diff --git a/agent-builder/.claude/context.md b/agent-builder/.claude/context.md index def715d..e43200e 100644 --- a/agent-builder/.claude/context.md +++ b/agent-builder/.claude/context.md @@ -154,13 +154,16 @@ All sandbox prereqs done. Sandbox mirrors production. - n8n_agent_worker postgres role — api_business DB, scoped to automation_ideas + agent_test_results - Credential in production Vault: secret/postgres/n8n-agent-worker -### REMAINING BEFORE BUILDER AGENTS: -- id=51 Secrets Execution Proxy — grill-me COMPLETE (June 21 session 4), build next session - - HTTP + shell commands; vault:// + bitwarden:// backends; per-caller auth keys in Vault - - Shell: sandbox-first always; tiered gate (read=auto, write=notify-after, destructive=blocking NTFY) - - Result redaction: literal secret replacement + pattern scan second pass - - Training: every execution logged (caller, command, sandbox result, real result, approval, redaction events) - - Deploy: server-01, Docker, Traefik + Cloudflare +### id=51 — DEPLOYED but NOT COMPLETE (June 22) +- Container: secrets-proxy-lv3xeu2manuimle458wbm9u9 on server-01, Coolify UUID: lv3xeu2manuimle458wbm9u9 +- Working: n8n_workflow_list ✅, vault_secret_exists ✅ +- PENDING before builder agents: + 1. Redeploy with latest image (bridge_health_check fix already in app.py + pushed to gitea.local) + 2. User adds Cloudflare route: secrets-proxy.reverseproxyserver.net → http://coolify-proxy:80 + 3. Add `192.168.1.88 gitea.local` to /etc/hosts on server-01 + 4. E2E test: bridge_health_check, bitwarden_item_exists, vault_secret_write +- Caller keys in Vault at secret/proxy/callers; claude-code key: 0ce8c396...591e9 +- Bitwarden bridge now LAN-exposed: 192.168.1.88:8083 ### June 21 session 2 facts for next session: - server-01 Coolify UUID: hvzbj1gkqb5696s7cc9lcf8y