Files
knowledge-wiki/brain.md
T

111 lines
16 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 🧠 Knowledge Wiki — Brain Summary
_Last updated: 2026-09-17 03:13 UTC_
## Workstreams & Status
| # | Workstream | Open Items | Priority |
|---|-----------|-----------|----------|
| 🔵 | VSSA — DPVP | 21 active, 1 opportunity | Phase 2 opportunity, AWS tagging, Azure-cost onboarding documentation, access governance/monitoring, Jira-targeted role grants/revocations, project-level backups, Architecture Decision process, unit-testing options, backlog migration to Jira |
| 🟡 | VSSA — Enterprise Architect | 4 active | Scope decision, Gytis outreach, Atea & IBM institution engagement, Government Developer Portal |
| 🟢 | Cognitive Architect | 8 active | Oleg follow-up; Aurimas Nogis/Hermes security follow-up; ArchiMate investigation; Texture/Jenny integration follow-up; Anthropic architect certification; IBM Video Streaming; cogarch backlog |
| 🟣 | SAP Delivery Powered By AI | 1 active | Michael Martine material review |
| 🏅 | Distinguished Engineer | 3 active | Elizabeth docs + summary; FutureNow/Baltic AI/client-relations upskilling with Jurgis |
**Total open:** 38 items | **Completed:** 7 (env vars deployed; Apptio AWS-connection investigation and Azure-cost onboarding completed; CA-01, CA-03, CA-04, and CA-B01 completed)
## Atea Cooperation
- `#atea-storm` is the continuity ledger for Atea-related contracts, opportunities, audits, and RFPs.
- Current tracked workstreams: VSSA AWS contract; VSSA DPVP contract and Phase 2 opportunity; Valstybės duomenų agentūra AWS portal audit; Lietuvos Geležinkeliai RFP; and two early Atea & IBM items (the user-provided title “Let's go to institutions” and a Government Developer Portal). Details for the two Atea & IBM items are not yet specified.
- DPVP Phase 2 discussion scope covers the portal, backend execution migration, VSSA on-premises onboarding, complex hybrid services, and organization scanning across AWS, Azure, and GCP. Ownership, prioritisation, estimates, dependencies, dates, scan baselines, and commercial route remain unconfirmed.
- VSSA AWS: an AWS Well-Architected Framework review has been proposed, not approved; workload/account scope, authorization, access, schedule, and remediation ownership remain open.
- DPVP backlog changes confirmed 2026-08-25: the Apptio AWS-connection investigation and Azure-cost onboarding are completed; the follow-up with Atea about TFE OIDC role assumption and July cost-estimation review were dropped. Open refinements include figuring out AWS tagging issues, documenting the Azure-cost onboarding approach, and having Julius locate documentation for the nightly AWS cost-allocation-tag enablement job.
- The portal audit is an opportunity only; active testing requires explicit written authorization and agreed scope.
- A consolidated executive summary was requested on 2026-07-29 and is maintained in `wiki/channels/1531661088209371198.md`.
## VSSA Client Investigation
- **Current delivery (2026-09-04):** repository `vssa-v1/documentation` publishes the Keycloak-protected **VSSA - Clients & Systems** Docusaurus site. The latest completed delivery records 290 clients, 551 canonical systems, 779 observations, and 118 contractor cards at commit `701494d175266bd5e6683f53c58d08b7cd69bc0e`; exact-head Actions task `1874` succeeded. RootAtSkic stopped and removed continuous-research job `88833e00b4a2` on 2026-09-04, so it no longer runs every two hours. The unassigned next range remains clients 121–140.
- **Entity classification (confirmed 2026-08-19):** Valstybės skaitmeninių sprendimų agentūra (VSSA) is a central-government client body, not a system or commercial contractor. Government bodies that centrally operate/provide shared services must not be converted to `CTR-*` entities merely because of that role.
- **Content organization (confirmed 2026-08-12):** after Lego requested an immediate research-led overall-page improvement cycle, commit `1542674` reorganized the portal around researched user tasks. Navigation is Overview, Clients, Systems, Methodology, and Data; deployment was validated by successful Actions run `2335` and representative HTTP-200 backend/browser checks.
- **Evidence/navigation requirements (confirmed 2026-08-12/14):** Overview, Clients, Systems, Contractors, Methodology, and Data have dedicated sidebars; Clients, Systems, and Contractors each expose Overview plus an expanded Registry. Internally generated `SYS-*`/`CTR-*` identifiers are documented, all generated client/system dossiers have References indexes, relationship evidence uses reusable cards, every client system observation links to its canonical system dossier, and every named contractor on an exact client-system row links to its Contractor Card. Multiple contractors are supported; unknown contractors remain explicit and unlinked.
- **VSSA skill governance (confirmed 2026-08-14):** `vssa-clients` is authoritative in `vssa-v1-skills-code-agent/vssa-clients`; merged `documentation-docusaurus` is authoritative in `vssa-v1-skills-code-agent/documentation-docusaurus` and includes the retired `gitea-docusaurus-projects` capabilities. Both runtime skills are symlinked to Gitea maintainer worktrees. The requested `corp-v1-skills-code-agent/documentation-docusaurus` repository was unavailable and was not touched.
- **Procurement research (confirmed directive and validated workflow, 2026-08-12):** Discord user `476287310627864587` is the designated instructor for CVP IS. In addition to tender search, use exact organization search → identity-checked organization profile → **PERŽIŪRĖTI VISUS PASKELBTUS SKELBIMUS**, extracting the actual `authorityId`/`orgGroupId` and relevant notice PDFs. Job `88833e00b4a2` must map supported records to exact clients/systems and keep RFI/RFP/specification/bid stages distinct from award, implementation, production use, hosting, and completion.
- **Lifecycle evidence rule (confirmed 2026-08-12):** a dated official announcement explicitly stating that a named system started operating/launched/went live is direct production-release evidence at the announcement’s stated precision; generic webpage metadata is not. Do not infer delivery kickoff from a production announcement.
## Key People
- **Lego** (root_at_skic) — Owner, Enterprise Architect
- **MartynasP** (w4rl0ck_21) — Hermes migration lead
- **Jerry** — TrueNAS admin
- **Julius Sulcas** — DPVP, was on time off
- **Rimvydas** — Architect, reports to Dimitrian via Edvinas
- **Gytis Račiukaitis** — E-Gov Gateway contact
- **Luis Diego Raga** — Pentest senior tester (Sep 1–28)
- **Oleg** — Cognitive Architect stakeholder
- **Andrius** — Built cogarch skill
- **Elizabeth** — Distinguished Engineer track
- **Jurgis** — FutureNow, Baltic AI, client-relations, and broader upskilling contact
- **Jenny** — Mentioned Texture integration and other Cognitive Architect items; exact items and role still need clarification
- **Michael Martine** — SAP material contact
- **Arunas Saltis** — DNS naming convention (internal hosting)
## Pending Reminders
- [ ] Follow up with Arunas Saltis — DNS naming convention (internal hosting) — added 2026-07-14
## Infrastructure
- TrueNAS SCALE 26.0.0-BETA.2 at lego-cloud.eu ✅
- Gitea: gitea.lego-cloud.eu (org: home-v1) ✅
- **General Gitea repository skill:** ✅ `gitea-repository-operations` — reusable API + SSH workflow for any repo; full wiki runbook at `wiki/infrastructure/gitea-repository-operations.md`
- **Gitea API credential (confirmed 2026-08-02):** use Bitwarden-provided `HL_V1_GITEA_ACCESS_TOKEN` for `gitea.lego-cloud.eu`; never use `GITHUB_TOKEN` for that instance or copy the Gitea token into `/opt/data/.env`. Bitwarden keys are exported without aliases and gateway restart is required after key changes.
- **Gitea recovery (confirmed 2026-08-11):** Gitea `1.27.0` crashed all SSH/Smart-HTTP Git-serving processes despite healthy web/API; upgrade to `1.27.1` restored API and both Git transports. The queued VSSA commit `6fc42ab` was pushed and remotely verified.
- **Gitea Pages pattern (verified 2026-08-11):** Actions runners build repositories and publish to `/gondor-v1-gitea-pages/<organization>/<repository>/`, exposed at `https://pages.apps.lego-cloud.eu/<organization>/<repository>/`. The Pages dataset must be allowed by `container.valid_volumes` and mounted into job containers. `skic-v1-playground/documentation` run 2326 and the live site were verified.
