memory: ratatoskr flipped to readonly — re-staged 439bebf policies.yaml to personal + safe restart reload
This commit is contained in:
+10
-7
@@ -142,13 +142,16 @@ _As of 2026-06-20:_
|
||||
recreate — avoided the stale-`:latest` footgun). worldtree-dev self-served the
|
||||
CI re-run via the claude-bot Actions token → **run 1290 GREEN, demo on
|
||||
v0.37.7**, capability routing live. claude-bot token migration DONE for
|
||||
worldtree-dev (off vh's personal PAT). **RATATOSKR RESOLVED (2026-06-20):**
|
||||
operator chose admin-now over readonly → worldtree-dev self-served the mint
|
||||
(`ratatoskr-admin` key_id 90db1fbd on personal, distinct from their send-only
|
||||
c990f0be) via their new admin key. The readonly-admin tier stays canonical +
|
||||
is API-mintable (d2e9f05); laying its `config/policies.yaml` to personal is now
|
||||
OPTIONAL/non-urgent (no consumer waiting) — do it only if least-privilege is
|
||||
later wanted.
|
||||
worldtree-dev (off vh's personal PAT). **RATATOSKR → READONLY (2026-06-20, final):**
|
||||
operator first said admin (worldtree-dev minted interim `ratatoskr-admin` 90db1fbd),
|
||||
then flipped to least-privilege → that key REVOKED (DELETE 200). I re-staged 439bebf's
|
||||
`config/policies.yaml` to `/opt/worldtree-personal/config` (byte-identical, sha256
|
||||
f3ca3e6…, `.bak-pre-439bebf`) and reloaded Heimdall via `docker restart
|
||||
worldtree-personal-worldtree-api-1` (same d2e9f05 SHA — the SAFE reload, no recreate/
|
||||
no `:latest` flip); personal came back healthy + the `readonly-admin` tier (7 read
|
||||
scopes incl. admin.events.read) is now in the loaded policy. worldtree-dev mints the
|
||||
ratatoskr readonly key themselves via their admin key. **Lesson: reload bind-mounted
|
||||
WT config via `docker restart <container>`, NEVER `compose up` (the `:latest` footgun).**
|
||||
|
||||
- **🟠 BACKUP DIAGNOSIS (2026-06-20, full probe) — REVISED from "all ana
|
||||
backups down": PBS + nh3-restic are HEALTHY & CURRENT; only the ANA-side
|
||||
|
||||
Reference in New Issue
Block a user