/chirone/thothii-data`, plus the nested Pi binds. The source is about 1.05 GB and the data
bind about 1.9 MB. No backup was created.
- Recovery evidence: existing containers can be inventoried for a stopped-container restart, but
backup destination, checksum/restore procedure and route ordering are not yet approved.
- Identity collision: legacy data and protected subtrees are numerically owned by UID/GID 10001.
The example in `docs/install/server.md` and the Project A Pi preparation use UID 10001 for the
new service. Do not create that host
identity or grant it access until a reviewed isolation/ownership strategy is approved.
- Candidate paths: documented examples `/srv/thothii` and `/srv/thothii-backups` are absent and
therefore only candidates; they have not been created. `127.0.0.1:18080` è il candidato
frontend e risultava libero al momento del survey, ma non è riservato e va ricontrollato prima
dello start. Existing `/home/chirone/thothii-data` must not be reused.
- Workspace: the canonical private remote is documented as
`git@github.com:mptyl/tht-workspace-psd.git`; a non-interactive read-only remote query resolved
`main` at `bfbabf9f2defcf861a3225296eaff8c6d44c0ac9`. No server checkout or dedicated deploy-key
reference is present at the documented local paths, and the credential's inability to push is
not yet proved.
- Pi/LLM: legacy Pi version `0.80.3` is visible, but provider/model/thinking/credential reference
and bounded reachability remain unknown.
- Shared scope: `.it` resolves locally and `.com` does not, Nginx is valid/active, Authentik
2026.2.1 and Supabase components are running. Owner, LB contract, Authentik inventory and
PostgreSQL catalog grants remain unproved and are not inferred.
- Decision: `SURVEY_NO_GO` for Project A private remains. The bounded work authorized now is
limited to planning/static preparation; no source clone, protected tree, backup, stop or start
has been performed.
## Activity 10: Retain evidence and run the missing bounded survey checks
@@ -357,20 +421,28 @@ Authentik, Aritmolab o repository esterni.
- Blockers: dipende dalla chiusura delle Activity 1–9 e dall'approvazione del retention root.
- Next step: avviare soltanto dopo la chiusura dei blocker precedenti.
## Fresh survey and owner gate
## Fresh survey and owner gates
Un nuovo `SURVEY_GO` richiede contemporaneamente:
Un nuovo `SURVEY_GO_PROJECT_A_PRIVATE` richiede:
- credenziale DWH precedente revocata e rotazione verificata;
- owner e autorità di modifica/rollback identificati;
- origine pubblica unica e load-balancer contract provati;
- accessi read-only Authentik, PostgreSQL, workspace Git e Pi/LLM verificati;
- owner e autorità di backup/stop/start/rollback identificati per il legacy e Project A;
- accessi read-only PostgreSQL, workspace Git e Pi/LLM verificati;
- identità DWH dimostrata read-only;
- backup e restart recipe legacy verificabili;
- risorse e percorsi della nuova installazione approvati;
- report redatto, secret-scan valido e checksum verificato;
- approvazione esplicita del proprietario.
`SURVEY_GO_PROJECT_B` richiede inoltre:
- collaudo Mac `rest_api` con chiave per installazione;
- 48 ore di osservazione comprendenti due cicli ETL delle 03:00;
- credenziale `legacy-shared` revocata, v1 positiva e legacy `401`;
- owner e autorità di modifica/rollback per tutti i componenti shared;
- origine pubblica unica e load-balancer contract provati;
- accesso read-only Authentik e inventario della release installata;
- ogni altro blocker pubblico/shared delle Activity 2–9 chiuso.
Il PASS tecnico del survey non autorizza automaticamente Project A. L'autorizzazione deve essere
registrata separatamente.
@@ -379,3 +451,4 @@ registrata separatamente.
| Data | Attività | Modifica | Autore |
|---|---|---|---|
| 2026-08-20 | Initial | Creata checklist; Activity 1 aperta, Activity 2–10 pending | Sol |
| 2026-08-21 | Sequencing amendment | Activity 1 deferred pre-B; survey ripreso read-only; Project A private resta NO-GO | Owner/Sol |
@@ -4,6 +4,11 @@
**Status:** Approved by the owner
**Owner sequencing amendment (2026-08-21):** the Mac `rest_api` acceptance and revocation of
`legacy-shared` are deferred to one mandatory pre-Project-B gate. This permits the bounded survey
and static, non-mutating Project A private preparation to proceed without changing the Mac. It does not
authorize stopping the legacy stack, starting the new stack, opening ingress, or beginning Project B.