- **Actions Docker (verified 2026-08-11):** use the runner-mounted `/var/run/docker.sock` directly (client `29.6.2-1`, Engine `29.0.4`). DinD is unnecessary and privileged DinD is not currently supported by this runner.
- **CogArch GitHub attribution (required 2026-08-25):** `cogarch-github` commits/PRs must disclose that Hermes acted using Oleg Lukasonok's PAT without implying Oleg performed or approved the action. When evidence permits, also name the Discord user who guided/originated the work; never invent uncertain attribution.
- **CogArch presentation governance (required 2026-09-04):** channel-dedicated `cogarch-storm` is maintained in `cognitive-architect-v1-skills-code-agent/cogarch-storm`. Any IBM-flavored, IBM-originated, IBM-audience, or IBM-branded presentation must additionally use `powerpoint-ibm-template`; that skill must always reference/load `powerpoint` and `powerpoint-advanced-python`.
- **CogArch Solution Factory / Argo evidence boundary (verified 2026-09-15):** exact live and archived label queries for `architecture-id=arch_kiSj9jBKI` returned no Workflow. The deployed Processing template contains conversion, chunking, image description, and merge steps, but completed Workflows are deleted after 24 hours and the accessible archive is empty. A separate `arch_xOQ5jks0b` High-Level Insights failure reached the code agent and exhausted retries with exit code 201; its overwritten detailed log reportedly showed operation timeout/retry-limit failure. A fail-open Redis DNS warning appeared in that failed run but did not recur in the read-only-verified rerun pod, so it is not the established cause.
- **CogArch Solution Factory BYOT MVP (decided 2026-09-16):** use one persistent OpenShift Secret per user, created/patched/deleted by the existing settings backend; do not introduce IBM Secrets Manager or a new secrets service initially. Require server-derived opaque names, backend ServiceAccount permissions limited to Secret `create`/`patch`/`delete` without reads, admission restriction to labelled `byot-*` objects, trusted WorkflowTemplates, no token leakage, and fail-closed behavior. Running workflows may retain old values; provider revocation and cluster-loss recovery remain separate concerns.
- **Emplonet v1 channel setup (confirmed 2026-09-08):** `#emplonet-v1-general` and `#emplonet-v1-ingrida` each have a dedicated local artifact workspace under `/opt/data/channels/`, a dedicated channel skill, and a private source repository in `emplonet-v1-skills-code-agent`; both are now included in the authoritative daily wiki scan and short config routing.
- **Lego CV workspace (confirmed 2026-09-14):** `#lego-v1-cv` uses `/opt/data/workspaces/channels/lego-v1-cv` and the private `lego-v1-skills-code-agent/lego-v1-cv` channel skill. The supplied CV source was converted into brand-neutral editable DOCX and PDF artifacts without embedded IBM logos while retaining professional content.
- **Wiki health check (repaired 2026-09-13):** `/opt/data/scripts/health-check.sh` no longer creates invalid multiline `0\n0` counts when `grep -c` finds no match, and its Discord test recognizes the gateway's actual inbound/send activity log forms. `bash -n` and a complete rerun passed all four checks; authenticated Discord REST still remains the source of truth for channel-scan coverage.
- **Hermes delegation baseline (live 2026-09-12):** `max_concurrent_children: 10` and `max_spawn_depth: 1`; RootAtSkic asked how to increase sub-agent capacity, but no configuration change was authorized or made.
- **Home v1 skill-repository descriptions (status 2026-09-09):** all 60 repositories in `home-v1-skills-code-agent` have non-empty Gitea descriptions, but the requested 3–5 sentence standard is met by 58/60. `hermes-codex` and `development-durable-wave-execution` still have one-sentence descriptions and remain open remediation.
- **TrueNAS channel skill (confirmed 2026-08-26):** `home-v1--truenas` is maintained in private Gitea repository `home-v1-skills-code-agent/home-v1--truenas` and loaded directly from its checkout. Commit `634e0e6` passed 10 offline tests, Gitea Actions task `1398`, remote readback, and a real authenticated read-only WebSocket query. Runtime access uses Bitwarden keys `HL_V1_TRUENAS_URL` and `HL_V1_TRUENAS_API_KEY`. The current IP-based URL fails strict certificate identity validation; use a certificate-matching DNS/CA path rather than permanent `--insecure` mode.
