115 lines
17 KiB
Markdown
115 lines
17 KiB
Markdown
# 🧠 Knowledge Wiki — Brain Summary
|
||
|
||
_Last updated: 2026-09-20 03:16 UTC_
|
||
|
||
## Workstreams & Status
|
||
|
||
| # | Workstream | Open Items | Priority |
|
||
|---|-----------|-----------|----------|
|
||
| 🔵 | VSSA — DPVP | 21 active, 1 opportunity | Phase 2 opportunity, AWS tagging, Azure-cost onboarding documentation, access governance/monitoring, Jira-targeted role grants/revocations, project-level backups, Architecture Decision process, unit-testing options, backlog migration to Jira |
|
||
| 🟡 | VSSA — Enterprise Architect | 4 active | Scope decision, Gytis outreach, Atea & IBM institution engagement, Government Developer Portal |
|
||
| 🟢 | Cognitive Architect | 8 active | Oleg follow-up; Aurimas Nogis/Hermes security follow-up; ArchiMate investigation; Texture/Jenny integration follow-up; Anthropic architect certification; IBM Video Streaming; cogarch backlog |
|
||
| 🟣 | SAP Delivery Powered By AI | 1 active | Michael Martine material review |
|
||
| 🏅 | Distinguished Engineer | 3 active | Elizabeth docs + summary; FutureNow/Baltic AI/client-relations upskilling with Jurgis |
|
||
|
||
**Total open:** 38 items | **Completed:** 7 (env vars deployed; Apptio AWS-connection investigation and Azure-cost onboarding completed; CA-01, CA-03, CA-04, and CA-B01 completed)
|
||
|
||
## Atea Cooperation
|
||
|
||
- `#atea-storm` is the continuity ledger for Atea-related contracts, opportunities, audits, and RFPs.
|
||
- Current tracked workstreams: VSSA AWS contract; VSSA DPVP contract and Phase 2 opportunity; Valstybės duomenų agentūra AWS portal audit; Lietuvos Geležinkeliai RFP; and two early Atea & IBM items (the user-provided title “Let's go to institutions” and a Government Developer Portal). Details for the two Atea & IBM items are not yet specified.
|
||
- DPVP Phase 2 discussion scope covers the portal, backend execution migration, VSSA on-premises onboarding, complex hybrid services, and organization scanning across AWS, Azure, and GCP. Ownership, prioritisation, estimates, dependencies, dates, scan baselines, and commercial route remain unconfirmed.
|
||
- VSSA AWS: an AWS Well-Architected Framework review has been proposed, not approved; workload/account scope, authorization, access, schedule, and remediation ownership remain open.
|
||
- DPVP backlog changes confirmed 2026-08-25: the Apptio AWS-connection investigation and Azure-cost onboarding are completed; the follow-up with Atea about TFE OIDC role assumption and July cost-estimation review were dropped. Open refinements include figuring out AWS tagging issues, documenting the Azure-cost onboarding approach, and having Julius locate documentation for the nightly AWS cost-allocation-tag enablement job.
|
||
- The portal audit is an opportunity only; active testing requires explicit written authorization and agreed scope.
|
||
- A consolidated executive summary was requested on 2026-07-29 and is maintained in `wiki/channels/1531661088209371198.md`.
|
||
|
||
## VSSA Client Investigation
|
||
|
||
- **Current delivery (2026-09-04):** repository `vssa-v1/documentation` publishes the Keycloak-protected **VSSA - Clients & Systems** Docusaurus site. The latest completed delivery records 290 clients, 551 canonical systems, 779 observations, and 118 contractor cards at commit `701494d175266bd5e6683f53c58d08b7cd69bc0e`; exact-head Actions task `1874` succeeded. RootAtSkic stopped and removed continuous-research job `88833e00b4a2` on 2026-09-04, so it no longer runs every two hours. The unassigned next range remains clients 121–140.
|
||
- **Entity classification (confirmed 2026-08-19):** Valstybės skaitmeninių sprendimų agentūra (VSSA) is a central-government client body, not a system or commercial contractor. Government bodies that centrally operate/provide shared services must not be converted to `CTR-*` entities merely because of that role.
|
||
- **Content organization (confirmed 2026-08-12):** after Lego requested an immediate research-led overall-page improvement cycle, commit `1542674` reorganized the portal around researched user tasks. Navigation is Overview, Clients, Systems, Methodology, and Data; deployment was validated by successful Actions run `2335` and representative HTTP-200 backend/browser checks.