**Design-time application baseline:** `main` at `5c0dc8c` (execution must freeze and record the
then-current `origin/main` SHA)
@@ -70,10 +75,14 @@ The program consists of one non-mutating common survey followed by two independe
projects:
```text
Common Survey PASS
Common Survey PASS for Project A private scope
-> Project A automated PASS
-> Project A human PASS
-> explicit authorization
-> Mac REST acceptance
-> 48-hour dual-key observation covering two 03:00 ETL cycles
-> legacy-shared revocation and negative proof
-> full pre-Project-B survey PASS
-> explicit Project B authorization
-> Project B automated PASS
-> Project B human PASS
-> final cutover acceptance
@@ -136,7 +145,8 @@ proved safe.
1. Freeze exact application and workspace SHAs and require clean source trees.
2. Publish and validate the multi-transport `psd-clinical` descriptor through the curator workflow.
3. Prove the Mac installation still selects REST and remains valid.
3. Preserve the Mac REST binding unchanged; its live acceptance is deferred to the mandatory
pre-Project-B gate.
4. Prepare the new source clone and protected operator/runtime directories beside the old source.
5. Extract only approved configuration facts from the legacy installation.
6. Create and verify backups and a restart recipe for the legacy stack.
@@ -182,12 +192,17 @@ Project A requires:
- optional private-route positive and negative isolation evidence when that route is used;
- completed human manual-test report with an explicit PASS.
The Mac row may be recorded only as `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. It is
not part of the private server acceptance, but it must become PASS before Project B starts.
Project A does not modify the production Aritmolab sidebar, production public route, or Authentik.
## Project B — Authentik and Aritmolab Integration
Project B begins only from the frozen, accepted Project A source, images, workspace revision, and
PASS report.
PASS report. It also requires the deferred Mac REST acceptance, the full 48-hour observation
window (including two scheduled 03:00 ETL cycles), revocation of `legacy-shared`, proof that the
legacy credential receives `401`, and the full pre-Project-B survey gate.
### Final request and data flow
@@ -46,6 +46,21 @@ a credential must read a protected file or use an echo-free prompt.
The detailed evidence directory is a protected path on the server selected during the survey. The
repository receives only redacted reports after explicit owner review.
## Owner-approved sequencing amendment — 2026-08-21
The Mac `rest_api` acceptance and revocation of `legacy-shared` move to a mandatory gate immediately
before Project B. The survey therefore records two distinct decisions:
- `SURVEY_GO_PROJECT_A_PRIVATE`: technical prerequisite for requesting Project A private execution;
- `SURVEY_GO_PROJECT_B`: the complete shared-infrastructure decision, including Mac acceptance,
observation and legacy revocation.
The amendment authorizes the read-only survey and static preparation of non-secret Project A
candidate facts and artifacts. While the current decision is `SURVEY_NO_GO`, it does not authorize
creating installation roots, cloning/building the candidate, creating protected configuration or
backup state, stopping the legacy stack, starting the new stack, changing public ingress, or
starting Project B. Those remain separate explicit gates after the scoped survey passes.
### Task 1: Freeze the planning source
**Files:**
@@ -100,10 +115,13 @@ load balancer, Aritmolab, Authentik, Supabase, the DWH, and protected credential
If an Authentik credential cannot be located, stop and ask the owner. If a configuration owner or
rollback boundary is unclear, stop; do not infer authority from file readability.
**Step 3: Review the survey GO/NO-GO**
**Step 3: Review the scoped survey GO/NO-GO**
Expected: GO requires a verified old-stack recovery path, a new-installation root, enough resources,
a read-only DWH path, and no unresolved shared-infrastructure mutation.
Expected: `SURVEY_GO_PROJECT_A_PRIVATE` requires a verified old-stack recovery path, an approved
new-installation root, enough resources, a direct read-only DWH path, workspace/model inputs, and
no unresolved mutation in the private Project A scope. Public-origin, load-balancer and Authentik
unknowns may remain explicitly deferred only while Project A is loopback-only and Task 10 is
omitted. `SURVEY_GO_PROJECT_B` retains the complete survey requirements.
**Step 4: Checkpoint the survey**
@@ -115,9 +133,10 @@ Hash the protected report and record only its path, SHA-256, timestamp, and GO r
- Execute: `docs/plans/2026-08-20-psd-server-project-a-standalone.md`
- Complete: `docs/testing/evidence/psd-server-project-a-report-template.md`
**Step 1: Confirm the survey is GO**
**Step 1: Confirm the survey is GO for Project A private scope**
Expected: the survey report hash matches the journal and no unresolved blocker remains.
Expected: the survey report hash matches the journal and no unresolved blocker remains inside the
Project A private scope. Before any stop/start, obtain a separate explicit owner authorization.
