diff --git a/PROJECT_STATE.md b/PROJECT_STATE.md index 5f5fd6a5..94df1def 100644 --- a/PROJECT_STATE.md +++ b/PROJECT_STATE.md @@ -7,9 +7,10 @@ > ThothII per il repository (app + CLI `tht`), (3) come usare l'applicazione ThothII di base > (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici > resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato. -> Last updated: 2026-08-20 (PSD server replacement and Authentik-integration program designed; -> executable survey, two gated project plans, human-test guides, and evidence templates prepared; -> no server mutation has been executed). +> Last updated: 2026-08-21 (DWH per-installation authentication is active in dual-key mode; +> the owner deferred Mac acceptance and legacy revocation to the mandatory pre-Project-B gate, +> authorized the read-only survey and Project A private preparation, and did not authorize either +> stopping the legacy stack or starting the new stack). > Point a fresh session here ("read PROJECT_STATE.md") before substantial work. ### PSD server deployment program — design approved, execution PENDING (2026-08-20) @@ -38,8 +39,19 @@ balancer can prove an operator-only temporary endpoint. Project B preserves the real user flow `Aritmolab homepage -> sidebar -> load balancer -> Nginx -> ThothII`, with direct ThothII-managed OIDC and no second Nginx `auth_request`. -- **State:** survey `PENDING`; Project A `PENDING`; Project B `BLOCKED_BY_PROJECT_A`; server and - external repositories/services unchanged by this planning work. +- **State:** survey `SURVEY_NO_GO` for Project A private; Project A + `BLOCKED_BY_SURVEY_AND_MUTATION_GATE`; Project B `BLOCKED_BY_PROJECT_A_AND_PRE_B_GATE`. + Remaining private-scope blockers are legacy rollback/backup, approved installation paths and UID + strategy, dedicated read-only workspace access, a dedicated direct-DWH role/route, and Pi/LLM + metadata. The catalog-only survey proved the currently available `postgres` identity owns + `datawarehouse` and has full write/DDL privileges, so it must not be reused by the new core. + Pi metadata resolves to 0.80.3, `deepseek/deepseek-v4-pro`, thinking `high`, but the bounded + no-session/no-tool reachability probe is FAIL and must be diagnosed without exposing auth data. +- **Sequencing amendment (owner, 2026-08-21):** use two survey decisions. Project A private may + proceed only after `SURVEY_GO_PROJECT_A_PRIVATE` and a separate stop/start authorization. Mac + `rest_api` acceptance, the 48-hour/two-ETL observation, and revocation of `legacy-shared` are + mandatory before `SURVEY_GO_PROJECT_B`. Current authorization covers read-only survey and + preparation only; old-stack stop and new-stack start remain forbidden. ### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18) diff --git a/docs/operations/psd-dwh-auth-rollout.md b/docs/operations/psd-dwh-auth-rollout.md index 480ae90e..415c5e3e 100644 --- a/docs/operations/psd-dwh-auth-rollout.md +++ b/docs/operations/psd-dwh-auth-rollout.md @@ -1,6 +1,6 @@ # PSD — rollout controllato DWH REST -Questo runbook rispecchia i Task 9–10 del [piano](../superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md). È descrittivo: non autorizza mutazioni ora. Activity 1 PSD resta `IN_DISCUSSION` fino a due consensi espliciti separati. +Questo runbook rispecchia i Task 9–10 del [piano](../superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md). Gate A e la parte dual-key di Gate B sono stati eseguiti con autorizzazioni separate. L'emendamento del proprietario del 2026-08-21 rinvia collaudo Mac, osservazione e revoca a prima di Project B; non autorizza ulteriori mutazioni. ## Invarianti @@ -29,11 +29,15 @@ Serve un secondo consenso: presentare file, backup, canale consegna Mac, osserva 2. Aggiungere solo `/etc/nginx/conf.d/dwh-auth-rate-limit.conf` e route DWH; preservare upstream `http://127.0.0.1:3001/`, mantenere byte-identiche le location vector e rimuovere la chiave prima di PostgREST. 3. Eseguire checker strutturale, scansione segreti con solo `PASS/FAIL` e metadati, installare candidati e `sudo nginx -t`. No raw diff: non eseguire o conservare raw diff, `nginx -T` o dump: il file legacy può contenere la chiave. Se uno fallisce, ripristinare backup prima di reload e registrare FAIL sanitizzato. 4. Dopo consenso fare reload, poi HTTPS `.it` con CA e file header curl protetti 0600: v1=2xx, legacy=2xx, casuale=401, assente=401 su `/dwh/rpc/ping`; guasto autenticatore=503, mai accesso permissivo. -5. Consegnare al Mac chiave e CA separatamente, verificare fingerprint fuori banda, configurare vault GUI o `API_KEY_FILE`, poi **Validate workspace source** e **Test workspace connections**. -6. Dopo osservazione revocare `legacy-shared` con ragione `shared-credential-rotation`; v1=2xx post-revoca, legacy=401 post-revoca e journal limitato senza chiavi/digest. +5. **Deferred pre-Project-B:** consegnare al Mac chiave e CA separatamente, verificare fingerprint fuori banda, configurare vault GUI o `API_KEY_FILE`, poi **Validate workspace source** e **Test workspace connections**. +6. **Deferred pre-Project-B:** completare 48 ore di osservazione comprendenti due cicli ETL delle 03:00, quindi revocare `legacy-shared` con ragione `shared-credential-rotation`; v1=2xx post-revoca, legacy=401 post-revoca e journal