diff --git a/.beads/issues.jsonl b/.beads/issues.jsonl index 1579832c14a..832c8440e09 100644 --- a/.beads/issues.jsonl +++ b/.beads/issues.jsonl @@ -1,20 +1,20 @@ -{"_type":"issue","id":"buzz-2i6","title":"Install nak on the Buzz hosts and run the real functional-probe rehearsal, then enable the prod updater timer","description":"The updater lane is deployed to staging (dormant) but the real functional-probe rehearsal is blocked: nak (the NIP-42 auth+publish+readback CLI the probe uses) is absent on the Buzz hosts. buzz-admin IS in the relay image. Steps: install nak on staging (+ prod), run functional-probe.sh against the live staging relay (throwaway member auth+publish+readback, un-invited refused, cleans up), then a controlled no-op-digest updater rehearsal on staging, THEN install-updater-lane.sh intent-ops-buzz --enable-timer for prod. Parent: buzz-ocv.4.","notes":"REHEARSAL PARTIAL on live staging 2026-07-29 (nak copied to /usr/local/bin/nak on intentsolutions; jq present). VERIFIED LIVE: closed relay up+healthy+CORS-applied; buzz-admin add-member/remove-member/list-members work — EXACT syntax is 'buzz-admin add-member --pubkey \u003chex-or-npub\u003e' (NOT positional; positional errors with usage). nak emits 64-char hex from 'nak key public'; relay accepts hex. add+remove round-trip proven; test member cleaned up (relay left clean: owner + 1 pre-existing member). REMAINING: the nak publish/readback NIP-42 flow hung with reactive '--auth' — the closed relay likely needs '--force-pre-auth' (authenticate BEFORE the EVENT/REQ), and readback (nak req -i \u003cid\u003e) on a closed relay also needs auth so the member NSEC must be threaded into functional-probe.sh's readback() (currently it only gets the event id). NEXT: (1) prove 'NOSTR_SECRET_KEY=\u003cnsec\u003e nak event -k1 -c X --auth --force-pre-auth \u003cws\u003e' returns an id against staging; (2) prove readback with the member key; (3) bake the verified commands + --pubkey into functional-probe.sh add_member/del_member/publish/readback; (4) then no-op-digest updater rehearsal on staging; (5) install-updater-lane.sh intent-ops-buzz --enable-timer.","status":"open","priority":1,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T21:47:43Z","created_by":"jeremylongshore","updated_at":"2026-07-29T21:51:24Z","labels":["go-live","probe","updater"],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-aet","title":"Author the authoritative Buzz naming and boundaries record and reconcile the blueprint ledger to prod-up","description":"Track B of the Buzz adoption plan (owner amendment 2026-07-29, do FIRST). Author the canonical naming+boundaries record in the fork 000-docs from the AUTHORITATIVE NAMING \u0026 REPOSITORY MODEL table: 6 assets (upstream block/buzz, code fork intent-solutions-io/buzz, contributor lab intent-solutions-io/intent-ops-buzz repo, production host intent-ops-buzz VPS, live ops lane intent-os ops/buzz, deferred plugin intent-solutions-io/intent-ops-buzz-plugin), the disambiguation rule (never bare 'intent-ops-buzz'), and the four-plane flow with two separate gates (contribution vs deployment). Reconcile the blueprint 001 completion ledger to reality (prod host built/deployed/verified pre-cutover, backups+restore proven), name the plugin repo deferred, and add the contributor-lab plane. Unblocks the parked contributor-lab architecture DRAFT (Track C). The amendment forbids durable architecture docs until this lands. Done-means: naming doc exists + internally consistent; ledger prod-up; no bare-intent-ops-buzz ambiguity; pnpm check green on the intent-os reconcile edit.","status":"closed","priority":1,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T19:19:37Z","created_by":"jeremylongshore","updated_at":"2026-07-29T19:36:54Z","started_at":"2026-07-29T19:19:43Z","closed_at":"2026-07-29T19:36:54Z","close_reason":"Track B shipped: authored fork 000-docs/006-DR-STND-authoritative-naming-and-boundaries.md (canonical six-asset table + host-vs-repo disambiguation rule + four-plane flow + two-gate model); reconciled the 001 blueprint ledger to prod-up (E2/E2d/E3 states, ELab row, E9 plugin named intent-ops-buzz-plugin + DEFERRED, new Phase 6 pointer); added the intent-os ops/buzz/README 'Naming \u0026 planes' section. Merged: fork PR #11 + intent-os PR #281 (estate-CI 3 green contexts: gates 128s, drills 212s, gitleaks). pnpm check EXIT=0; no bare-intent-ops-buzz ambiguity remains.","labels":["architecture","ledger","naming"],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-nry.3","title":"Run the full go-live gate suite against production on the dedicated box","description":"All E3 gates, unchanged and BLOCKING before any invite, now executed against PROD: unauth probe matrix off-network; functional membership probe (NIP-42 publish + readback, un-invited key refused); backup restore drill — restore STAGING from PROD's backup artifacts (doubles as the off-site proof); updater planted-fault drill on staging; key runbooks rehearsed; resource caps verified. Depends on the prod-deploy child.","notes":"Go-live gates PARTIAL against prod: (1) functional membership probe GREEN — owner NIP-42 auth -\u003e publish -\u003e readback OK; un-invited key REFUSED (closed relay enforcing, member_count:1 on boot). (2) unauth HTTP probe matrix PASS — media PUT 405, git 404/405, hooks 400, admin 404; public readiness/NIP-11/web-client 200. (3) resource caps + loopback-only publish + isolated bridge net verified. REMAINING/BLOCKING before any invite: backup-restore drill, updater planted-fault drill, key runbooks — all depend on backup+updater wiring (buzz-ocv.4, not built).\nRESTORE DRILL PROVEN (buzz-nry.3 gate item): restored the first prod archive into an ISOLATED dev-box scratch project (prod/staging untouched, prod 4/4 healthy throughout). 40 tables restored; the exact prod-published event 9717ccaa physically present; relay_members=1 + member_count:1 on boot; media restored; relay identity stable (same key-\u003e35cd57ab); relay boots healthy; un-invited refused; restart persistence holds. RTO ~3min, RPO = backup point (18:36:41Z). Caveat: headless nak auth-on-REQ readback didn't complete in-harness (passed on prod). Evidence: ops/buzz/RUNBOOK-backup-restore.md. STILL BLOCKING before invite: updater planted-fault drill, key runbooks, off-site copy.","status":"open","priority":1,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:31:30Z","created_by":"jeremylongshore","updated_at":"2026-07-29T18:45:39Z","labels":["hosting"],"dependencies":[{"issue_id":"buzz-nry.3","depends_on_id":"buzz-nry.2","type":"blocks","created_at":"2026-07-29T10:31:31Z","created_by":"jeremylongshore","metadata":"{}"},{"issue_id":"buzz-nry.3","depends_on_id":"buzz-nry","type":"parent-child","created_at":"2026-07-29T10:31:29Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":1,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-nry.2","title":"Deploy production from the proven staging artifacts with fresh secrets and cut DNS over","description":"Same digest-pinned compose as staging; FRESH prod secrets minted on the new box (new relay identity key, new bootstrap op owner key until the owner's desktop key swaps in, new db/redis/minio creds — staging keys never promote); buzz.intentsolutions.io A record repoints to the new host at cutover; the shared-VPS stack renames to buzz-staging.intentsolutions.io (its Caddy block + env updated; stays closed + internal for drills and image promotion). Depends on the bootstrap child.","notes":"Prod deploy DONE (apex cutover pending): staging-proven digest-pinned compose deployed to intent-ops-buzz with FRESH prod secrets (new relay identity + new bootstrap owner key + new db/redis/minio; staging keys NOT promoted). 