docs: add STATUS.md + questions-v1.md for TSGCOO handoff
STATUS.md tracks the full state of the agent identity bootstrap: what's
built, all 6 blockers with specific remediation steps, the provisioning
execution path, and repo inventory.
questions-v1.md captures 7 questions for Charles (4 blocking, 3
non-blocking). Blocking: docker group, BW credentials, Cloudron invites,
Gitea push access.
Also adds AGENTS.md, STATUS.md, questions-v1.md to README index.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
This commit is contained in:
@@ -0,0 +1,91 @@
|
||||
# STATUS.md — TSGCOO Orchestration Layer
|
||||
|
||||
> Maintained by the TSGCOO agent. Charles reads this to monitor progress.
|
||||
> Last updated: 2026-08-13
|
||||
|
||||
## Current State
|
||||
|
||||
**Phase:** Orientation complete. Environment partially set up. Agent identity
|
||||
provisioning execution is BLOCKED on user-provided prerequisites.
|
||||
|
||||
**Primary task:** Redmine [#442](https://projects.knownelement.com/issues/442) —
|
||||
stand up first 3 AI agent identities (vp-techops, vp-secops, vp-techcompliance).
|
||||
|
||||
## What's Built
|
||||
|
||||
### This session (TSGCOO)
|
||||
- [x] Full orientation — read all 7 planning docs, the provisioning automation,
|
||||
and the TSYSGroupAIOS template framework
|
||||
- [x] AGENTS.md created for org-buildout repo (committed)
|
||||
- [x] Git config set up (TSGCOO identity)
|
||||
- [x] TSYSGroupAIOS framework copied from /tmp/template-test to ~/projects/TSYSGroupAIOS
|
||||
- [x] **4 missing scripts built and committed:**
|
||||
- `bw-run.sh` — credential sourcing layer (replaces `~/.creds/*.env`)
|
||||
- `clone-as.sh` — per-agent git identity on clone
|
||||
- `agent-profile.sh` — sourced agent context switching (8 agents registered)
|
||||
- `bw-git-credential.sh` — git credential helper backed by Bitwarden
|
||||
- [x] agent-identity-provisioning repo cloned to ~/projects/
|
||||
|
||||
### Previous agent (reachableceo)
|
||||
- [x] Complete planning docs (org-buildout repo — 7 files)
|
||||
- [x] Playwright provisioning automation (agent-identity-provisioning repo)
|
||||
- provision-agent.py (664 lines) — Cloudron enrollment, SSO login, API key gen
|
||||
- bw-helper.py (188 lines) — BW CLI wrapper
|
||||
- Dockerfile + docker-compose.yml
|
||||
- agents.yaml.example manifest template
|
||||
- [x] TSYSGroupAIOS template framework (was at /tmp/template-test, NOT on Gitea)
|
||||
|
||||
## Blockers / Needs Human Input
|
||||
|
||||
These are the prerequisites from `tsgcoo-bootstrap-prompt.md` §4. None are met.
|
||||
|
||||
| # | Item | Status | Detail |
|
||||
|---|---|---|---|
|
||||
| 1 | **Docker group membership** | BLOCKED | `docker` binary exists but TSGCOO is not in the docker group. `docker info` → permission denied on socket. Fix: `sudo usermod -aG docker TSGCOO` (requires re-login). |
|
||||
| 2 | **Bitwarden CLI** | BLOCKED | `bw` not installed. Needed for all credential operations. Fix: install bw CLI, or rely on the provisioning Docker container (needs docker access first). |
|
||||
| 3 | **BW credentials** | BLOCKED | `~/.config/bw/env` does not exist. Need BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD for the dedicated COO BW account. |
|
||||
| 4 | **Cloudron invite links** | BLOCKED | `agents.yaml` does not exist (only `.example`). Need real invite URLs for vp-techops, vp-secops, vp-techcompliance (Q3) and optionally coo, svp-knel, svp-tctc (Q4). |
|
||||
| 5 | **Gitea push credentials** | BLOCKED | Cannot push to any repo (no auth). Need either BW-sourced Gitea token or manual credential setup. |
|
||||
| 6 | **Discourse admin access** | DEFERRED | Needed for VP SecOps category creation. Can be done after agent provisioning (assign to vp-techops). |
|
||||
|
||||
## What's Ready to Execute (once blockers resolved)
|
||||
|
||||
The provisioning pipeline is ready. Once items 1-5 are resolved:
|
||||
|
||||
```bash
|
||||
# 1. Log into Bitwarden
|
||||
. ~/.config/bw/env
|
||||
bw login --apikey
|
||||
export BW_SESSION=$(bw unlock --raw)
|
||||
|
||||
# 2. Fill in the manifest
|
||||
cd ~/projects/agent-identity-provisioning
|
||||
cp agents.yaml.example agents.yaml
|
||||
# Edit: replace REPLACE_WITH_TOKEN with real Cloudron invite links
|
||||
|
||||
# 3. Set BW creds for the container
|
||||
cp .env.example .env
|
||||
# Fill in BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD
|
||||
|
||||
# 4. Build and run (provisions all Q3 agents)
|
||||
docker compose up --build
|
||||
|
||||
# Or provision one agent at a time (recommended for first run)
|
||||
docker compose run --rm provision --agent vp-techops
|
||||
```
|
||||
|
||||
## Inbox
|
||||
|
||||
- TSYSGroupAIOS needs to be pushed to Gitea as a template repo (blocked on #5)
|
||||
- BW migration of reachableceo's ~/.creds/ → Redmine #440 (due Aug 19)
|
||||
- Cross-linking audit → Redmine #441
|
||||
- Provisioning code needs code review against live Cloudron UI selectors (Q1 in questions-v1.md)
|
||||
- TSYSGroupAIOS needs BASELINE-PROMPT.md (referenced everywhere, not in template)
|
||||
|
||||
## Repo Inventory
|
||||
|
||||
| Repo | Location | Status |
|
||||
|---|---|---|
|
||||
| org-buildout (this repo) | ~/org-buildout | Cloned, AGENTS.md committed, can't push |
|
||||
| agent-identity-provisioning | ~/projects/agent-identity-provisioning | Cloned, not modified |
|
||||
| TSYSGroupAIOS | ~/projects/TSYSGroupAIOS | Created from template + 4 new scripts, 2 commits, not pushed to Gitea |
|
||||
Reference in New Issue
Block a user