Files
claude-projects/claude-config/decisions/DECISIONS.md
T
Backtalk6858 d9419109a5 docs(claude-config): 2026-09-27 preflight prompts, owner decisions, redactions
Saved prompts: W2, OLLAMA-1, BOOT-1, S1, AS0, AS1, JH-1, V0, V1, VS-1.
DECISIONS.md 2026-09-27 entry (sudo-bridge retired, Jenkins deploys via
agent-sudo deploy_service, Chatterbox-Turbo, vault-sandbox auto-unseal).
Voice A1/A2 superseded. Redacted two plaintext secrets in agent-builder
context (still in history; rotation tracked under #192).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 12:46:31 -05:00

29 KiB
Raw Blame History

Decision Log

Every adopt / reject / defer call about how we use Claude / Claude Code. Newest at top. Each entry links back to the research that drove it, so the reasoning survives.

Format

## YYYY-MM-DD — <short decision title>
- **Decision:** adopt / reject / defer — <what>
- **Why:** <one or two lines>
- **Research:** <link to research/ file(s)>
- **Implementation:** <link to config/ artifacts, or "n/a" / "pending">
- **Revisit when:** <trigger that would reopen this>

2026-09-20 — PARTNER MEETING OUTCOME (reported 2026-09-27): digital-business decisions DEFERRED to Sunday 2026-10-04

  • The in-person 09-20 meeting pushed every final decision on ConfettiPrintCo (Etsy), J.M. Hartley (KDP) and The Boring API Company to the 10-04 meeting. Why: Hailee had not had time to read the plans and wanted to decide informed. Nothing launched. The question sheet (26 questions) carries over unchanged; all launch-relative dates in the three plans slip at least two weeks and are recomputed in the Stage 2 update. business_ideas.decisions row 26.
  • Subscription: Kaleb is on Claude Max 5x ($100/month) since 2026-09-24 (partner-authorized). Next step: Max 20x ($200/month) once business income justifies it. claude -p batches draw from the Max pool; still no Anthropic API key.

2026-09-20 — DECIDED by Kaleb (20:52), pending partner ratification tonight (S7): launch order revised after the cost check

  • Etsy first, KDP in parallel at $0, API last and paused. The cost check found Etsy ≈ $21 cash (nonrefundable $15 set-up fee + 30 listing fees), KDP $0, API $20/month (Vercel Hobby is non-commercial only; Pro needed). Only the API hosting and the KDP ad budget depend on another business paying. Etsy has the fastest cash. The DocForge build starts only after a first sale in Etsy or KDP, or a partner decision to carry $20/month (about 6 Etsy sales a month at $3.62 net covers it). Swap rule: if the free no-shop API test fails and Etsy verification is pending around 10-01, KDP leads. business_ideas.decisions row 25.
  • Published to partners: all three plans (section 9 = question sheet, cost corrections) and Business/game plan/Partner Meeting 2026-09-20 - Digital Businesses Question Sheet.md (all 26 questions S1–S7, E1–E7, K1–K6, A1–A6, ratify list, decision log). Visible to Tyler_CEO and Hailee_Mktg through the Nextcloud /Business external mount; a dated copy is in the shared Partner Meetings folder. The nextcloud-business-watcher container is Exited (137), so Nextcloud was rescanned by hand with occ.

2026-09-15 — DECIDED (20:15): NetBird + Twingate deployment — both tools, distinct roles

