STATUS.md tracks the full state of the agent identity bootstrap: what's
built, all 6 blockers with specific remediation steps, the provisioning
execution path, and repo inventory.
questions-v1.md captures 7 questions for Charles (4 blocking, 3
non-blocking). Blocking: docker group, BW credentials, Cloudron invites,
Gitea push access.
Also adds AGENTS.md, STATUS.md, questions-v1.md to README index.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
2.9 KiB
questions-v1.md — TSGCOO → Charles
Git-tracked questions/answers/decisions. Please edit inline. Per prompt.md: gathering questions in a git-tracked way is imperative.
Blocking questions (need answers before provisioning can run)
Q1: Docker group membership
TSGCOO is not in the docker group — docker info fails with "permission denied
on socket". The provisioning runs entirely in Docker (Playwright container).
Action needed: sudo usermod -aG docker TSGCOO then re-login, or add TSGCOO
to the docker group another way.
CNW:
Q2: Bitwarden account and credentials
The ~/.config/bw/env file does not exist. The bootstrap prompt says it should
contain BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD for a dedicated COO BW account.
Questions:
- Has the dedicated "COO" Bitwarden account been created?
- Can you populate
~/.config/bw/envwith the API credentials?
CNW:
Q3: Cloudron invite links
The provisioning manifest (agents.yaml) needs real Cloudron invite URLs.
Only the agents.yaml.example template exists, with REPLACE_WITH_TOKEN placeholders.
Questions:
- Have Cloudron user invites been generated for vp-techops, vp-secops, vp-techcompliance (Q3 agents)?
- Can you paste the invite URLs so I can populate agents.yaml?
CNW:
Q4: Gitea push access
I can clone public repos from Gitea but cannot push (no credentials). The TSYSGroupAIOS framework + 4 new scripts need to be pushed to Gitea.
Questions:
- Should I wait for BW-based git credentials (bw-git-credential.sh)?
- Or can you provide a Gitea token for the TSGCOO identity to push with?
CNW:
Non-blocking questions (can proceed without, but need answers for correctness)
Q5: Cloudron SSO architecture (from transition-map §5, open decision #1)
Are Gitea/Discourse/Redmine Cloudron-managed (auto-SSO on first login)? Or standalone? The provisioning code assumes Cloudron SSO auto-provisions accounts. If SSO is NOT auto-provisioning, the provisioning flow needs adjustment.
CNW:
Q6: Provisioning selectors (from agent-identity-provisioning/questions-v1.md Q1)
The Playwright automation uses generic CSS selectors for Cloudron's invite acceptance, 2FA enrollment, and per-system API key pages. These need verification against the live UI.
Options:
- I run the provisioning with
--headed(needs display) and iterate live - You provide screenshots of the Cloudron invite/2FA flow
- We do a dry-run first and fix selectors as they fail
Which approach do you prefer?
CNW:
Q7: BASELINE-PROMPT.md
The TSYSGroupAIOS template (from /tmp/template-test) does not contain
BASELINE-PROMPT.md (the 14 canonical principles). It's referenced by
tsgcoo-bootstrap-prompt.md and the provisioning repo's AGENTS.md.
Question: Where does BASELINE-PROMPT.md live? Should I create it based on the principles documented in prompt.md, or does it exist somewhere I haven't looked?
CNW: