Files
knowledge-wiki/brain.md
T

16 KiB
Raw Blame History

🧠 Knowledge Wiki — Brain Summary

Last updated: 2026-09-17 03:13 UTC

Workstreams & Status

# Workstream Open Items Priority
🔵 VSSA — DPVP 21 active, 1 opportunity Phase 2 opportunity, AWS tagging, Azure-cost onboarding documentation, access governance/monitoring, Jira-targeted role grants/revocations, project-level backups, Architecture Decision process, unit-testing options, backlog migration to Jira
🟡 VSSA — Enterprise Architect 4 active Scope decision, Gytis outreach, Atea & IBM institution engagement, Government Developer Portal
🟢 Cognitive Architect 8 active Oleg follow-up; Aurimas Nogis/Hermes security follow-up; ArchiMate investigation; Texture/Jenny integration follow-up; Anthropic architect certification; IBM Video Streaming; cogarch backlog
🟣 SAP Delivery Powered By AI 1 active Michael Martine material review
🏅 Distinguished Engineer 3 active Elizabeth docs + summary; FutureNow/Baltic AI/client-relations upskilling with Jurgis

Total open: 38 items | Completed: 7 (env vars deployed; Apptio AWS-connection investigation and Azure-cost onboarding completed; CA-01, CA-03, CA-04, and CA-B01 completed)

Atea Cooperation

  • #atea-storm is the continuity ledger for Atea-related contracts, opportunities, audits, and RFPs.
  • Current tracked workstreams: VSSA AWS contract; VSSA DPVP contract and Phase 2 opportunity; Valstybės duomenų agentūra AWS portal audit; Lietuvos Geležinkeliai RFP; and two early Atea & IBM items (the user-provided title “Let's go to institutions” and a Government Developer Portal). Details for the two Atea & IBM items are not yet specified.
  • DPVP Phase 2 discussion scope covers the portal, backend execution migration, VSSA on-premises onboarding, complex hybrid services, and organization scanning across AWS, Azure, and GCP. Ownership, prioritisation, estimates, dependencies, dates, scan baselines, and commercial route remain unconfirmed.
  • VSSA AWS: an AWS Well-Architected Framework review has been proposed, not approved; workload/account scope, authorization, access, schedule, and remediation ownership remain open.
  • DPVP backlog changes confirmed 2026-08-25: the Apptio AWS-connection investigation and Azure-cost onboarding are completed; the follow-up with Atea about TFE OIDC role assumption and July cost-estimation review were dropped. Open refinements include figuring out AWS tagging issues, documenting the Azure-cost onboarding approach, and having Julius locate documentation for the nightly AWS cost-allocation-tag enablement job.
  • The portal audit is an opportunity only; active testing requires explicit written authorization and agreed scope.
  • A consolidated executive summary was requested on 2026-07-29 and is maintained in wiki/channels/1531661088209371198.md.

