docs: defer DWH client cutover before Project B
This commit is contained in:
+17
-5
@@ -7,9 +7,10 @@
|
||||
> ThothII per il repository (app + CLI `tht`), (3) come usare l'applicazione ThothII di base
|
||||
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-20 (PSD server replacement and Authentik-integration program designed;
|
||||
> executable survey, two gated project plans, human-test guides, and evidence templates prepared;
|
||||
> no server mutation has been executed).
|
||||
> Last updated: 2026-08-21 (DWH per-installation authentication is active in dual-key mode;
|
||||
> the owner deferred Mac acceptance and legacy revocation to the mandatory pre-Project-B gate,
|
||||
> authorized the read-only survey and Project A private preparation, and did not authorize either
|
||||
> stopping the legacy stack or starting the new stack).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### PSD server deployment program — design approved, execution PENDING (2026-08-20)
|
||||
@@ -38,8 +39,19 @@
|
||||
balancer can prove an operator-only temporary endpoint. Project B preserves the real user flow
|
||||
`Aritmolab homepage -> sidebar -> load balancer -> Nginx -> ThothII`, with direct ThothII-managed
|
||||
OIDC and no second Nginx `auth_request`.
|
||||
- **State:** survey `PENDING`; Project A `PENDING`; Project B `BLOCKED_BY_PROJECT_A`; server and
|
||||
external repositories/services unchanged by this planning work.
|
||||
- **State:** survey `SURVEY_NO_GO` for Project A private; Project A
|
||||
`BLOCKED_BY_SURVEY_AND_MUTATION_GATE`; Project B `BLOCKED_BY_PROJECT_A_AND_PRE_B_GATE`.
|
||||
Remaining private-scope blockers are legacy rollback/backup, approved installation paths and UID
|
||||
strategy, dedicated read-only workspace access, a dedicated direct-DWH role/route, and Pi/LLM
|
||||
metadata. The catalog-only survey proved the currently available `postgres` identity owns
|
||||
`datawarehouse` and has full write/DDL privileges, so it must not be reused by the new core.
|
||||
Pi metadata resolves to 0.80.3, `deepseek/deepseek-v4-pro`, thinking `high`, but the bounded
|
||||
no-session/no-tool reachability probe is FAIL and must be diagnosed without exposing auth data.
|
||||
- **Sequencing amendment (owner, 2026-08-21):** use two survey decisions. Project A private may
|
||||
proceed only after `SURVEY_GO_PROJECT_A_PRIVATE` and a separate stop/start authorization. Mac
|
||||
`rest_api` acceptance, the 48-hour/two-ETL observation, and revocation of `legacy-shared` are
|
||||
mandatory before `SURVEY_GO_PROJECT_B`. Current authorization covers read-only survey and
|
||||
preparation only; old-stack stop and new-stack start remain forbidden.
|
||||
|
||||
### Authentication final-review fix round 2 — remediation PASS, release gates remain (2026-08-18)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user