Commit Graph
255 Commits
Author SHA1 Message Date
marcopan 1184b6db16 docs: converge operator guidance on tht 2026-08-19 16:12:11 +02:00
marcopan 32a17d83a9 docs(auth): add acceptance and PSD deployment plan 2026-08-19 14:29:53 +02:00
marcopan cd5f505c8a fix(auth): close Windows remediation review findings 2026-08-18 12:46:54 +02:00
marcopan 3c6ddfaef1 docs(auth): plan important finding remediation 2026-08-18 10:10:37 +02:00
marcopanandCommandCodeBot 1d045a44a6 docs: add canonical Evidence structure design
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-08-18 09:52:53 +02:00
marcopan 8a3fa5031d test(auth): gate local and OIDC authentication release 2026-08-18 06:02:25 +02:00
marcopan 91925d64bf docs(auth): address authentication guide review 2026-08-18 03:33:00 +02:00
marcopan f4f38717e1 docs(auth): document local OIDC and Authentik operation 2026-08-18 03:07:33 +02:00
marcopan 9558eaa508 feat(auth): integrate authentication with installation lifecycle 2026-08-17 20:21:42 +02:00
marcopan 9196639cb3 docs(auth): add authentication design and implementation plan 2026-08-16 17:07:32 +02:00
marcopan 351361f72f feat: finish Pi and workspace management updates 2026-08-16 14:19:32 +02:00
marcopan 900faad983 fix: close Pi management final review findings 2026-08-14 20:15:21 +02:00
marcopan dc83a55555 docs: correct Pi operator recovery guidance 2026-08-14 18:41:34 +02:00
marcopan a8623a2b18 docs: clarify Pi reload and update workflows 2026-08-14 18:34:04 +02:00
marcopan ab33e0ed0a docs: describe read-only workspace runtime configuration 2026-08-14 18:01:02 +02:00
marcopan a227cbe755 docs: plan Pi restart operator workflow 2026-08-14 17:32:07 +02:00
marcopan 1f6a49b985 docs: design Pi restart operator workflow 2026-08-14 17:09:58 +02:00
marcopan 747020a330 feat: declare workspace repository in installation config 2026-08-14 16:32:58 +02:00
marcopan 3a50c447c3 docs: plan read-only workspace secret implementation 2026-08-14 16:12:26 +02:00
marcopan 870af3422b docs: define read-only workspace secret architecture 2026-08-14 16:09:55 +02:00
marcopan 55567f17f2 docs: record P7 live preprocessing PASS on the real PSD DWH 2026-08-13 20:06:23 +02:00
marcopan 84b233d937 docs: record P7 publication + live stack (pending VPN) 2026-08-13 16:41:46 +02:00
marcopan 3046ac34c6 feat: restructure PSD repo (P7) and add operator setup templates + checklist 2026-08-13 16:14:32 +02:00
marcopan aa22183ac7 docs: plan P7 PSD migration to the workspace registry 2026-08-13 16:10:43 +02:00
marcopan ecd986f208 docs: aggregate P2-P6 acceptance, full-suite results, and user guide 2026-08-13 13:00:08 +02:00
marcopan 486e144fcd docs: record P6 manual acceptance 2026-08-13 12:51:26 +02:00
marcopan be0e68e77d docs: record P6 implementation, contract, and automated acceptance PASS 2026-08-13 12:44:19 +02:00
marcopan e80a8b35ec docs: plan P6 commit-addressed Evidence materialization 2026-08-13 12:27:26 +02:00
marcopan 9605f77acb docs: record P5 manual acceptance 2026-08-13 12:25:08 +02:00
marcopan 55a61931b1 docs: record P5 implementation and finalize the P5 manual walkthrough 2026-08-13 05:10:22 +02:00
marcopan 0459a6cd3e feat: operator schema accept command for curated FK review (P5) 2026-08-13 05:06:23 +02:00
marcopan 60e4048d4b docs: plan P5 curated FK annotations in Git 2026-08-13 04:50:29 +02:00