VSSA Client Investigation

  • Current delivery (2026-09-04): repository vssa-v1/documentation publishes the Keycloak-protected VSSA - Clients & Systems Docusaurus site. The latest completed delivery records 290 clients, 551 canonical systems, 779 observations, and 118 contractor cards at commit 701494d175266bd5e6683f53c58d08b7cd69bc0e; exact-head Actions task 1874 succeeded. RootAtSkic stopped and removed continuous-research job 88833e00b4a2 on 2026-09-04, so it no longer runs every two hours. The unassigned next range remains clients 121–140.
  • Entity classification (confirmed 2026-08-19): Valstybės skaitmeninių sprendimų agentūra (VSSA) is a central-government client body, not a system or commercial contractor. Government bodies that centrally operate/provide shared services must not be converted to CTR-* entities merely because of that role.
  • Content organization (confirmed 2026-08-12): after Lego requested an immediate research-led overall-page improvement cycle, commit 1542674 reorganized the portal around researched user tasks. Navigation is Overview, Clients, Systems, Methodology, and Data; deployment was validated by successful Actions run 2335 and representative HTTP-200 backend/browser checks.
  • Evidence/navigation requirements (confirmed 2026-08-12/14): Overview, Clients, Systems, Contractors, Methodology, and Data have dedicated sidebars; Clients, Systems, and Contractors each expose Overview plus an expanded Registry. Internally generated SYS-*/CTR-* identifiers are documented, all generated client/system dossiers have References indexes, relationship evidence uses reusable cards, every client system observation links to its canonical system dossier, and every named contractor on an exact client-system row links to its Contractor Card. Multiple contractors are supported; unknown contractors remain explicit and unlinked.
  • VSSA skill governance (confirmed 2026-08-14): vssa-clients is authoritative in vssa-v1-skills-code-agent/vssa-clients; merged documentation-docusaurus is authoritative in vssa-v1-skills-code-agent/documentation-docusaurus and includes the retired gitea-docusaurus-projects capabilities. Both runtime skills are symlinked to Gitea maintainer worktrees. The requested corp-v1-skills-code-agent/documentation-docusaurus repository was unavailable and was not touched.
  • Procurement research (confirmed directive and validated workflow, 2026-08-12): Discord user 476287310627864587 is the designated instructor for CVP IS. In addition to tender search, use exact organization search → identity-checked organization profile → PERŽIŪRĖTI VISUS PASKELBTUS SKELBIMUS, extracting the actual authorityId/orgGroupId and relevant notice PDFs. Job 88833e00b4a2 must map supported records to exact clients/systems and keep RFI/RFP/specification/bid stages distinct from award, implementation, production use, hosting, and completion.
  • Lifecycle evidence rule (confirmed 2026-08-12): a dated official announcement explicitly stating that a named system started operating/launched/went live is direct production-release evidence at the announcement’s stated precision; generic webpage metadata is not. Do not infer delivery kickoff from a production announcement.

Key People

  • Lego (root_at_skic) — Owner, Enterprise Architect
  • MartynasP (w4rl0ck_21) — Hermes migration lead
  • Jerry — TrueNAS admin
  • Julius Sulcas — DPVP, was on time off
  • Rimvydas — Architect, reports to Dimitrian via Edvinas
  • Gytis Račiukaitis — E-Gov Gateway contact
  • Luis Diego Raga — Pentest senior tester (Sep 1–28)
  • Oleg — Cognitive Architect stakeholder
  • Andrius — Built cogarch skill
  • Elizabeth — Distinguished Engineer track
  • Jurgis — FutureNow, Baltic AI, client-relations, and broader upskilling contact
  • Jenny — Mentioned Texture integration and other Cognitive Architect items; exact items and role still need clarification
  • Michael Martine — SAP material contact
  • Arunas Saltis — DNS naming convention (internal hosting)

Pending Reminders

  • Follow up with Arunas Saltis — DNS naming convention (internal hosting) — added 2026-07-14