4 containers healthy; own Caddy ingress TLS + security headers; serving under buzz-prod.intentsolutions.io. REMAINING (gated on Jeremy's client-generated desktop key): repoint buzz.intentsolutions.io -\u003e 169.58.95.32, rename staging to buzz-staging., swap prod BUZZ_DOMAIN/RELAY_URL/CORS to apex, swap RELAY_OWNER_PUBKEY to Jeremy's desktop pubkey.","status":"open","priority":1,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:31:22Z","created_by":"jeremylongshore","updated_at":"2026-07-29T18:17:43Z","labels":["hosting"],"dependencies":[{"issue_id":"buzz-nry.2","depends_on_id":"buzz-nry","type":"parent-child","created_at":"2026-07-29T10:31:22Z","created_by":"jeremylongshore","metadata":"{}"},{"issue_id":"buzz-nry.2","depends_on_id":"buzz-nry.1","type":"blocks","created_at":"2026-07-29T10:31:31Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":1,"dependent_count":1,"comment_count":0} -{"_type":"issue","id":"buzz-nry.1","title":"Bootstrap the new production host to estate conventions","description":"Mirror ops/host conventions on the dedicated box: verify OS is Ubuntu 24.04 (reinstall via provider panel if not), tailnet join, ufw (22 tailnet-only + 80/443 public), fail2ban, unattended-upgrades, docker, its OWN Caddy instance (separate failure domain = separate ingress), age host key + sops, borg client, Netdata bound to tailnet. BLOCKED until the owner installs the dev box's SSH key (ssh-copy-id) — first-access step, keeps the root password out of chat.","status":"closed","priority":1,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:31:15Z","created_by":"jeremylongshore","updated_at":"2026-07-29T18:06:58Z","started_at":"2026-07-29T17:57:57Z","closed_at":"2026-07-29T18:06:58Z","close_reason":"intent-ops-buzz bootstrapped to estate baseline + verified: Ubuntu 24.04.4 LTS, hostname intent-ops-buzz, joined tailnet 100.74.181.116 (untagged/user-owned, matching estate); ufw default-deny (tailnet-trusted iface + public 80/443 only, public 22 CLOSED/times-out); sshd key-only + PermitRootLogin no + PasswordAuthentication no; non-root sudo admin 'intentsolutions' (NOPASSWD, docker group); fail2ban + unattended-upgrades active; 2G swap swappiness=10; docker 29.6 (log-rotation + live-restore) + compose v5.3; caddy 2.11 (own ingress); age host key at /etc/intentsolutions/age.key (recipient age1ztnq3d4htgf8vk2nj2p64xpeew6ks8lvk8stw70a6g83f3f9kcgstsltxg); borg client; sops 3.9.4; Netdata bound loopback+tailnet only (127.0.0.1:19999 + 100.74.181.116:19999, not public). 7/7 services active.","labels":["hosting"],"dependencies":[{"issue_id":"buzz-nry.1","depends_on_id":"buzz-nry","type":"parent-child","created_at":"2026-07-29T10:31:15Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":1,"comment_count":0} -{"_type":"issue","id":"buzz-nry","title":"Stand up the dedicated Buzz production VPS and cut buzz.intentsolutions.io over to it","description":"Track D of the revised adoption plan (owner topology decision 2026-07-29, fork 000-docs/005): a fast-moving pre-1.0 stack must not share a failure domain with revenue workloads, so Buzz production runs on its OWN VPS (procured 2026-07-29; concrete host detail in the private ops repo, ops/buzz lane). The shared-VPS stack is re-designated permanent STAGING (epic buzz-ocv). Prod deploy = the proven staging artifacts (same digest-pinned compose) with FRESH secrets — new relay identity key, new bootstrap owner key until the owner's desktop key swaps in, new db/redis/minio creds; staging keys never promote. DNS repoints at cutover; staging renames to buzz-staging.intentsolutions.io (closed + internal, drills + image promotion). ALL go-live gates then run against PROD before any invite. GATE: first SSH access requires the owner to install the dev box's key on the new host.","notes":"GitHub: intent-solutions-io/buzz#9 — https://github.com/intent-solutions-io/buzz/issues/9. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-nry` and `bd-sync close buzz-nry` mirror to GH and Plane automatically.\n\nPlane: BUZZ-3 — https://projects.intentsolutions.io/internal/projects/?peekIssue=BUZZ-3","status":"in_progress","priority":1,"issue_type":"epic","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:31:08Z","created_by":"jeremylongshore","updated_at":"2026-07-29T17:57:57Z","started_at":"2026-07-29T17:57:57Z","labels":["hosting"],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-bsy","title":"Build the Buzz three-store restore tool (restore.sh) and its restore drill","description":"The wrapped updater's ordered store-restore on a bad-migration revert calls ops/buzz/scripts/restore.sh (--recovery-point \u003cid\u003e --env \u003cenv\u003e) in intent-os. Until it exists+drilled, the updater fail-closes to exit 5 (manual page) rather than faking a DB rollback. Build restore.sh (pg_dump -Fc restore + MinIO media + git volume from a bound recovery point, dangling-ref walk) + a restore drill, so bad-migration recovery is fully unattended. Parent: wrapped-updater lane (buzz-ocv.4).","status":"open","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T20:13:56Z","created_by":"jeremylongshore","updated_at":"2026-07-29T20:13:56Z","labels":["backup","restore","updater"],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.6","title":"Add the mobile pairing sidecar overlay and validate a real desktop-to-mobile pairing","description":"Track E2 (external infra review; upstream #2734 / PR #2736): the first-party compose bundle lacks the buzz-pair-relay sidecar, so Android members cannot pair — and the all-in onboarding wave includes Android. Review the pinned image for the buzz-pair-relay entrypoint, add an estate overlay service (same image, entrypoint buzz-pair-relay, internal :5000, healthcheck) + a Caddy /pair* route. Claim it works only after a REAL desktop-to-mobile pairing succeeds; if wave 1 doesn't require it, document the limitation honestly instead.","status":"open","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:30:45Z","created_by":"jeremylongshore","updated_at":"2026-07-29T16:30:45Z","labels":["clients","hosting"],"dependencies":[{"issue_id":"buzz-ocv.6","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T10:30:45Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.5","title":"Set the Tauri desktop origins in the relay CORS config and verify with the packaged desktop client","description":"Track E1 (external infra review, verified vs upstream #3490): current env allows only https://buzz.intentsolutions.io as an origin; packaged Tauri desktop clients present tauri://localhost (macOS/Linux) or http://tauri.localhost (Windows), so desktop join is BLOCKED. Verify the pinned image's CORS env handling, add the two Tauri origins (no permissive-CORS shortcuts), restart, confirm relay healthy + correct Access-Control-Allow-Origin echo. Final verification is a join from the PACKAGED desktop client on the owner's workstation, not a dev build.","notes":"CORS CONFIG FIXED (intent-os PR #283, merged via estate-CI 3 green). BUZZ_CORS_ORIGINS composed in version-controlled compose from required BUZZ_DOMAIN + tauri://localhost + http://tauri.localhost (environment: overrides env_file; non-secret Tauri origins out of sops). Closes the desktop-join gap AND a latent permissive-CORS gap (relay goes permissive only when the var is EMPTY; required BUZZ_DOMAIN makes empty impossible). Proof: ops/buzz/tests/cors-config-test.sh 2/2, wired into ci:drills. REMAINING (owner-gated): apply on staging (docker compose up -d relay) + verify a real join with the PACKAGED desktop client on Jeremy's workstation (dev build won't exercise Tauri origins).