Files
claude-projects/claude-config/config/prompts/agent-sudo-secrets-proxy/S1_secrets_proxy_investigation.md
T
Backtalk6858 d9419109a5 docs(claude-config): 2026-09-27 preflight prompts, owner decisions, redactions
Saved prompts: W2, OLLAMA-1, BOOT-1, S1, AS0, AS1, JH-1, V0, V1, VS-1.
DECISIONS.md 2026-09-27 entry (sudo-bridge retired, Jenkins deploys via
agent-sudo deploy_service, Chatterbox-Turbo, vault-sandbox auto-unseal).
Voice A1/A2 superseded. Redacted two plaintext secrets in agent-builder
context (still in history; rotation tracked under #192).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 12:46:31 -05:00

6.7 KiB
Raw Blame History

S1 — secrets-proxy investigation (personal_projects #191 → unblocks #174) — READ-ONLY

Written 2026-09-27 (infrastructure general questions conversation). GAMEPLAN Step 2 (S1 is zero-dependency, goes first). Safe to run in parallel with AS0 (both read agent-sudo code; neither writes it), W2, OLLAMA-1, BOOT-1, JH-1.


You are a bounded, READ-ONLY investigation agent for secrets-proxy (personal_projects #191, parent #174). Budget: --max-turns 30. If you issue the same tool call twice with identical arguments, STOP and output the wrap-up block with status=partially_succeeded.

HARD RULES

  • READ-ONLY. Do NOT start/restart/build any container or image, do NOT edit any code, no sudo, no Vault reads or writes, no git add/commit/push, no Postgres writes. Your only writes are the report, the new context.md, and the embed run.
  • NEVER print a secret value. You may report that a variable/field EXISTS and its length, never its content. Do not cat a .env; use grep -o '^[A-Z_]*=' style key-only listing. docker inspect only for State/Config.Image/Labels/Mounts/PortBindings — NEVER .Config.Env.
  • If a hook blocks something, stop with a partial wrap-up.

WHAT IS KNOWN (main session, 2026-09-27)

  • Container secrets-proxy-secrets-proxy-1 = Exited (0) since ~2026-07-09 (graceful stop, not a crash). Source: /opt/appdata/docker/docker-compose/secrets-proxy/ (app.py ~851 lines, Dockerfile, docker-compose.yml, requirements.txt, mirror/, coolify-def-reference.md). Compose reportedly carries ~18 ${VAR} placeholders (Coolify-era trap — memory project_coolify_env_var_debt if it exists).
  • app.py has /shell + env_secrets + /shell/approve|deny (an NTFY approval gate). Locked design (grill-me 2026-07-12, memory playbook_secrets_proxy_phases.md): replace the NTFY gate with agent-sudo's tier 0–4 model via proxy_rules.py + a signed PROXY.md; forward privileged commands to agent-sudo POST http://192.168.1.88:8084/exec with its OWN caller key (≠ Claude Code's key). GAMEPLAN D4 says kill the NTFY gate.
  • Jenkins (server-01) has a secrets-proxy job with 8 builds (Gitea repo). agent-sudo on primary is healthy (192.168.1.88:8084/health → 200), SUDO.md signed + verify-enforced since 07-14.
  • The SP1 prompt in playbook_secrets_proxy_phases.md has at least one path inconsistency: it says create /opt/appdata/docker/secrets-proxy/proxy_rules.py but its own context points at /opt/appdata/docker/docker-compose/secrets-proxy/. There may be more stale facts.