Infrastructure

  • TrueNAS SCALE 26.0.0-BETA.2 at lego-cloud.eu ✅
  • Gitea: gitea.lego-cloud.eu (org: home-v1) ✅
  • General Gitea repository skill: ✅ gitea-repository-operations — reusable API + SSH workflow for any repo; full wiki runbook at wiki/infrastructure/gitea-repository-operations.md
  • Gitea API credential (confirmed 2026-08-02): use Bitwarden-provided HL_V1_GITEA_ACCESS_TOKEN for gitea.lego-cloud.eu; never use GITHUB_TOKEN for that instance or copy the Gitea token into /opt/data/.env. Bitwarden keys are exported without aliases and gateway restart is required after key changes.
  • Gitea recovery (confirmed 2026-08-11): Gitea 1.27.0 crashed all SSH/Smart-HTTP Git-serving processes despite healthy web/API; upgrade to 1.27.1 restored API and both Git transports. The queued VSSA commit 6fc42ab was pushed and remotely verified.
  • Gitea Pages pattern (verified 2026-08-11): Actions runners build repositories and publish to /gondor-v1-gitea-pages/<organization>/<repository>/, exposed at https://pages.apps.lego-cloud.eu/<organization>/<repository>/. The Pages dataset must be allowed by container.valid_volumes and mounted into job containers. skic-v1-playground/documentation run 2326 and the live site were verified.
  • Actions Docker (verified 2026-08-11): use the runner-mounted /var/run/docker.sock directly (client 29.6.2-1, Engine 29.0.4). DinD is unnecessary and privileged DinD is not currently supported by this runner.
  • CogArch GitHub attribution (required 2026-08-25): cogarch-github commits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution.
  • CogArch presentation governance (required 2026-09-04): channel-dedicated cogarch-storm is maintained in cognitive-architect-v1-skills-code-agent/cogarch-storm. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally use powerpoint-ibm-template; that skill must always reference/load powerpoint and powerpoint-advanced-python.
  • CogArch Solution Factory / Argo evidence boundary (verified 2026-09-15): exact live and archived label queries for architecture-id=arch_kiSj9jBKI returned no Workflow. The deployed Processing template contains conversion, chunking, image description, and merge steps, but completed Workflows are deleted after 24 hours and the accessible archive is empty. A separate arch_xOQ5jks0b High-Level Insights failure reached the code agent and exhausted retries with exit code 201; its overwritten detailed log reportedly showed operation timeout/retry-limit failure. A fail-open Redis DNS warning appeared in that failed run but did not recur in the read-only-verified rerun pod, so it is not the established cause.
  • CogArch Solution Factory BYOT MVP (decided 2026-09-16): use one persistent OpenShift Secret per user, created/patched/deleted by the existing settings backend; do not introduce IBM Secrets Manager or a new secrets service initially. Require server-derived opaque names, backend ServiceAccount permissions limited to Secret create/patch/delete without reads, admission restriction to labelled byot-* objects, trusted WorkflowTemplates, no token leakage, and fail-closed behavior. Running workflows may retain old values; provider revocation and cluster-loss recovery remain separate concerns.
  • Emplonet v1 channel setup (confirmed 2026-09-08): #emplonet-v1-general and #emplonet-v1-ingrida each have a dedicated local artifact workspace under /opt/data/channels/, a dedicated channel skill, and a private source repository in emplonet-v1-skills-code-agent; both are now included in the authoritative daily wiki scan and short config routing.
  • Lego CV workspace (confirmed 2026-09-14): #lego-v1-cv uses /opt/data/workspaces/channels/lego-v1-cv and the private lego-v1-skills-code-agent/lego-v1-cv channel skill. The supplied CV source was converted into brand-neutral editable DOCX and PDF artifacts without embedded IBM logos while retaining professional content.
  • Wiki health check (repaired 2026-09-13): /opt/data/scripts/health-check.sh no longer creates invalid multiline 0\n0 counts when grep -c finds no match, and its Discord test recognizes the gateway's actual inbound/send activity log forms. bash -n and a complete rerun passed all four checks; authenticated Discord REST still remains the source of truth for channel-scan coverage.
  • Hermes delegation baseline (live 2026-09-12): max_concurrent_children: 10 and max_spawn_depth: 1; RootAtSkic asked how to increase sub-agent capacity, but no configuration change was authorized or made.
  • Home v1 skill-repository descriptions (status 2026-09-09): all 60 repositories in home-v1-skills-code-agent have non-empty Gitea descriptions, but the requested 3–5 sentence standard is met by 58/60. hermes-codex and development-durable-wave-execution still have one-sentence descriptions and remain open remediation.
  • TrueNAS channel skill (confirmed 2026-08-26): home-v1--truenas is maintained in private Gitea repository home-v1-skills-code-agent/home-v1--truenas and loaded directly from its checkout. Commit 634e0e6 passed 10 offline tests, Gitea Actions task 1398, remote readback, and a real authenticated read-only WebSocket query. Runtime access uses Bitwarden keys HL_V1_TRUENAS_URL and HL_V1_TRUENAS_API_KEY. The current IP-based URL fails strict certificate identity validation; use a certificate-matching DNS/CA path rather than permanent --insecure mode.
  • Gondor v1 (2026-08-02): Hermes SSH access as lego is verified to Osgiliath 000 and both Minas Tirith workers; use the gondor-v1-nodes skill. Open ingress incident: Argo CD's hostPort 80/443 ingress-nginx conflicts with Osgiliath's system Nginx; repair through home-v1/gondor-v1.git, not a transient live patch.
  • Hermes outage (2026-08-04–11): confirmed Codex quota exhaustion first blocked model responses while Discord/cron remained alive; a separate likely host/container-runtime failure then stopped all gateway, scheduler, log, and health progress after 2026-08-04 14:00:42 UTC. Physical restart at 2026-08-11 00:11:40 restored service without Hermes repair. Exact host-level trigger remains UNKNOWN because previous-boot TrueNAS/kernel/ZFS/runtime/hardware telemetry is unavailable inside the container.
  • world-v1/network-v1: ✅ global Internet address book; IP-level mapping now separates registry holder, route origin, operator, and service. Initial records: 0.0.0.0 and 1.1.1.1; wiki page at wiki/infrastructure/network-v1.md
  • Keycloak: keycloak.lego-cloud.eu ✅
  • Hermes Dashboard: jarvis-jr-v1.lego-cloud.eu ✅
  • STT Whisper: 192.168.1.218:39000 🔲
  • Piper TTS: 192.168.1.218:39001 🔲

