Problem: the hexagon's Phase 2 (plans/2026-08-15-hexagonal-architecture.md) must give the use-cases-to-be their contract surface: driven-port interfaces, test fakes, the secrets interface moved into core, and the postgres package inside the adapters tree — before the first vertical slice (Phase 3) can wire a composition root. Change: - internal/core/ports: full driven-port catalog per plan §3.3 — repositories as transaction-scoped aggregates whose inputs carry derived checks, audit, and events (§3.6), plus CommandExecutor, TargetResolver, Checker, Secrets, EventPublisher, Provisioner. Port-local payload types (Event, AuditEntry, CheckDef, KnowledgeEntry, ExecResult) keep signatures off infrastructure; TypeTree aliases internal/ontology (pure over domain) until checkdefaults is absorbed. ReadModels intentionally not declared yet — it materializes with the Phase 3 slice and grows as report handlers rewire. - secrets.Backend is now an alias of ports.Secrets; implementations (Infisical, SOPS, Manager) unchanged. mcp's local secretBackend subset is deleted; tool constructors take ports.Secrets. - internal/db → internal/adapters/postgres (mechanical import rewrite; package identifier stays db until the Phase 3 repository split). sqlc.yaml, Makefile, golangci exclusions, and docs follow the move; make generate-check verified. - internal/adapters/ssh: Executor implements ports.CommandExecutor over the actuator dial pool + RunStreaming (10-min default timeout carried over from the httpapi path). - internal/adapters/remote: Resolver implements ports.TargetResolver delegating to internal/remote (still pool-based; drops onto ports.EntityRepository when repositories land in Phase 3 — documented transitional import). - internal/core/ports/portstest: importable fakes — in-memory EntityRepo (with check-then-act SetState, side-effect recording), RecordingExecutor, FakeChecker, SpyPublisher; port-satisfaction guards; tests. Risk: ports are declared ahead of implementations — signatures firm up per phase as slices land (documented in the package doc); the remote→postgres transitional import is explicit and dissolves in Phase 3. Verification: go vet, make test (race, 19 packages), generate-check, golangci on core+adapters — 0 issues; full-repo baseline down 365→344.
7.6 KiB
7.6 KiB
Plans
Pre-flight runbooks for planned changes. When a plan is executed, move it to
done/ and add changelog entries on affected node pages. If things
went sideways, open an investigation.
Active
| Date | Title | Status |
|---|---|---|
| 2026-07-05 | Oikos Prometheus LXC | Planned — not started |
| 2026-07-08 | Oikos gaps, broken things, and improvements | In Progress — security items (B1-B5) and doc drift (E) still open |
| 2026-07-08 | Control room web UI | In Progress — packaging/auth sections superseded by the Wails plan's Phase 0 (client/server split); M4 still open |
| 2026-07-08 | Liveness, drift, and UX cohesion | In Progress — Phase 5 deferred |
| 2026-07-10 | General gated execution: unlimited actions, gated by risk | In Progress — request_execution enum retired (60effcb); only auto-act revival (item 10) still open |
| 2026-07-11 | Nomos agent code review: gaps and improvement plan | In Progress — only C1 (unauthenticated nomos gateway) still open, deferred |
| 2026-07-14 | Activity gaps | In Progress |
| 2026-07-14 | Activity timeline | In Progress |
| 2026-07-17 | Codebase review, lint audit, and documentation maintenance | Report delivered — doc/tooling fixes applied; code refactors pending |
| 2026-07-20 | Mascot physics/window-interaction audit | P0–P2 implemented; P3 ("cool stuff") ideas open |
| 2026-07-21 | Frontend as OS + Apps — architecture audit & refactor | Planned — Phase 1 ready |
| 2026-08-04 | Hermes MCP client integration | Done — deployed |
| 2026-08-05 | Agent execution safety: QEMU guest agent gate + host-mutation guard | Done — implemented (1b9c761) |
| 2026-08-05 | Backend evaluation: architecture, security, and reliability improvements | Done — all three phases (B, D, E) implemented as code (0.28.0–0.29.0), deployed, and hardened via review. Remaining: C (security) and F (performance) backlog. |
| 2026-08-15 | Hexagonal architecture — design and phased refactor | In Progress — Phases 0–2 done (ADR 0016, client extracted to dtoro/oikos-web, ports + adapters scaffold); Phase 3 next |
Done
See done/ for executed plans:
Conventions
- File name:
YYYY-MM-DD-<slug>.md. Use the target date if known, otherwise the planning date. - Status:
Planned→In Progress→Done(move todone/on completion). - When done: add a changelog entry on every affected node page, then move the file to
done/. - Plans are append-only once execution starts — don't rewrite pre-flight intent after the fact.