\nCORS APPLIED LIVE to BOTH hosts 2026-07-29 (intent-os PR #284 records; compose applied with backup + config-gate + relay recreate). Staging BUZZ_CORS_ORIGINS=https://buzz.intentsolutions.io,tauri://localhost,http://tauri.localhost ; prod=…buzz-prod…,tauri…; relay healthy + _readiness 200 on each. Desktop-join unblocked on the live boxes. ONLY remaining: packaged-desktop-client verify on Jeremy's workstation (owner-gated).","status":"in_progress","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T16:30:36Z","created_by":"jeremylongshore","updated_at":"2026-07-29T21:47:44Z","started_at":"2026-07-29T21:16:21Z","labels":["clients","hosting"],"dependencies":[{"issue_id":"buzz-ocv.5","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T10:30:35Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.4","title":"Wire backups and the wrapped updater, register everything in the estate","description":"nightly pg_dump artifact into the borg set + three-store recovery point; weekly updater snapshot-promote-probe-revert; automations.md + catalog rows; E3 drill gates filed","notes":"Track E additions (external infra review 2026-07-29): the wrapped updater's promotion checklist MUST include — release-notes review; a staging boot; a probe-hang check (upstream #2723/PR #2724 — git conformance probe can wedge startup; our pinned digest boots healthy with BUZZ_GIT_CONFORMANCE_PROBE=true, but a future image must prove it on staging before promotion); a CORS/Tauri-origin regression check; a pairing regression check. Also confirmed: upstream's own 'backup' command is a checklist, not a backup — our pg_dump + three-store recovery-point design stands; off-site copy rides the estate B2/borg chain.\nBackup automation BUILT + RAN (evidence): scripts/backup.sh on prod produced encrypted borg archive intent-ops-buzz-prod-2026-07-29T183641Z (pg_dump 167KB schema-head-6 + media(6) + git + identity + manifest w/ sha256s); flock, retention 14/8/6, freshness marker, Slack notify (interim — Buzz replaces Slack post-migration), nonzero-on-fail. systemd buzz-backup.timer enabled (daily 04:20 UTC). Runbook ops/buzz/RUNBOOK-backup-restore.md. STILL OPEN: off-site B2 push (owner-gated estate-wide, Epic 1.1 B2 not provisioned) + borg repokey export off-box + Netdata backup-age alert + the wrapped updater.\nGIT CONFORMANCE PROBE risk (Priority 4) — evidence-based decision: pinned image = v0.2.0 / source rev 0d9be2f (built 2026-07-10). Upstream fix PR #2724 is still OPEN (NOT merged) -\u003e the bounded-timeout fix is NOT in our image. BUT fault test on a scratch relay (MinIO unreachable + BUZZ_GIT_CONFORMANCE_PROBE=true): the probe ran ('git object-store conformance probe A3 gate') and the relay EXITED with 's3 backend error' after ~63s (bounded by reqwest timeout) — it FAILS CLOSED, does not hang indefinitely. DECISION: KEEP the probe ON (real consistency gate; compose gates minio-healthy-before-relay; fails-closed not hangs), and MANDATE a deploy-wrapper HARD TIMEOUT (Priority 3) that bounds the relay-healthy wait + auto-reverts regardless of app behaviour — this covers the untested 'accepted-but-nonresponsive' case. Removal-of-risk condition: promote a digest containing merged #2724. Untested residual: MinIO-nonresponsive half-open (harder to reproduce safely).\nWrapped-updater half SHIPPED (intent-os PR #282, merged via estate-CI 3 green: gates 127s / drills 220s / gitleaks). Built ops/buzz/scripts/{updater,functional-probe,_repin-and-start}.sh over the drilled estate watchtower-gate/deploy-wrapper; hermetic planted-fault drill ops/buzz/tests/updater-drill.sh 6/6 (clean promote, bad-release auto-revert+store-restore+re-probe, hard-timeout hang guard rc124, scan-hold fail-closed, snapshot-abort, absent-restore manual page); systemd buzz-updater.{service,timer} (weekly Sun 05:30 UTC); runbook RUNBOOK-wrapped-updater.md; registered backup+updater timers in mission-control/automations.md; drill wired into ci:drills. STILL OPEN on .4: install the timer on the intent-ops-buzz production host + first real run; restore.sh three-store tool (follow-up bead filed). Real functional-probe-against-live-staging is buzz-ocv.3.\nUpdater lane DEPLOYED to staging (dormant) via install-updater-lane.sh (intent-os PR #284): 3 buzz scripts + 2 estate deps (watchtower-gate/deploy-wrapper -\u003e /srv/buzz/lib/) + systemd units; daemon-reload OK, timer disabled/inactive. Fixed container-name (buzz-relay-1) + governed-notify + systemd env wiring from live state. Prod updater install + timer-enable gated on the real staging functional-probe rehearsal (blocked on installing nak — new bead).","status":"in_progress","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T15:47:20Z","created_by":"jeremylongshore","updated_at":"2026-07-29T21:47:44Z","started_at":"2026-07-29T18:34:08Z","labels":["hosting"],"dependencies":[{"issue_id":"buzz-ocv.4","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T09:47:20Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.3","title":"Prove the deployment: smokes, functional membership probe, and the off-network unauth probe matrix","description":"/health + /_readiness + NIP-11; nak NIP-42 member publish/readback + un-invited refusal; media PUT / git packs / hooks endpoints all 401-403","status":"open","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T15:47:19Z","created_by":"jeremylongshore","updated_at":"2026-07-29T15:47:19Z","labels":["hosting"],"dependencies":[{"issue_id":"buzz-ocv.3","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T09:47:18Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.2","title":"Wire the estate Caddy ingress with the compensating edge controls","description":"site block + WS passthrough, body-size caps, timeouts, security headers; caddy validate + reload","status":"open","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T15:47:18Z","created_by":"jeremylongshore","updated_at":"2026-07-29T15:47:18Z","labels":["hosting"],"dependencies":[{"issue_id":"buzz-ocv.2","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T09:47:17Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv.1","title":"Provision DNS, secrets, and the /srv/buzz compose stack, booted closed from first start","description":"dns + sops env (relay identity key, bootstrap op owner key, HMAC, db/redis/minio creds) + estate-owned compose with digest-pinned image, loopback publish, resource caps","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T15:47:17Z","created_by":"jeremylongshore","updated_at":"2026-07-29T15:52:10Z","closed_at":"2026-07-29T15:52:10Z","close_reason":"buzz.intentsolutions.io A record live (Porkbun lane); secrets generated (relay identity + bootstrap op owner + HMAC + db/redis/minio) deployed as /srv/buzz/.env mode 600 with sops master in intent-os ops/buzz/secrets/buzz.prod.env.sops (dev+VPS age recipients); estate-owned compose (digest-pinned image, loopback publish 3004/3084, mem/cpus/pids caps, own bridge net) deployed; all 4 containers healthy; _readiness 200; NIP-11 serving; closed-relay env from first boot","labels":["hosting"],"dependencies":[{"issue_id":"buzz-ocv.1","depends_on_id":"buzz-ocv","type":"parent-child","created_at":"2026-07-29T09:47:16Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-ocv","title":"Stand up the closed Buzz relay stack on the estate VPS behind the wrapped update lane","description":"RE-SCOPED 2026-07-29 (owner topology decision, fork 000-docs/005): this stack on the SHARED estate VPS is STAGING, permanently — same compose, same gates; restore drills and updater planted-fault drills run here, never on prod. Production moves to a DEDICATED VPS (Track D epic). Original scope: /srv/buzz compose stack (relay pinned by digest, Postgres 17, Redis 7, MinIO interim) closed from first boot, sops-held secrets, loopback publish behind estate Caddy, resource caps, DNS, smokes + unauth probe matrix, pg_dump backup wiring, wrapped updater. At cutover this env renames to buzz-staging.intentsolutions.io. E3 go-live gates run against PROD on the dedicated box before any invite.","notes":"GitHub: intent-solutions-io/buzz#8 — https://github.com/intent-solutions-io/buzz/issues/8. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-ocv` and `bd-sync close buzz-ocv` mirror to GH and Plane automatically.\n\nPlane: BUZZ-2 — https://projects.intentsolutions.io/internal/projects/?peekIssue=BUZZ-2\nTOPOLOGY RE-SCOPE (owner decision 2026-07-29, recorded as fork 000-docs/005): this shared-VPS stack is re-designated permanent STAGING — same compose, same gates; restore drills and updater planted-fault drills run here, never on prod. Production moves to a dedicated VPS (epic buzz-nry / GH #9 / Plane BUZZ-3). At cutover this env renames to buzz-staging.intentsolutions.io; staging keys never promote to prod. New Track-E children under this epic: .5 Tauri/CORS desktop-join fix, .6 mobile pairing sidecar overlay; updater promotion-checklist additions noted on .4.","status":"in_progress","priority":2,"issue_type":"epic","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T15:47:04Z","created_by":"jeremylongshore","updated_at":"2026-07-29T16:32:24Z","started_at":"2026-07-29T15:47:21Z","labels":["hosting"],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-4ei.4","title":"Mirror the epic three-way and seed repo and estate memory","description":"GitHub cluster issue on intent-solutions-io/buzz + Plane BUZZ project via bd-sync link; auto-memory for the buzz working dir; estate memory buzz-adoption-state; private ops/buzz/README.md operator authority.","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:24:21Z","created_by":"jeremylongshore","updated_at":"2026-07-29T04:36:11Z","closed_at":"2026-07-29T04:36:11Z","close_reason":"Three-way mirror live: buzz-4ei linked via bd-sync to intent-solutions-io/buzz#1 + Plane BUZZ-1 (comments fanned out); Plane project BUZZ created; estate anchor spine-8fl linked to the same pair; memories seeded (buzz working-dir auto-memory + intent-os buzz-adoption-state + ops/buzz/README.md operator authority)","labels":["bead-tooling"],"dependencies":[{"issue_id":"buzz-4ei.4","depends_on_id":"buzz-4ei","type":"parent-child","created_at":"2026-07-28T22:24:21Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-4ei.3","title":"Implement the missing test layers with the in-repo audit harness, Layer 1 git hooks required","description":"/implement-tests for gaps found by the baseline audit; in-repo enforcement only (cargo/vendored harness), additive files only, staged for review.","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:24:20Z","created_by":"jeremylongshore","updated_at":"2026-07-29T06:21:36Z","closed_at":"2026-07-29T06:21:36Z","close_reason":"Merged in PR #6 (fa14f3f16): scripts/fork-gates/{additive-only,must-survive} + vendored audit-harness + 10-file hash-pin manifest + tracked lefthook-local.yml (escape-scan pre-commit; gates+verify pre-push) + decision record 000-docs/004. All four gates green on the merged tree; zero upstream-path edits","labels":["test-hygiene"],"dependencies":[{"issue_id":"buzz-4ei.3","depends_on_id":"buzz-4ei","type":"parent-child","created_at":"2026-07-28T22:24:20Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-4ei.2","title":"Run the testing-SOP baseline audit and produce TEST_AUDIT.md against the 7-layer taxonomy","description":"Diagnostic only: classify the fork, map upstream's suite (just test-unit / docker integration / e2e via buzz-test-client) to the 7 layers, write TEST_AUDIT.md. Staged, not auto-committed.","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:24:19Z","created_by":"jeremylongshore","updated_at":"2026-07-29T04:26:01Z","closed_at":"2026-07-29T04:26:01Z","close_reason":"TEST_AUDIT.md written (diagnostic only): upstream suite strong across all 7 layers (~5700 Rust test fns, lefthook L1, clippy/biome/cargo-deny L2, Playwright E2E); fork-lane gaps = additive-only invariant gate + in-repo harness, handed to buzz-4ei.3","labels":["test-hygiene"],"dependencies":[{"issue_id":"buzz-4ei.2","depends_on_id":"buzz-4ei","type":"parent-child","created_at":"2026-07-28T22:24:19Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-4ei.1","title":"Author the master blueprint, decision record, deploy posture, and FORK.md as additive-only artifacts","description":"000-docs/{000-INDEX,001-PP-PLAN,002-DR-DECR,003-OD-DEPL} + FORK.md; zero upstream-path edits.","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:24:18Z","created_by":"jeremylongshore","updated_at":"2026-07-29T04:26:00Z","closed_at":"2026-07-29T04:26:00Z","close_reason":"Authored additive-only: 000-docs/{000-INDEX,001-PP-PLAN blueprint,002-DR-DECR decision record,003-OD-DEPL deploy posture} + FORK.md; git diff upstream/main --stat shows only fork-added paths","labels":["fork-infra"],"dependencies":[{"issue_id":"buzz-4ei.1","depends_on_id":"buzz-4ei","type":"parent-child","created_at":"2026-07-28T22:24:18Z","created_by":"jeremylongshore","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-4ei","title":"Stand up the Intent Solutions fork infrastructure for the Buzz adoption","description":"Phase 1 / E1 of 000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md: fork + clone + beads/Dolt activation, master blueprint + decision record + deploy posture + FORK.md, testing-SOP baseline (TEST_AUDIT.md), three-way mirror (GitHub cluster issue + Plane BUZZ) and memory seeding. Additive-only: zero upstream-path edits.","notes":"GitHub: intent-solutions-io/buzz#1 — https://github.com/intent-solutions-io/buzz/issues/1. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-4ei` and `bd-sync close buzz-4ei` mirror to GH and Plane automatically.\n\nPlane: BUZZ-1 — https://projects.intentsolutions.io/internal/projects/?peekIssue=BUZZ-1\nE1 milestone: blueprint set + FORK.md + TEST_AUDIT.md authored (buzz-4ei.1, .2 closed); beads write-path root-caused (bd contributor-role fork routing) and fixed via --role maintainer; PR opening next. Note: epic was re-minted from buzz-ekg to buzz-4ei during the store rebuild.\nE1 shipped: PR intent-solutions-io/buzz#2 squash-merged to fork main (6cf4df96f) after CodeRabbit review (4 findings fixed in e49ed40a6, 2 declined with reasons). Children .1/.2/.4 closed with evidence; .3 (fork-lane test layers) remains open — epic stays in_progress until it lands. Deferred: epic-boundary Dolt tag until dolt-mcp-vcs is available (system dolt CLI is version-skewed vs bd's embedded engine).","status":"closed","priority":2,"issue_type":"epic","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:24:17Z","created_by":"jeremylongshore","updated_at":"2026-07-29T06:21:39Z","started_at":"2026-07-29T04:25:59Z","closed_at":"2026-07-29T06:21:39Z","close_reason":"E1 complete: all 4 children closed with evidence (PRs #2/#3/#5/#6 merged; blueprint ledger E1=COMPLETE; GH cluster #1 auto-closed by PR #6). Fork contract now machine-enforced. Phase 2 hosting opens per blueprint after the MX cutover.","dependency_count":0,"dependent_count":0,"comment_count":0} -{"_type":"issue","id":"buzz-bkt","title":"acceptance probe","status":"closed","priority":2,"issue_type":"task","owner":"jeremylongshore@users.noreply.github.com","created_at":"2026-07-29T04:23:48Z","created_by":"jeremylongshore","updated_at":"2026-07-29T04:23:49Z","started_at":"2026-07-29T04:23:49Z","closed_at":"2026-07-29T04:23:49Z","close_reason":"probe","dependency_count":0,"dependent_count":0,"comment_count":0} +{"_type": "issue", "id": "buzz-2i6", "title": "Install nak on the Buzz hosts and run the real functional-probe rehearsal, then enable the prod updater timer", "description": "The updater lane is deployed to staging (dormant) but the real functional-probe rehearsal is blocked: nak (the NIP-42 auth+publish+readback CLI the probe uses) is absent on the Buzz hosts. buzz-admin IS in the relay image. Steps: install nak on