D1: deploy.sh CI gate — read-only SHA via git ls-remote, Gitea commit-status
poll, portable mkdir deploy lock (macOS, no flock), TOCTOU guard, token
passed via curl --config - (not argv), graceful misconfig tolerance.
D2: version-tagged images — OIKOS_VERSION=v$VERSION, keep-last-3 prune derived
from 'docker compose config --images'; VERSION read after pull.
D3: per-IP rate limiting — new internal/httpapi/ratelimit.go (x/time/rate),
rightmost-XFF, /healthz exempt, ctx-driven sweep; disabled by default.
D4: mem_limit/cpus on all 10 compose services.
D5: staleness-aware health probes — new internal/health package wired into
scheduler (:8093) and notifier (:8094); nomos already had :8092.
Two /review passes hardened the deploy lock, TOCTOU guard, token hygiene,
and XFF handling.
7.3 KiB
7.3 KiB
Plans
Pre-flight runbooks for planned changes. When a plan is executed, move it to
done/ and add changelog entries on affected node pages. If things
went sideways, open an investigation.
Active
| Date | Title | Status |
|---|---|---|
| 2026-07-05 | Oikos Prometheus LXC | Planned — not started |
| 2026-07-08 | Oikos gaps, broken things, and improvements | In Progress — security items (B1-B5) and doc drift (E) still open |
| 2026-07-08 | Control room web UI | In Progress — packaging/auth sections superseded by the Wails plan's Phase 0 (client/server split); M4 still open |
| 2026-07-08 | Liveness, drift, and UX cohesion | In Progress — Phase 5 deferred |
| 2026-07-10 | General gated execution: unlimited actions, gated by risk | In Progress — request_execution enum retired (60effcb); only auto-act revival (item 10) still open |
| 2026-07-11 | Nomos agent code review: gaps and improvement plan | In Progress — only C1 (unauthenticated nomos gateway) still open, deferred |
| 2026-07-14 | Activity gaps | In Progress |
| 2026-07-14 | Activity timeline | In Progress |
| 2026-07-17 | Codebase review, lint audit, and documentation maintenance | Report delivered — doc/tooling fixes applied; code refactors pending |
| 2026-07-20 | Mascot physics/window-interaction audit | P0–P2 implemented; P3 ("cool stuff") ideas open |
| 2026-07-21 | Frontend as OS + Apps — architecture audit & refactor | Planned — Phase 1 ready |
| 2026-08-04 | Hermes MCP client integration | Done — deployed |
| 2026-08-05 | Agent execution safety: QEMU guest agent gate + host-mutation guard | Done — implemented (1b9c761) |
| 2026-08-05 | Backend evaluation: architecture, security, and reliability improvements | In Progress — Phase 0 (B) + Phase 2 (D1–D5) done; Phase 1 (C) pending |
Done
See done/ for executed plans:
Conventions
- File name:
YYYY-MM-DD-<slug>.md. Use the target date if known, otherwise the planning date. - Status:
Planned→In Progress→Done(move todone/on completion). - When done: add a changelog entry on every affected node page, then move the file to
done/. - Plans are append-only once execution starts — don't rewrite pre-flight intent after the fact.