|
||
- **Evidence/navigation requirements (confirmed 2026-08-12/14):** Overview, Clients, Systems, Contractors, Methodology, and Data have dedicated sidebars; Clients, Systems, and Contractors each expose Overview plus an expanded Registry. Internally generated `SYS-*`/`CTR-*` identifiers are documented, all generated client/system dossiers have References indexes, relationship evidence uses reusable cards, every client system observation links to its canonical system dossier, and every named contractor on an exact client-system row links to its Contractor Card. Multiple contractors are supported; unknown contractors remain explicit and unlinked.
|
||
- **VSSA skill governance (confirmed 2026-08-14):** `vssa-clients` is authoritative in `vssa-v1-skills-code-agent/vssa-clients`; merged `documentation-docusaurus` is authoritative in `vssa-v1-skills-code-agent/documentation-docusaurus` and includes the retired `gitea-docusaurus-projects` capabilities. Both runtime skills are symlinked to Gitea maintainer worktrees. The requested `corp-v1-skills-code-agent/documentation-docusaurus` repository was unavailable and was not touched.
|
||
- **Procurement research (confirmed directive and validated workflow, 2026-08-12):** Discord user `476287310627864587` is the designated instructor for CVP IS. In addition to tender search, use exact organization search → identity-checked organization profile → **PERŽIŪRĖTI VISUS PASKELBTUS SKELBIMUS**, extracting the actual `authorityId`/`orgGroupId` and relevant notice PDFs. Job `88833e00b4a2` must map supported records to exact clients/systems and keep RFI/RFP/specification/bid stages distinct from award, implementation, production use, hosting, and completion.
|
||
- **Lifecycle evidence rule (confirmed 2026-08-12):** a dated official announcement explicitly stating that a named system started operating/launched/went live is direct production-release evidence at the announcement’s stated precision; generic webpage metadata is not. Do not infer delivery kickoff from a production announcement.
|
||
|
||
## Key People
|
||
|
||
- **Lego** (root_at_skic) — Owner, Enterprise Architect
|
||
- **MartynasP** (w4rl0ck_21) — Hermes migration lead
|
||
- **Jerry** — TrueNAS admin
|
||
- **Julius Sulcas** — DPVP, was on time off
|
||
- **Rimvydas** — Architect, reports to Dimitrian via Edvinas
|
||
- **Gytis Račiukaitis** — E-Gov Gateway contact
|
||
- **Luis Diego Raga** — Pentest senior tester (Sep 1–28)
|
||
- **Oleg** — Cognitive Architect stakeholder
|
||
- **Andrius** — Built cogarch skill
|
||
- **Elizabeth** — Distinguished Engineer track
|
||
- **Jurgis** — FutureNow, Baltic AI, client-relations, and broader upskilling contact
|
||
- **Jenny** — Mentioned Texture integration and other Cognitive Architect items; exact items and role still need clarification
|
||
- **Michael Martine** — SAP material contact
|
||
- **Arunas Saltis** — DNS naming convention (internal hosting)
|
||
|
||
## Pending Reminders
|
||
|
||
- [ ] Follow up with Arunas Saltis — DNS naming convention (internal hosting) — added 2026-07-14
|
||
- [ ] Check the theorem about the uncountability of logics — added 2026-09-23
|
||
|
||
## Infrastructure
|
||
|
||
- TrueNAS SCALE 26.0.0-BETA.2 at lego-cloud.eu ✅
|
||
- Gitea: gitea.lego-cloud.eu (org: home-v1) ✅
|
||
- **General Gitea repository skill:** ✅ `gitea-repository-operations` — reusable API + SSH workflow for any repo; full wiki runbook at `wiki/infrastructure/gitea-repository-operations.md`
|
||
- **Gitea API credential (confirmed 2026-08-02):** use Bitwarden-provided `HL_V1_GITEA_ACCESS_TOKEN` for `gitea.lego-cloud.eu`; never use `GITHUB_TOKEN` for that instance or copy the Gitea token into `/opt/data/.env`. Bitwarden keys are exported without aliases and gateway restart is required after key changes.
|
||
- **Gitea recovery (confirmed 2026-08-11):** Gitea `1.27.0` crashed all SSH/Smart-HTTP Git-serving processes despite healthy web/API; upgrade to `1.27.1` restored API and both Git transports. The queued VSSA commit `6fc42ab` was pushed and remotely verified.
|
||
- **Gitea Pages pattern (verified 2026-08-11):** Actions runners build repositories and publish to `/gondor-v1-gitea-pages/<organization>/<repository>/`, exposed at `https://pages.apps.lego-cloud.eu/<organization>/<repository>/`. The Pages dataset must be allowed by `container.valid_volumes` and mounted into job containers. `skic-v1-playground/documentation` run 2326 and the live site were verified.