limitato senza chiavi/digest. ## Rollback e chiusura Durante dual-key il rollback ripristina solo route/servizio revisionati, verifica `nginx -t` e fa reload autorizzato. Non ripristina chiavi revocate, PostgreSQL, dati legacy o stack. Scatta per TLS, risposte inattese, salute degradata o assenza di consenso. -Activity 1 diventa `PASS` solo con v1=2xx post-revoca, legacy=401 post-revoca, servizio/Nginx validi, log sanitizzati, rollback leggibile e accettazione owner; poi avanza a Activity 2, con programma ancora `SURVEY_NO_GO`. Compilare [evidenza](../testing/evidence/psd-dwh-auth-rollout-report-template.md) e [collaudo](../testing/dwh-auth-manual-acceptance.md). +Activity 1 resta `DEFERRED_PRE_PROJECT_B`: dual-key è attivo, ma PASS richiede ancora v1=2xx +post-revoca, legacy=401 post-revoca, servizio/Nginx validi, log sanitizzati, rollback leggibile e +accettazione owner. Il rinvio non blocca il survey e Project A privato; blocca Project B. Compilare +[evidenza](../testing/evidence/psd-dwh-auth-rollout-report-template.md) e +[collaudo](../testing/dwh-auth-manual-acceptance.md). diff --git a/docs/operations/psd-server-survey-remediation-checklist.md b/docs/operations/psd-server-survey-remediation-checklist.md index 32c30e5f..36de83d9 100644 --- a/docs/operations/psd-server-survey-remediation-checklist.md +++ b/docs/operations/psd-server-survey-remediation-checklist.md @@ -22,16 +22,17 @@ Authentik, Aritmolab o repository esterni. - Survey report: `/var/tmp/thothii-psd-survey.fJh7DS/survey-report.md` - Survey report SHA-256: `36461b6c7d1e44d055f24d6919e892b7017352ac9eb99ac67b9ae62f0614f8e7` - Legacy stack: deve restare acceso e invariato durante la discussione di questa lista -- Project A remains forbidden fino a un nuovo `SURVEY_GO` e all'approvazione esplicita del proprietario +- La preparazione statica di Project A privato è autorizzata; stop del legacy e start del nuovo + restano vietati fino a `SURVEY_GO_PROJECT_A_PRIVATE` e a un consenso di mutazione separato - Project B remains forbidden fino ai PASS automatico, umano e del proprietario per Project A ## Current activity and resume point -- Current activity: `1` -- Title: Rotate or revoke the exposed DWH credential safely -- Resume from: Activity 1, review the approved implementation plan and choose its execution mode +- Current activity: `2` +- Title: Identify accountable owners for the private Project A scope +- Resume from: Activity 2, assign owner/authority for legacy rollback, direct DWH, workspace and Pi/LLM - Discussion rule: una sola attività può essere `IN_DISCUSSION` -- Allowed states: `PENDING`, `IN_DISCUSSION`, `BLOCKED`, `PASS` +- Allowed states: `PENDING`, `IN_DISCUSSION`, `DEFERRED_PRE_PROJECT_B`, `BLOCKED`, `PASS` ## How to use this checklist @@ -51,20 +52,20 @@ Authentik, Aritmolab o repository esterni. | ID | Attività | Stato | Responsabile | Prossimo gate | |---|---|---|---|---| -| 1 | Rotazione controllata della credenziale DWH esposta | `IN_DISCUSSION` | Proprietario del progetto | Revisionare il piano eseguibile e scegliere l’esecuzione | -| 2 | Assegnazione dei responsabili dei componenti condivisi | `PENDING` | Unassigned | Elenco owner confermato | -| 3 | Risoluzione del dominio pubblico `.it` oppure `.com` | `PENDING` | Unassigned | Origine autorevole documentata | -| 4 | Topologia e responsabilità del load balancer | `PENDING` | Unassigned | Route, health, TLS, rollback e allowlist verificati | -| 5 | Accesso read-only protetto ad Authentik | `PENDING` | Unassigned | Inventario API autorizzato e redatto | -| 6 | Accesso catalog-only protetto a PostgreSQL | `PENDING` | Unassigned | Catalogo, grant e PostgREST verificati | -| 7 | Backup e rollback del vecchio ThothII | `PENDING` | Unassigned | Backup verificabile e restart recipe completa | -| 8 | Accesso Git read-only al workspace PSD | `PENDING` | Unassigned | SHA, descriptor e deploy key verificati | -| 9 | Metadati Pi e LLM verificabili | `PENDING` | Unassigned | Versione, policy e reachability redatte | +| 1 | Rotazione controllata della credenziale DWH esposta | `DEFERRED_PRE_PROJECT_B` | Proprietario del progetto | Chiusura obbligatoria prima di Project B | +| 2 | Assegnazione dei responsabili dei componenti condivisi | `IN_DISCUSSION` | Proprietario del progetto | Owner privati A e shared B distinti | +| 3 | Risoluzione del dominio pubblico `.it` oppure `.com` | `BLOCKED` | Unassigned | Necessario per Project B, non per A privato | +| 4 | Topologia e responsabilità del load balancer | `BLOCKED` | Unassigned | Necessario per Project B/route opzionale | +| 5 | Accesso read-only protetto ad Authentik | `BLOCKED` | Unassigned | Necessario per Project B, non per A privato | +| 6 | Accesso catalog-only protetto a PostgreSQL | `BLOCKED` | Unassigned | DWH direct read-only ancora da provare | +| 7 | Backup e rollback del vecchio ThothII | `BLOCKED` | Proprietario del progetto | Procedura e destinazione da approvare | +| 8 | Accesso Git read-only al workspace PSD | `BLOCKED` | Curator da confermare | Checkout/deploy key server mancanti | +| 9 | Metadati Pi e LLM verificabili | `BLOCKED` | Unassigned | Policy e reachability redatte mancanti | | 10 | Conservazione evidenze e nuovo survey bounded | `PENDING` | Unassigned | Nuovo report e decisione proprietario | ## Activity 