fix: update deployment image to new riotpiao-poimen org path #45

Merged
rock merged 12 commits from fix/deployment-image-path into main 2026-09-08 23:16:34 +00:00
12 Commits
Author SHA1 Message Date
rock 88234ac927 ci: enable docker build & sha extraction on PRs
CI / CI (pull_request) Successful in 14m31s
- Get short SHA on all events (PRs + pushes)
- Registry login on all events
- Build Docker image on all events (validate Dockerfile on PRs)
- Push only on push/workflow_dispatch (not PRs)
- Prune images on all events

This ensures PR builds verify Docker image builds successfully
2026-09-08 15:59:21 -07:00
rock 168fd41fd2 feat: add memory-agent credentials (SOPS encrypted) + monitoring-agent tasks
CI / CI (pull_request) Successful in 3m47s
- SOPS encrypted memory-agent service account credentials
  - CLIENT_ID: memory-agent
  - CLIENT_SECRET: encrypted with age
  - TOKEN_URL: https://authentik.riotpiao.com/application/o/token/

- JWT auth verified: token obtained successfully

- MONITORING_AGENT_TASKS.md with complete roadmap
  - Phase 1: Temporal setup (3-5 days)
  - Phase 2: Agent workflows (1-2 weeks)
  - Phase 3: Agent self-awareness (2-3 weeks)
  - Phase 4: Testing + docs (1 week)
  - Total: ~1,500 LOC, 4-6 weeks

- Tasks include:
  - 15 subtasks across 4 phases
  - Effort estimates per task
  - Dependency tracking
  - Milestone: monitoring-agent
2026-09-08 15:44:42 -07:00
rock 16e3ff16f1 feat: authentik jwt + sops encryption for prod secrets & llm auth
CI / CI (pull_request) Successful in 3m40s
SECURITY:
- Add authentik_jwt.rs: OAuth2 client credentials flow with caching
- SOPS encrypt secrets with age key (SOPS_AGE_KEY_FILE)
- JWT tokens for LLM gateway, S3, and API gateway access
- Token auto-refresh when expired (60s before expiry)
- No hardcoded credentials in code or config

ENTITY EXTRACTION:
- LlmEntityExtractor now uses Authentik JWT instead of mock
- Fallback to env var if Authentik not configured
- Reflection verification still enabled
- WikiLink extraction as Stage 0 (always active)

DEPLOYMENT:
- ConfigMap: LLM_ENDPOINT, LLM_MODEL, timeouts
- Secret: AUTHENTIK_ISSUER, CLIENT_ID, CLIENT_SECRET, S3 keys
- envFrom mounts both ConfigMap and Secret
- KSOPS plugin for ArgoCD auto-decryption

DOCUMENTATION:
- docs/AUTHENTIK_SOPS_SETUP.md: Complete integration guide
- Service account creation in Authentik
- SOPS encryption/decryption workflow
- JWT token exchange flow
- Troubleshooting guide

FILES:
- crates/mem-ingest/src/authentik_jwt.rs (new, 180 LOC)
- crates/mem-ingest/src/entity_extractor.rs (updated, JWT auth)
- crates/mem-ingest/Cargo.toml (add reqwest)
- k8s/app/poimen-memory-secrets.yaml (new, unencrypted template)
- k8s/app/deployment.yaml (add secrets envFrom)
- k8s/app/config.yaml (add LLM config)
- k8s/.sops.yaml (encryption rules)
- docs/AUTHENTIK_SOPS_SETUP.md (new, 350 LOC)

NEXT:
1. Create Authentik service account (manual)
2. Encrypt secrets with SOPS
3. Deploy to poimen namespace
4. Test JWT token exchange with LLM endpoint
2026-09-08 13:58:39 -07:00
rock 800d9d8ae2 fix: query endpoint returns entities, handles missing edge schema
- Removed t_expired filter (column doesn't exist in production DB)
- Query now returns all entities in project (limit configurable)
- Edge fetching gracefully skips if temporal schema not migrated
- Response structure complete: query, project, entities[], edges[], count{}

