Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion pmoves/docker-compose.core.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion pmoves/docker-compose.ui.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions pmoves/docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3912,7 +3912,7 @@ services:
- pmoves_bus
- pmoves_data
healthcheck:
test: ["CMD-SHELL", "wget -qO- http://localhost:8107/healthz >/dev/null 2>&1 || exit 1"]
test: ["CMD-SHELL", "curl -fsS http://localhost:8107/healthz >/dev/null || exit 1"]
interval: 30s
timeout: 10s
retries: 3
Expand Down Expand Up @@ -4774,7 +4774,7 @@ services:
profiles: ["agents", "botz"]
networks: [pmoves_app]
healthcheck:
test: ["CMD-SHELL", "wget -qO- http://localhost:8504/ >/dev/null 2>&1 || exit 1"]
test: ["CMD-SHELL", "curl -fsS http://localhost:8504/ >/dev/null || exit 1"]
interval: 30s
timeout: 10s
retries: 3
Expand Down
7 changes: 7 additions & 0 deletions pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md
Original file line number Diff line number Diff line change
Expand Up @@ -2048,3 +2048,10 @@ b8cea26c8\ that added it to the top-level equired\ array). (2) PMOVES-pinokio PR
- `2026-08-21T13:45:00Z` CLAIM+RELEASE `5090-CLAUDE (Opus 4.8)` scope: **Track 0 fleet-convergence sync of the 5090 node + a merge-wave level-set handed to the 4090 (merge owner). Git ops on this node only — no new PRs.** **What landed:** (1) monorepo `main` fast-forwarded **12 commits** to `origin/main@ce003f6cbe` — the "out of sync / conflicting" impression was a **stale local checkout, not a divergence** (#2656 Docker MCP Gateway, #2653 three Pinokio submodules, #2646 AGENTS.md/skills reorg, #2660/#2659/#2657/#2655 all already on origin; **#2656 is MERGED, not conflicting**). (2) the 4 new submodules initialized — `PMOVES-mcp-gateway` (#2656), `PMOVES-pterm` / `PMOVES-gepeto` / `PMOVES-pinokiod` (#2653); `PMOVES-ollama` also initialized. Discarded local `known-roads.jsonl` audit appends (grants for already-merged #2658) to unblock the FF. **Left untouched (coordination-gated, NOT clobbered):** `PMOVES-DoX/.git/modules/…/index.lock` — a **STALE 3-week-old (Jul 29) 0-byte lock**; the guard blocks its removal, so it is an operator `! rm` if DoX reconciliation is wanted (pointer-drift only, not convergence-critical). And the fork→gitlink **promotion drift** the fleet audit surfaced (`Pmoves-Health-wger` 290 behind hardened, `Pmoves-pretext` 32, `Pmoves-cipher` 4, `pmoves/integrations/archon` 1) — that is the **fleet-fork-sync promotion lane**, 4090 / merge-wave territory, not done unilaterally. **Merge-wave level-set for the 4090** (fresh states 2026-08-21): **READY** (mergeable; review ± rebase) — **#2663** keygen master-repoint (**this is the RELEASED/UNCLAIMED keygen lane** from the 4090 correction directly above — closes the last submodule gap, tip `36ef041`→master head per #2591), **#2662** docs(merge+cipher), **#2647** agent-zero v2.10, **#2446** ffmpeg-whisper CUDA (GPU-build validation stays 4090/5090 per its own DRAFT warning). **BLOCKED** — **#2642** allowlist-5-forks (CONFLICTING/DIRTY, needs conflict fix first). **STALE** — **#2554** agent-zero v2.9, superseded by #2647 → recommend close. This session's edge PRs all **MERGED**: #2644 (sso browser 302→login redirect), #2650 (cf-dns-token provisioning tool + OAuth runbook), #2658 (traefik DNS-01 via public resolvers — edge certs now issue for auth/health/wealth.pmoves.ai), #2661 (`make rebuild-edge-svc`). **Docker MCP Gateway rollout is UNOWNED:** #2656 merged the *substrate + decision* (Docker MCP Gateway = compose-fleet via `remote` entries; Microsoft/BoTZ gateway = parked for Kubernetes) — the *rollout* (catalog authoring, compose stand-up, 5-client config regen via `mcp_config_generator.py` NOT hand-edit `.claude/mcp.json`, github-issue-triage dead-wiring fix, 2 unregistered SSE endpoints, 4 image builds) per `MCP_GATEWAY_WIRING_RESEARCH.md` §5 needs an owner. **Interim access for DARKXSIDE:** the 4 SSO edge services serve real LE certs + 302→login (sso-auth rebuilt this session — its container had predated #2644; fixed via the new `make rebuild-edge-svc SVC=sso-auth`). Reaching them on the tailnet needs a **Tailscale admin split-DNS** entry (the 4 FQDNs → 5090 tailnet IP) — no public DNS, certs/SSO untouched. **cataclysmstudios.com CF Pages deploy stays the 4090's lane** (scaffold committed; deploy pending: CF-token funnel → wrangler pages deploy → Hostinger→CF NS migration → SSL; email records preserved). **Alignment yardstick — the 4 customer types** (CF page): Enterprise/UN-NGO · Communities/Co-ops · Disaster Response · Creators. **Three-body:** delivery=5090-CLAUDE (git sync + level-set), control=DARKXSIDE + 4090-CLAUDE (own the merge wave + cataclysmstudios deploy), memory=this trail + plan file `~/.claude/plans/snoopy-bubbling-flask.md`. CHIT trail **unsigned-local**. `agent_signature: ACK::5090-CLAUDE::CONVERGENCE-SYNC-MERGEWAVE-LEVELSET::2026-08-21`.