staging (+ prod), run functional-probe.sh against the live staging relay (throwaway member auth+publish+readback, un-invited refused, cleans up), then a controlled no-op-digest updater rehearsal on staging, THEN install-updater-lane.sh intent-ops-buzz --enable-timer for prod. Parent: buzz-ocv.4.", "notes": "REHEARSAL PARTIAL on live staging 2026-07-29 (nak copied to /usr/local/bin/nak on the staging host; jq present). VERIFIED LIVE: closed relay up+healthy+CORS-applied; buzz-admin add-member/remove-member/list-members work — EXACT syntax is 'buzz-admin add-member --pubkey ' (NOT positional; positional errors with usage). nak emits 64-char hex from 'nak key public'; relay accepts hex. add+remove round-trip proven; test member cleaned up (relay left clean: owner + 1 pre-existing member). REMAINING: the nak publish/readback NIP-42 flow hung with reactive '--auth' — the closed relay likely needs '--force-pre-auth' (authenticate BEFORE the EVENT/REQ), and readback (nak req -i ) on a closed relay also needs auth so the member NSEC must be threaded into functional-probe.sh's readback() (currently it only gets the event id). NEXT: (1) prove 'NOSTR_SECRET_KEY= nak event -k1 -c X --auth --force-pre-auth ' returns an id against staging; (2) prove readback with the member key; (3) bake the verified commands + --pubkey into functional-probe.sh add_member/del_member/publish/readback; (4) then no-op-digest updater rehearsal on staging; (5) install-updater-lane.sh intent-ops-buzz --enable-timer.", "status": "open", "priority": 1, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T21:47:43Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T21:51:24Z", "labels": ["go-live", "probe", "updater"], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-aet", "title": "Author the authoritative Buzz naming and boundaries record and reconcile the blueprint ledger to prod-up", "description": "Track B of the Buzz adoption plan (owner amendment 2026-07-29, do FIRST). Author the canonical naming+boundaries record in the fork 000-docs from the AUTHORITATIVE NAMING & REPOSITORY MODEL table: 6 assets (upstream block/buzz, code fork intent-solutions-io/buzz, contributor lab intent-solutions-io/intent-ops-buzz repo, production host intent-ops-buzz VPS, live ops lane intent-os ops/buzz, deferred plugin intent-solutions-io/intent-ops-buzz-plugin), the disambiguation rule (never bare 'intent-ops-buzz'), and the four-plane flow with two separate gates (contribution vs deployment). Reconcile the blueprint 001 completion ledger to reality (prod host built/deployed/verified pre-cutover, backups+restore proven), name the plugin repo deferred, and add the contributor-lab plane. Unblocks the parked contributor-lab architecture DRAFT (Track C). The amendment forbids durable architecture docs until this lands. Done-means: naming doc exists + internally consistent; ledger prod-up; no bare-intent-ops-buzz ambiguity; pnpm check green on the intent-os reconcile edit.", "status": "closed", "priority": 1, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T19:19:37Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T19:36:54Z", "started_at": "2026-07-29T19:19:43Z", "closed_at": "2026-07-29T19:36:54Z", "close_reason": "Track B shipped: authored fork 000-docs/006-DR-STND-authoritative-naming-and-boundaries.md (canonical six-asset table + host-vs-repo disambiguation rule + four-plane flow + two-gate model); reconciled the 001 blueprint ledger to prod-up (E2/E2d/E3 states, ELab row, E9 plugin named intent-ops-buzz-plugin + DEFERRED, new Phase 6 pointer); added the intent-os ops/buzz/README 'Naming & planes' section. Merged: fork PR #11 + intent-os PR #281 (estate-CI 3 green contexts: gates 128s, drills 212s, gitleaks). pnpm check EXIT=0; no bare-intent-ops-buzz ambiguity remains.", "labels": ["architecture", "ledger", "naming"], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-nry.3", "title": "Run the full go-live gate suite against production on the dedicated box", "description": "The full E3 go-live gate suite to RUN against PROD before any invite (all BLOCKING, none assumed passed): unauth probe matrix off-network; functional membership probe (NIP-42 publish+readback, un-invited refused); backup restore drill (restore staging from prod's artifacts); updater planted-fault drill on staging; key runbooks rehearsed; resource caps verified. Status is tracked per-gate in the notes and in intent-os ops/buzz — the off-site backup leg and several gates remain OPEN; this description is scope, not a completion claim.", "notes": "Go-live gates PARTIAL against prod: (1) functional membership probe GREEN — owner NIP-42 auth -> publish -> readback OK; un-invited key REFUSED (closed relay enforcing, member_count:1 on boot). (2) unauth HTTP probe matrix PASS — media PUT 405, git 404/405, hooks 400, admin 404; public readiness/NIP-11/web-client 200. (3) resource caps + loopback-only publish + isolated bridge net verified. REMAINING/BLOCKING before any invite: backup-restore drill, updater planted-fault drill, key runbooks — all depend on backup+updater wiring (buzz-ocv.4, not built).\nRESTORE DRILL PROVEN (buzz-nry.3 gate item): restored the first prod archive into an ISOLATED dev-box scratch project (prod/staging untouched, prod 4/4 healthy throughout). 40 tables restored; the exact prod-published event 9717ccaa physically present; relay_members=1 + member_count:1 on boot; media restored; relay identity stable (same key->35cd57ab); relay boots healthy; un-invited refused; restart persistence holds. RTO ~3min, RPO = backup point (18:36:41Z). Caveat: headless nak auth-on-REQ readback didn't complete in-harness (passed on prod). Evidence: ops/buzz/RUNBOOK-backup-restore.md. STILL BLOCKING before invite: updater planted-fault drill, key runbooks, off-site copy.", "status": "open", "priority": 1, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:31:30Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T18:45:39Z", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-nry.3", "depends_on_id": "buzz-nry.2", "type": "blocks", "created_at": "2026-07-29T10:31:31Z", "created_by": "jeremylongshore", "metadata": "{}"}, {"issue_id": "buzz-nry.3", "depends_on_id": "buzz-nry", "type": "parent-child", "created_at": "2026-07-29T10:31:29Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 1, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-nry.2", "title": "Deploy production from the proven staging artifacts with fresh secrets and cut DNS over", "description": "Deploy prod from the proven staging artifacts (same digest-pinned compose) with FRESH secrets minted on the new box (new relay identity, new bootstrap owner key until the owner's desktop key swaps in, new db/redis/minio; staging keys never promote). DNS cuts over to the prod host at go-live; the shared stack renames to the staging domain. Deploy specifics + addressing in intent-os ops/buzz. Depends on the bootstrap child.", "notes": "Prod deploy DONE (apex cutover pending): staging-proven digest-pinned compose deployed with FRESH prod secrets; 4 containers healthy; own Caddy ingress TLS + security headers. REMAINING (gated on the owner's client-generated desktop key): DNS cutover to the prod host, rename staging to the staging domain, swap BUZZ_DOMAIN/RELAY_URL/CORS to the apex, swap RELAY_OWNER_PUBKEY to the owner's desktop pubkey. Addressing + specifics in intent-os ops/buzz.", "status": "open", "priority": 1, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:31:22Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T18:17:43Z", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-nry.2", "depends_on_id": "buzz-nry", "type": "parent-child", "created_at": "2026-07-29T10:31:22Z", "created_by": "jeremylongshore", "metadata": "{}"}, {"issue_id": "buzz-nry.2", "depends_on_id": "buzz-nry.1", "type": "blocks", "created_at": "2026-07-29T10:31:31Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 