memory: cb2a79a readonly-admin allow-rules re-staged to demo+personal (PDP is rule-based)

This commit is contained in:
2026-06-20 16:43:44 -07:00
parent b13f66aea9
commit ec671e86c5
+11 -3
View File
@@ -149,9 +149,17 @@ _As of 2026-06-20:_
f3ca3e6…, `.bak-pre-439bebf`) and reloaded Heimdall via `docker restart
worldtree-personal-worldtree-api-1` (same d2e9f05 SHA — the SAFE reload, no recreate/
no `:latest` flip); personal came back healthy + the `readonly-admin` tier (7 read
scopes incl. admin.events.read) is now in the loaded policy. worldtree-dev mints the
ratatoskr readonly key themselves via their admin key. **Lesson: reload bind-mounted
WT config via `docker restart <container>`, NEVER `compose up` (the `:latest` footgun).**
scopes incl. admin.events.read) is now in the loaded policy. **FOLLOW-UP cb2a79a
(v0.37.9):** the 439bebf tier-only stage was NOT sufficient — WT's PDP is RULE-based,
so a tier with scopes but NO allow RULES is default-denied; cb2a79a adds the 4
readonly-admin allow rules. Re-staged cb2a79a `config/policies.yaml` to BOTH demo +
personal (sha256 d853e51…, `.bak-pre-cb2a79a`) + restarted BOTH API containers
(`worldtree-worldtree-api-1` + `…-personal-…`); both healthy + serving. (Still on
d2e9f05 image — CI cb2a79a deploy pending, but the bind-mount policy is the
load-bearing fix.) worldtree-dev mints the ratatoskr readonly key via their admin key.
**Lessons: (1) reload bind-mounted WT config via `docker restart <container>`, NEVER
`compose up` (the `:latest` footgun); (2) a WT tier needs allow RULES, not just
scopes — the PDP is rule-based, scopes alone default-deny.**
- **🟠 BACKUP DIAGNOSIS (2026-06-20, full probe) — REVISED from "all ana
backups down": PBS + nh3-restic are HEALTHY & CURRENT; only the ANA-side