From ec671e86c573c0ddeb9da749ce2706ca8d27b49d Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Sat, 20 Jun 2026 16:43:44 -0700 Subject: [PATCH] memory: cb2a79a readonly-admin allow-rules re-staged to demo+personal (PDP is rule-based) --- persistent-memory.md | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/persistent-memory.md b/persistent-memory.md index e2ff87b..71c9298 100644 --- a/persistent-memory.md +++ b/persistent-memory.md @@ -149,9 +149,17 @@ _As of 2026-06-20:_ f3ca3e6…, `.bak-pre-439bebf`) and reloaded Heimdall via `docker restart worldtree-personal-worldtree-api-1` (same d2e9f05 SHA — the SAFE reload, no recreate/ no `:latest` flip); personal came back healthy + the `readonly-admin` tier (7 read - scopes incl. admin.events.read) is now in the loaded policy. worldtree-dev mints the - ratatoskr readonly key themselves via their admin key. **Lesson: reload bind-mounted - WT config via `docker restart `, NEVER `compose up` (the `:latest` footgun).** + scopes incl. admin.events.read) is now in the loaded policy. **FOLLOW-UP cb2a79a + (v0.37.9):** the 439bebf tier-only stage was NOT sufficient — WT's PDP is RULE-based, + so a tier with scopes but NO allow RULES is default-denied; cb2a79a adds the 4 + readonly-admin allow rules. Re-staged cb2a79a `config/policies.yaml` to BOTH demo + + personal (sha256 d853e51…, `.bak-pre-cb2a79a`) + restarted BOTH API containers + (`worldtree-worldtree-api-1` + `…-personal-…`); both healthy + serving. (Still on + d2e9f05 image — CI cb2a79a deploy pending, but the bind-mount policy is the + load-bearing fix.) worldtree-dev mints the ratatoskr readonly key via their admin key. + **Lessons: (1) reload bind-mounted WT config via `docker restart `, NEVER + `compose up` (the `:latest` footgun); (2) a WT tier needs allow RULES, not just + scopes — the PDP is rule-based, scopes alone default-deny.** - **🟠 BACKUP DIAGNOSIS (2026-06-20, full probe) — REVISED from "all ana backups down": PBS + nh3-restic are HEALTHY & CURRENT; only the ANA-side