|
||
- **Actions Docker (verified 2026-08-11):** use the runner-mounted `/var/run/docker.sock` directly (client `29.6.2-1`, Engine `29.0.4`). DinD is unnecessary and privileged DinD is not currently supported by this runner.
|
||
- **CogArch GitHub attribution (required 2026-08-25):** `cogarch-github` commits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution.
|
||
- **CogArch presentation governance (required 2026-09-04):** channel-dedicated `cogarch-storm` is maintained in `cognitive-architect-v1-skills-code-agent/cogarch-storm`. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally use `powerpoint-ibm-template`; that skill must always reference/load `powerpoint` and `powerpoint-advanced-python`.
|
||
- **CogArch Solution Factory / Argo evidence boundary (verified 2026-09-15):** exact live and archived label queries for `architecture-id=arch_kiSj9jBKI` returned no Workflow. The deployed Processing template contains conversion, chunking, image description, and merge steps, but completed Workflows are deleted after 24 hours and the accessible archive is empty. A separate `arch_xOQ5jks0b` High-Level Insights failure reached the code agent and exhausted retries with exit code 201; its overwritten detailed log reportedly showed operation timeout/retry-limit failure. A fail-open Redis DNS warning appeared in that failed run but did not recur in the read-only-verified rerun pod, so it is not the established cause.
|
||
- **CogArch Solution Factory BYOT MVP (decided 2026-09-16):** use one persistent OpenShift Secret per user, created/patched/deleted by the existing settings backend; do not introduce IBM Secrets Manager or a new secrets service initially. Require server-derived opaque names, backend ServiceAccount permissions limited to Secret `create`/`patch`/`delete` without reads, admission restriction to labelled `byot-*` objects, trusted WorkflowTemplates, no token leakage, and fail-closed behavior. Running workflows may retain old values; provider revocation and cluster-loss recovery remain separate concerns.
|
||
- **Emplonet v1 channel setup (confirmed 2026-09-08):** `#emplonet-v1-general` and `#emplonet-v1-ingrida` each have a dedicated local artifact workspace under `/opt/data/channels/`, a dedicated channel skill, and a private source repository in `emplonet-v1-skills-code-agent`; both are now included in the authoritative daily wiki scan and short config routing.
|
||
- **Lego CV workspace (confirmed 2026-09-14):** `#lego-v1-cv` uses `/opt/data/workspaces/channels/lego-v1-cv` and the private `lego-v1-skills-code-agent/lego-v1-cv` channel skill. The supplied CV source was converted into brand-neutral editable DOCX and PDF artifacts without embedded IBM logos while retaining professional content.
|
||
- **Wiki health check (repaired 2026-09-13):** `/opt/data/scripts/health-check.sh` no longer creates invalid multiline `0\n0` counts when `grep -c` finds no match, and its Discord test recognizes the gateway's actual inbound/send activity log forms. `bash -n` and a complete rerun passed all four checks; authenticated Discord REST still remains the source of truth for channel-scan coverage.
|
||
- **Wiki usability/format questions (open 2026-09-19):** RootAtSkic wants a practical way to discover/retrieve channel wiki Markdown files instead of relying on numeric Discord-ID filenames, and asked whether migration to a Google “OKF” format would help. “OKF” and the desired delivery interface remain unclear; no migration is authorized.
|
||
- **Jev evaluation (open 2026-09-19):** investigate Jev’s practical Home v1 uses, TrueNAS app availability/deployability, and likely impact; the request did not authorize deployment.
|
||
- **Operator communication preference (confirmed 2026-09-19):** use retained knowledge of RootAtSkic’s character/principles and provide concise, decision-oriented summaries rather than large reading dumps.
|
||
- **Hermes delegation baseline (live 2026-09-12):** `max_concurrent_children: 10` and `max_spawn_depth: 1`; RootAtSkic asked how to increase sub-agent capacity, but no configuration change was authorized or made.
|
||
- **Home v1 skill-repository descriptions (status 2026-09-09):** all 60 repositories in `home-v1-skills-code-agent` have non-empty Gitea descriptions, but the requested 3–5 sentence standard is met by 58/60. `hermes-codex` and `development-durable-wave-execution` still have one-sentence descriptions and remain open remediation.
|
||
- **TrueNAS channel skill (confirmed 2026-08-26):** `home-v1--truenas` is maintained in private Gitea repository `home-v1-skills-code-agent/home-v1--truenas` and loaded directly from its checkout. Commit `634e0e6` passed 10 offline tests, Gitea Actions task `1398`, remote readback, and a real authenticated read-only WebSocket query. Runtime access uses Bitwarden keys `HL_V1_TRUENAS_URL` and `HL_V1_TRUENAS_API_KEY`. The current IP-based URL fails strict certificate identity validation; use a certificate-matching DNS/CA path rather than permanent `--insecure` mode.
