# 🧠 Knowledge Wiki — Brain Summary _Last updated: 2026-09-11 03:09 UTC_ ## Workstreams & Status | # | Workstream | Open Items | Priority | |---|-----------|-----------|----------| | 🔵 | VSSA — DPVP | 21 active, 1 opportunity | Phase 2 opportunity, AWS tagging, Azure-cost onboarding documentation, access governance/monitoring, Jira-targeted role grants/revocations, project-level backups, Architecture Decision process, unit-testing options, backlog migration to Jira | | 🟡 | VSSA — Enterprise Architect | 4 active | Scope decision, Gytis outreach, Atea & IBM institution engagement, Government Developer Portal | | 🟢 | Cognitive Architect | 8 active | Oleg follow-up; Aurimas Nogis/Hermes security follow-up; ArchiMate investigation; Texture/Jenny integration follow-up; Anthropic architect certification; IBM Video Streaming; cogarch backlog | | 🟣 | SAP Delivery Powered By AI | 1 active | Michael Martine material review | | 🏅 | Distinguished Engineer | 3 active | Elizabeth docs + summary; FutureNow/Baltic AI/client-relations upskilling with Jurgis | **Total open:** 38 items | **Completed:** 7 (env vars deployed; Apptio AWS-connection investigation and Azure-cost onboarding completed; CA-01, CA-03, CA-04, and CA-B01 completed) ## Atea Cooperation - `#atea-storm` is the continuity ledger for Atea-related contracts, opportunities, audits, and RFPs. - Current tracked workstreams: VSSA AWS contract; VSSA DPVP contract and Phase 2 opportunity; Valstybės duomenų agentūra AWS portal audit; Lietuvos Geležinkeliai RFP; and two early Atea & IBM items (the user-provided title “Let's go to institutions” and a Government Developer Portal). Details for the two Atea & IBM items are not yet specified. - DPVP Phase 2 discussion scope covers the portal, backend execution migration, VSSA on-premises onboarding, complex hybrid services, and organization scanning across AWS, Azure, and GCP. Ownership, prioritisation, estimates, dependencies, dates, scan baselines, and commercial route remain unconfirmed. - VSSA AWS: an AWS Well-Architected Framework review has been proposed, not approved; workload/account scope, authorization, access, schedule, and remediation ownership remain open. - DPVP backlog changes confirmed 2026-08-25: the Apptio AWS-connection investigation and Azure-cost onboarding are completed; the follow-up with Atea about TFE OIDC role assumption and July cost-estimation review were dropped. Open refinements include figuring out AWS tagging issues, documenting the Azure-cost onboarding approach, and having Julius locate documentation for the nightly AWS cost-allocation-tag enablement job. - The portal audit is an opportunity only; active testing requires explicit written authorization and agreed scope. - A consolidated executive summary was requested on 2026-07-29 and is maintained in `wiki/channels/1531661088209371198.md`. ## VSSA Client Investigation - **Current delivery (2026-09-04):** repository `vssa-v1/documentation` publishes the Keycloak-protected **VSSA - Clients & Systems** Docusaurus site. The latest completed delivery records 290 clients, 551 canonical systems, 779 observations, and 118 contractor cards at commit `701494d175266bd5e6683f53c58d08b7cd69bc0e`; exact-head Actions task `1874` succeeded. RootAtSkic stopped and removed continuous-research job `88833e00b4a2` on 2026-09-04, so it no longer runs every two hours. The unassigned next range remains clients 121–140. - **Entity classification (confirmed 2026-08-19):** Valstybės skaitmeninių sprendimų agentūra (VSSA) is a central-government client body, not a system or commercial contractor. Government bodies that centrally operate/provide shared services must not be converted to `CTR-*` entities merely because of that role. - **Content organization (confirmed 2026-08-12):** after Lego requested an immediate research-led overall-page improvement cycle, commit `1542674` reorganized the portal around researched user tasks. Navigation is Overview, Clients, Systems, Methodology, and Data; deployment was validated by successful Actions run `2335` and representative HTTP-200 backend/browser checks. - **Evidence/navigation requirements (confirmed 2026-08-12/14):** Overview, Clients, Systems, Contractors, Methodology, and Data have dedicated sidebars; Clients, Systems, and Contractors each expose Overview plus an expanded Registry. Internally generated `SYS-*`/`CTR-*` identifiers are documented, all generated client/system dossiers have References indexes, relationship evidence uses reusable cards, every client system observation links to its canonical system dossier, and every named contractor on an exact client-system row links to its Contractor Card. Multiple contractors are supported; unknown contractors remain explicit and unlinked. - **VSSA skill governance (confirmed 