1: Rotate or revoke the exposed DWH credential safely -- Status: `IN_DISCUSSION` +- Status: `DEFERRED_PRE_PROJECT_B` - Accountable owner: Proprietario del progetto (confermato dall'utente) - Objective: sostituire o revocare in modo controllato la credenziale DWH comparsa nell'output interno del survey, senza interrompere consumer legittimi e senza esporne nuovamente il valore. @@ -161,16 +162,17 @@ Authentik, Aritmolab o repository esterni. trasporto. Il proprietario del progetto è accountable per coordinare la rotazione. Il meccanismo target è il servizio server-only `dwh-auth`, indipendente dallo stack ThothII, con registro a file e una chiave revocabile per installazione. -- Blockers: il piano eseguibile attende la revisione del proprietario; mancano ancora la - sorgente protetta per importare la chiave legacy, la procedura realizzata di aggiornamento e - verifica del Mac, la documentazione TLS implementata, l'autorizzazione ai due gate di mutazione - e la revoca provata della vecchia chiave. -- Next step: revisionare il piano eseguibile e scegliere tra esecuzione subagent-driven o inline. - Le Task 1–8 non mutano il server; le Task 9–10 richiedono due autorizzazioni esplicite separate. +- Owner amendment 2026-08-21: Gate A e dual-key Gate B sono eseguiti; il Mac live test, le 48 ore + comprendenti due cicli ETL delle 03:00 e la revoca di `legacy-shared` sono rinviati al gate + obbligatorio prima di Project B. Il rinvio non equivale a PASS. +- Blockers: per chiudere Activity 1 restano il collaudo Mac, l'osservazione completa, la revoca, + v1 positivo post-revoca e legacy `401`. +- Next step: continuare Activity 2–10 per lo scope Project A privato; riaprire Activity 1 prima di + congelare il candidato Project B. ## Activity 2: Identify accountable owners for shared components -- Status: `PENDING` +- Status: `IN_DISCUSSION` - Accountable owner: Unassigned - Objective: associare ogni componente condiviso a una persona o a un team con autorità di lettura, modifica, approvazione e rollback. @@ -185,11 +187,12 @@ Authentik, Aritmolab o repository esterni. - Discussion notes: Not discussed - Decision: No decision recorded - Blockers: nessun owner condiviso è stato ancora formalmente confermato. -- Next step: compilare la matrice owner/componente dopo la chiusura dell'Activity 1. +- Next step: compilare ora la matrice distinguendo componenti necessari a Project A privato e + componenti shared/pubblici rinviabili a Project B. ## Activity 3: Resolve the authoritative public origin -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: scegliere sulla base di evidenze l'unica origine pubblica finale tra il dominio `.it` osservato e il dominio `.com` riportato nel piano. @@ -209,7 +212,7 @@ Authentik, Aritmolab o repository esterni. ## Activity 4: Establish the load-balancer contract -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: documentare il confine effettivo del load balancer e la procedura reversibile per le route temporanea e finale. @@ -230,7 +233,7 @@ Authentik, Aritmolab o repository esterni. ## Activity 5: Provide protected read-only Authentik survey access -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: permettere un inventario Authentik bounded e read-only della versione installata. - Why this is required: applicazioni, provider, flow, mapping, gruppi, service account, permessi API @@ -250,7 +253,7 @@ Authentik, Aritmolab o repository esterni. ## Activity 6: Provide protected catalog-only PostgreSQL survey access -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: verificare database, schemi, ruoli, grant, migrazioni e PostgREST con sole query di catalogo. @@ -265,14 +268,22 @@ Authentik, Aritmolab o repository esterni. 6. registrare TLS/CA, backup e convenzioni per ruoli migrator/runtime. - Required redacted evidence: risultati catalogici bounded, nomi dei ruoli, attributi e grant, schemi PostgREST, riferimento a backup e TLS; nessuna stringa di connessione. -- Discussion notes: Not discussed -- Decision: No decision recorded -- Blockers: non esiste ancora un meccanismo psql approvato post-rotazione. -- Next step: far predisporre dal DBA l'accesso catalog-only. +- Discussion notes: il wrapper ETL `ConnectionFactory` ha aperto una sessione dichiarata + read-only e ha eseguito sole query aggregate a `pg_catalog`. Il database è PostgreSQL 15.8; + l'identità disponibile è `postgres`, owner dello schema `datawarehouse`, con `USAGE` e + `CREATE`. Su tutte le 163 relazioni catalogate possiede SELECT e anche tutti i privilegi di + scrittura/DDL tabellari verificati. Nessun nome tabella o dato clinico è stato raccolto. +- Decision: il meccanismo esistente è valido per il survey catalogico, ma è vietato come identità + runtime del nuovo core perché non è least-privilege né read-only. +- Blockers: il DBA deve fornire un ruolo dedicato con soli USAGE/SELECT e una route diretta + certificabile dal nuovo core. Il PostgREST DWH è loopback host su 127.0.0.1:3001 e non prova il + percorso PostgreSQL diretto richiesto da Project A. +- Next step: definire con il DBA ruolo, secret-file protetto, TLS/rete e query di grant da ripetere; + non creare il ruolo durante il survey. ## Activity 7: Prove legacy backup and rollback -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: dimostrare che il vecchio ThothII possa essere preservato e ripristinato prima di qualsiasi stop. @@ -287,14 +298,26 @@ Authentik, Aritmolab o repository esterni. 