reshape: move OHM transcripts under ohm/ for org-wide multi-app layout; add org-wide root README

This commit is contained in:
2026-06-03 06:54:38 -07:00
parent bd21825bc2
commit 3713299f08
73 changed files with 200 additions and 181 deletions
@@ -0,0 +1,272 @@
# Session 0034.0 — Transcript
> Date: 2026-05-28
> Start: 2026-05-28T20-25 (PST implied) · End: 2026-05-28T20-31
> Goal: Advance the OHM roadmap by one disjoint, parallel-safe item.
> The big feature arc (#26#29) shipped at end of 0033; every remaining
> feature candidate is operator/date-gated. So this session took the one
> **fully-unblocked** item the brief named: the **#18/#20 Gitea-webhook
> ops cleanup**.
>
> Outcome: **deleted the stale `wiggleverse/meta` Gitea hook** (id=1,
> pointing at the deprovisioned `http://rfc.wiggleverse.org` — now
> NXDOMAIN) via the Gitea API (HTTP 204). Verified the deleted hook's
> repo was legacy (live `META_REPO=ohm-meta`); a full org-wide webhook
> sweep afterward shows the only remaining hook anywhere is the correct
> live `wiggleverse/ohm-meta` → `https://ohm.wiggleverse.org`. Also
> verified the runbook's SMTP_HOST/SMTP_USER overlay gap is **closed**
> (email healthy). No app code, no deploy, no secret/config change — OHM
> stayed live at v0.29.0 throughout. ROADMAP #18 row updated + pushed
> (`ec4ff4d`); runbook annotated (gestures #1 + #5 marked DONE).
---
## Launch prompt
OHM roadmap driver session, parallel-safe. Claim ID first; read
SESSION-PROTOCOL §7 + ohm-rfc/ROADMAP.md; verify live state (last two
briefs were stale). State at hand-off (end of 0033): OHM live at rfc-app
**v0.29.0** (pin=0.29.0, deploy lock free, deploys.id=40); #28 fully done
(all three parts); flotilla v1.2.0 current. PICK ONE disjoint item. The
feature arc (#26#29 + #28) is clear; remaining candidates are mostly
blocked/date-gated: #21A Amplitude audit (~06-04, needs data), #20/#18
ops (DMARC Phase B ~06-04; stale `wiggleverse/meta` webhook still points
at deprovisioned rfc.wiggleverse.org — delete it; bounce-source wiring),
#22 pro-consent copy (operator+counsel), #31b polish (screenshots), #33
repo-naming (operator-led), #34 GCP name-alignment close-out (operator
accepts 0031 rec). **"If no feature item is unblocked, the highest-value
unblocked work is the #18/#20 ops cleanup."** Hard rules: never ask for
secret bytes; fresh worktree+venv for rfc-app builds; FF-merge via gitea
API; push tag to benstill mirror before deploy; finalize+publish
transcript LAST, handoff in chat before publish.
---
## Plan / TODO
- [x] Claim session ID (→ 0034); read SESSION-PROTOCOL §7 + ROADMAP.
- [x] Verify live state vs. (warned-stale) brief: health, pin, hooks.
- [x] Pick the one fully-unblocked item: #18/#20 webhook ops cleanup.
- [x] Re-inventory live Gitea hooks; confirm the stale one is still there.
- [x] Confirm the stale domain is dead + the deleted repo is legacy.
- [x] Delete stale `wiggleverse/meta` hook id=1 (HTTP 204) + verify.
- [x] Full org-wide webhook sweep — confirm no other stale hooks.
- [x] Verify the runbook's SMTP overlay gap (closed) + bounce-source state.
- [x] Update ROADMAP #18 (ohm-rfc) + runbook (ohm-infra); commit + push.
- [x] Finalize + publish transcript (this file); handoff in chat first.
---
## State verification (the brief warned it might be stale — it was accurate)
Unlike the last two sessions, the 0033 brief held up under verification:
- `https://ohm.wiggleverse.org/api/health` → `{"version":"0.29.0",
"status":"ok"}`. ohm-rfc `.rfc-app-version` = `0.29.0`. Deploy lock
free. #28 row struck through (all three parts shipped, deploys.id=40).
- Only `--INPROGRESS` placeholders in the shared repo were the stale
**0026 / 0027** (work long-shipped — ignored per standing guidance).
- Claimed session **0034** via `claim-session-id.sh --start
2026-05-28T20-25` (the push is the atomic claim).
**Item triage.** Walked every open candidate against "is it actually
unblocked, no operator gesture, no date gate, no app-code-shape
decision":
| Item | Status | Why blocked |
|---|---|---|
| #21 Part A (Amplitude audit) | blocked | needs ~1 week real data (~06-04) |
| #20 Phase B (DMARC `p=quarantine`) | blocked | date-gated, ≥1 week clean `rua` (~06-04) |
| #22 (pro-consent copy) | blocked | operator-drafted + counsel-gated |
| #31b (UX polish) | blocked | needs operator screenshots |
| #33 (repo naming) | blocked | operator-led, URL-breaking |
| #34 (GCP name align) | blocked | operator accepts the 0031 recommendation |
| **#18/#20 webhook ops cleanup** | **UNBLOCKED** | no date gate, no app code, no operator gesture |
So the brief's fallback was exactly right, and this session executed it.