  • Decision (adopt): run BOTH NetBird and Twingate with distinct roles, overriding the "retire Twingate" line in the mesh-VPN research. Twingate = scoped zero-trust access for PARTNERS to Nextcloud (they don't join a mesh) — the real fix for Tyler's CGNAT and the fastest path to working partner meetings. NetBird (self-hosted) = the OWNER's own device mesh (primary host, server-01, laptop, phone) + pulling owner admin surfaces off cloudflared. The mesh-tool-vs-Tailscale pick itself stands (NetBird, 3.98 vs 3.19).
  • Sequencing (adopt): Twingate first (deadline: partner meeting Sun 2026-09-20), NetBird self-hosted after.
  • NetBird bootstrap (adopt): bootstrap on NetBird Cloud free tier (€0, 5 users/100 machines), then migrate to self-hosted. Why: decouples "does the mesh work for my nodes/roaming" from "can I self-host the control plane cleanly," so a snag in the 3 unverified items (Authelia-OIDC / TURN-through-cloudflared / mgmt DB engine) doesn't leave the owner meshless. Data plane is P2P WireGuard either way; the cloud tenant is temporary and sees coordination metadata only, never traffic.
  • server-01 = validation sandbox ONLY (test-only per feedback_sandbox_isolation; exceptions Ollama/GPU + Obsidian). NetBird's stack is validated on server-01 as a throwaway; all real services — Twingate connector + production NetBird control plane — deploy on the PRIMARY server.
  • Partner change in scope: Austin has LEFT the business → remove all his access; onboard Hailee (new 33% partner). Hailee inherits Austin's old Marketing/People role, but is eased into it more gradually than Austin was (staged onboarding, not day-one full handoff).
  • Infra week priority (adopt): Twingate + partner swap (deadline) → secrets-proxy #174 + agent-sudo #176 (retire sudo-bridge, unlock autonomous agent work — highest leverage) → NetBird self-hosted → voice system. Wed personal block = media_pipeline unchanged.
  • Research: research/netbird-vs-tailscale-mesh-vpn.md; Plan: research/netbird-twingate-gameplan.md.
  • Implementation: prompts config/prompts/K_netbird-twingate-preflight.md (read-only preflight, running 2026-09-15) + config/prompts/L_twingate-partner-swap-deploy.md (execution, next infra block) + a Hailee-Nextcloud-onboarding agent.
  • Revisit when: bootstrap→self-hosted cutover proven, OR any of the 3 unverified items forces a design change, OR the flip condition in the mesh-VPN research is hit.

2026-09-15 — DECIDED (17:04): post-agent decisions — support-email disclosure, Vercel KV, Etsy meeting order

  • Support-email disclosure = Option 1, NO line in the email (decisions row 22). Signature "The Boring API Company · support", no human name; one sentence on the docs/listing ("support replies are prepared with AI assistance and reviewed by our team"); prompt never denies being AI. Why: controlled studies mostly find AI labels lower perceived authenticity; user's Brevo cold-email footer was dropped as unprofessional; no cited law requires a line while the human gate runs. REVISIT TRIGGER: the day auto-send is enabled, add a short notice to the auto-send variant only (EU AI Act Art. 50 in force 2026-08-02; FTC reasonable-consumer test). Source: research/ai-support-disclosure-research.md.
  • Vercel KV dropped (row 23): now Marketplace/Upstash-backed. Counter + 15-customer alert live in Postgres via the N8N telemetry webhook.
  • Etsy: partner meeting Sunday 2026-09-20 on the normal cadence; manual first batch of 3 listings moves to Mon 2026-09-21; weekly metrics pulled via Open API OAuth, not manual CSV (row 24). Gameplan week 1 to be revised.
  • Gameplans written by two Fable agents: research/etsy-launch-gameplan.md, kdp-launch-gameplan.md, docforge-build-gameplan.md. Title C gated on a week-9 rank re-read (kids 13/18, pet 11/18, UNVERIFIED).

2026-09-15 — DECIDED (grill-me 15:48–16:40): KDP report §7 (agent E) + API report (agent D) questions closed — ALL digital-business grill-mes DONE

KDP (decisions rows 14–17; business_projects 40 noted)

  • "100,000 Whys" brand dropped entirely; each title carries its own series name. Generic Whys = revisit only as a later colour title funded by profit.
  • Format/price: A seniors = 6×9 black ink, white, 16 pt, 140 pp, $12.99 ($5.09 royalty). B couples 52×7 = 6×9 black ink, cream, 12 pt, 120 pp, $9.99 ($3.54). Kindle $4.99/70% after paperback live. Recompute at final page count.
  • Kids revisited (user request): single-theme black-ink kids "why" (15/18) = title C candidate, after A+B prove disclosure doesn't hurt reach. Competes with pet-behaviour (rank read via search snippets in the gameplan session, no manual browsing). Profession-interview Q&A PARKED.
  • Kill criteria: keep 10 copies / 90 d / BSR #500k; replace "$3 per owner-hour" with royalty per title < $10 at day 90; policy removal = hard stop on its own. A+B evaluation ≈ 2026-12-25.

API (decisions rows 18–21; business_projects 43 noted, 48 DocForge, 49 support inbox)

  • DocForge approved, evaluated against the course framework + project_api_creation_playbook.md: launch endpoints = HTML→PDF + PDF→tables JSON (the PPT "twist"; plain text extraction included; Markdown later). Course stack kept — Express/TypeScript on Vercel (@sparticuz/chromium, pure-JS PDF parser), NOT FastAPI/WeasyPrint on the owner box (= report Q5 answered: box is not prod). No Upstash. Verify cold-start latency; raise function timeout to 60 s. Pricing $12/$39/$99 + $0.005/req overage in the playbook quota layout; price ladder applies. Security: renderer network blocked (SSRF), upload + page caps. EDGAR Events waits for first paid subscriber or day-60 kill.
  • Analytics = own-side telemetry, day one: gateway subscriber/plan headers → DocForge POST → N8N webhook (cloudflared) → marketing_* weekly-metrics table; Vercel KV counter + 15-customer alert (this IS the framework's "customer counter", built at launch not after first sale). Manual: monthly revenue-email transcription by partner/employee (~10 min).
  • GitHub: public example repo IN; manual Q&A answering OUT.
  • Support inbox (user addition): company Gmail, working name "The Boring API Company" (e.g. boring.api.company@gmail.com) as the listing + repo support contact. Automation: N8N polls Gmail (official API/MCP — same relaxation as Etsy Open API) → Claude drafts → code sample verified on the LIVE endpoint via RapidAPI gateway (own free key; sandbox step dropped 16:40, server-01 only for bug reproduction) → weekly human gate logged as training data → auto-send after 20 consecutive unedited passes. Disclosure line UNDECIDED (user: may look unprofessional) → research task. All API dev is AI-driven; support must be Claude-answerable.
  • Partner meeting additions: partner takes Reddit for DocForge?; support address + account owner + umbrella brand.

Credits: $25.29 → $17.21 across Etsy + KDP + course evaluation (~$8 / 8 Qs incl. logging). Fable grill-mes cost more than the $0.25/Q estimate when they include research — revise to ~$1/Q.


2026-09-15 — DECIDED (grill-me 15:40–15:47): Etsy report §8 questions closed (agent F)

Context: 4 of 6 report questions were already settled by the strategy grill-me (Open API approved, Pinterest parked to day 30, throughput = automated pipeline, tables approved). Two remained.

  • Q1 demand method → API, not manual. etsy.com returns 403 to every non-browser client because it sits behind DataDome (JS + captcha interstitial). Scraping stays banned. Instead: Etsy Open API v3 findAllListingsActive (app key only, no OAuth) — count = supply, favourites + review counts of top 20 = demand proxy, tags of top 20 = vocabulary (autocomplete not exposed). Google Trends returns 429 server-side → optional manual check. User registers the developer app 2026-09-16 (own account; same app later does OAuth uploads), keystring → Vault. Claude scripts scoring over 20 phrases. Gate unchanged: <2 strong phrases under 50k results = Etsy fails gate → KDP first. business_projects 47 created; decisions row 12.
  • Q5 POD gate → accepted + third condition. No Printify listings until (1) one digital listing has a Bestseller/Popular badge, (2) ≥$50 cumulative profit (= cross-funding gate), (3) customer-message owner named at the partner meeting. Pipeline stays digital-only until all three hold. decisions row 13.
  • Verify when key exists: provisional-app daily rate limit (scoring needs <100 calls).

2026-09-15 — DECIDED (grill-me 14:53–15:29): digital-businesses launch strategy (agent J, 6 Qs) + standing operating rules