6. eseguire il backup soltanto nella successiva fase autorizzata, prima dello stop. - Required redacted evidence: inventario, percorso backup, checksum, owner, restart recipe e rollback route; nessun contenuto di secret. -- Discussion notes: il legacy stack è ancora attivo e invariato. -- Decision: No decision recorded -- Blockers: lifecycle supportato, backup owner e comandi esatti non stabiliti. -- Next step: approvare la procedura senza eseguirla durante la discussione. +- Discussion notes: il legacy stack è ancora attivo e invariato. Compose project `thothii` usa + `/home/chirone/ThothII/compose.yaml`; i servizi sono `core` e `frontend`, senza named volume. + Il solo bind applicativo RW è `/home/chirone/thothii-data` (con i bind Pi annidati); Evidence è + un bind RO esterno. Una lettura tar verso `/dev/null` di source e data ha dato + `legacy_backup_readability=PASS`. Il source è circa 1.05 GB e il data bind circa 1.9 MB. + I dry-run Compose passano solo fornendo il path non segreto + `PI_AUTH_FILE=/home/chirone/thothii-data/pi-config/agent/auth.json` insieme a + `--env-file deploy/thothii.env -p thothii -f compose.yaml`; stop individua entrambi i container + e start è sintatticamente valido (non trova container arrestati mentre lo stack è ancora attivo). +- Decision: il controller e le radici da archiviare sono identificati; nessun backup o stop è stato + eseguito. Per un rollback normale i container restano esistenti e il controller usa `start`. +- Blockers: scegliere/approvare la destinazione protetta, creare il backup con manifest/checksum, + verificare la leggibilità dell'archivio, definire la gestione della route durante lo stop e + ottenere il consenso separato prima di eseguire stop/start. +- Next step: approvare manifest, destinazione e comandi; eseguire backup e checksum soltanto nel + successivo gate di mutazione. ## Activity 8: Provide read-only PSD workspace Git access -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: verificare il repository remoto condiviso e il suo stato corrente dal server senza capacità di push. @@ -315,7 +338,7 @@ Authentik, Aritmolab o repository esterni. ## Activity 9: Make Pi and LLM metadata verifiable -- Status: `PENDING` +- Status: `BLOCKED` - Accountable owner: Unassigned - Objective: verificare versione Pi, provider, modello, thinking level, riferimento credenziale e reachability LLM senza esporre il secret. @@ -330,10 +353,51 @@ Authentik, Aritmolab o repository esterni. - Required redacted evidence: versione, provider, model ID, thinking level, endpoint sanitizzato, percorso/mode della credenziale e risultato di reachability. - Discussion notes: host `x86_64`; due GPU NVIDIA osservate, ma `nvidia-smi` non è utilizzabile per - mismatch driver/libreria NVML. Il deployment CPU resta da valutare con le immagini pinned. -- Decision: No decision recorded -- Blockers: configurazione Pi protetta non leggibile e nessun endpoint LLM credential-free noto. -- Next step: ottenere un controllo assistito o permessi read-only mirati. + mismatch driver/libreria NVML. Una lettura whitelist di `settings.json` ha rilevato Pi 0.80.3, + provider `deepseek`, modello `deepseek-v4-pro` e thinking `high`, senza leggere + `auth.json`. Un singolo probe senza tool, contesto o sessione ha prodotto solo + `pi_reachability=FAIL`. Il catalogo custom dichiara inoltre il solo provider `local-qwen`. +- Decision: i metadati sono verificati, ma reachability e coerenza default/catalogo non passano. +- Blockers: diagnosticare il FAIL senza esporre la credenziale e confermare il provider/modello + approvato per Project A; il mismatch NVML/GPU resta rischio separato, non un motivo per assumere + che il percorso CPU funzioni. +- Next step: eseguire un controllo assistito e sanitizzato della configurazione provider, quindi + ripetere una sola reachability probe bounded. + +## Read-only resume — 2026-08-21 + +- Host/source: Linux x86_64, Docker 29.1.1, Compose 2.40.3, application worktree clean at + `7118950416b3008a8182825de027c7f8b235de57`; Qdrant/Ollama images are local, while the required + embedding image/model is not yet proved local. +- Capacity: approximately 1.1 TB free on `/home` and 36 GB on `/`; several loopback candidate + ports are currently free. These facts do not reserve a path or port. +- Legacy: project `thothii` is still running and unchanged. Source is + `/home/chirone/ThothII` at `6ca4275`; the only RW application bind is + `/home/chirone/thothii-data`, plus the nested Pi binds. The source is about 1.05 GB and the data + bind about 1.9 MB. No backup was created. +- Recovery evidence: existing containers can be inventoried for a stopped-container restart, but + backup destination, checksum/restore procedure and route ordering are not yet approved. +- Identity collision: legacy data and protected subtrees are numerically owned by UID/GID 10001. + The example in `docs/install/server.md` and the Project A Pi preparation use UID 10001 for the + new service. Do not create that host + identity or grant it access until a reviewed isolation/ownership strategy is approved. +- Candidate paths: documented examples `/srv/thothii` and `/srv/thothii-backups` are absent and + therefore only candidates; they have not been created. `127.0.0.1:18080` è il candidato + frontend e risultava libero al momento del survey, ma non è riservato e va ricontrollato prima + dello start. Existing `/home/chirone/thothii-data` must not be reused. +- Workspace: the canonical private remote is documented as + `git@github.com:mptyl/tht-workspace-psd.git`; a non-interactive read-only remote query resolved + `main` at `bfbabf9f2defcf861a3225296eaff8c6d44c0ac9`. No server checkout or dedicated deploy-key + reference is present at the documented local paths, and the credential's inability to push is + not yet proved. +- Pi/LLM: legacy Pi version `0.80.3` is visible, but provider/model/thinking/credential reference + and bounded reachability remain unknown. +- Shared scope: `.it` resolves locally and `.com` does not, Nginx is valid/active, Authentik + 2026.2.1 and Supabase components are running. Owner, LB contract, Authentik inventory and + PostgreSQL catalog grants remain unproved and are not inferred. +- Decision: `SURVEY_NO_GO` for Project A private remains. The bounded work authorized now is + limited to planning/static preparation; no source clone, protected tree, backup, stop or start + has been performed. ## Activity 10: Retain evidence and run the missing bounded survey checks @@ -357,20 +421,28 @@ Authentik, Aritmolab o repository esterni. - Blockers: dipende dalla chiusura delle Activity 1–9 e dall'approvazione del retention root. - Next step: avviare soltanto dopo la chiusura dei blocker precedenti. -## Fresh survey and owner gate +## Fresh survey and owner gates -Un nuovo `SURVEY_GO` richiede contemporaneamente: +Un nuovo `SURVEY_GO_PROJECT_A_PRIVATE` richiede: -- credenziale DWH precedente revocata e rotazione verificata; -- owner e autorità di modifica/rollback identificati; -- origine pubblica unica e load-balancer contract provati; -- accessi read-only Authentik, PostgreSQL, workspace Git e Pi/LLM verificati; +- owner e autorità di backup/stop/start/rollback identificati per il legacy e Project A; +- accessi read-only PostgreSQL, workspace Git e Pi/LLM verificati; - identità DWH dimostrata read-only; - backup e restart recipe legacy verificabili; - risorse e percorsi della nuova installazione approvati; - report redatto, secret-scan valido e checksum verificato; - approvazione esplicita del proprietario. +`SURVEY_GO_PROJECT_B` richiede inoltre: + +- collaudo Mac `rest_api` con chiave per installazione; +- 48 ore di osservazione comprendenti due cicli ETL delle 03:00; +- credenziale `legacy-shared` revocata, v1 positiva e legacy `401`; +- owner e autorità di modifica/rollback per tutti i componenti shared; +- origine pubblica unica e load-balancer contract provati; +- accesso read-only Authentik e inventario della release installata; +- ogni altro blocker pubblico/shared delle Activity 2–9 chiuso. + Il PASS tecnico del survey non autorizza automaticamente Project A. L'autorizzazione deve essere registrata separatamente. @@ -379,3 +451,4 @@ registrata separatamente. | Data | Attività | Modifica | Autore | |---|---|---|---| | 2026-08-20 | Initial | Creata checklist; Activity 1 aperta, Activity 2–10 pending | Sol | +| 2026-08-21 | Sequencing amendment | Activity 1 deferred pre-B; survey ripreso read-only; Project A private resta NO-GO | Owner/Sol | diff --git a/docs/plans/2026-08-20-psd-server-deployment-program-design.md b/docs/plans/2026-08-20-psd-server-deployment-program-design.md index 190e8dfd..c7caa35f 100644 --- a/docs/plans/2026-08-20-psd-server-deployment-program-design.md +++ b/docs/plans/2026-08-20-psd-server-deployment-program-design.md @@ -4,6 +4,11 @@ **Status:** Approved by the owner +**Owner sequencing amendment (2026-08-21):** the Mac `rest_api` acceptance and revocation of +`legacy-shared` are deferred to one mandatory pre-Project-B gate. This permits the bounded survey +and static, non-mutating Project A private preparation to proceed without changing the Mac. It does not +authorize stopping the legacy stack, starting the new stack, opening ingress, or beginning Project B. + **Design-time application baseline:** `main` at `5c0dc8c` (execution must freeze and record the then-current `origin/main` SHA) @@ -70,10 +75,14 @@ The program consists of one non-mutating common survey followed by two independe projects: ```text -Common Survey PASS +Common Survey PASS for Project A private scope -> Project A automated PASS -> Project A human PASS - -> explicit authorization + -> Mac REST acceptance + -> 48-hour dual-key observation covering two 03:00 ETL cycles + -> legacy-shared revocation and negative proof + -> full pre-Project-B survey PASS + -> explicit Project B authorization -> Project B automated PASS -> Project B human PASS -> final cutover acceptance @@ -136,7 +145,8 @@ proved safe. 1. Freeze exact application and workspace SHAs and require clean source trees. 2. Publish and validate the multi-transport `psd-clinical` descriptor through the curator workflow. -3. Prove the Mac installation still selects REST and remains valid. +3. Preserve the Mac REST binding unchanged; its live acceptance is deferred to the mandatory + pre-Project-B gate. 4. Prepare the new source clone and protected operator/runtime directories beside the old source. 