---
## What got done
### 1. Re-inventoried the live hooks (read-only)
Pulled the `ohm-rfc-app-gitea-bot-token` from Secret Manager (kept in a
shell var, never echoed) and listed hooks on the three repos the runbook
flagged:
- `wiggleverse/meta` → **id=1, active, `http://rfc.wiggleverse.org/api/webhooks/gitea`** ← the stale one.
- `wiggleverse/ohm-meta` → id=2, active, `https://ohm.wiggleverse.org/api/webhooks/gitea` ← correct/live.
- `wiggleverse/rfc-0001-human` → no hooks (matches inventory).
### 2. Confirmed it was safe to delete (two independent checks)
- **Dead target:** `rfc.wiggleverse.org` no longer resolves (NXDOMAIN) —
the hook was firing failed POSTs on every push to `wiggleverse/meta`
and transmitting the HMAC request signature over plain HTTP to a domain
we no longer control (a latent subdomain-takeover signature-leak; moot
right now since it doesn't resolve, but exactly why stale hooks get
removed not left).
- **Legacy repo:** live `flotilla overlay show ohm-rfc-app` returns
`META_REPO=ohm-meta`. So `wiggleverse/meta` is **not** OHM's content
source — the deleted hook was on a legacy repo, not something that
should have been *repointed*. Deletion (not repoint) was the correct
call.
### 3. Deleted the hook + verified
`DELETE …/repos/wiggleverse/meta/hooks/1` → **HTTP 204**. Re-listing
`wiggleverse/meta` returns no hooks (clean).
### 4. Full org-wide webhook sweep
Listed hooks across **every** repo `ohm-bot` can see. After the deletion,
the only hook remaining anywhere is `wiggleverse/ohm-meta` id=2 → the
correct live URL. No other stale hooks exist. (`ben.stull/ohm-rfc`
remains invisible to the bot — needs operator self-check, as the runbook
already noted.)
### 5. Verified the runbook's SMTP overlay gap is closed
The runbook's read-only "anytime" gesture #1 worried `SMTP_HOST` /
`SMTP_USER` might be missing from the overlay (which would silently
dead-letter all mail). Confirmed **closed**: `SMTP_HOST=smtp-relay.gmail.com`,
`SMTP_USER=ben.stull@wiggleverse.org`, `SMTP_PORT=587`, `SMTP_STARTTLS=1`,
`SMTP_PASSWORD` bound to `ohm-rfc-app-smtp-password@latest`. Email is
healthy; the live overlay is the source of truth.
### 6. Recorded
- **ohm-rfc** ROADMAP #18 row rewritten (deletion + sweep + SMTP-gap-
closed finding + the still-remaining operator/date-gated items);
committed + pushed (`ec4ff4d`).
- **ohm-infra** runbook (`EMAIL-AND-WEBHOOK-HARDENING-RUNBOOK.md`)
annotated: gesture #1 (SMTP gap) and #5 (stale hook) marked ✅ DONE
with findings; a Session-0034 progress banner added at the top of the
operator-execution sequence. (ohm-infra is local-only — not a git repo
— so this is a working-file update, consistent with how it holds the
session placeholders.)
---
## What is NOT done (and why — all operator/date-gated)
- **Bounce-source wiring (runbook #10).** `WEBHOOK_EMAIL_BOUNCE_SECRET`
and the receiver endpoint (`POST /api/webhooks/email-bounce`) both
exist, but nothing POSTs to them. Path A (inbox-side filter on the
monitored alias + manual curl per bounce) is operator inbox work; Path
B (a Gmail-API bounce-parser service, or switch to a transactional
provider) is a follow-up project. Neither is autonomously completable
without Workspace access / new-service scope. Left for the operator.
- **`ben.stull/ohm-rfc` hook (runbook #4/#8).** The pin-source repo; the
bot lacks admin so its hooks can't be listed via API. Operator
self-checks via the Gitea web UI; a hook there would let OHM react to
`.rfc-app-version` bumps in real time instead of waiting on the
reconciler.
- **`wiggleverse/rfc-0001-human` hook (runbook #6/#7).** None present.
The runbook explicitly flags this as a *confirm-with-operator* decision
(does the meta-repo hook already cover the published-RFC surface?), so
per the two-layer rule it's not a unilateral driver call. Recommend
adding it (instant content refresh) — but the operator's call.
- **DMARC Phase B, SPF `-all`, From→`ohm@` migration, Postmaster Tools,
`rua` processor** — DNS / Workspace-dashboard work, mostly date-gated
(Phase B wants ≥1 week clean `rua` data, ~06-04).
---
## Friction / notes
- **No release this session, by design.** The one unblocked item was an
ops gesture against an external service (Gitea), not a code change.
Manufacturing a flotilla/rfc-app version bump just to "have shipped a
version" would have been noise. The honest unit of work here is a
deleted webhook + verified state + accurate handoff.
