wiki: sync 2026-09-17 03:16 UTC — 4 file(s) updated

This commit is contained in:
2026-09-17 03:16:13 +00:00
parent 9334eb99d5
commit a954b28345
4 changed files with 23 additions and 4 deletions
+2 -1
View File
@@ -1,6 +1,6 @@
# 🧠 Knowledge Wiki — Brain Summary
_Last updated: 2026-09-16 03:11 UTC_
_Last updated: 2026-09-17 03:13 UTC_
## Workstreams & Status
@@ -67,6 +67,7 @@ _Last updated: 2026-09-16 03:11 UTC_
- **CogArch GitHub attribution (required 2026-08-25):** `cogarch-github` commits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution.
- **CogArch presentation governance (required 2026-09-04):** channel-dedicated `cogarch-storm` is maintained in `cognitive-architect-v1-skills-code-agent/cogarch-storm`. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally use `powerpoint-ibm-template`; that skill must always reference/load `powerpoint` and `powerpoint-advanced-python`.
- **CogArch Solution Factory / Argo evidence boundary (verified 2026-09-15):** exact live and archived label queries for `architecture-id=arch_kiSj9jBKI` returned no Workflow. The deployed Processing template contains conversion, chunking, image description, and merge steps, but completed Workflows are deleted after 24 hours and the accessible archive is empty. A separate `arch_xOQ5jks0b` High-Level Insights failure reached the code agent and exhausted retries with exit code 201; its overwritten detailed log reportedly showed operation timeout/retry-limit failure. A fail-open Redis DNS warning appeared in that failed run but did not recur in the read-only-verified rerun pod, so it is not the established cause.
- **CogArch Solution Factory BYOT MVP (decided 2026-09-16):** use one persistent OpenShift Secret per user, created/patched/deleted by the existing settings backend; do not introduce IBM Secrets Manager or a new secrets service initially. Require server-derived opaque names, backend ServiceAccount permissions limited to Secret `create`/`patch`/`delete` without reads, admission restriction to labelled `byot-*` objects, trusted WorkflowTemplates, no token leakage, and fail-closed behavior. Running workflows may retain old values; provider revocation and cluster-loss recovery remain separate concerns.
- **Emplonet v1 channel setup (confirmed 2026-09-08):** `#emplonet-v1-general` and `#emplonet-v1-ingrida` each have a dedicated local artifact workspace under `/opt/data/channels/`, a dedicated channel skill, and a private source repository in `emplonet-v1-skills-code-agent`; both are now included in the authoritative daily wiki scan and short config routing.
- **Lego CV workspace (confirmed 2026-09-14):** `#lego-v1-cv` uses `/opt/data/workspaces/channels/lego-v1-cv` and the private `lego-v1-skills-code-agent/lego-v1-cv` channel skill. The supplied CV source was converted into brand-neutral editable DOCX and PDF artifacts without embedded IBM logos while retaining professional content.
- **Wiki health check (repaired 2026-09-13):** `/opt/data/scripts/health-check.sh` no longer creates invalid multiline `0\n0` counts when `grep -c` finds no match, and its Discord test recognizes the gateway's actual inbound/send activity log forms. `bash -n` and a complete rerun passed all four checks; authenticated Discord REST still remains the source of truth for channel-scan coverage.
+2 -2
View File
@@ -1,6 +1,6 @@
# Channel Wiki: #jarvis-jr-knowledge-wiki
_Channel ID: 1519069810166599764_
_Last sync: 2026-09-16 03:11 UTC_
_Last sync: 2026-09-17 03:13 UTC_
## Purpose
Operate and audit Hermes's persistent Discord knowledge system: channel inventory, monitored-channel coverage, per-channel context, recurring syncs, and Gitea mirroring.
@@ -24,7 +24,7 @@ Operate and audit Hermes's persistent Discord knowledge system: channel inventor
- Verify config refresh and Gitea push independently after monitoring changes.
- The authoritative sync mapping now contains 33 text-channel IDs, including the recently provisioned `#cogarch-v1-iac`, `#cogarch-v1-shorts`, `#cogarch-v1-argo-workflows`, `#jarvis-jr-v1-storm`, and `#lego-v1-cv` channels; one retained legacy ID (`#jarvis-jr-test-001`) remains inaccessible with Discord error `10003 Unknown Channel`.
- ✅ On 2026-09-13 the recurring health-check defect was repaired: zero-match `grep -c` output can no longer become the invalid multiline value `0\n0`, and the Discord check now recognizes the gateway's actual inbound/send activity log forms. A syntax check and complete rerun passed all four checks; the same run's authenticated Discord REST scan succeeded for 31/32 monitored channels.
- ⚠️ Run #155 on 2026-09-16 scanned 32/33 monitored IDs; `#jarvis-jr-test-001` remains inaccessible with Discord `10003 Unknown Channel`. Six human messages in `#cogarch-v1-argo-workflows` advanced its anchor through `1549399634302992447` and established that the failed run's fail-open Redis warning did not recur in the read-only-verified rerun pod; the overwritten detailed agent log reportedly contained operation timeout/retry-limit errors.
- ⚠️ Run #156 on 2026-09-17 scanned 32/33 monitored IDs; `#jarvis-jr-test-001` remains inaccessible with Discord `10003 Unknown Channel`. Nine human messages in `#cogarch-v1-argo-workflows` advanced its anchor through `1549783805877813279` and established the BYOT MVP decision: one persistent OpenShift Secret per user, managed by the existing backend with write-only Secret RBAC plus admission restriction, rather than IBM Secrets Manager or a new internal service.
## Channel Workspace
- Channel-owned working files belong under `/opt/data/channels/jarvis-jr-knowledge-wiki/`, grouped by purpose.
+10 -1
View File
@@ -1,7 +1,7 @@
# Channel Wiki: #cogarch-v1-argo-workflows
_Channel ID: 1548051220533481536_
_Created: 2026-09-11 UTC_
_Last sync: 2026-09-16 03:11 UTC_
_Last sync: 2026-09-17 03:13 UTC_
## Purpose
@@ -20,10 +20,16 @@ Observe, analyze, and preserve evidence about Cognitive Architect Solution Facto
- Observation does not authorize upstream edits, external publication, or IBM merges. IBM merges require human approval.
- **Hard authority boundary:** Hermes must perform no write action against Cognitive Architect Argo Workflows in any environment unless Discord user `1518725627845283888` explicitly overrides this restriction.
- Production Argo Workflows access is read-only through the dedicated channel-skill helper. Its API token must never enter model context, command arguments, logs, or artifacts.
- **BYOT MVP decision (2026-09-16):** use one persistent OpenShift Secret per user and do not introduce IBM Secrets Manager or another internal secrets service for the initial version. The existing settings backend creates, patches, and deletes the Secret; a trusted Solution Factory WorkflowTemplate selects it for the user's workflow pod.
- BYOT Secret names are server-derived from opaque internal user identifiers. The browser and workflow parameters must not choose Secret names.
- The settings backend uses a dedicated OpenShift ServiceAccount whose Role allows only `create`, `patch`, and `delete` on Secrets, with no `get`, `list`, or `watch`. Because native RBAC cannot constrain creates by name prefix or label, a `ValidatingAdmissionPolicy` must restrict that identity to correctly labelled `byot-*` Opaque Secrets containing only the approved token key.
- Users must not be able to supply arbitrary Workflow YAML, Secret references, volumes, service accounts, or pod patches. Worker pods should not mount Kubernetes API tokens unless required, and BYOT values must never enter Argo parameters, logs, errors, annotations, command arguments, traces, or artifacts.
- BYOT fails closed when selected but unavailable; it must not silently fall back to the shared credential pool. Already-running workflows may retain an old token after rotation/deletion, and deleting Solution Factory's copy does not revoke the credential at the provider. Initial disaster recovery may use encrypted OpenShift backup or require user re-entry.
## Active Topics
- Investigate production Solution Factory workflow-template behavior and failures through GET-only Argo access.
- Implement and validate the approved per-user OpenShift Secret BYOT MVP, including write-only backend RBAC, admission restriction, trusted WorkflowTemplates, no secret leakage, fail-closed behavior, and an explicit cluster-loss recovery choice.
## Key Context
@@ -47,6 +53,7 @@ Observe, analyze, and preserve evidence about Cognitive Architect Solution Facto
- Select the first Solution Factory behavior or workflow to observe.
- ✅ The requested standalone HTML investigation page was delivered in Discord messages `1548064910263586922`–`1548064913602379868`.
- Obtain the exact `iter_...` ID and approximate start time for `arch_kiSj9jBKI` to determine whether it should remain inside Argo's 24-hour retention window and to correlate any external S3 or Solution Factory history.
- Validate the BYOT MVP end to end: create/rotate/delete only the authenticated user's Secret; prove the backend cannot read Secrets or mutate unrelated ones; prove workflows cannot select another user's Secret; verify no token leakage; and choose encrypted backup versus user re-entry after catastrophic cluster loss.
## Evidence
@@ -54,3 +61,5 @@ Observe, analyze, and preserve evidence about Cognitive Architect Solution Facto
- Previous processed human message: `1548759488570466527` (2026-09-13 18:17 UTC; RootAtSkic confirmed that the lookup must use the exact Kubernetes selector `architecture-id=arch_kiSj9jBKI`; live and archived Argo queries using that selector returned no items).
- `1549364076239397005` — RootAtSkic requested diagnosis of failed High-Level Insights for `arch_xOQ5jks0b` / `iter_fMfOM35fb`; read-only Argo inspection isolated the failure to knowledge-wiki-plan agent exit code 201 after retries.