5. Extract only approved configuration facts from the legacy installation. 6. Create and verify backups and a restart recipe for the legacy stack. @@ -182,12 +192,17 @@ Project A requires: - optional private-route positive and negative isolation evidence when that route is used; - completed human manual-test report with an explicit PASS. +The Mac row may be recorded only as `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. It is +not part of the private server acceptance, but it must become PASS before Project B starts. + Project A does not modify the production Aritmolab sidebar, production public route, or Authentik. ## Project B — Authentik and Aritmolab Integration Project B begins only from the frozen, accepted Project A source, images, workspace revision, and -PASS report. +PASS report. It also requires the deferred Mac REST acceptance, the full 48-hour observation +window (including two scheduled 03:00 ETL cycles), revocation of `legacy-shared`, proof that the +legacy credential receives `401`, and the full pre-Project-B survey gate. ### Final request and data flow diff --git a/docs/plans/2026-08-20-psd-server-deployment-program.md b/docs/plans/2026-08-20-psd-server-deployment-program.md index e469e908..c8b5b692 100644 --- a/docs/plans/2026-08-20-psd-server-deployment-program.md +++ b/docs/plans/2026-08-20-psd-server-deployment-program.md @@ -46,6 +46,21 @@ a credential must read a protected file or use an echo-free prompt. The detailed evidence directory is a protected path on the server selected during the survey. The repository receives only redacted reports after explicit owner review. +## Owner-approved sequencing amendment — 2026-08-21 + +The Mac `rest_api` acceptance and revocation of `legacy-shared` move to a mandatory gate immediately +before Project B. The survey therefore records two distinct decisions: + +- `SURVEY_GO_PROJECT_A_PRIVATE`: technical prerequisite for requesting Project A private execution; +- `SURVEY_GO_PROJECT_B`: the complete shared-infrastructure decision, including Mac acceptance, + observation and legacy revocation. + +The amendment authorizes the read-only survey and static preparation of non-secret Project A +candidate facts and artifacts. While the current decision is `SURVEY_NO_GO`, it does not authorize +creating installation roots, cloning/building the candidate, creating protected configuration or +backup state, stopping the legacy stack, starting the new stack, changing public ingress, or +starting Project B. Those remain separate explicit gates after the scoped survey passes. + ### Task 1: Freeze the planning source **Files:** @@ -100,10 +115,13 @@ load balancer, Aritmolab, Authentik, Supabase, the DWH, and protected credential If an Authentik credential cannot be located, stop and ask the owner. If a configuration owner or rollback boundary is unclear, stop; do not infer authority from file readability. -**Step 3: Review the survey GO/NO-GO** +**Step 3: Review the scoped survey GO/NO-GO** -Expected: GO requires a verified old-stack recovery path, a new-installation root, enough resources, -a read-only DWH path, and no unresolved shared-infrastructure mutation. +Expected: `SURVEY_GO_PROJECT_A_PRIVATE` requires a verified old-stack recovery path, an approved +new-installation root, enough resources, a direct read-only DWH path, workspace/model inputs, and +no unresolved mutation in the private Project A scope. Public-origin, load-balancer and Authentik +unknowns may remain explicitly deferred only while Project A is loopback-only and Task 10 is +omitted. `SURVEY_GO_PROJECT_B` retains the complete survey requirements. **Step 4: Checkpoint the survey** @@ -115,9 +133,10 @@ Hash the protected report and record only its path, SHA-256, timestamp, and GO r - Execute: `docs/plans/2026-08-20-psd-server-project-a-standalone.md` - Complete: `docs/testing/evidence/psd-server-project-a-report-template.md` -**Step 1: Confirm the survey is GO** +**Step 1: Confirm the survey is GO for Project A private scope** -Expected: the survey report hash matches the journal and no unresolved blocker remains. +Expected: the survey report hash matches the journal and no unresolved blocker remains inside the +Project A private scope. Before any stop/start, obtain a separate explicit owner authorization. **Step 2: Execute Project A task-by-task** @@ -126,12 +145,14 @@ Do not configure Authentik, change the production Aritmolab sidebar, or open the **Step 3: Run the Project A human guide** Follow `docs/testing/psd-server-project-a-manual.md`. Record PASS/FAIL for every case; do not infer -manual PASS from automated output. +manual PASS from automated output. The Mac REST row may be +`DEFERRED_PRE_PROJECT_B` only under the dated owner amendment. **Step 4: Close the Project A report** Expected: automated gates and the human guide are PASS; one harmless PSD session reached F8 and -produced validated read-only SQL; rollback remains available. +produced validated read-only SQL; rollback remains available. The accepted report must list the +Mac REST item as an explicit deferred prerequisite rather than silently treating it as PASS. **Step 5: Obtain explicit owner approval** @@ -145,6 +166,10 @@ Record the approval and report digest. Project B remains forbidden without