Hermes Migration

  • Status: ✅ Live, cron active, backlog ownership officially handed to Hermes role (2026-07-16)
  • UPGRADED: Hermes is now sole agent on SKIC Discord server (2026-07-17 07:44 UTC, confirmed by Lego)
  • Hermes role ID: 1527260007307935776 | Discord permissions: Administrator ✅
  • morning-standup cron ✅ first successful fire: 2026-07-17 05:01 UTC; enhanced 2026-07-27 to include drawio-desktop#2499 monitoring (Lego directive: merge into standup, not separate job)
  • 🆕 Lego directive (2026-07-27 10:57 UTC): start building a dedicated skill for Hermes itself
  • Backlog files: wiki/vssa-dpvp/action-plan.md, wiki/cognitive-architect/action-plan.md
  • MartynasP model-access documentation: ⏳ still pending
  • Gitea wiki sync ✅ — pushing to skic-v1-playground/knowledge-wiki on every run (started 2026-07-17 09:30 UTC)
  • ✅ Gitea push restored — after Lego requested another access check at 11:08 UTC, SSH access to origin/main was verified at 15:08 UTC. Remote and local main both pointed to 35eb834; all previously queued commits are now on Gitea.
  • 🔴 Lego directive (2026-07-20 08:49 UTC): "please fix your issues yourself" — Hermes must resolve the Gitea push issue autonomously
  • ⚠️ Responsiveness incident (2026-07-20 09:54–11:03 UTC): Lego repeatedly asked whether the issues were fixed and what Hermes was doing; visible progress/status updates are expected during incident resolution.
  • Voice behavior (confirmed 2026-07-31): generate clear, human-friendly, conversational responses and let the participant guide with questions; avoid dense written-style delivery in live voice sessions.

Wiki Files

  • /opt/data/wiki/vssa-dpvp/action-plan.md — DPVP backlog
  • /opt/data/wiki/vssa-enterprise-architect/action-plan.md — EA consultancy
  • /opt/data/wiki/cognitive-architect/action-plan.md — CogArch backlog + pentest
  • /opt/data/wiki/sap-delivery/action-plan.md — SAP track
  • /opt/data/wiki/distinguished-engineer/action-plan.md — DE track
  • /opt/data/wiki/infrastructure/README.md — Services & endpoints
  • /opt/data/wiki/infrastructure/gitea-repository-operations.md — reusable Gitea repository runbook and skill reference
  • /opt/data/wiki/infrastructure/network-v1.md — global Internet address book and IP-level ownership/operation model
  • /opt/data/wiki/discord/README.md — Discord config
  • /opt/data/wiki/hermes-setup/README.md — Migration status
  • /opt/data/wiki/behavior/README.md — Operating rules