2026-08-14):** `vssa-clients` is authoritative in `vssa-v1-skills-code-agent/vssa-clients`; merged `documentation-docusaurus` is authoritative in `vssa-v1-skills-code-agent/documentation-docusaurus` and includes the retired `gitea-docusaurus-projects` capabilities. Both runtime skills are symlinked to Gitea maintainer worktrees. The requested `corp-v1-skills-code-agent/documentation-docusaurus` repository was unavailable and was not touched. - **Procurement research (confirmed directive and validated workflow, 2026-08-12):** Discord user `476287310627864587` is the designated instructor for CVP IS. In addition to tender search, use exact organization search → identity-checked organization profile → **PERŽIŪRĖTI VISUS PASKELBTUS SKELBIMUS**, extracting the actual `authorityId`/`orgGroupId` and relevant notice PDFs. Job `88833e00b4a2` must map supported records to exact clients/systems and keep RFI/RFP/specification/bid stages distinct from award, implementation, production use, hosting, and completion. - **Lifecycle evidence rule (confirmed 2026-08-12):** a dated official announcement explicitly stating that a named system started operating/launched/went live is direct production-release evidence at the announcement’s stated precision; generic webpage metadata is not. Do not infer delivery kickoff from a production announcement. ## Key People - **Lego** (root_at_skic) — Owner, Enterprise Architect - **MartynasP** (w4rl0ck_21) — Hermes migration lead - **Jerry** — TrueNAS admin - **Julius Sulcas** — DPVP, was on time off - **Rimvydas** — Architect, reports to Dimitrian via Edvinas - **Gytis Račiukaitis** — E-Gov Gateway contact - **Luis Diego Raga** — Pentest senior tester (Sep 1–28) - **Oleg** — Cognitive Architect stakeholder - **Andrius** — Built cogarch skill - **Elizabeth** — Distinguished Engineer track - **Jurgis** — FutureNow, Baltic AI, client-relations, and broader upskilling contact - **Jenny** — Mentioned Texture integration and other Cognitive Architect items; exact items and role still need clarification - **Michael Martine** — SAP material contact - **Arunas Saltis** — DNS naming convention (internal hosting) ## Pending Reminders - [ ] Follow up with Arunas Saltis — DNS naming convention (internal hosting) — added 2026-07-14 ## Infrastructure - TrueNAS SCALE 26.0.0-BETA.2 at lego-cloud.eu ✅ - Gitea: gitea.lego-cloud.eu (org: home-v1) ✅ - **General Gitea repository skill:** ✅ `gitea-repository-operations` — reusable API + SSH workflow for any repo; full wiki runbook at `wiki/infrastructure/gitea-repository-operations.md` - **Gitea API credential (confirmed 2026-08-02):** use Bitwarden-provided `HL_V1_GITEA_ACCESS_TOKEN` for `gitea.lego-cloud.eu`; never use `GITHUB_TOKEN` for that instance or copy the Gitea token into `/opt/data/.env`. Bitwarden keys are exported without aliases and gateway restart is required after key changes. - **Gitea recovery (confirmed 2026-08-11):** Gitea `1.27.0` crashed all SSH/Smart-HTTP Git-serving processes despite healthy web/API; upgrade to `1.27.1` restored API and both Git transports. The queued VSSA commit `6fc42ab` was pushed and remotely verified. - **Gitea Pages pattern (verified 2026-08-11):** Actions runners build repositories and publish to `/gondor-v1-gitea-pages///`, exposed at `https://pages.apps.lego-cloud.eu///`. The Pages dataset must be allowed by `container.valid_volumes` and mounted into job containers. `skic-v1-playground/documentation` run 2326 and the live site were verified. - **Actions Docker (verified 2026-08-11):** use the runner-mounted `/var/run/docker.sock` directly (client `29.6.2-1`, Engine `29.0.4`). DinD is unnecessary and privileged DinD is not currently supported by this runner. - **CogArch GitHub attribution (required 2026-08-25):** `cogarch-github` commits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution. - **CogArch presentation governance (required 2026-09-04):** channel-dedicated `cogarch-storm` is maintained in `cognitive-architect-v1-skills-code-agent/cogarch-storm`. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally use `powerpoint-ibm-template`; that skill must always reference/load `powerpoint` and `powerpoint-advanced-python`. - **Emplonet v1 channel setup (confirmed 2026-09-08):** `#emplonet-v1-general` and `#emplonet-v1-ingrida` each have a dedicated local artifact workspace under `/opt/data/channels/`, a dedicated channel skill, and a private source repository in `emplonet-v1-skills-code-agent`; both are now included in the authoritative daily wiki scan and short config routing. - **Wiki health-check defect (observed 2026-09-10 and recurring 2026-09-11):** `/opt/data/scripts/health-check.sh` exits `1` because the zero-match Discord count becomes the invalid multiline value `0\n0`, and its gateway-log heuristic reports no