17 KiB
17 KiB
🧠 Knowledge Wiki — Brain Summary
Last updated: 2026-09-20 03:16 UTC
Workstreams & Status
| # | Workstream | Open Items | Priority |
|---|---|---|---|
| 🔵 | VSSA — DPVP | 21 active, 1 opportunity | Phase 2 opportunity, AWS tagging, Azure-cost onboarding documentation, access governance/monitoring, Jira-targeted role grants/revocations, project-level backups, Architecture Decision process, unit-testing options, backlog migration to Jira |
| 🟡 | VSSA — Enterprise Architect | 4 active | Scope decision, Gytis outreach, Atea & IBM institution engagement, Government Developer Portal |
| 🟢 | Cognitive Architect | 8 active | Oleg follow-up; Aurimas Nogis/Hermes security follow-up; ArchiMate investigation; Texture/Jenny integration follow-up; Anthropic architect certification; IBM Video Streaming; cogarch backlog |
| 🟣 | SAP Delivery Powered By AI | 1 active | Michael Martine material review |
| 🏅 | Distinguished Engineer | 3 active | Elizabeth docs + summary; FutureNow/Baltic AI/client-relations upskilling with Jurgis |
Total open: 38 items | Completed: 7 (env vars deployed; Apptio AWS-connection investigation and Azure-cost onboarding completed; CA-01, CA-03, CA-04, and CA-B01 completed)
Atea Cooperation
#atea-stormis the continuity ledger for Atea-related contracts, opportunities, audits, and RFPs.- Current tracked workstreams: VSSA AWS contract; VSSA DPVP contract and Phase 2 opportunity; Valstybės duomenų agentūra AWS portal audit; Lietuvos Geležinkeliai RFP; and two early Atea & IBM items (the user-provided title “Let's go to institutions” and a Government Developer Portal). Details for the two Atea & IBM items are not yet specified.
- DPVP Phase 2 discussion scope covers the portal, backend execution migration, VSSA on-premises onboarding, complex hybrid services, and organization scanning across AWS, Azure, and GCP. Ownership, prioritisation, estimates, dependencies, dates, scan baselines, and commercial route remain unconfirmed.
- VSSA AWS: an AWS Well-Architected Framework review has been proposed, not approved; workload/account scope, authorization, access, schedule, and remediation ownership remain open.
- DPVP backlog changes confirmed 2026-08-25: the Apptio AWS-connection investigation and Azure-cost onboarding are completed; the follow-up with Atea about TFE OIDC role assumption and July cost-estimation review were dropped. Open refinements include figuring out AWS tagging issues, documenting the Azure-cost onboarding approach, and having Julius locate documentation for the nightly AWS cost-allocation-tag enablement job.
- The portal audit is an opportunity only; active testing requires explicit written authorization and agreed scope.
- A consolidated executive summary was requested on 2026-07-29 and is maintained in
wiki/channels/1531661088209371198.md.
VSSA Client Investigation
- Current delivery (2026-09-04): repository
vssa-v1/documentationpublishes the Keycloak-protected VSSA - Clients & Systems Docusaurus site. The latest completed delivery records 290 clients, 551 canonical systems, 779 observations, and 118 contractor cards at commit701494d175266bd5e6683f53c58d08b7cd69bc0e; exact-head Actions task1874succeeded. RootAtSkic stopped and removed continuous-research job88833e00b4a2on 2026-09-04, so it no longer runs every two hours. The unassigned next range remains clients 121–140. - Entity classification (confirmed 2026-08-19): Valstybės skaitmeninių sprendimų agentūra (VSSA) is a central-government client body, not a system or commercial contractor. Government bodies that centrally operate/provide shared services must not be converted to
CTR-*entities merely because of that role. - Content organization (confirmed 2026-08-12): after Lego requested an immediate research-led overall-page improvement cycle, commit