- **No secret bytes touched the conversation.** The bot token lived only
in a shell variable for the API calls and was never printed; Gitea's
hook-listing API masks `config.secret` anyway. Hard rule held trivially.
- **§19.2 candidate, now strongly motivated:** the runbook's proposed
**`flotilla webhook list` / `flotilla webhook check`** verb (its §19.2
candidate #4) would have turned this session's manual token-fetch +
per-repo curl + sweep into one command. This session is the second time
the gesture was done by hand. It's a clean, fully-unblocked, in-repo
(flotilla) addition — but it needs a small design call (which repos are
the deployment's "expected" hook set, and what `check` exits non-zero
on), which is why it's flagged for the next driver rather than built
blind here. Strong recommend for the next flotilla minor.
---
## Cut state (end of session)
- **OHM live:** `https://ohm.wiggleverse.org/api/health` → `version=0.29.0`,
`status=ok` (unchanged — this session touched no app code/config/deploy).
- **Gitea webhooks:** exactly one hook org-wide — `wiggleverse/ohm-meta`
id=2 → `https://ohm.wiggleverse.org/api/webhooks/gitea`. Stale
`wiggleverse/meta` id=1 deleted.
- **SMTP overlay:** complete + healthy (HOST/USER/PASSWORD all bound).
- **ohm-rfc:** `main` pushed (`ec4ff4d`); ROADMAP #18 ops-side updated.
- **ohm-infra:** runbook annotated (local working file).
- **flotilla:** v1.2.0, unchanged.
---
## Operator-plate (manual gestures waiting on the operator)
The #18/#20 long tail, none of it blocking anything else:
1. **Bounce source** — decide Path A (inbox filter + manual curl to
`/api/webhooks/email-bounce`) vs Path B (Gmail-API parser / provider
switch). Path A is enough for v1.
2. **`ben.stull/ohm-rfc` hook** — self-check via Gitea web UI; add if
absent (real-time pin-bump reaction).
3. **`wiggleverse/rfc-0001-human` hook** — decide whether it's needed
(vs. the reconciler + the ohm-meta hook). Recommend adding.
4. **DNS/DMARC ramp** — Phase B (`p=quarantine`) once ≥1 week of clean
`rua` data (~06-04); then SPF `-all`, Postmaster Tools, `rua`
processor, eventual `ohm@` From migration.
---
## Next-session prompt (handoff)
> OHM roadmap driver session, parallel-safe. Claim your ID first
> (`claim-session-id.sh --start <now PST>`); read SESSION-PROTOCOL §7 +
> ohm-rfc/ROADMAP.md; **verify live state before trusting this brief.**
>
> STATE (end of 0034, 2026-05-28): OHM live at rfc-app **v0.29.0**
> (`/api/health` ok, pin=0.29.0, deploy lock free, deploys.id=40).
> flotilla **v1.2.0**. The feature arc #26#29 (+#28) is fully shipped.
> This session (0034) did the #18/#20 webhook ops cleanup: **deleted the
> stale `wiggleverse/meta` hook** (it pointed at the dead
> rfc.wiggleverse.org); a full org sweep confirms the only remaining hook
> is the correct `wiggleverse/ohm-meta` one. SMTP overlay verified
> healthy. ROADMAP #18 updated (`ec4ff4d`).
>
> PICK ONE disjoint item. Most feature candidates are still blocked:
> - **#21 Part A** (Amplitude audit) / **#20 Phase B** (DMARC
> `p=quarantine`) — date-gated ~2026-06-04 (need ≥1 week of data).
> - **#22** pro-consent copy — operator-drafted + counsel-gated.
> - **#31b** UX polish — needs operator screenshots.
> - **#33** repo naming / **#34** GCP name-align close-out — operator-led.
>
> If still no feature item is unblocked, two clean, fully-unblocked,
> no-operator-gesture options:
> 1. **`flotilla webhook list` / `flotilla webhook check` verb** (the
> runbook's §19.2 candidate #4). Pure-flotilla, in-repo, parallel-safe;
> formalizes the manual hook-inventory gesture sessions keep doing by
> hand. Small design call needed: the deployment's "expected" hook set
> (derive from `META_REPO` + corpus/pin repo + the health-URL-derived
> webhook URL) and what `check` exits non-zero on. Earns a flotilla
> v1.3.0.
> 2. The **framework-side email-hygiene minor** in
> `ohm-infra/RFC-APP-EMAIL-HYGIENE-PROPOSAL.md` (List-Unsubscribe
> headers, explicit Date/Message-ID, multipart text+html, mandatory
> webhook_secret, Reply-To=From). A real rfc-app minor + pin bump +
> deploy — read the proposal first; it's well-scoped.
>
> Hard rules: never ask for secret bytes — give the
> `printf '%s' "$(pbpaste)" | .venv/bin/ohm-rfc-app-flotilla secret set
> ohm-rfc-app <KEY>` gesture. Fresh worktree + own venv for any rfc-app
> build. FF-merge via gitea API; push the tag to the benstull mirror
> before deploy. You're empowered to merge/tag/pin-bump/deploy end-to-end.
> Finalize + publish your transcript LAST; handoff in chat before publish.