Files
oikos/plans/index.md
dtoro 0c0f35a3a9
Some checks failed
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
feat(web): split SPA from oikos binary, require auth on every route
Phase 0 of plans/2026-07-12-wails-desktop-app.md. The control-room SPA
is no longer embedded (web/embed.go deleted); it's a standalone static
build served separately (make ui / make deploy-ui). The api process
adds CORS and drops the dev-open auth bypass — every route now needs a
real bearer token, including SSE (?token= query param, EventSource
can't set headers) and api's own /agent proxy to nomos (previously
unauthenticated by omission).

nomos was an unauthenticated client of api's /mcp and approval-decision
endpoints; closing dev-open would have broken it, so it now sends
Authorization: Bearer $OIKOS_MCP_BEARER_TOKEN on every call back to api.

SPA gets a runtime config module (config.ts) and a Config.svelte
first-launch/reconfigure page, reachable afterwards via a "Connection"
entry in the sidebar footer. Every fetch() in api.ts routes through
fetchWithAuth so the same build works same-origin (browser prod, Vite
dev proxy) or cross-origin (future Wails webview, remote access).

Six gaps found against the plan and the live Caddy topology while
implementing — documented in the plan's "Plan review" section, most
notably: api's own /agent mount was never behind combinedAuth (fixed),
and production's Authentik forward-auth needs a bearer-token bypass for
API routes that this repo's Caddyfile.oikos reference copy now has, but
the real dtoro/caddy-conf deploy does not yet.

Verified live: cross-origin static SPA + API, CORS, bearer auth, SSE
query-token auth, and localStorage persistence all confirmed working
in-browser. Full Go test suite and npm run build pass with no
regressions against the pre-change baseline.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 15:49:42 +02:00

4.1 KiB

Plans

Pre-flight runbooks for planned changes. When a plan is executed, move it to done/ and add changelog entries on affected node pages. If things went sideways, open an investigation.

Active

Date Title Status
2026-07-05 Oikos Prometheus LXC Planned — not started
2026-07-08 Oikos gaps, broken things, and improvements In Progress — security items (B1-B5) and doc drift (E) still open
2026-07-08 Control room web UI In Progress
2026-07-08 Liveness, drift, and UX cohesion In Progress — Phase 5 deferred
2026-07-10 General gated execution: unlimited actions, gated by risk In Progress — enum retirement + auto-act revival still open
2026-07-11 Nomos agent code review: gaps and improvement plan In Progress — only C1 (unauthenticated nomos gateway) still open, deferred
2026-07-12 Wails desktop application In Progress — Phase 0 done, Phase 1 not started

Done

See done/ for executed plans:

Date Title
2026-06-01 Slate AX → SODOLA managed switch migration
2026-06-04 Deprecate claudio-bot
2026-06-25 Yuvomi deployment — house.hubris.network
2026-06-29 Grimmory migration — Booklore → dedicated LXC
2026-06-24 TRMNL plugins LXC (128) + middleware deploy pipeline
2026-07-06 Adopt wiki-hq doc architecture
2026-07-07 MCP tool completion — Hermes operator interface
2026-07-07 DB as single source of truth for agent knowledge
2026-07-07 Comprehensive audit: stale files, state gaps, and next steps
2026-07-07 Client lifecycle in Go — enrollment through deprecation
2026-07-08 Fix MCP analysis tools
2026-07-06 Consolidate Oikos control plane onto mac-mini
2026-07-08 Signal triggers: host health checks
2026-07-08 Plan vs implementation cross-reference
2026-07-08 Nomos resident agent (renames Hermes)
2026-07-09 Chat sessions: reliability, cost, and session-management fixes
2026-07-09 Session execution, UX, and learning improvements
2026-07-10 Autonomous plan execution: close the observation gap
2026-07-11 Tasks: the chat page as goal-structured autonomous work
2026-07-11 Concurrent task execution: safety + throughput + frontend correctness
2026-07-11 UI review: information architecture, usability, and best practices
2026-07-11 Task completion safety net: every live task is stuck "Running"

Conventions

  • File name: YYYY-MM-DD-<slug>.md. Use the target date if known, otherwise the planning date.
  • Status: PlannedIn ProgressDone (move to done/ on completion).
  • When done: add a changelog entry on every affected node page, then move the file to done/.
  • Plans are append-only once execution starts — don't rewrite pre-flight intent after the fact.