**Step 2: Execute Project A task-by-task**
@@ -126,12 +145,14 @@ Do not configure Authentik, change the production Aritmolab sidebar, or open the
**Step 3: Run the Project A human guide**
Follow `docs/testing/psd-server-project-a-manual.md`. Record PASS/FAIL for every case; do not infer
manual PASS from automated output.
manual PASS from automated output. The Mac REST row may be
`DEFERRED_PRE_PROJECT_B` only under the dated owner amendment.
**Step 4: Close the Project A report**
Expected: automated gates and the human guide are PASS; one harmless PSD session reached F8 and
produced validated read-only SQL; rollback remains available.
produced validated read-only SQL; rollback remains available. The accepted report must list the
Mac REST item as an explicit deferred prerequisite rather than silently treating it as PASS.
**Step 5: Obtain explicit owner approval**
@@ -145,6 +166,10 @@ Record the approval and report digest. Project B remains forbidden without it.
**Step 1: Recheck source and running images**
Before freezing the candidate, close the pre-Project-B gate: validate the Mac installation with its
per-installation key, finish the 48-hour observation window including two 03:00 ETL cycles, revoke
`legacy-shared`, prove legacy `401` and v1 success, and obtain `SURVEY_GO_PROJECT_B`.
Run the Project A plan's identity commands again. Record application SHA, workspace SHA, core image
ID, frontend image ID, Qdrant image digest, Ollama image digest, and local-auth configuration revision.
@@ -12,13 +12,16 @@
## Preconditions
- Common survey result is GO and its digest is recorded.
- Common survey result is `SURVEY_GO_PROJECT_A_PRIVATE` and its digest is recorded.
- Every path below is replaced by the exact survey result before execution.
- No production Nginx/load-balancer/sidebar/Authentik change is in scope.
- The old stack remains running only until backup verification finishes; old and new stacks never
run together.
- The server's workspace deploy credential remains read-only. A curator with write access publishes
the workspace change.
- Owner amendment 2026-08-21 defers live Mac `rest_api` acceptance and `legacy-shared` revocation to
the mandatory pre-Project-B gate. It does not authorize stop/start; those require a later explicit
owner gate even after private preparation is complete.
### Task 1: Freeze exact inputs
@@ -121,11 +124,11 @@ git push --set-upstream origin codex/psd-direct-transport
Merge through the repository's normal review path. Record the resulting `main` SHA.
**Step 6: Prove the Mac REST installation is unchanged**
**Step 6: Record the deferred Mac REST proof**
The owner pulls/activates the new workspace commit on the Mac, confirms selected transport
`rest_api`, runs workspace inspection/connection diagnostics, and records PASS. Project A server
deployment stops if this cross-installation proof is not available.
Do not change the Mac during Project A. Record `DEFERRED_PRE_PROJECT_B`, the unchanged expected
transport `rest_api`, and the exact future diagnostics. The proof must become PASS before Project B,
after protected delivery/configuration of the per-installation key.
### Task 3: Back up and stop the legacy installation
@@ -416,6 +419,11 @@ remembered-session survival after core restart. Do not retain cookie jars after
### Task 10: Optionally add the private network-path test
**Current scope boundary (owner, 2026-08-21):** omit this entire task and keep Project A
loopback-only. Any future use requires a separate shared-infrastructure authorization after the
public-origin and load-balancer activities pass; the Project A private survey decision alone is
insufficient.
**Files:**
- Modify only surveyed test-specific load-balancer/Nginx files
- Create: test certificate through the existing managed mechanism
@@ -487,12 +495,14 @@ secrets in the ordinary evidence archive.
**Step 3: Complete human acceptance**
Every row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly blocking.
Every private-server row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly
blocking. Only the Mac REST row may be `DEFERRED_PRE_PROJECT_B` under the dated owner amendment.
**Step 4: Record the gate**
Record exact SHAs/images, workspace revision, preprocessing identity/counts, session ID, report
digest, rollback status, and explicit `PROJECT_A_PASS` or `PROJECT_A_FAIL`.
digest, rollback status, and explicit `PROJECT_A_PRIVATE_PASS` or `PROJECT_A_FAIL`. A private PASS
does not authorize Project B while the deferred gate remains open.
**Step 5: Stop on FAIL**
@@ -13,6 +13,11 @@
## Preconditions
- Project A automated and human reports are PASS and explicitly owner-approved.
- The Mac `rest_api` installation passes source validation and connection diagnostics with its
per-installation key.
- The dual-key observation has lasted at least 48 hours and includes two scheduled 03:00 ETL cycles.
- `legacy-shared` is revoked; v1 remains successful and the legacy credential is proven `401`.
- The current survey decision is `SURVEY_GO_PROJECT_B`, not only the private Project A decision.
- Application SHA, workspace SHA, images, Project A report digest, and rollback configuration match
the accepted evidence.
- The production route is closed before authentication/session-storage changes.