  • Decision (Q3, chain): LOCK Etsy → KDP → API now. Swap Etsy/KDP only if the Etsy browser demand method fails its own gate (no shortlist niche with page-1 badges + non-saturated count). Demand method runs this week (was due 09-14; not yet run; delegable).
  • Decision (Q1, Etsy scope): first 10 listings = template-driven planner stickers + dashboards, then junk-journal kits; birthday printables PARKED (never scored, no designs exist). business_projects 39 scope changes accordingly.
  • Decision (Q1b, Etsy product pipeline — NEW scope): build an automated product pipeline: keyword intake → code-templated PDF generation (typographic/geometric products, not painterly AI art = avoids "AI slop") → optional local SDXL motifs on server-01 → scripted assembly + 6 mockups → claude -p listing copy incl. AI-disclosure line → Claude-judge QA → 15-min/week human approve/reject gate (every verdict logged as training data) → upload via Etsy official Open API v3 with OAuth on our own shop. Rule change: "never automate the logged-in Etsy account" is RELAXED to "official Open API on our own shop only; no browser automation, no scraping." Consequence: this is a build project before a listing project; first 10 listings will NOT be live by 09-21 — do one manual batch this week with generated assets to start the shop clock, pipeline built during weekday blocks over ~2 weeks. DocForge (API) slot 2026-10-05 may slip behind it.
  • Decision (Q2, KDP title A): seniors large-print Q&A = title A, publish by 2026-09-25 (Q4 gift window, live by ~Nov 1). "365 Questions for Couples" = title B with the "52 weeks × 7" hook. KDP upload stays manual (no publishing API; ~1 h/title) — content generation automated.
  • Decision (Q4, Pinterest): OUT for launch week. Becomes a day-30 decision once 30 listings exist: 10 min/day × 2 weeks manual warm-up by an employee is cheap → partner-meeting item.
  • Decision (Q5, cross-funding): ALLOWED. Etsy profit may fund KDP's first $90/mo ad month (~Nov) only after Etsy clears its own scale gate ($50 profit + one page-1 badge); every transfer logged (amount + trigger). Portfolio = one marketing-reserve ledger.
  • Decision (Q6, tables + hub): APPROVED five marketing_* tables in business_projects DB (keyword intake, listing drafts, QA verdicts, opt-ins, weekly metrics) + one static hub site (/confetti, /jmhartley, /docs) on Traefik/cloudflared. Table build moves EARLIER (this week, weekday block) because the Etsy pipeline needs them as state store. Domain: *.reverseproxyserver.net is available; whether it is brand-suitable for customer-facing pages → partner meeting (buy ~$12/yr domain otherwise).
  • Standing rule (NEW, from user): default = automated/passive; manual work gets a hearing when it changes profitability or feasibility ("don't sacrifice feasibility for passivity"). Labour pool = 3 partners + up to 3 employees; hiring possible. Full passivity is the long-term goal (incl. a self-owned store where our own automation rules apply).
  • Standing rule (NEW, from user): weekends OFF. All work goes in weekday business block or personal block; overtime possible; weekend = absolute last resort. Anything previously weekend-scheduled is parked for automation.
  • Partner meeting required before go-live: non-automatable duties (Etsy account owner, customer messages, Payments/taxes, takedown response, weekly QA gate → partner's mother?, KDP manual uploads, demand method), Pinterest day-30 opt-in, hub domain/brand, marketing_* ownership.
  • Billing fact (2026-09-15): user is on Pro; Max upgrade likely soon. claude -p shares the subscription pool (no separate SDK credits) → generation batches use --model claude-sonnet-5 (or haiku) until Max.
  • Why: agent J's strategy (2026-09-15) reconciled the parked 09-10 cross-business question; the user's passivity goal reframed Etsy from a Canva/design job into a code pipeline, which is what the owner can actually sustain.
  • Research: ../research/digital-businesses-marketing-strategy.md, D/E/F evaluations.
  • Implementation: pending — marketing_* tables + pipeline (weekday blocks), business_ideas.decisions rows 8–11, context.md ×4 updated. Per-report grill-mes (Etsy F §8, KDP E §7, API D) still to run.
  • Revisit when: demand method fails its gate (swap Etsy/KDP); partner meeting changes the delegation plan; Max upgrade lands (model choice for batches).

2026-09-08 — DECIDED (23:55): GitHub-sourced cold email RETIRED (business_projects 42)

  • Decision: the lead pipeline may NOT resume as designed. GitHub AUP §7 forbids using information from the Service "(whether scraped, collected through our API, or obtained otherwise) ... for the purposes of sending unsolicited emails to users"; ToS §H repeats it for the API and threatens account/API suspension. Our pipeline collects emails via the GraphQL API and cold-emails them = the named act. Personalization and low volume do not cure "unsolicited."
  • Why: verbatim policy text fetched 2026-09-08; the old approach also yielded only 4 free-tier subscribers.
  • Research: ../research/github-aup-lead-pipeline.md
  • Implementation: N8N workflow 4fuzFJAclba2Syy7 stays PAUSED permanently in its current form; lead_pull GraphQL email lookup is not to be run again. Replacement = business_projects 43 (marketing overhaul: RapidAPI listing/SEO, content/docs, opt-in channels).
  • Revisit when: never for cold email from GitHub data; opt-in contact only.

2026-09-08 — DECIDED (23:42): HyperAgent ABANDONED; marketing system to be overhauled

  • Decision: REJECT HyperAgent for all three jobs (API clients, KDP, Etsy). The marketing product is Howie Liu's closed cloud hyperagent.com (~$20 base + $4–35/task, pricing UNVERIFIED: page 403); the OSS namesake (@hyperbrowser/agent, AGPL, last real commit 2026-02-13) needs a headless patch and unverified Ollama. Logged-in automation of Amazon/Etsy/LinkedIn is banned by their terms. User: "too expensive too fast, and the same legal issue will recur on most platforms." If a public-page browser agent is ever wanted: evaluate browser-use, not HyperAgent.
  • Consequence (user): the GitHub-scrape → cold-email pipeline is the core of API-business marketing (from the purchased course) but produced 4 free-tier subscribers and may violate GitHub AUP §7 → business_projects 42 (priority 1) + new business_projects row: overhaul the marketing system for all digital businesses — user is not a salesman; needs customer acquisition that does not depend on cold sales. This is Horizon A work (the revenue job).
  • Research: ../research/hyperagent-marketing-fit.md (copy in Obsidian Business/Research)
  • Implementation: n/a for HyperAgent. Marketing overhaul: research prompt to be written (API Idea conversation), then grill-me, then per-business plan.
  • Revisit when: never for HyperAgent; browser-use only if a public-page-only need appears.

2026-09-08 — DECIDED (23:32): executor = Claude Code, stay; jcode REJECTED; migration parked behind the hybrid brain

  • Decision: REJECT jcode (fails R1: reuses ~/.claude/.credentials.json and spoofs the Claude Code client — banned and server-side enforced since 2026-04-04; 1 maintainer; installer injects a SessionStart hook, issue #811 — never install on primary). REJECT every OSS executor for Claude work (all fail R1). DEFER Gemini CLI. Keep everything as is (user's words): no model change, no tool change. The "bigger context window" is a model property (Sonnet 5 = native 1M on Pro, verified on code.claude.com/docs/en/model-config; Opus 1M needs usage credits); the "CLAUDE.md size limit" was a misread — only the MEMORY.md index is capped. Revisit path (user): hybrid brain first (offload context to the local model), then a trained local brain, then when claude -p at a higher level or API billing becomes affordable, revisit moving off Claude Code — and only if our skills and processes can come with us; if they cannot, Claude Code is where we stay.
  • Why: report B scored Claude Code first under the rules; every alternative's only route to Claude on Pro is the prohibited one.
  • Research: ../research/jcode-vs-claude-code.md
  • Implementation: n/a. Queued, low priority: personal_projects 245 (window-aware context-monitor + when to use Sonnet 5 1M) — build only if long sessions become a real pain.
  • Revisit when: hybrid brain deployed AND local model trained AND (claude -p budget raised OR API billing on) AND skills/hooks portable to the target.

2026-09-08 — DECIDED (23:20): harness layer = KEEP OUR BASELINE; no LifeOS, no trial

  • Decision: ADOPT the baseline (Claude Code native + our hooks/skills/memory tiers/semantic recall). REJECT LifeOS/PAI, SuperClaude, Claude-Flow, claude-mem, Letta; DEFER Basic Memory (trial only if the ~24.4 KB MEMORY.md cap still hurts after the defrag skill). Voice: the locked bespoke plan (faster-whisper + XTTS on server-01, PTT, agent playback queue) STANDS — LifeOS voice output is gated on an ElevenLabs cloud key and its Linux STT is unverified. Steal three ideas (personal_projects rows logged 2026-09-08): LifeOS Doctor hook-reconcile check, oh-my-claudecode keyword→skill injector, Basic-Memory-style MEMORY.md defrag skill. Open-sourcing our layer = parked (Horizon B) but build as if publishable.
  • Why: baseline scored 14/21 vs best candidate 11; Anthropic's legal page (2026-02-19, enforced 2026-04-04) confines Pro OAuth to the unmodified Claude Code binary, which disqualifies any add-on that moves the token out of it; nothing on the list ships Linux voice. Agent A's "fix /recall first" precondition was false on live test (both Ollama hosts 200).
  • Research: ../research/ai-harness-layer-research.md
  • Implementation: n/a (nothing to install); three steal rows in personal_projects.
  • Revisit when: Anthropic changes OAuth terms; a candidate ships Linux-native local voice; MEMORY.md cap still hurts after the defrag skill exists.