1542674reorganized the portal around researched user tasks. Navigation is Overview, Clients, Systems, Methodology, and Data; deployment was validated by successful Actions run2335and representative HTTP-200 backend/browser checks. - Evidence/navigation requirements (confirmed 2026-08-12/14): Overview, Clients, Systems, Contractors, Methodology, and Data have dedicated sidebars; Clients, Systems, and Contractors each expose Overview plus an expanded Registry. Internally generated
SYS-*/CTR-*identifiers are documented, all generated client/system dossiers have References indexes, relationship evidence uses reusable cards, every client system observation links to its canonical system dossier, and every named contractor on an exact client-system row links to its Contractor Card. Multiple contractors are supported; unknown contractors remain explicit and unlinked. - VSSA skill governance (confirmed 2026-08-14):
vssa-clientsis authoritative invssa-v1-skills-code-agent/vssa-clients; mergeddocumentation-docusaurusis authoritative invssa-v1-skills-code-agent/documentation-docusaurusand includes the retiredgitea-docusaurus-projectscapabilities. Both runtime skills are symlinked to Gitea maintainer worktrees. The requestedcorp-v1-skills-code-agent/documentation-docusaurusrepository was unavailable and was not touched. - Procurement research (confirmed directive and validated workflow, 2026-08-12): Discord user
476287310627864587is the designated instructor for CVP IS. In addition to tender search, use exact organization search → identity-checked organization profile → PERŽIŪRĖTI VISUS PASKELBTUS SKELBIMUS, extracting the actualauthorityId/orgGroupIdand relevant notice PDFs. Job88833e00b4a2must map supported records to exact clients/systems and keep RFI/RFP/specification/bid stages distinct from award, implementation, production use, hosting, and completion. - Lifecycle evidence rule (confirmed 2026-08-12): a dated official announcement explicitly stating that a named system started operating/launched/went live is direct production-release evidence at the announcement’s stated precision; generic webpage metadata is not. Do not infer delivery kickoff from a production announcement.
Key People
- Lego (root_at_skic) — Owner, Enterprise Architect
- MartynasP (w4rl0ck_21) — Hermes migration lead
- Jerry — TrueNAS admin
- Julius Sulcas — DPVP, was on time off
- Rimvydas — Architect, reports to Dimitrian via Edvinas
- Gytis Račiukaitis — E-Gov Gateway contact
- Luis Diego Raga — Pentest senior tester (Sep 1–28)
- Oleg — Cognitive Architect stakeholder
- Andrius — Built cogarch skill
- Elizabeth — Distinguished Engineer track
- Jurgis — FutureNow, Baltic AI, client-relations, and broader upskilling contact
- Jenny — Mentioned Texture integration and other Cognitive Architect items; exact items and role still need clarification
- Michael Martine — SAP material contact
- Arunas Saltis — DNS naming convention (internal hosting)
Pending Reminders
- Follow up with Arunas Saltis — DNS naming convention (internal hosting) — added 2026-07-14
Infrastructure
- TrueNAS SCALE 26.0.0-BETA.2 at lego-cloud.eu ✅
- Gitea: gitea.lego-cloud.eu (org: home-v1) ✅
- General Gitea repository skill: ✅
gitea-repository-operations— reusable API + SSH workflow for any repo; full wiki runbook atwiki/infrastructure/gitea-repository-operations.md - Gitea API credential (confirmed 2026-08-02): use Bitwarden-provided
HL_V1_GITEA_ACCESS_TOKENforgitea.lego-cloud.eu; never useGITHUB_TOKENfor that instance or copy the Gitea token into/opt/data/.env. Bitwarden keys are exported without aliases and gateway restart is required after key changes. - Gitea recovery (confirmed 2026-08-11): Gitea
1.27.0crashed all SSH/Smart-HTTP Git-serving processes despite healthy web/API; upgrade to1.27.1restored API and both Git transports. The queued VSSA commit6fc42abwas pushed and remotely verified. - Gitea Pages pattern (verified 2026-08-11): Actions runners build repositories and publish to