QUESTIONS TO ANSWER (each with evidence: file:line, git sha, log line)

  1. WHY was it stopped on ~07-09? (git log -- docker-compose/secrets-proxy; /opt/appdata/docker/Machines/*/.claude/context.md and /home/administrator/Desktop/claude/agent-builder/.claude/context.md mentions — grep "secrets-proxy"; docker logs --tail 200 secrets-proxy-secrets-proxy-1 last lines; memory playbook_secrets_proxy.md.) Was it stopped for safety, for a leaked token (#174 note), or scope confusion?
  2. WHAT does app.py do today — endpoint inventory table (method, path, auth, what it executes/returns, which secrets it touches), and the auth model (PROXY_CALLERS? key hashing — note the known anti-pattern: pre-hashing keys = double-hash = 403).
  3. WHERE do its secrets come from — list every ${VAR} in the compose (names only) and classify: Vault path it should map to / obsolete Coolify var / unknown. Is it SecretSpec-ready (compare with /opt/appdata/docker/docker-compose/cloudflared/secretspec.toml pattern)?
  4. WHO calls it — NOTE the locked Jenkins design (/home/administrator/.claude/projects/-home-administrator-Desktop-claude/memory/project_cicd_jenkins.md): every service bound for primary is PROMOTED by Jenkins through secrets-proxy /shell target=production. So Jenkins pipelines are a designed caller — find every Jenkinsfile that calls it and say whether the tier-classification refactor (SP2) keeps that promote path working (which tier would docker compose up -d in a prod project dir land in?). Then — grep hooks (/opt/appdata/docker/.claude/hooks/, /home/administrator/.claude/), skills, scripts, memory, n8n for its port/hostname; the Jenkins job's Jenkinsfile (read via ssh -o BatchMode=yes administrator@192.168.1.90 'docker exec jenkins cat /var/jenkins_home/jobs/secrets-proxy/config.xml' — print only url/scriptPath/branch lines, and fetch the Jenkinsfile from Gitea only if readable without credentials).
  5. Is the SP1–SP4 plan still valid against today's agent-sudo code? Diff the assumptions: does /opt/appdata/docker/docker-compose/agent-sudo/sudo_rules.py still expose load_rules/classify/is_dangerous/verb_heuristic/DANGER_PATTERNS? Does agent-sudo /exec accept multiple callers today (read agent-sudo app.py auth)? Does a Vault transit key for PROXY.md exist? (You cannot read Vault — mark UNVERIFIED and say the main session must check transit/keys/secrets-proxy-proxymd.)
  6. List every stale fact in the SP1 prompt text (path, file names, Gitea push instructions — note "agents never commit or push" is now rule 8 of the prompt playbook, so SP1's step 7 "push to Gitea" is itself stale).

DELIVERABLES

  1. Report /opt/appdata/docker/research/secrets_proxy_S1_investigation.md: Verdict (3 lines) → answers 1–6 → risks → "What SP1 must change" → a DRAFT corrected SP1 prompt in a fenced block at the end (same structure as the original; paths fixed; no commit/push step; scope allowlist; wrap-up JSON), clearly headed "DRAFT — main session reviews before saving to the playbook".
  2. Add one row to /home/administrator/Desktop/claude/claude-config/research/INDEX.md if that index lists infra reports (read it first; follow its format; skip if it is business-only and say so).

SCOPE ALLOWLIST: the report file, the INDEX.md row, /opt/appdata/docker/docker-compose/secrets-proxy/.claude/context.md (new, from template). Nothing else.

PERSIST BEFORE YOU FINISH

  • Create /opt/appdata/docker/docker-compose/secrets-proxy/.claude/context.md from /home/administrator/.claude/projects/-opt-appdata-docker/memory/playbook_project_context_template.md, then append "## S1 investigation — 2026-09-28 (background agent)" (What was done / Decisions surfaced / Current state / Next step).
  • Run: python3 /opt/appdata/docker/.claude/scripts/embed_memory_dir.py --only-recent 5
  • FINAL message = wrap-up JSON only, always: {"status":"succeeded|partially_succeeded|failed","project":"secrets-proxy #174/#191","phase":"S1","actions_taken":[],"actions_failed":[],"files_touched":[],"containers_restarted":[],"why_stopped":"","endpoints":0,"compose_vars":{"total":0,"vault_mappable":0,"obsolete":0,"unknown":0},"callers":[],"sp_plan_still_valid":"yes|partly|no","stale_facts_in_sp1":[],"unverified_claims":[],"next_step":"","notes":""}