2026-09-27 — DECIDED (owner, infra general questions): agent-sudo/secrets-proxy/voice/sandbox calls

  • Decision: adopt all recommendations: (1) sudo-bridge is RETIRED in favour of agent-sudo (owner: sudo-bridge = security theatre); nothing may route through or depend on it. (2) Jenkins → primary deploy path = a narrow agent-sudo /exec deploy-service op that runs the SecretSpec resolver, NOT raw docker compose through secrets-proxy /shell (that path never worked). (3) #193: keep agent-sudo fail-closed + add Vault-wait/backoff in the one human unit edit; replace the symlinked unit with a root-owned copy. (4) Narrow the two over-broad tier-0 read rules (SUDO.md l.39, l.53) and re-sign. (5) #192 leaked key in git history: accept + document after rotation (dead key); rotate the Gitea remote token + Coolify token too. (6) Re-check the TTS engine before V2 (XTTS-v2 upstream defunct, non-commercial licence). (7) V1 STT image pull onto server-01 approved. (8) Single Ollama = server-01 GPU. (9) vault-sandbox must have the same auto-unseal as primary Vault (vault-watch-unseal.service + root-only key file); copy it over if missing — vault-sandbox restart deferred until then. (10) secrets-proxy 07-09 stop = during the agent-sudo redesign (when sudo-bridge was found inadequate and agent-sudo chosen) — owner recollection, no written record.
  • Why: agents AS0/S1/BOOT-1 findings 2026-09-27 (tiers 1–3 not implementable as built; secrets-proxy holes; boot-order port/DNS loss on server-01).
  • Research: /opt/appdata/docker/research/{agent_sudo_readiness_2026-09-28,secrets_proxy_S1_investigation}.md, /opt/appdata/docker/boot-recovery/README.md
  • Implementation: pending — AS1 prompt, corrected SP1, voice V1/TTS research, vault-sandbox auto-unseal.
  • Revisit when: agent-sudo tiers 1–3 are live on both hosts (re-evaluate secrets-proxy's remaining scope).

2026-09-08 — DECIDED (grill-me 22:50): AI-harness LAYER scope, rubric, hard rules, trial depth

  • Decision: ADOPT the framing — research the layer around Claude Code (memory/skills/hooks/routing/voice), not the executor; premise "we run LifeOS" is FALSE (nothing installed). Rubric = 4 pains (200K/80% checklist; ~24.4 KB MEMORY.md cap; rule adherence beyond the skills track; voice + life ops). Hard rules = R1 Pro OAuth/no API key, R2 merge-not-replace our hooks, R3 free + OSS. Distro = soft factor (LMDE 7 now; Arch/Omarchy or Fedora possible; Ubuntu never). Depth = research then ONE sandboxed trial in the server-01 Incus VM. Voice rides on the harness verdict. Fixed candidates + native-baseline row (baseline may win).
  • Why: every candidate is the same category as the layer we already built; the only honest comparison is against that baseline plus Claude Code's own newer features.
  • Research: prompts in ../config/prompts/ (A harness layer, B jcode/executor, C HyperAgent); outputs land in research/. Grill-me note: Obsidian Resources/Grill-Me/2026-09-08 — AI Harness Layer.md.
  • Implementation: pending — spawn A → B → C one at a time; follow-up grill-me after each.
  • Revisit when: Anthropic changes subscription-OAuth terms; distro changes; skill run logs show rule adherence solved; Max upgrade lands.
  • Side effect: the Docker Sandboxes "revisit when a host moves to Ubuntu 24.04+" trigger (CA-D11 entry below) is DEAD — Ubuntu is excluded; fallback remains @anthropic-ai/sandbox-runtime.