<!-- GRAPHITI_MARK: 5090-CLAUDE::CONVERGENCE-SYNC-MERGEWAVE-LEVELSET::2026-08-21 -->

<!-- GRAPHITI_MARK: SPARK-KIMI::POSTMERGE-WAVE-2662-2674::2026-08-22 -->

## SPARK-KIMI post-merge wave validation (4090 wave #2662/#2664/#2666/#2667/#2669/#2673/#2674 + #2656) + regression repair (2026-08-22)

- `2026-08-22T14:35:00Z` CLAIM+RELEASE `SPARK-KIMI (Crush, GLM via qwen3-coder)` scope: **post-merge validation of 4090's landed wave on SPARK + two node regressions found in the pass + fix-forward PR for the defect classes the recreate pass exposed.** **Wave applied:** main FF `120e4c40a`→`baa863c7c`; `git submodule sync` (#2673 six-fork hardened branches) + `PMOVES-mcp-gateway` initialized (#2656); rolling converge brought 65/81 containers to primary-checkout provenance (was 24), applying #2664's dependency graph; monitoring stack recreated from primary via fixed `up-obs` (#2667 — SPARK had no stray-dir instance of the trap, binds were already real configs); `supabase-vector` recreated with #2669's proxy-var fix; #2662/#2666/#2674 are docs/CI/tooling — no node step. **Regressions found + fixed in-pass:** (1) `model-registry` 4699-fail streak = stale `nats:pmoves` creds predating the rotation — recreated from primary, healthy, 0 auth violations; (2) `edge-functions` 2349-restart loop = `functions/` bind pointing at the EMPTY temp-worktree copy (`dockerfile-restore-fix`) + 8 sibling CLI-stack containers split-brained across worktrees — recreated under canonical `-p pmoves` from primary, 13/13 healthy, `main function started`; first attempt mistakenly used `-p pmoves-supabase` creating 8 double-named duplicates sharing `pmoves_api` aliases — torn down immediately, root cause is the monolith-default-name pattern (old set WAS project `pmoves`). **Fix-forward PR (this branch):** (a) `a2ui-renderer` + `tokenism-ui` healthchecks `wget`→`curl` — images ship curl only, both services returned 200 while permanently "unhealthy" (streak 14+, false-negative probes; `tensorzero-ui` already uses the curl-fallback pattern); splits regenerated; both healthy post-recreate. (b) hi-rag-gateway v1 Dockerfile CUDA stanza guarded to `x86_64` — the unpinned cu121-index install has no modern aarch64 wheels and silently downgraded locked torch 2.9.1→2.0.1 on GB10 (transformers 4.57.3 then dies on `torch.compiler`); the rolling rebuild surfaced it live; arch-guard build (no build-arg) now yields torch 2.9.1+cpu healthy. The x86 unpinned-clobber question stays with the **hi-rag v1 retirement-or-repin** routed lane. **Routed (not self-assigned):** mcp-gateway deployment on SPARK blocked — `MCP_GATEWAY_AUTH_TOKEN` absent from vault post-funnel (unowned rollout lane per 5090's 08-21 entry; #2665 owns the pipeline); funnel flagged 2 alias divergences needing an operator receipt-check (`AGENT_ZERO_MCP_TOKEN`/`MCP_SERVER_TOKEN`, `KIMI_CODING_API`/`MOONSHOT_API_KEY`); `pmoves-ui` remains truthful-503 (direct-postgres creds, routed); media-video/audio CUDA GB10 rebuild (routed); 9 spark-kimi-worktree containers left as-is (external ×5, yt-cookies ×2, archon-ui ×1, juicefs ×1 — #2664 delta is depends_on-only, next cold start converges them). **Validated post-wave:** openroom desktop 200 (still running the session's fork-fix image); p7 canonical `/healthz` 200/13 rooms; legacy :8122 session route live (422 on empty body = schema validation); #2668 all checks green awaiting review; fork PR #5 MERGEABLE/REVIEW_REQUIRED. **Three-body:** delivery=SPARK-KIMI, control=4090 (merge wave owner), memory=this trail. CHIT trail **unsigned-local** (no passphrase in session). `agent_signature: ACK::SPARK-KIMI::POSTMERGE-WAVE-2662-2674::2026-08-22`.

5 changes: 4 additions & 1 deletion pmoves/services/hi-rag-gateway/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,12 @@ RUN pip install --no-cache-dir -r requirements.txt
# --- CUDA-enabled Torch for Qwen reranker (optional) ---
# If the host uses NVIDIA runtime, install CUDA wheels (cu121). This is safe on CPU-only hosts too,
# but you can skip by setting TORCH_SKIP_CUDA=1 at build time.
# x86_64 only: the cu121 index carries no modern aarch64 torch, so on ARM hosts the
# unpinned install silently resolves to torch 2.0.1 and clobbers the locked 2.9.x
# (observed on GB10/SPARK 2026-08-22: transformers 4.57.3 then dies on torch.compiler).
ARG TORCH_CUDA_VERSION=cu121
ARG TORCH_SKIP_CUDA=0
RUN if [ "$TORCH_SKIP_CUDA" != "1" ]; then pip install --no-cache-dir --index-url https://download.pytorch.org/whl/${TORCH_CUDA_VERSION} torch torchvision torchaudio || true ; else echo "Skipping CUDA Torch install"; fi
RUN if [ "$TORCH_SKIP_CUDA" != "1" ] && [ "$(uname -m)" = "x86_64" ]; then pip install --no-cache-dir --index-url https://download.pytorch.org/whl/${TORCH_CUDA_VERSION} torch torchvision torchaudio || true ; else echo "Skipping CUDA Torch install"; fi

# Copy service code and shared libraries
COPY services/hi-rag-gateway/ .
Expand Down
Loading