Files
org-buildout/questions-v1.md
TSYS Group COO fbf9a6571c docs: add STATUS.md + questions-v1.md for TSGCOO handoff
STATUS.md tracks the full state of the agent identity bootstrap: what's
built, all 6 blockers with specific remediation steps, the provisioning
execution path, and repo inventory.

questions-v1.md captures 7 questions for Charles (4 blocking, 3
non-blocking). Blocking: docker group, BW credentials, Cloudron invites,
Gitea push access.

Also adds AGENTS.md, STATUS.md, questions-v1.md to README index.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-07 14:51:13 -05:00

81 lines
2.9 KiB
Markdown

# questions-v1.md — TSGCOO → Charles
> Git-tracked questions/answers/decisions. Please edit inline.
> Per prompt.md: gathering questions in a git-tracked way is imperative.
## Blocking questions (need answers before provisioning can run)
### Q1: Docker group membership
TSGCOO is not in the docker group — `docker info` fails with "permission denied
on socket". The provisioning runs entirely in Docker (Playwright container).
**Action needed:** `sudo usermod -aG docker TSGCOO` then re-login, or add TSGCOO
to the docker group another way.
**CNW:**
### Q2: Bitwarden account and credentials
The `~/.config/bw/env` file does not exist. The bootstrap prompt says it should
contain BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD for a dedicated COO BW account.
**Questions:**
- Has the dedicated "COO" Bitwarden account been created?
- Can you populate `~/.config/bw/env` with the API credentials?
**CNW:**
### Q3: Cloudron invite links
The provisioning manifest (`agents.yaml`) needs real Cloudron invite URLs.
Only the `agents.yaml.example` template exists, with `REPLACE_WITH_TOKEN` placeholders.
**Questions:**
- Have Cloudron user invites been generated for vp-techops, vp-secops,
vp-techcompliance (Q3 agents)?
- Can you paste the invite URLs so I can populate agents.yaml?
**CNW:**
### Q4: Gitea push access
I can clone public repos from Gitea but cannot push (no credentials). The
TSYSGroupAIOS framework + 4 new scripts need to be pushed to Gitea.
**Questions:**
- Should I wait for BW-based git credentials (bw-git-credential.sh)?
- Or can you provide a Gitea token for the TSGCOO identity to push with?
**CNW:**
## Non-blocking questions (can proceed without, but need answers for correctness)
### Q5: Cloudron SSO architecture (from transition-map §5, open decision #1)
Are Gitea/Discourse/Redmine Cloudron-managed (auto-SSO on first login)? Or
standalone? The provisioning code assumes Cloudron SSO auto-provisions accounts.
If SSO is NOT auto-provisioning, the provisioning flow needs adjustment.
**CNW:**
### Q6: Provisioning selectors (from agent-identity-provisioning/questions-v1.md Q1)
The Playwright automation uses generic CSS selectors for Cloudron's invite
acceptance, 2FA enrollment, and per-system API key pages. These need
verification against the live UI.
**Options:**
1. I run the provisioning with `--headed` (needs display) and iterate live
2. You provide screenshots of the Cloudron invite/2FA flow
3. We do a dry-run first and fix selectors as they fail
**Which approach do you prefer?**
**CNW:**
### Q7: BASELINE-PROMPT.md
The TSYSGroupAIOS template (from /tmp/template-test) does not contain
`BASELINE-PROMPT.md` (the 14 canonical principles). It's referenced by
tsgcoo-bootstrap-prompt.md and the provisioning repo's AGENTS.md.
**Question:** Where does BASELINE-PROMPT.md live? Should I create it based on
the principles documented in prompt.md, or does it exist somewhere I haven't
looked?
**CNW:**