2026-09-08 — DECIDED: the four small Agent-Sudo / recovery calls (grill-me 21:15–21:30)

  • Decision: A1 = (a) tier 1 captures scoped-undo (implement D4; fix the test that pins tier-3-only). A3 = (c) primary tier-2 stays 503 — dissolved by CA-D11. A7(A) = no, an explicit tier-4 SUDO.md rule is not an attack signal (audit-only). Recovery layer = host systemd level-0 (control-plane-up oneshot+timer, fixed command list, ip_nonlocal_bind=1) with Hermes as level-1; row 193 recommendation = keep fail-closed once the daemon has backoff. A7(A) and the recovery shape were defaults I took — object to reopen.
  • Why: the 09-07 outage was boot order (LAN-IP port binds before WiFi), not a crash; an irreversible tier-1 is a gate removed without a constraint added.
  • Research: ../research/autonomy-isolation-evaluation.md §1, §5 #1/#4
  • Implementation: GAMEPLAN_security-infra-deploy.md Steps 0, 4
  • Revisit when: Ethernet + a redundant host exist (D3 long-term), or tier-1 undo latency is measured >2 s.

2026-09-08 — DECIDED (grill-me 21:10): run Claude Code inside an isolation boundary + brokers (CA-D11)

  • Decision: ADOPT — autonomous runner first (background agents + unattended runs move into the VM; the interactive session stays on primary under auto mode + hook until brokers are proven, then migrates). Supersedes personal_projects rows 217 (jail on primary) + 216 (primary substrate). Detail: Claude Code runs in an Incus KVM VM on server-01 (non-root, no sudo, no docker.sock, no Vault creds, egress allowlist); all host reach goes through the existing brokers (Agent-Sudo, secrets-proxy, Jenkins). Inside that boundary, auto mode / --dangerously-skip-permissions is the Anthropic-sanctioned case. Docker Sandboxes rejected for now (unsupported on LMDE 7 / Debian 13; duplicate VMM beside Incus) — steal its credential-injection + egress-policy ideas.
  • Why: today the agent shell is root-equivalent on the production host; the July design brokered actions but never said where the agent runs. The hypervisor already exists (Incus qemu driver, KVM).
  • Research: ../research/autonomy-isolation-evaluation.md §3–§4
  • Implementation: GAMEPLAN_security-infra-deploy.md Step 3; CA-D11 amendment lands with it.
  • Revisit when: a host moves to Ubuntu 24.04+ (Docker Sandboxes becomes supported) (DEAD 2026-09-08 22:55: Ubuntu excluded by the user), or Incus VM overhead proves too high (fallback: @anthropic-ai/sandbox-runtime).

2026-09-08 — DECIDED (grill-me 21:12): re-scope Constrained Autonomy around auto mode

  • Decision: ADOPT — keep security-enforcement.py as a deny-only + training-log layer; drop CA-P1-full / D2 structural classifier / CA-P4 learned-allowlist promotion (auto mode's classifier now does the judgment half, default on Pro); keep CA-P3 (secrets path) and CA-P5 (Hermes recovery ladder). Add explicit deterministic denies for irreversible prod verbs (force-push, prod compose down, DB migrations) to cover auto mode's measured 17% miss on overeager actions.
  • Why: the prompt-theater tax CA-P1 attacked is solved upstream; regex should do what a model classifier can't (unbypassable denies), not compete with it.
  • Research: ../research/autonomy-isolation-evaluation.md §3a, §5 #5–6
  • Implementation: GAMEPLAN Step 5 (hook v3, deny-only).
  • Revisit when: auto mode is removed from Pro, or its false-negative rate is published as materially better.

2026-09-08 — Establish claude-config as the research + config home

  • Decision: adopt — this directory is where Claude/Claude-Code research, decisions, and config/implementation work now live.
  • Why: research (local-ai-coding-stack brief, jcode/OpenCode, etc.) had no dedicated home; findings were scattered.
  • Research: ../research/INDEX.md
  • Implementation: directory structure + .claude/context.md + README created this session.
  • Revisit when: a standalone git repo is wanted, or the parent-dir "claude-config" audit context should be unified with this one.