it. **Step 1: Recheck source and running images** +Before freezing the candidate, close the pre-Project-B gate: validate the Mac installation with its +per-installation key, finish the 48-hour observation window including two 03:00 ETL cycles, revoke +`legacy-shared`, prove legacy `401` and v1 success, and obtain `SURVEY_GO_PROJECT_B`. + Run the Project A plan's identity commands again. Record application SHA, workspace SHA, core image ID, frontend image ID, Qdrant image digest, Ollama image digest, and local-auth configuration revision. diff --git a/docs/plans/2026-08-20-psd-server-project-a-standalone.md b/docs/plans/2026-08-20-psd-server-project-a-standalone.md index bec5c6a4..007c1f6f 100644 --- a/docs/plans/2026-08-20-psd-server-project-a-standalone.md +++ b/docs/plans/2026-08-20-psd-server-project-a-standalone.md @@ -12,13 +12,16 @@ ## Preconditions -- Common survey result is GO and its digest is recorded. +- Common survey result is `SURVEY_GO_PROJECT_A_PRIVATE` and its digest is recorded. - Every path below is replaced by the exact survey result before execution. - No production Nginx/load-balancer/sidebar/Authentik change is in scope. - The old stack remains running only until backup verification finishes; old and new stacks never run together. - The server's workspace deploy credential remains read-only. A curator with write access publishes the workspace change. +- Owner amendment 2026-08-21 defers live Mac `rest_api` acceptance and `legacy-shared` revocation to + the mandatory pre-Project-B gate. It does not authorize stop/start; those require a later explicit + owner gate even after private preparation is complete. ### Task 1: Freeze exact inputs @@ -121,11 +124,11 @@ git push --set-upstream origin codex/psd-direct-transport Merge through the repository's normal review path. Record the resulting `main` SHA. -**Step 6: Prove the Mac REST installation is unchanged** +**Step 6: Record the deferred Mac REST proof** -The owner pulls/activates the new workspace commit on the Mac, confirms selected transport -`rest_api`, runs workspace inspection/connection diagnostics, and records PASS. Project A server -deployment stops if this cross-installation proof is not available. +Do not change the Mac during Project A. Record `DEFERRED_PRE_PROJECT_B`, the unchanged expected +transport `rest_api`, and the exact future diagnostics. The proof must become PASS before Project B, +after protected delivery/configuration of the per-installation key. ### Task 3: Back up and stop the legacy installation @@ -416,6 +419,11 @@ remembered-session survival after core restart. Do not retain cookie jars after ### Task 10: Optionally add the private network-path test +**Current scope boundary (owner, 2026-08-21):** omit this entire task and keep Project A +loopback-only. Any future use requires a separate shared-infrastructure authorization after the +public-origin and load-balancer activities pass; the Project A private survey decision alone is +insufficient. + **Files:** - Modify only surveyed test-specific load-balancer/Nginx files - Create: test certificate through the existing managed mechanism @@ -487,12 +495,14 @@ secrets in the ordinary evidence archive. **Step 3: Complete human acceptance** -Every row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly blocking. +Every private-server row in `docs/testing/psd-server-project-a-manual.md` must be PASS or explicitly +blocking. Only the Mac REST row may be `DEFERRED_PRE_PROJECT_B` under the dated owner amendment. **Step 4: Record the gate** Record exact SHAs/images, workspace revision, preprocessing identity/counts, session ID, report -digest, rollback status, and explicit `PROJECT_A_PASS` or `PROJECT_A_FAIL`. +digest, rollback status, and explicit `PROJECT_A_PRIVATE_PASS` or `PROJECT_A_FAIL`. A private PASS +does not authorize Project B while the deferred gate remains open. **Step 5: Stop on FAIL** diff --git a/docs/plans/2026-08-20-psd-server-project-b-authentik.md b/docs/plans/2026-08-20-psd-server-project-b-authentik.md index 60beec93..2baf0e1e 100644 --- a/docs/plans/2026-08-20-psd-server-project-b-authentik.md +++ b/docs/plans/2026-08-20-psd-server-project-b-authentik.md @@ -13,6 +13,11 @@ ## Preconditions - Project A automated and human reports are PASS and explicitly owner-approved. +- The Mac `rest_api` installation passes source validation and connection diagnostics with its + per-installation key. +- The dual-key observation has lasted at least 48 hours and includes two scheduled 03:00 ETL cycles. +- `legacy-shared` is revoked; v1 remains successful and the legacy credential is proven `401`. +- The current survey decision is `SURVEY_GO_PROJECT_B`, not only the private Project A decision. - Application SHA, workspace SHA, images, Project A report digest, and rollback configuration match the accepted evidence. - The production route is closed before authentication/session-storage changes. diff --git a/docs/plans/2026-08-20-psd-server-survey.md b/docs/plans/2026-08-20-psd-server-survey.md index 28668755..963ec60e 100644 --- a/docs/plans/2026-08-20-psd-server-survey.md +++ b/docs/plans/2026-08-20-psd-server-survey.md @@ -290,10 +290,14 @@ ThothII, and core → Supabase DWH/auth session schema/Qdrant/Ollama/LLM/Authent Separate files owned by the new ThothII installation, workspace curator, Nginx, load balancer, Aritmolab, Authentik, and Supabase. Mark shared files as owner-gated. -**Step 3: State GO or NO-GO** +**Step 3: State the scoped GO or NO-GO decisions** -GO requires all mandatory paths, permissions, backup owners, and rollback boundaries. NO-GO must -name concrete missing facts and the person/system needed to resolve them. +State both `SURVEY_GO_PROJECT_A_PRIVATE` and `SURVEY_GO_PROJECT_B`. The private decision requires +all paths, permissions, backup owners and rollback boundaries used by Project A; it may defer +public-origin, load-balancer, Authentik and Mac REST closeout facts that Project A does not mutate. +The Project B decision requires every shared/public fact plus the Mac acceptance, completed +observation window and revoked legacy credential. Each NO-GO must name concrete missing facts and +the person/system needed to resolve them. **Step 4: Hash and retain the report** diff --git a/docs/testing/evidence/psd-server-project-a-report-template.md b/docs/testing/evidence/psd-server-project-a-report-template.md index cc36259b..80bd0c75 100644 --- a/docs/testing/evidence/psd-server-project-a-report-template.md +++ b/docs/testing/evidence/psd-server-project-a-report-template.md @@ -6,7 +6,7 @@ ## Decision -- Result: `PROJECT_A_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING` +- Result: `PROJECT_A_PRIVATE_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING` - Decision timestamp UTC: - Owner/reviewer: - Protected evidence path: @@ -18,7 +18,7 @@ - Plan source SHA: - Workspace previous SHA: - Workspace multi-transport SHA: -- Mac REST validation result/evidence reference: +- Mac REST validation result/evidence reference: `DEFERRED_PRE_PROJECT_B` - Native `tht` version/build identity: - Core image ID/digest: - Frontend image ID/digest: @@ -63,7 +63,7 @@ - Workspace ID/revision: - Server transport: postgres_direct -- Mac transport remains rest_api: PASS/FAIL +- Mac transport remains rest_api: `DEFERRED_PRE_PROJECT_B` - Supabase database name: - DWH schema: datawarehouse - Read-only role proof reference: @@ -95,4 +95,5 @@ - Legacy rollback remains available: - Secret scan result: - Unrelated failures or pending items: +- Pre-Project-B blockers: Mac validation, 48-hour/two-ETL observation, legacy revocation - Reason for final decision: diff --git a/docs/testing/evidence/psd-server-project-b-report-template.md b/docs/testing/evidence/psd-server-project-b-report-template.md index 8ed22c23..057a3a48 100644 --- a/docs/testing/evidence/psd-server-project-b-report-template.md +++ b/docs/testing/evidence/psd-server-project-b-report-template.md @@ -13,6 +13,10 @@ - Protected evidence path: - Evidence manifest SHA-256: - Accepted Project A report digest: +- Mac `rest_api` acceptance evidence: +- Dual-key observation interval and two 03:00 ETL-cycle evidence: +- `legacy-shared` revocation evidence (v1 success, legacy `401`): +- `SURVEY_GO_PROJECT_B` report digest: ## Frozen candidate diff --git a/docs/testing/evidence/psd-server-survey-report-template.md b/docs/testing/evidence/psd-server-survey-report-template.md index 8213b0b6..9b4ee6d3 100644 --- a/docs/testing/evidence/psd-server-survey-report-template.md +++ b/docs/testing/evidence/psd-server-survey-report-template.md @@ -6,12 +6,13 @@ ## Decision -- Result: `SURVEY_GO` / `SURVEY_NO_GO` +- Project A private result: `SURVEY_GO_PROJECT_A_PRIVATE` / `SURVEY_NO_GO` +- Project B result: `SURVEY_GO_PROJECT_B` / `SURVEY_NO_GO` - Timestamp UTC: - Operator: - Protected evidence path: - Report SHA-256: -- Blocking unknowns: +- Blocking unknowns by scope: ## Host diff --git a/docs/testing/psd-server-project-a-manual.md b/docs/testing/psd-server-project-a-manual.md index 0966c405..47f7de02 100644 --- a/docs/testing/psd-server-project-a-manual.md +++ b/docs/testing/psd-server-project-a-manual.md @@ -103,11 +103,15 @@ Eseguire: | Trasporto server | `postgres_direct` | | | | Database/schema | database Supabase rilevato, schema `datawarehouse` | | | | Utente DWH | read-only dimostrato dai grant | | | -| Workspace Mac | prova separata conferma ancora `rest_api` | | | +| Workspace Mac | `DEFERRED_PRE_PROJECT_B`; in quel gate deve confermare `rest_api` | | | | Qdrant | 1024 dimensioni, cosine, indici payload richiesti | | | | Ollama | `qwen3-embedding:0.6b` | | | | Evidence | corpus Git attivo alla stessa revisione | | | +Per l'emendamento del proprietario del 2026-08-21, solo la riga Workspace Mac può restare +`DEFERRED_PRE_PROJECT_B` nella chiusura privata di Project A. Non equivale a PASS e deve essere +eseguita prima di Project B insieme all'osservazione dual-key e alla revoca legacy. + ## 5. Preprocessing e idempotenza Esaminare i due risultati consecutivi del preprocessing prodotti da Sol. @@ -157,9 +161,9 @@ Verificare infine: | Tutti i controlli obbligatori PASS | | | Nessun secret raccolto | | | Rollback vecchio stack ancora disponibile | | -| Progetto B autorizzabile | | +| Progetto B autorizzabile | NO finché il gate Mac/osservazione/revoca non è PASS | -Decisione finale: `PROJECT_A_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING` +Decisione finale: `PROJECT_A_PRIVATE_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING` Revisore e data: ______________________________________