1, "dependent_count": 1, "comment_count": 0} +{"_type": "issue", "id": "buzz-nry.1", "title": "Bootstrap the new production host to estate conventions", "description": "Bootstrap the dedicated prod host to estate ops/host conventions: Ubuntu 24.04, tailnet-only SSH, ufw, fail2ban, unattended-upgrades, docker, its own Caddy (separate ingress = separate failure domain), age host key + sops, borg client, Netdata (tailnet-bound). Host addressing, key paths, and access detail live ONLY in intent-os ops/buzz. Gated on the owner installing the dev-box SSH key.", "status": "closed", "priority": 1, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:31:15Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T18:06:58Z", "started_at": "2026-07-29T17:57:57Z", "closed_at": "2026-07-29T18:06:58Z", "close_reason": "intent-ops-buzz bootstrapped to estate baseline + verified: Ubuntu 24.04.4 LTS, hostname intent-ops-buzz, joined tailnet [tailnet addr — intent-os ops/buzz] (untagged/user-owned, matching estate); ufw default-deny (tailnet-trusted iface + public 80/443 only, public 22 CLOSED/times-out); sshd key-only + PermitRootLogin no + PasswordAuthentication no; a non-root sudo admin account (NOPASSWD, docker group); fail2ban + unattended-upgrades active; 2G swap swappiness=10; docker 29.6 (log-rotation + live-restore) + compose v5.3; caddy 2.11 (own ingress); age host key at [host key path — intent-os ops/host] (recipient [host age recipient — intent-os ops/host/secrets]); borg client; sops 3.9.4; Netdata bound loopback+tailnet only (127.0.0.1:19999 + [tailnet addr — intent-os ops/buzz]:19999, not public). 7/7 services active.", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-nry.1", "depends_on_id": "buzz-nry", "type": "parent-child", "created_at": "2026-07-29T10:31:15Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 1, "comment_count": 0} +{"_type": "issue", "id": "buzz-nry", "title": "Stand up the dedicated Buzz production VPS and cut the prod domain over to it", "description": "Track D: Buzz production runs on its OWN dedicated VPS (owner topology decision 2026-07-29, fork 000-docs/005) so a fast-moving pre-1.0 stack does not share a failure domain with revenue workloads. The shared-VPS stack becomes permanent STAGING (epic buzz-ocv). Prod = the proven staging artifacts (same digest-pinned compose) with FRESH secrets; staging keys never promote. All go-live gates run against prod before any invite. Concrete host detail (addressing, keys, DNS, deploy specifics) lives ONLY in the private intent-os ops/buzz lane.", "notes": "GitHub: intent-solutions-io/buzz#9 — https://github.com/intent-solutions-io/buzz/issues/9. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-nry` and `bd-sync close buzz-nry` mirror to GH and Plane automatically.\n\nPlane: BUZZ-3 — (Plane, internal)", "status": "in_progress", "priority": 1, "issue_type": "epic", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:31:08Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T17:57:57Z", "started_at": "2026-07-29T17:57:57Z", "labels": ["hosting"], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-bsy", "title": "Build the Buzz three-store restore tool (restore.sh) and its restore drill", "description": "The wrapped updater's ordered store-restore on a bad-migration revert calls ops/buzz/scripts/restore.sh (--recovery-point --env ) in intent-os. Until it exists+drilled, the updater fail-closes to exit 5 (manual page) rather than faking a DB rollback. Build restore.sh (pg_dump -Fc restore + MinIO media + git volume from a bound recovery point, dangling-ref walk) + a restore drill, so bad-migration recovery is fully unattended. Parent: wrapped-updater lane (buzz-ocv.4).", "status": "open", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T20:13:56Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T20:13:56Z", "labels": ["backup", "restore", "updater"], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.6", "title": "Add the mobile pairing sidecar overlay and validate a real desktop-to-mobile pairing", "description": "Track E2 (external infra review; upstream #2734 / PR #2736): the first-party compose bundle lacks the buzz-pair-relay sidecar, so Android members cannot pair — and the all-in onboarding wave includes Android. Review the pinned image for the buzz-pair-relay entrypoint, add an estate overlay service (same image, entrypoint buzz-pair-relay, internal :5000, healthcheck) + a Caddy /pair* route. Claim it works only after a REAL desktop-to-mobile pairing succeeds; if wave 1 doesn't require it, document the limitation honestly instead.", "status": "open", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:30:45Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T16:30:45Z", "labels": ["clients", "hosting"], "dependencies": [{"issue_id": "buzz-ocv.6", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T10:30:45Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.5", "title": "Set the Tauri desktop origins in the relay CORS config and verify with the packaged desktop client", "description": "Track E1 (external infra review, verified vs upstream #3490): current env allows only https://the prod domain as an origin; packaged Tauri desktop clients present tauri://localhost (macOS/Linux) or http://tauri.localhost (Windows), so desktop join is BLOCKED. Verify the pinned image's CORS env handling, add the two Tauri origins (no permissive-CORS shortcuts), restart, confirm relay healthy + correct Access-Control-Allow-Origin echo. Final verification is a join from the PACKAGED desktop client on the owner's workstation, not a dev build.", "notes": "CORS CONFIG FIXED (intent-os PR #283, merged via estate-CI 3 green). BUZZ_CORS_ORIGINS composed in version-controlled compose from required BUZZ_DOMAIN + tauri://localhost + http://tauri.localhost (environment: overrides env_file; non-secret Tauri origins out of sops). Closes the desktop-join gap AND a latent permissive-CORS gap (relay goes permissive only when the var is EMPTY; required BUZZ_DOMAIN makes empty impossible). Proof: ops/buzz/tests/cors-config-test.sh 2/2, wired into ci:drills. REMAINING (owner-gated): apply on staging (docker compose up -d relay) + verify a real join with the PACKAGED desktop client on Jeremy's workstation (dev build won't exercise Tauri origins).\nCORS APPLIED LIVE to BOTH hosts 2026-07-29 (intent-os PR #284 records; compose applied with backup + config-gate + relay recreate). Staging BUZZ_CORS_ORIGINS=https://the prod domain,tauri://localhost,http://tauri.localhost ; prod=…buzz-prod…,tauri…; relay healthy + _readiness 200 on each. Desktop-join unblocked on the live boxes. ONLY remaining: packaged-desktop-client verify on Jeremy's workstation (owner-gated).", "status": "in_progress", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T16:30:36Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T21:47:44Z", "started_at": "2026-07-29T21:16:21Z", "labels": ["clients", "hosting"], "dependencies": [{"issue_id": "buzz-ocv.5", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T10:30:35Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.4", "title": "Wire backups and the wrapped updater, register everything in the estate", "description": "nightly pg_dump artifact into the borg set + three-store recovery point; weekly updater snapshot-promote-probe-revert; automations.md + catalog rows; E3 drill gates filed", "notes": "Track E additions (external infra review 2026-07-29): the wrapped updater's promotion checklist MUST include — release-notes review; a staging boot; a probe-hang check (upstream #2723/PR #2724 — git conformance probe can wedge startup; our pinned digest boots healthy with BUZZ_GIT_CONFORMANCE_PROBE=true, but a future image must prove it on staging before promotion); a CORS/Tauri-origin regression check; a pairing regression check. Also confirmed: upstream's own 'backup' command is a checklist, not a backup — our pg_dump + three-store recovery-point design stands; off-site copy rides the estate B2/borg chain.