Files
org-buildout/STATUS.md
T
TSYS Group COO dce7164889 feat: container-based Bitwarden CLI using native Rust binary (no Node.js)
Replace the Node.js @bitwarden/cli dependency with the pre-compiled
native Rust binary (v2026.7.0) for CMMC/ITAR/STIG audit readiness.
The Node.js dependency tree was a significant attack surface that
would fail security audits.

Infrastructure:
- docker/bw-native/Dockerfile: minimal debian-slim + native bw binary
- scripts/bw-cli.sh: host wrapper handling full auth lifecycle
  (config, API-key login, unlock, sync) inside the container
- scripts/bw-entrypoint.sh: container entrypoint for auth lifecycle
- scripts/bw-install.sh: one-command installer (download, build, deploy)

Root causes fixed:
- ~/.config/bw/env values now single-quoted (master password has $
  chars that shell expansion corrupted, truncating 32→16 chars)
- Added BW_SERVER for self-hosted instance (pwvault.turnsys.com)
- Entrypoint bw config server tolerates re-run (|| true)

All scripts pass shellcheck with zero warnings including info-level.
Verified: bw status (unlocked, coo@turnsys.com), generate, list items.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-07 14:51:13 -05:00

6.0 KiB

STATUS.md — TSGCOO Orchestration Layer

Maintained by the TSGCOO agent. Charles reads this to monitor progress. Last updated: 2026-08-13

Current State

Phase: Bitwarden access operational. Container-based CLI (native Rust, no Node.js) deployed and verified. Agent identity provisioning unblocked on BW access — still needs Cloudron invite links and Gitea push credentials.

Primary task: Redmine #442 — stand up first 3 AI agent identities (vp-techops, vp-secops, vp-techcompliance).

What's Built

This session (TSGCOO) — BW Infrastructure

  • Bitwarden access operational — container-based CLI using native Rust binary (no Node.js at any layer, CMMC/ITAR/STIG-friendly)
    • docker/bw-native/Dockerfile — minimal debian-slim + bw v2026.7.0
    • scripts/bw-cli.sh — host wrapper (auth lifecycle handled internally)
    • scripts/bw-entrypoint.sh — container entrypoint (config, login, unlock, sync)
    • scripts/bw-install.sh — one-command installer
    • All scripts pass shellcheck (zero warnings, including info-level)
    • Verified: bw status (unlocked, coo@turnsys.com @ pwvault.turnsys.com)
  • Fixed ~/.config/bw/env: single-quoted all values (master password has $ chars that shell expansion corrupted), added BW_SERVER
  • Full orientation — read all 7 planning docs, the provisioning automation, and the TSYSGroupAIOS template framework
  • AGENTS.md created for org-buildout repo (committed)
  • Git config set up (TSGCOO identity)
  • TSYSGroupAIOS framework copied from /tmp/template-test to ~/projects/TSYSGroupAIOS
  • 4 missing scripts built and committed:
    • bw-run.sh — credential sourcing layer (replaces ~/.creds/*.env)
    • clone-as.sh — per-agent git identity on clone
    • agent-profile.sh — sourced agent context switching (8 agents registered)
    • bw-git-credential.sh — git credential helper backed by Bitwarden
  • BASELINE-PROMPT.md created — the 14 canonical agent principles (was referenced everywhere but didn't exist)
  • prereq-check.sh built — environment readiness verifier
  • agent-identity-provisioning repo cloned to ~/projects/
  • Code review of provisioning automation — found and fixed critical bugs:
    • Email domain bug (tsys-cloudron.knel.net → turnsys.com) — would have failed all provisioning
    • STATE_DIR at module level (crashed --dry-run/--help)
    • IndexError on empty password_inputs list
    • State file unreachable on exception (moved to finally)
    • BW item_exists swallowing network errors as "not found" (duplicate creds)
    • Dockerfile npx install with || true (silent BW CLI failure)
    • Missing .dockerignore (secrets leaking into image)
    • Added explicit cloudron_email to agents.yaml.example

Previous agent (reachableceo)

  • Complete planning docs (org-buildout repo — 7 files)
  • Playwright provisioning automation (agent-identity-provisioning repo)
    • provision-agent.py (664 lines) — Cloudron enrollment, SSO login, API key gen
    • bw-helper.py (188 lines) — BW CLI wrapper
    • Dockerfile + docker-compose.yml
    • agents.yaml.example manifest template
  • TSYSGroupAIOS template framework (was at /tmp/template-test, NOT on Gitea)

Blockers / Needs Human Input

These are the prerequisites from tsgcoo-bootstrap-prompt.md §4. None are met.

# Item Status Detail
1 Docker group membership RESOLVED TSGCOO has docker access. All 20+ containers running.
2 Bitwarden CLI RESOLVED Container-based native Rust binary deployed. bw on PATH via ~/.local/bin/bw wrapper. No Node.js.
3 BW credentials RESOLVED ~/.config/bw/env exists with single-quoted values. Verified: coo@turnsys.com unlocked on pwvault.turnsys.com. Vault is empty (new account, not yet populated).
4 Cloudron invite links BLOCKED agents.yaml does not exist (only .example). Need real invite URLs for vp-techops, vp-secops, vp-techcompliance (Q3) and optionally coo, svp-knel, svp-tctc (Q4).
5 Gitea push credentials BLOCKED Cannot push to any repo (no auth). Need either BW-sourced Gitea token or manual credential setup.
6 Discourse admin access DEFERRED Needed for VP SecOps category creation. Can be done after agent provisioning (assign to vp-techops).

What's Ready to Execute (once blockers resolved)

BW access is operational. The remaining blockers are:

  • Cloudron invite links (item 4) — needed to run the provisioning pipeline
  • Gitea push credentials (item 5) — needed to push repos to Gitea

Once item 4 is resolved:

# BW is already operational via the container wrapper
bw status   # verify access

# Fill in the manifest
cd ~/projects/agent-identity-provisioning
cp agents.yaml.example agents.yaml
# Edit: replace REPLACE_WITH_TOKEN with real Cloudron invite links

# Set BW creds for the container
cp .env.example .env
# Fill in from ~/.config/bw/env

# Build and run (provisions all Q3 agents)
docker compose up --build

# Or provision one agent at a time (recommended for first run)
docker compose run --rm provision --agent vp-techops

Inbox

  • TSYSGroupAIOS needs to be pushed to Gitea as a template repo (blocked on #5)
  • BW migration of reachableceo's ~/.creds/ → Redmine #440 (due Aug 19)
  • Cross-linking audit → Redmine #441
  • Provisioning code needs code review against live Cloudron UI selectors (Q1 in questions-v1.md)
  • TSYSGroupAIOS needs BASELINE-PROMPT.md (referenced everywhere, not in template)

Repo Inventory

Repo Location Commits this session Status
org-buildout (this repo) ~/org-buildout 3 (AGENTS.md, STATUS.md, questions-v1.md) Can't push (no Gitea auth)
agent-identity-provisioning ~/projects/agent-identity-provisioning 1 (critical bug fixes) Can't push (no Gitea auth)
TSYSGroupAIOS ~/projects/TSYSGroupAIOS 5 (framework + 4 scripts + BASELINE-PROMPT.md + prereq-check.sh) Can't push (no Gitea auth, repo doesn't exist on Gitea yet)