connection. Authenticated Discord REST reads then succeeded for 27/28 monitored channels on both runs, so the check needs repair and its result must not be treated as proof of Discord API unavailability. - **Home v1 skill-repository descriptions (status 2026-09-09):** all 60 repositories in `home-v1-skills-code-agent` have non-empty Gitea descriptions, but the requested 3–5 sentence standard is met by 58/60. `hermes-codex` and `development-durable-wave-execution` still have one-sentence descriptions and remain open remediation. - **TrueNAS channel skill (confirmed 2026-08-26):** `home-v1--truenas` is maintained in private Gitea repository `home-v1-skills-code-agent/home-v1--truenas` and loaded directly from its checkout. Commit `634e0e6` passed 10 offline tests, Gitea Actions task `1398`, remote readback, and a real authenticated read-only WebSocket query. Runtime access uses Bitwarden keys `HL_V1_TRUENAS_URL` and `HL_V1_TRUENAS_API_KEY`. The current IP-based URL fails strict certificate identity validation; use a certificate-matching DNS/CA path rather than permanent `--insecure` mode. - **Gondor v1 (2026-08-02):** Hermes SSH access as `lego` is verified to Osgiliath 000 and both Minas Tirith workers; use the `gondor-v1-nodes` skill. Open ingress incident: Argo CD's hostPort 80/443 `ingress-nginx` conflicts with Osgiliath's system Nginx; repair through `home-v1/gondor-v1.git`, not a transient live patch. - **Hermes outage (2026-08-04–11):** confirmed Codex quota exhaustion first blocked model responses while Discord/cron remained alive; a separate likely host/container-runtime failure then stopped all gateway, scheduler, log, and health progress after 2026-08-04 14:00:42 UTC. Physical restart at 2026-08-11 00:11:40 restored service without Hermes repair. Exact host-level trigger remains **UNKNOWN** because previous-boot TrueNAS/kernel/ZFS/runtime/hardware telemetry is unavailable inside the container. - **world-v1/network-v1:** ✅ global Internet address book; IP-level mapping now separates registry holder, route origin, operator, and service. Initial records: `0.0.0.0` and `1.1.1.1`; wiki page at `wiki/infrastructure/network-v1.md` - Keycloak: keycloak.lego-cloud.eu ✅ - Hermes Dashboard: jarvis-jr-v1.lego-cloud.eu ✅ - STT Whisper: 192.168.1.218:39000 🔲 - Piper TTS: 192.168.1.218:39001 🔲 ## Hermes Migration - Status: ✅ Live, cron active, **backlog ownership officially handed to Hermes role** (2026-07-16) - **UPGRADED: Hermes is now sole agent on SKIC Discord server** (2026-07-17 07:44 UTC, confirmed by Lego) - Hermes role ID: `1527260007307935776` | Discord permissions: Administrator ✅ - **morning-standup cron** ✅ first successful fire: 2026-07-17 05:01 UTC; enhanced 2026-07-27 to include drawio-desktop#2499 monitoring (Lego directive: merge into standup, not separate job) - 🆕 **Lego directive (2026-07-27 10:57 UTC):** start building a dedicated skill for Hermes itself - Backlog files: `wiki/vssa-dpvp/action-plan.md`, `wiki/cognitive-architect/action-plan.md` - MartynasP model-access documentation: ⏳ still pending - **Gitea wiki sync** ✅ — pushing to skic-v1-playground/knowledge-wiki on every run (started 2026-07-17 09:30 UTC) - ✅ **Gitea push restored** — after Lego requested another access check at 11:08 UTC, SSH access to `origin/main` was verified at 15:08 UTC. Remote and local `main` both pointed to `35eb834`; all previously queued commits are now on Gitea. - 🔴 **Lego directive (2026-07-20 08:49 UTC):** "please fix your issues yourself" — Hermes must resolve the Gitea push issue autonomously - ⚠️ **Responsiveness incident (2026-07-20 09:54–11:03 UTC):** Lego repeatedly asked whether the issues were fixed and what Hermes was doing; visible progress/status updates are expected during incident resolution. - **Voice behavior (confirmed 2026-07-31):** generate clear, human-friendly, conversational responses and let the participant guide with questions; avoid dense written-style delivery in live voice sessions. ## Wiki Files - `/opt/data/wiki/vssa-dpvp/action-plan.md` — DPVP backlog - `/opt/data/wiki/vssa-enterprise-architect/action-plan.md` — EA consultancy - `/opt/data/wiki/cognitive-architect/action-plan.md` — CogArch backlog + pentest - `/opt/data/wiki/sap-delivery/action-plan.md` — SAP track - `/opt/data/wiki/distinguished-engineer/action-plan.md` — DE track - `/opt/data/wiki/infrastructure/README.md` — Services & endpoints - `/opt/data/wiki/infrastructure/gitea-repository-operations.md` — reusable Gitea repository runbook and skill reference - `/opt/data/wiki/infrastructure/network-v1.md` — global Internet address book and IP-level ownership/operation model - `/opt/data/wiki/discord/README.md` — Discord config - `/opt/data/wiki/hermes-setup/README.md` — Migration status - `/opt/data/wiki/behavior/README.md` — Operating rules