\nBackup automation BUILT + RAN (evidence): scripts/backup.sh on prod produced encrypted borg archive intent-ops-buzz-prod-2026-07-29T183641Z (pg_dump 167KB schema-head-6 + media(6) + git + identity + manifest w/ sha256s); flock, retention 14/8/6, freshness marker, Slack notify (interim — Buzz replaces Slack post-migration), nonzero-on-fail. systemd buzz-backup.timer enabled (daily 04:20 UTC). Runbook ops/buzz/RUNBOOK-backup-restore.md. STILL OPEN: off-site B2 push (owner-gated estate-wide, Epic 1.1 B2 not provisioned) + borg repokey export off-box + Netdata backup-age alert + the wrapped updater.\nGIT CONFORMANCE PROBE risk (Priority 4) — evidence-based decision: pinned image = v0.2.0 / source rev 0d9be2f (built 2026-07-10). Upstream fix PR #2724 is still OPEN (NOT merged) -> the bounded-timeout fix is NOT in our image. BUT fault test on a scratch relay (MinIO unreachable + BUZZ_GIT_CONFORMANCE_PROBE=true): the probe ran ('git object-store conformance probe A3 gate') and the relay EXITED with 's3 backend error' after ~63s (bounded by reqwest timeout) — it FAILS CLOSED, does not hang indefinitely. DECISION: KEEP the probe ON (real consistency gate; compose gates minio-healthy-before-relay; fails-closed not hangs), and MANDATE a deploy-wrapper HARD TIMEOUT (Priority 3) that bounds the relay-healthy wait + auto-reverts regardless of app behaviour — this covers the untested 'accepted-but-nonresponsive' case. Removal-of-risk condition: promote a digest containing merged #2724. Untested residual: MinIO-nonresponsive half-open (harder to reproduce safely).\nWrapped-updater half SHIPPED (intent-os PR #282, merged via estate-CI 3 green: gates 127s / drills 220s / gitleaks). Built ops/buzz/scripts/{updater,functional-probe,_repin-and-start}.sh over the drilled estate watchtower-gate/deploy-wrapper; hermetic planted-fault drill ops/buzz/tests/updater-drill.sh 6/6 (clean promote, bad-release auto-revert+store-restore+re-probe, hard-timeout hang guard rc124, scan-hold fail-closed, snapshot-abort, absent-restore manual page); systemd buzz-updater.{service,timer} (weekly Sun 05:30 UTC); runbook RUNBOOK-wrapped-updater.md; registered backup+updater timers in mission-control/automations.md; drill wired into ci:drills. STILL OPEN on .4: install the timer on the intent-ops-buzz production host + first real run; restore.sh three-store tool (follow-up bead filed). Real functional-probe-against-live-staging is buzz-ocv.3.\nUpdater lane DEPLOYED to staging (dormant) via install-updater-lane.sh (intent-os PR #284): 3 buzz scripts + 2 estate deps (watchtower-gate/deploy-wrapper -> /srv/buzz/lib/) + systemd units; daemon-reload OK, timer disabled/inactive. Fixed container-name (buzz-relay-1) + governed-notify + systemd env wiring from live state. Prod updater install + timer-enable gated on the real staging functional-probe rehearsal (blocked on installing nak — new bead).", "status": "in_progress", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T15:47:20Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T21:47:44Z", "started_at": "2026-07-29T18:34:08Z", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-ocv.4", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T09:47:20Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.3", "title": "Prove the deployment: smokes, functional membership probe, and the off-network unauth probe matrix", "description": "/health + /_readiness + NIP-11; nak NIP-42 member publish/readback + un-invited refusal; media PUT / git packs / hooks endpoints all 401-403", "status": "open", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T15:47:19Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T15:47:19Z", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-ocv.3", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T09:47:18Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.2", "title": "Wire the estate Caddy ingress with the compensating edge controls", "description": "site block + WS passthrough, body-size caps, timeouts, security headers; caddy validate + reload", "status": "open", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T15:47:18Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T15:47:18Z", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-ocv.2", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T09:47:17Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv.1", "title": "Provision DNS, secrets, and the /srv/buzz compose stack, booted closed from first start", "description": "dns + sops env (relay identity key, bootstrap op owner key, HMAC, db/redis/minio creds) + estate-owned compose with digest-pinned image, loopback publish, resource caps", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T15:47:17Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T15:52:10Z", "closed_at": "2026-07-29T15:52:10Z", "close_reason": "the prod domain A record live (Porkbun lane); secrets generated (relay identity + bootstrap op owner + HMAC + db/redis/minio) deployed as /srv/buzz/.env mode 600 with sops master in intent-os ops/buzz/secrets/buzz.prod.env.sops (dev+VPS age recipients); estate-owned compose (digest-pinned image, loopback publish 3004/3084, mem/cpus/pids caps, own bridge net) deployed; all 4 containers healthy; _readiness 200; NIP-11 serving; closed-relay env from first boot", "labels": ["hosting"], "dependencies": [{"issue_id": "buzz-ocv.1", "depends_on_id": "buzz-ocv", "type": "parent-child", "created_at": "2026-07-29T09:47:16Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-ocv", "title": "Stand up the closed Buzz relay stack on the estate VPS behind the wrapped update lane", "description": "RE-SCOPED 2026-07-29 (owner topology decision, fork 000-docs/005): this stack on the SHARED estate VPS is STAGING, permanently — same compose, same gates; restore drills and updater planted-fault drills run here, never on prod. Production moves to a DEDICATED VPS (Track D epic). Original scope: /srv/buzz compose stack (relay pinned by digest, Postgres 17, Redis 7, MinIO interim) closed from first boot, sops-held secrets, loopback publish behind estate Caddy, resource caps, DNS, smokes + unauth probe matrix, pg_dump backup wiring, wrapped updater. At cutover this env renames to the staging domain. E3 go-live gates run against PROD on the dedicated box before any invite.", "notes": "GitHub: intent-solutions-io/buzz#8 — https://github.com/intent-solutions-io/buzz/issues/8. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-ocv` and `bd-sync close buzz-ocv` mirror to GH and Plane automatically.