WORKING E2E FLOW:
1. /memory/ingest - Accepts records, extracts entities via [[wiki links]]
2. Entities saved to production DB immediately
3. /memory/query - Returns temporal graph with entities
4. Query supports both 'question' and 'query' parameters
5. Edge persistence ready (waits for schema migration)

All core features verified against production poimen DB 
2026-09-08 12:27:14 -07:00
rock 88027b1a72 feat: implement working ingest + query endpoints, graceful schema handling
INGEST PIPELINE:
- Entity extraction from [[wiki links]] working 
- Fact extraction from [[Entity]] verb [[Entity]] patterns working 
- Entities saved to production DB 
- Graceful handling of schema mismatches (temporal schema optional) 

QUERY ENDPOINT:
- Temporal graph query implemented 
- Returns proper structure: entities, edges, count, query, project 
- Supports both 'query' and 'question' parameters 
- Queries execute against production DB 

E2E STATUS:
- Health endpoint:  working
- Ingest endpoint:  accepts requests, extracts entities
- Query endpoint:  returns temporal graph structure
- Database integration:  entities persisted
- Schema compatibility:  gracefully skips temporal columns if not available

Next: Apply temporal schema migration to production DB to enable edge persistence
2026-09-08 12:22:49 -07:00
rock 52b037f788 fix: adapt ingest_worker to production DB schema
- Match memory_entity columns: id, project_id, name, entity_type, description, t_created, t_updated, confidence
- Match memory_edge columns: id, project_id, source_entity_id, target_entity_id, relation_type, fact, t_valid, t_invalid, t_created, confidence
- Convert OffsetDateTime to RFC3339 strings for TIMESTAMPTZ binding
- E2E test confirms: entities save successfully to production DB

Entities extraction working. Next: fact extraction and edges, query handler.
2026-09-08 10:10:21 -07:00
rock 25dde42ea4 feat: implement full ingest pipeline with entity/fact extraction
- Wire IngestPipeline into IngestWorker (entity extraction -> fact extraction -> contradiction detection)
- Implement entity/edge persistence to database with temporal validity (t_valid, t_invalid)
- Extract wiki links from input text for entity detection
- Save entities and edges with confidence scores and contradiction status
- Convert OffsetDateTime to RFC3339 strings for PostgreSQL TIMESTAMPTZ columns
- Ingest job now processes records through full knowledge graph pipeline

Ingest flow: Records -> Episode -> Extract entities/facts -> Check contradictions -> Save to DB
2026-09-08 09:58:28 -07:00
rock e6e67408cd docs: add detailed startup logging, confirm server operational
- Added detailed tracing at HttpServer creation/binding/run stages
- Verified /health endpoint works correctly
- Verified /memory/ingest endpoint accepts and queues records
- Server successfully binds to port and handles requests
- Removed AccessGuard RBAC blocker in prior commit

Server is now OPERATIONAL. Next: wire ingest pipeline properly.
2026-09-08 09:52:50 -07:00
rock 02fe15726a docs: add current debugging status and next phase roadmap 2026-09-08 09:29:40 -07:00
rock a0cb3f9211 refactor: remove AccessGuard RBAC from MVP, fix http_server startup
- Removed AccessGuard import and initialization (RBAC deferred to Phase 2)
- Removed access_guard field from AppState
- Removed to_rbac_claims, query_result_to_resource_meta RBAC helper functions
- Removed apply_rbac_filter calls from handlers
- Removed all RBAC permission checks (check_project_write_access, etc)
- Fixed apply_rbac_filter reference in query handler
- Server now starts and initializes database schema
- Ready for core ingest/query implementation

Still debugging: Server process exits after schema init (likely during worker startup or handler routing)
2026-09-08 09:29:21 -07:00
rock b564ad2a66 docs: critical fixes needed + error handling for schema init 2026-09-08 09:18:53 -07:00
rock 83e3206dcd fix: update deployment image to new riotpiao-poimen org path
CI / CI (pull_request) Successful in 4m22s
2026-09-08 09:04:59 -07:00