/gondor-v1-gitea-pages/<organization>/<repository>/, exposed athttps://pages.apps.lego-cloud.eu/<organization>/<repository>/. The Pages dataset must be allowed bycontainer.valid_volumesand mounted into job containers.skic-v1-playground/documentationrun 2326 and the live site were verified. - Actions Docker (verified 2026-08-11): use the runner-mounted
/var/run/docker.sockdirectly (client29.6.2-1, Engine29.0.4). DinD is unnecessary and privileged DinD is not currently supported by this runner. - CogArch GitHub attribution (required 2026-08-25):
cogarch-githubcommits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution. - CogArch presentation governance (required 2026-09-04): channel-dedicated
cogarch-stormis maintained incognitive-architect-v1-skills-code-agent/cogarch-storm. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally usepowerpoint-ibm-template; that skill must always reference/loadpowerpointandpowerpoint-advanced-python. - CogArch Solution Factory / Argo evidence boundary (verified 2026-09-15): exact live and archived label queries for
architecture-id=arch_kiSj9jBKIreturned no Workflow. The deployed Processing template contains conversion, chunking, image description, and merge steps, but completed Workflows are deleted after 24 hours and the accessible archive is empty. A separatearch_xOQ5jks0bHigh-Level Insights failure reached the code agent and exhausted retries with exit code 201; its overwritten detailed log reportedly showed operation timeout/retry-limit failure. A fail-open Redis DNS warning appeared in that failed run but did not recur in the read-only-verified rerun pod, so it is not the established cause. - CogArch Solution Factory BYOT MVP (decided 2026-09-16): use one persistent OpenShift Secret per user, created/patched/deleted by the existing settings backend; do not introduce IBM Secrets Manager or a new secrets service initially. Require server-derived opaque names, backend ServiceAccount permissions limited to Secret
create/patch/deletewithout reads, admission restriction to labelledbyot-*objects, trusted WorkflowTemplates, no token leakage, and fail-closed behavior. Running workflows may retain old values; provider revocation and cluster-loss recovery remain separate concerns. - Emplonet v1 channel setup (confirmed 2026-09-08):
#emplonet-v1-generaland#emplonet-v1-ingridaeach have a dedicated local artifact workspace under/opt/data/channels/, a dedicated channel skill, and a private source repository inemplonet-v1-skills-code-agent; both are now included in the authoritative daily wiki scan and short config routing. - Lego CV workspace (confirmed 2026-09-14):
#lego-v1-cvuses/opt/data/workspaces/channels/lego-v1-cvand the privatelego-v1-skills-code-agent/lego-v1-cvchannel skill. The supplied CV source was converted into brand-neutral editable DOCX and PDF artifacts without embedded IBM logos while retaining professional content. - Wiki health check (repaired 2026-09-13):
/opt/data/scripts/health-check.shno longer creates invalid multiline0\n0counts whengrep -cfinds no match, and its Discord test recognizes the gateway's actual inbound/send activity log forms.bash -nand a complete rerun passed all four checks; authenticated Discord REST still remains the source of truth for channel-scan coverage. - Wiki usability/format questions (open 2026-09-19): RootAtSkic wants a practical way to discover/retrieve channel wiki Markdown files instead of relying on numeric Discord-ID filenames, and asked whether migration to a Google “OKF” format would help. “OKF” and the desired delivery interface remain unclear; no migration is authorized.
- Jev evaluation (open 2026-09-19): investigate Jev’s practical Home v1 uses, TrueNAS app availability/deployability, and likely impact; the request did not authorize deployment.
- Operator communication preference (confirmed 2026-09-19): use retained knowledge of RootAtSkic’s character/principles and provide concise, decision-oriented summaries rather than large reading dumps.