|
||
- **Gondor v1 (2026-08-02):** Hermes SSH access as `lego` is verified to Osgiliath 000 and both Minas Tirith workers; use the `gondor-v1-nodes` skill. Open ingress incident: Argo CD's hostPort 80/443 `ingress-nginx` conflicts with Osgiliath's system Nginx; repair through `home-v1/gondor-v1.git`, not a transient live patch.
|
||
- **Hermes outage (2026-08-04–11):** confirmed Codex quota exhaustion first blocked model responses while Discord/cron remained alive; a separate likely host/container-runtime failure then stopped all gateway, scheduler, log, and health progress after 2026-08-04 14:00:42 UTC. Physical restart at 2026-08-11 00:11:40 restored service without Hermes repair. Exact host-level trigger remains **UNKNOWN** because previous-boot TrueNAS/kernel/ZFS/runtime/hardware telemetry is unavailable inside the container.
|
||
- **world-v1/network-v1:** ✅ global Internet address book; IP-level mapping now separates registry holder, route origin, operator, and service. Initial records: `0.0.0.0` and `1.1.1.1`; wiki page at `wiki/infrastructure/network-v1.md`
|
||
- Keycloak: keycloak.lego-cloud.eu ✅
|
||
- Hermes Dashboard: jarvis-jr-v1.lego-cloud.eu ✅
|
||
- STT Whisper: 192.168.1.218:39000 🔲
|
||
- Piper TTS: 192.168.1.218:39001 🔲
|
||
|
||
## Hermes Migration
|
||
- Status: ✅ Live, cron active, **backlog ownership officially handed to Hermes role** (2026-07-16)
|
||
- **UPGRADED: Hermes is now sole agent on SKIC Discord server** (2026-07-17 07:44 UTC, confirmed by Lego)
|
||
- Hermes role ID: `1527260007307935776` | Discord permissions: Administrator ✅
|
||
- **morning-standup cron** ✅ first successful fire: 2026-07-17 05:01 UTC; enhanced 2026-07-27 to include drawio-desktop#2499 monitoring (Lego directive: merge into standup, not separate job)
|
||
- 🆕 **Lego directive (2026-07-27 10:57 UTC):** start building a dedicated skill for Hermes itself
|
||
- Backlog files: `wiki/vssa-dpvp/action-plan.md`, `wiki/cognitive-architect/action-plan.md`
|
||
- MartynasP model-access documentation: ⏳ still pending
|
||
- **Gitea wiki sync** ✅ — pushing to skic-v1-playground/knowledge-wiki on every run (started 2026-07-17 09:30 UTC)
|
||
- ✅ **Gitea push restored** — after Lego requested another access check at 11:08 UTC, SSH access to `origin/main` was verified at 15:08 UTC. Remote and local `main` both pointed to `35eb834`; all previously queued commits are now on Gitea.
|
||
- 🔴 **Lego directive (2026-07-20 08:49 UTC):** "please fix your issues yourself" — Hermes must resolve the Gitea push issue autonomously
|
||
- ⚠️ **Responsiveness incident (2026-07-20 09:54–11:03 UTC):** Lego repeatedly asked whether the issues were fixed and what Hermes was doing; visible progress/status updates are expected during incident resolution.
|
||
- **Voice behavior (confirmed 2026-07-31):** generate clear, human-friendly, conversational responses and let the participant guide with questions; avoid dense written-style delivery in live voice sessions.
|
||
|
||
## Wiki Files
|
||
- `/opt/data/wiki/vssa-dpvp/action-plan.md` — DPVP backlog
|
||
- `/opt/data/wiki/vssa-enterprise-architect/action-plan.md` — EA consultancy
|
||
- `/opt/data/wiki/cognitive-architect/action-plan.md` — CogArch backlog + pentest
|
||
- `/opt/data/wiki/sap-delivery/action-plan.md` — SAP track
|
||
- `/opt/data/wiki/distinguished-engineer/action-plan.md` — DE track
|
||
- `/opt/data/wiki/infrastructure/README.md` — Services & endpoints
|
||
- `/opt/data/wiki/infrastructure/gitea-repository-operations.md` — reusable Gitea repository runbook and skill reference
|
||
- `/opt/data/wiki/infrastructure/network-v1.md` — global Internet address book and IP-level ownership/operation model
|
||
- `/opt/data/wiki/discord/README.md` — Discord config
|
||
- `/opt/data/wiki/hermes-setup/README.md` — Migration status
|
||
- `/opt/data/wiki/behavior/README.md` — Operating rules
|