- **Gondor v1 (2026-08-02):** Hermes SSH access as `lego` is verified to Osgiliath 000 and both Minas Tirith workers; use the `gondor-v1-nodes` skill. Open ingress incident: Argo CD's hostPort 80/443 `ingress-nginx` conflicts with Osgiliath's system Nginx; repair through `home-v1/gondor-v1.git`, not a transient live patch.
- **Hermes outage (2026-08-04–11):** confirmed Codex quota exhaustion first blocked model responses while Discord/cron remained alive; a separate likely host/container-runtime failure then stopped all gateway, scheduler, log, and health progress after 2026-08-04 14:00:42 UTC. Physical restart at 2026-08-11 00:11:40 restored service without Hermes repair. Exact host-level trigger remains **UNKNOWN** because previous-boot TrueNAS/kernel/ZFS/runtime/hardware telemetry is unavailable inside the container.
- **world-v1/network-v1:** ✅ global Internet address book; IP-level mapping now separates registry holder, route origin, operator, and service. Initial records: `0.0.0.0` and `1.1.1.1`; wiki page at `wiki/infrastructure/network-v1.md`
- Keycloak: keycloak.lego-cloud.eu ✅
- Hermes Dashboard: jarvis-jr-v1.lego-cloud.eu ✅
- STT Whisper: 192.168.1.218:39000 🔲
- Piper TTS: 192.168.1.218:39001 🔲
## Hermes Migration
- Status: ✅ Live, cron active, **backlog ownership officially handed to Hermes role** (2026-07-16)
- **UPGRADED: Hermes is now sole agent on SKIC Discord server** (2026-07-17 07:44 UTC, confirmed by Lego)
- Hermes role ID: `1527260007307935776` | Discord permissions: Administrator ✅
- **morning-standup cron** ✅ first successful fire: 2026-07-17 05:01 UTC; enhanced 2026-07-27 to include drawio-desktop#2499 monitoring (Lego directive: merge into standup, not separate job)
- 🆕 **Lego directive (2026-07-27 10:57 UTC):** start building a dedicated skill for Hermes itself
- Backlog files: `wiki/vssa-dpvp/action-plan.md`, `wiki/cognitive-architect/action-plan.md`
- MartynasP model-access documentation: ⏳ still pending
- **Gitea wiki sync** ✅ — pushing to skic-v1-playground/knowledge-wiki on every run (started 2026-07-17 09:30 UTC)
- ✅ **Gitea push restored** — after Lego requested another access check at 11:08 UTC, SSH access to `origin/main` was verified at 15:08 UTC. Remote and local `main` both pointed to `35eb834`; all previously queued commits are now on Gitea.
- 🔴 **Lego directive (2026-07-20 08:49 UTC):** "please fix your issues yourself" — Hermes must resolve the Gitea push issue autonomously
- ⚠️ **Responsiveness incident (2026-07-20 09:54–11:03 UTC):** Lego repeatedly asked whether the issues were fixed and what Hermes was doing; visible progress/status updates are expected during incident resolution.
- **Voice behavior (confirmed 2026-07-31):** generate clear, human-friendly, conversational responses and let the participant guide with questions; avoid dense written-style delivery in live voice sessions.
## Wiki Files
- `/opt/data/wiki/vssa-dpvp/action-plan.md` — DPVP backlog
- `/opt/data/wiki/vssa-enterprise-architect/action-plan.md` — EA consultancy
- `/opt/data/wiki/cognitive-architect/action-plan.md` — CogArch backlog + pentest
- `/opt/data/wiki/sap-delivery/action-plan.md` — SAP track
- `/opt/data/wiki/distinguished-engineer/action-plan.md` — DE track
- `/opt/data/wiki/infrastructure/README.md` — Services & endpoints
- `/opt/data/wiki/infrastructure/gitea-repository-operations.md` — reusable Gitea repository runbook and skill reference
- `/opt/data/wiki/infrastructure/network-v1.md` — global Internet address book and IP-level ownership/operation model
- `/opt/data/wiki/discord/README.md` — Discord config
- `/opt/data/wiki/hermes-setup/README.md` — Migration status
- `/opt/data/wiki/behavior/README.md` — Operating rules