\n\nPlane: BUZZ-2 — (Plane, internal)\nTOPOLOGY RE-SCOPE (owner decision 2026-07-29, recorded as fork 000-docs/005): this shared-VPS stack is re-designated permanent STAGING — same compose, same gates; restore drills and updater planted-fault drills run here, never on prod. Production moves to a dedicated VPS (epic buzz-nry / GH #9 / Plane BUZZ-3). At cutover this env renames to the staging domain; staging keys never promote to prod. New Track-E children under this epic: .5 Tauri/CORS desktop-join fix, .6 mobile pairing sidecar overlay; updater promotion-checklist additions noted on .4.", "status": "in_progress", "priority": 2, "issue_type": "epic", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T15:47:04Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T16:32:24Z", "started_at": "2026-07-29T15:47:21Z", "labels": ["hosting"], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-4ei.4", "title": "Mirror the epic three-way and seed repo and estate memory", "description": "GitHub cluster issue on intent-solutions-io/buzz + Plane BUZZ project via bd-sync link; auto-memory for the buzz working dir; estate memory buzz-adoption-state; private ops/buzz/README.md operator authority.", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:24:21Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T04:36:11Z", "closed_at": "2026-07-29T04:36:11Z", "close_reason": "Three-way mirror live: buzz-4ei linked via bd-sync to intent-solutions-io/buzz#1 + Plane BUZZ-1 (comments fanned out); Plane project BUZZ created; estate anchor spine-8fl linked to the same pair; memories seeded (buzz working-dir auto-memory + intent-os buzz-adoption-state + ops/buzz/README.md operator authority)", "labels": ["bead-tooling"], "dependencies": [{"issue_id": "buzz-4ei.4", "depends_on_id": "buzz-4ei", "type": "parent-child", "created_at": "2026-07-28T22:24:21Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-4ei.3", "title": "Implement the missing test layers with the in-repo audit harness, Layer 1 git hooks required", "description": "/implement-tests for gaps found by the baseline audit; in-repo enforcement only (cargo/vendored harness), additive files only, staged for review.", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:24:20Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T06:21:36Z", "closed_at": "2026-07-29T06:21:36Z", "close_reason": "Merged in PR #6 (fa14f3f16): scripts/fork-gates/{additive-only,must-survive} + vendored audit-harness + 10-file hash-pin manifest + tracked lefthook-local.yml (escape-scan pre-commit; gates+verify pre-push) + decision record 000-docs/004. All four gates green on the merged tree; zero upstream-path edits", "labels": ["test-hygiene"], "dependencies": [{"issue_id": "buzz-4ei.3", "depends_on_id": "buzz-4ei", "type": "parent-child", "created_at": "2026-07-28T22:24:20Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-4ei.2", "title": "Run the testing-SOP baseline audit and produce TEST_AUDIT.md against the 7-layer taxonomy", "description": "Diagnostic only: classify the fork, map upstream's suite (just test-unit / docker integration / e2e via buzz-test-client) to the 7 layers, write TEST_AUDIT.md. Staged, not auto-committed.", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:24:19Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T04:26:01Z", "closed_at": "2026-07-29T04:26:01Z", "close_reason": "TEST_AUDIT.md written (diagnostic only): upstream suite strong across all 7 layers (~5700 Rust test fns, lefthook L1, clippy/biome/cargo-deny L2, Playwright E2E); fork-lane gaps = additive-only invariant gate + in-repo harness, handed to buzz-4ei.3", "labels": ["test-hygiene"], "dependencies": [{"issue_id": "buzz-4ei.2", "depends_on_id": "buzz-4ei", "type": "parent-child", "created_at": "2026-07-28T22:24:19Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-4ei.1", "title": "Author the master blueprint, decision record, deploy posture, and FORK.md as additive-only artifacts", "description": "000-docs/{000-INDEX,001-PP-PLAN,002-DR-DECR,003-OD-DEPL} + FORK.md; zero upstream-path edits.", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:24:18Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T04:26:00Z", "closed_at": "2026-07-29T04:26:00Z", "close_reason": "Authored additive-only: 000-docs/{000-INDEX,001-PP-PLAN blueprint,002-DR-DECR decision record,003-OD-DEPL deploy posture} + FORK.md; git diff upstream/main --stat shows only fork-added paths", "labels": ["fork-infra"], "dependencies": [{"issue_id": "buzz-4ei.1", "depends_on_id": "buzz-4ei", "type": "parent-child", "created_at": "2026-07-28T22:24:18Z", "created_by": "jeremylongshore", "metadata": "{}"}], "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-4ei", "title": "Stand up the Intent Solutions fork infrastructure for the Buzz adoption", "description": "Phase 1 / E1 of 000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md: fork + clone + beads/Dolt activation, master blueprint + decision record + deploy posture + FORK.md, testing-SOP baseline (TEST_AUDIT.md), three-way mirror (GitHub cluster issue + Plane BUZZ) and memory seeding. Additive-only: zero upstream-path edits.", "notes": "GitHub: intent-solutions-io/buzz#1 — https://github.com/intent-solutions-io/buzz/issues/1. MIRROR RULE: bd-sync handles fan-out — `bd-sync note buzz-4ei` and `bd-sync close buzz-4ei` mirror to GH and Plane automatically.\n\nPlane: BUZZ-1 — (Plane, internal)\nE1 milestone: blueprint set + FORK.md + TEST_AUDIT.md authored (buzz-4ei.1, .2 closed); beads write-path root-caused (bd contributor-role fork routing) and fixed via --role maintainer; PR opening next. Note: epic was re-minted from buzz-ekg to buzz-4ei during the store rebuild.\nE1 shipped: PR intent-solutions-io/buzz#2 squash-merged to fork main (6cf4df96f) after CodeRabbit review (4 findings fixed in e49ed40a6, 2 declined with reasons). Children .1/.2/.4 closed with evidence; .3 (fork-lane test layers) remains open — epic stays in_progress until it lands. Deferred: epic-boundary Dolt tag until dolt-mcp-vcs is available (system dolt CLI is version-skewed vs bd's embedded engine).", "status": "closed", "priority": 2, "issue_type": "epic", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:24:17Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T06:21:39Z", "started_at": "2026-07-29T04:25:59Z", "closed_at": "2026-07-29T06:21:39Z", "close_reason": "E1 complete: all 4 children closed with evidence (PRs #2/#3/#5/#6 merged; blueprint ledger E1=COMPLETE; GH cluster #1 auto-closed by PR #6). Fork contract now machine-enforced. Phase 2 hosting opens per blueprint after the MX cutover.", "dependency_count": 0, "dependent_count": 0, "comment_count": 0} +{"_type": "issue", "id": "buzz-bkt", "title": "acceptance probe", "status": "closed", "priority": 2, "issue_type": "task", "owner": "jeremylongshore@users.noreply.github.com", "created_at": "2026-07-29T04:23:48Z", "created_by": "jeremylongshore", "updated_at": "2026-07-29T04:23:49Z", "started_at": "2026-07-29T04:23:49Z", "closed_at": "2026-07-29T04:23:49Z", "close_reason": "probe", "dependency_count": 0, "dependent_count": 0, "comment_count": 0} diff --git a/000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md b/000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md index 1ca30180663..8b681bfff24 100644 --- a/000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md +++ b/000-docs/001-PP-PLAN-buzz-adoption-master-blueprint.md @@ -90,8 +90,9 @@ Asset names are governed by `006-DR-STND-authoritative-naming-and-boundaries.md` (canonical). Never write the bare phrase `intent-ops-buzz` — it is either the **production host** or the **repository**; always disambiguate. -(Phase 6 of the adoption program — the LMS↔estate integration audit — lives -entirely in the private operations repo; it has no epic here.) +(The LMS↔estate integration audit — an adjacent adoption-program workstream — +lives entirely in the private operations repo; it has no phase or epic here. +Phase 6 in this tree is the contributor laboratory, below.) --- diff --git a/000-docs/006-DR-STND-authoritative-naming-and-boundaries.md b/000-docs/006-DR-STND-authoritative-naming-and-boundaries.md index 4643580ac82..7c906ebbbf0 100644 --- a/000-docs/006-DR-STND-authoritative-naming-and-boundaries.md +++ b/000-docs/006-DR-STND-authoritative-naming-and-boundaries.md @@ -57,7 +57,7 @@ Each plane does exactly one job. The lab **executes** tests; the Intent Eval Platform **decides** what the evidence means; Intent OS **records** what is approved and running; the host **runs** it. -``` +```text block/buzz ◄──PR── intent-solutions-io/buzz (contribute: clean contrib/* branches) │ candidate SHA ▼