marcopan 3397911670 docs: record P3+P4 manual acceptance and rebind P4 automated run to e056c19 2026-08-13 04:44:50 +02:00
marcopan e056c19e62 feat: P4 qdrant collection lifecycle (self-heal + guarded rebuild)
- shared TS collection manager: self-heal creates missing collection (1024/cosine)
  and missing keyword payload indexes; never mutates incompatible contracts
  (semantic_index_incompatible); async index visibility polled with bounded deadline
- session admission (qdrantEnsure) uses the manager in self-heal mode; operator path
  keeps require_existing semantics
- runtime lease exposes semanticQdrantUrl to the operator
- operator commands vector-inspect/vector-rebuild with exact confirmation guards
- thothctl workspace vector inspect|rebuild (Go) with --collection/--confirm/--destroy
- p4 acceptance runner: real Qdrant (v1.18.2) lifecycle checks, 11/11 PASS
- docs: CLI contract, manual walkthrough P4 (PENDING), PROJECT_STATE
2026-08-12 20:00:14 +02:00
marcopan 230a876314 docs: plan P4 qdrant collection lifecycle 2026-08-12 18:55:33 +02:00
marcopan e23e526966 feat: P3 effective configuration, memory root, and revision-scoped records 2026-08-12 16:01:25 +02:00
marcopan 13f74de4fa docs: record P2 manual acceptance and plan P3 effective configuration 2026-08-12 14:44:27 +02:00
marcopan 3c5c2e8afd docs: finalize P2 manuals, project state, and install-doc service contract 2026-08-11 20:09:11 +02:00
marcopan 17f2e48463 feat: thothctl workspace preprocessing CLI and file-ingress contracts (P2) 2026-08-11 18:40:11 +02:00
marcopan 3cfc8c53e6 docs: align P2-P6 planning artifacts with the P1.1 registry contract 2026-08-11 17:44:40 +02:00
marcopan d927233210 docs: record P1.1 manual acceptance and plan P2-P6 adaptation 2026-08-11 17:24:34 +02:00
marcopan a22d232aa2 test: add independent P1.1 acceptance and manual tooling 2026-08-11 16:04:44 +02:00
marcopan c2f33e58d7 docs: define the P1.1 registry layout and curator flow 2026-08-11 15:22:57 +02:00
marcopan 7356d6794b docs: add P1.1 workspace directory plan 2026-08-11 14:22:28 +02:00
marcopan 5310c6555b docs: make schema v3 the only workspace contract 2026-08-11 02:53:41 +02:00
marcopan 5d016ce635 docs: revise schema-v3-only cleanup plan 2026-08-10 19:50:24 +02:00
marcopan ce90b4410d docs: add P2 host preprocessing plan 2026-08-10 19:04:51 +02:00
marcopan 16ee92c8f9 docs: design P2-P6 workspace preprocessing 2026-08-10 18:59:31 +02:00
marcopan c7338969d7 fix: bind complete P1 manual dist graph and snapshot identity
prepare records an immutable manifest of every regular backend/dist file
(path/size/sha256/dev/ino) in the owned root and binds its record identity
in ownership; serve revalidates record and every file before spawn, passes
the manifest to the child on fd 4, and the immutable preload hash-verifies
all files at startup and serves only cached verified bytes for any import
below backend/dist, so imported dependency replacement is refused before
RUNNING or never executes. The render command validates the commit
snapshot.json manifest, binds snapshot bytes to the manifest digest and the
installed Git blob, and passes the expected digest to the renderer, which
revalidates head/files digest with bounded no-follow reads and renders only
verified bytes with lease release on refusal.
2026-08-10 17:36:24 +02:00
marcopan 96362929d7 fix: harden P1 manual acceptance audit gates 2026-08-09 23:32:42 +02:00