- Latest processed human message: `1549399634302992447` (2026-09-15 12:40 UTC; `whyt6249` requested comparison against rerun pod `phase-0200-high-level-insights-9p7vz-run-step-2817085442`; live read-only inspection found no recurrence of the Redis warning).
- `1549783805877813279` — `whyt6249` accepted the direct per-user OpenShift Secret approach as the BYOT decision and requested its summary after exploring IBM Secrets Manager, encrypted-database, broker, Vault/OpenBao, and direct-cluster alternatives.
- Latest processed human message: `1549783805877813279` (2026-09-16 14:07 UTC; requested summarizing the agreed BYOT decision).
+9
View File
@@ -1,5 +1,14 @@
# Sync Log
### Run #156 — 2026-09-17 03:13 UTC ⚠️
- **Channels scanned:** 32/33 authoritative monitored text-channel IDs via authenticated Discord REST, strictly within guild `1518726359512387766`. Channel metadata confirmed guild membership for every accessible ID. **Failure:** retained `#jarvis-jr-test-001` (`1518733120831226028`) returned `404 {"message": "Unknown Channel", "code": 10003`; its anchor could not advance.
- **New human activity:** 9 messages in `#cogarch-v1-argo-workflows`; no human activity newer than the durable anchors in the other 31 accessible monitored channels.
- **Durable knowledge captured:** `whyt6249` finalized the Solution Factory BYOT MVP after evaluating alternatives. The initial design uses one persistent OpenShift Secret per user, managed directly by the existing settings backend, without IBM Secrets Manager or a new internal secrets service. Required controls are server-derived opaque names, a dedicated backend ServiceAccount limited to Secret `create`/`patch`/`delete` with no reads, admission restriction to approved labelled `byot-*` Secrets, trusted WorkflowTemplates, secret-leak prevention, and fail-closed behavior. Running workflows may retain old values after rotation/deletion; provider revocation and cluster-loss recovery are separate concerns.
- **Processed anchors:** unchanged except `#cogarch-v1-argo-workflows` advanced to `1549783805877813279`. Current anchors: `#atea-storm` `1532359647435165829`; `#general` `1544265696228151357`; `#zeta-functions` `1531221244530397214`; `#network-v1` `1529573612510511214`; `#vssa-storm-1st-contract` `1532462731142103040`; `#dpvp-phase-2-opportunity` `1546854087910498384`; `#vssa-storm` `1546850319449854092`; `#vssa-dpvp-storm` `1546441933382230157`; `#vssa-dpvp-cvpa-audit` `1533830589722132510`; `#cogarch-model-v1-storm` `1528684615898759258`; `#cogarch-storm` `1545429834761510992`; `#cogarch-storm-skills` `1529471826697392228`; `#cogarch-storm-drawio-custom-shapes` `1531292165874126998`; `#cogarch-storm-cogarch-hub-web` no human-message anchor; `#cogarch-v1-iac` `1547955261845672029`; `#cogarch-v1-shorts` `1549106928137801853`; `#cogarch-v1-argo-workflows` `1549783805877813279` **NEW**; `#jarvis-jr-v1-storm` `1548063523270168617`; `#playground-eduard-melman` `1536841496366415932`; `#lego-as-enterprise-architect-within-vssa` `1523377235153780836`; `#jarvis-jr-test-001` `1532723701039108117` retained after fetch failure; `#jarvis-jr-enablement-voice` `1519063294973841571`; `#jarvis-jr-general` `1548063732297498785`; `#jarvis-jr-knowledge-wiki` `1547935398355927141`; `#jarvis-jr-truenas` `1543961473745944586`; `#lego-planner-v1` `1549157428094959656`; `#vssa-account-strategy` `1524753167483408526`; `#jarvis-jr-v1-hermes-setup` `1536529995176878242`; `#jarvis-jr-v1-hermes` `1546833203753525320`; `#skic-v1-playground` `1536839098277437601`; `#emplonet-v1-general` `1546855047374180382`; `#emplonet-v1-ingrida` `1546855606370181141`; `#lego-v1-cv` `1549020705843060847`.
- **Files updated:** `channels/1548051220533481536.md`, `channels/1519069810166599764.md`, `MEMORY.md`, and `sync-log.md`.
- **Health:** pre-run check passed state.db integrity, gateway process, Discord gateway activity, and disk-space checks.
- **Config routing and Gitea mirror:** executed after this entry; verified results are reported in the delivered run summary.
### Run #155 — 2026-09-16 03:11 UTC ⚠️
- **Channels scanned:** 32/33 authoritative monitored text-channel IDs via authenticated Discord REST, strictly within guild `1518726359512387766`. Channel metadata confirmed guild membership for every accessible ID. **Failure:** retained `#jarvis-jr-test-001` (`1518733120831226028`) returned `404 {"message": "Unknown Channel", "code": 10003`; its anchor could not advance.
- **New human activity:** 6 messages in `#cogarch-v1-argo-workflows`; no human activity newer than the durable anchors in the other 31 accessible monitored channels.