+7 -3
View File
@@ -290,10 +290,14 @@ ThothII, and core → Supabase DWH/auth session schema/Qdrant/Ollama/LLM/Authent
Separate files owned by the new ThothII installation, workspace curator, Nginx, load balancer,
Aritmolab, Authentik, and Supabase. Mark shared files as owner-gated.
**Step 3: State GO or NO-GO**
**Step 3: State the scoped GO or NO-GO decisions**
GO requires all mandatory paths, permissions, backup owners, and rollback boundaries. NO-GO must
name concrete missing facts and the person/system needed to resolve them.
State both `SURVEY_GO_PROJECT_A_PRIVATE` and `SURVEY_GO_PROJECT_B`. The private decision requires
all paths, permissions, backup owners and rollback boundaries used by Project A; it may defer
public-origin, load-balancer, Authentik and Mac REST closeout facts that Project A does not mutate.
The Project B decision requires every shared/public fact plus the Mac acceptance, completed
observation window and revoked legacy credential. Each NO-GO must name concrete missing facts and
the person/system needed to resolve them.
**Step 4: Hash and retain the report**
@@ -6,7 +6,7 @@
## Decision
- Result: `PROJECT_A_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING`
- Result: `PROJECT_A_PRIVATE_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING`
- Decision timestamp UTC:
- Owner/reviewer:
- Protected evidence path:
@@ -18,7 +18,7 @@
- Plan source SHA:
- Workspace previous SHA:
- Workspace multi-transport SHA:
- Mac REST validation result/evidence reference:
- Mac REST validation result/evidence reference: `DEFERRED_PRE_PROJECT_B`
- Native `tht` version/build identity:
- Core image ID/digest:
- Frontend image ID/digest:
@@ -63,7 +63,7 @@
- Workspace ID/revision:
- Server transport: postgres_direct
- Mac transport remains rest_api: PASS/FAIL
- Mac transport remains rest_api: `DEFERRED_PRE_PROJECT_B`
- Supabase database name:
- DWH schema: datawarehouse
- Read-only role proof reference:
@@ -95,4 +95,5 @@
- Legacy rollback remains available:
- Secret scan result:
- Unrelated failures or pending items:
- Pre-Project-B blockers: Mac validation, 48-hour/two-ETL observation, legacy revocation
- Reason for final decision:
@@ -13,6 +13,10 @@
- Protected evidence path:
- Evidence manifest SHA-256:
- Accepted Project A report digest:
- Mac `rest_api` acceptance evidence:
- Dual-key observation interval and two 03:00 ETL-cycle evidence:
- `legacy-shared` revocation evidence (v1 success, legacy `401`):
- `SURVEY_GO_PROJECT_B` report digest:
## Frozen candidate
@@ -6,12 +6,13 @@
## Decision
- Result: `SURVEY_GO` / `SURVEY_NO_GO`
- Project A private result: `SURVEY_GO_PROJECT_A_PRIVATE` / `SURVEY_NO_GO`
- Project B result: `SURVEY_GO_PROJECT_B` / `SURVEY_NO_GO`
- Timestamp UTC:
- Operator:
- Protected evidence path:
- Report SHA-256:
- Blocking unknowns:
- Blocking unknowns by scope:
## Host
+7 -3
View File
@@ -103,11 +103,15 @@ Eseguire:
| Trasporto server | `postgres_direct` | | |
| Database/schema | database Supabase rilevato, schema `datawarehouse` | | |
| Utente DWH | read-only dimostrato dai grant | | |
| Workspace Mac | prova separata conferma ancora `rest_api` | | |
| Workspace Mac | `DEFERRED_PRE_PROJECT_B`; in quel gate deve confermare `rest_api` | | |
| Qdrant | 1024 dimensioni, cosine, indici payload richiesti | | |
| Ollama | `qwen3-embedding:0.6b` | | |
| Evidence | corpus Git attivo alla stessa revisione | | |
Per l'emendamento del proprietario del 2026-08-21, solo la riga Workspace Mac può restare
`DEFERRED_PRE_PROJECT_B` nella chiusura privata di Project A. Non equivale a PASS e deve essere
eseguita prima di Project B insieme all'osservazione dual-key e alla revoca legacy.
## 5. Preprocessing e idempotenza
Esaminare i due risultati consecutivi del preprocessing prodotti da Sol.
@@ -157,9 +161,9 @@ Verificare infine:
| Tutti i controlli obbligatori PASS | |
| Nessun secret raccolto | |
| Rollback vecchio stack ancora disponibile | |
| Progetto B autorizzabile | |
| Progetto B autorizzabile | NO finché il gate Mac/osservazione/revoca non è PASS |
Decisione finale: `PROJECT_A_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING`
Decisione finale: `PROJECT_A_PRIVATE_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING`
Revisore e data: ______________________________________