- Hermes delegation baseline (live 2026-09-12):
max_concurrent_children: 10andmax_spawn_depth: 1; RootAtSkic asked how to increase sub-agent capacity, but no configuration change was authorized or made. - Home v1 skill-repository descriptions (status 2026-09-09): all 60 repositories in
home-v1-skills-code-agenthave non-empty Gitea descriptions, but the requested 3–5 sentence standard is met by 58/60.hermes-codexanddevelopment-durable-wave-executionstill have one-sentence descriptions and remain open remediation. - TrueNAS channel skill (confirmed 2026-08-26):
home-v1--truenasis maintained in private Gitea repositoryhome-v1-skills-code-agent/home-v1--truenasand loaded directly from its checkout. Commit634e0e6passed 10 offline tests, Gitea Actions task1398, remote readback, and a real authenticated read-only WebSocket query. Runtime access uses Bitwarden keysHL_V1_TRUENAS_URLandHL_V1_TRUENAS_API_KEY. The current IP-based URL fails strict certificate identity validation; use a certificate-matching DNS/CA path rather than permanent--insecuremode. - Gondor v1 (2026-08-02): Hermes SSH access as
legois verified to Osgiliath 000 and both Minas Tirith workers; use thegondor-v1-nodesskill. Open ingress incident: Argo CD's hostPort 80/443ingress-nginxconflicts with Osgiliath's system Nginx; repair throughhome-v1/gondor-v1.git, not a transient live patch. - Hermes outage (2026-08-04–11): confirmed Codex quota exhaustion first blocked model responses while Discord/cron remained alive; a separate likely host/container-runtime failure then stopped all gateway, scheduler, log, and health progress after 2026-08-04 14:00:42 UTC. Physical restart at 2026-08-11 00:11:40 restored service without Hermes repair. Exact host-level trigger remains UNKNOWN because previous-boot TrueNAS/kernel/ZFS/runtime/hardware telemetry is unavailable inside the container.
- world-v1/network-v1: ✅ global Internet address book; IP-level mapping now separates registry holder, route origin, operator, and service. Initial records:
0.0.0.0and1.1.1.1; wiki page atwiki/infrastructure/network-v1.md - Keycloak: keycloak.lego-cloud.eu ✅
- Hermes Dashboard: jarvis-jr-v1.lego-cloud.eu ✅
- STT Whisper: 192.168.1.218:39000 🔲
- Piper TTS: 192.168.1.218:39001 🔲
Hermes Migration
- Status: ✅ Live, cron active, backlog ownership officially handed to Hermes role (2026-07-16)
- UPGRADED: Hermes is now sole agent on SKIC Discord server (2026-07-17 07:44 UTC, confirmed by Lego)
- Hermes role ID:
1527260007307935776| Discord permissions: Administrator ✅ - morning-standup cron ✅ first successful fire: 2026-07-17 05:01 UTC; enhanced 2026-07-27 to include drawio-desktop#2499 monitoring (Lego directive: merge into standup, not separate job)
- 🆕 Lego directive (2026-07-27 10:57 UTC): start building a dedicated skill for Hermes itself
- Backlog files:
wiki/vssa-dpvp/action-plan.md,wiki/cognitive-architect/action-plan.md - MartynasP model-access documentation: ⏳ still pending
- Gitea wiki sync ✅ — pushing to skic-v1-playground/knowledge-wiki on every run (started 2026-07-17 09:30 UTC)
- ✅ Gitea push restored — after Lego requested another access check at 11:08 UTC, SSH access to
origin/mainwas verified at 15:08 UTC. Remote and localmainboth pointed to35eb834; all previously queued commits are now on Gitea. - 🔴 Lego directive (2026-07-20 08:49 UTC): "please fix your issues yourself" — Hermes must resolve the Gitea push issue autonomously
- ⚠️ Responsiveness incident (2026-07-20 09:54–11:03 UTC): Lego repeatedly asked whether the issues were fixed and what Hermes was doing; visible progress/status updates are expected during incident resolution.
- Voice behavior (confirmed 2026-07-31): generate clear, human-friendly, conversational responses and let the participant guide with questions; avoid dense written-style delivery in live voice sessions.
Wiki Files
/opt/data/wiki/vssa-dpvp/action-plan.md— DPVP backlog/opt/data/wiki/vssa-enterprise-architect/action-plan.md— EA consultancy/opt/data/wiki/cognitive-architect/action-plan.md— CogArch backlog + pentest/opt/data/wiki/sap-delivery/action-plan.md— SAP track/opt/data/wiki/distinguished-engineer/action-plan.md— DE track/opt/data/wiki/infrastructure/README.md— Services & endpoints/opt/data/wiki/infrastructure/gitea-repository-operations.md— reusable Gitea repository runbook and skill reference/opt/data/wiki/infrastructure/network-v1.md— global Internet address book and IP-level ownership/operation model/opt/data/wiki/discord/README.md— Discord config/opt/data/wiki/hermes-setup/README.md— Migration status/opt/data/wiki/behavior/README.md— Operating rules