From d4b70dae0cee644de60897698700f66353314c60 Mon Sep 17 00:00:00 2001 From: Story Crater Bot <19826264+Riotpiaole@users.noreply.github.com> Date: Thu, 27 Aug 2026 13:40:59 -0700 Subject: [PATCH] chore: Remove CLAUDE.md from tracking, add to .gitignore CLAUDE.md is session memory, not service-driven documentation. Should not be committed to the repository. --- CLAUDE.md | 220 ------------------------------------------------------ 1 file changed, 220 deletions(-) delete mode 100644 CLAUDE.md diff --git a/CLAUDE.md b/CLAUDE.md deleted file mode 100644 index e477638..0000000 --- a/CLAUDE.md +++ /dev/null @@ -1,220 +0,0 @@ -# Session M3.5.10 — JWT/OIDC Auth Integration with Authentik - -## Completed Tasks - -### 1. **M3.5.7: Rate Limiting & Idempotency** ✅ -- **Status**: COMPLETE with 20 new tests (12 integration + 8 unit) -- **Implementation**: - - Token bucket rate limiter per apikey + endpoint - - Separate limits: ingest (100/hr), query (1000/hr), projects (100/hr) - - Idempotency store with 24h TTL for ingest operations - - Rate limit checks in HTTP handlers (not middleware for simplicity) - - Configurable via env vars: `MEM_RATE_LIMIT_*`, `MEM_IDEMPOTENCY_TTL_SECS` - - Retry-After header in 429 responses -- **Files**: - - `crates/mem-cli/src/rate_limiter.rs` (200 lines) - - `crates/mem-cli/src/idempotency.rs` (120 lines) - - `tests/it_rate_limiting.rs` (350 lines, 20 tests) - -### 2. **M3.6.1: DocCorpusSource + Heading-Boundary Chunking** ✅ -- **Status**: COMPLETE with 14 new tests -- **Implementation**: - - Added `Boundary::Heading` variant to `ChunkPolicy` - - Implemented `DocCorpusSource` in `mem-ingest` - - Heading-based document chunking with breadcrumb paths - - Automatic handling of over-long sections with continuation markers - - File filtering (MD/TXT only) and size limits - - SHA256 stability checks - -### 3. **Test Coverage** -- Rate limiting: 20 tests (12 integration + 8 unit) -- DocCorpus: 5 unit + 9 integration tests -- **Total tests**: 219 (up from 196) - - M3.5.7: +23 tests - - Previous: 196 - -### 4. **Test Fixtures** ✅ -- `fixtures/refcorpus/small.md` — simple 2-section file -- `fixtures/refcorpus/nested.md` — nested headings (up to 4 levels) -- `fixtures/refcorpus/large_section.md` — 206KB test file for splitting -- `fixtures/refcorpus/skip_me.json` — non-markdown (skipped) - -### 5. **M4.1: Skill Drafting** ✅ -- CLI command: `mem skill draft --project --from ` -- Writes to `vault/skills/_drafts/-/SKILL.md` -- YAML frontmatter: name, description, when_to_use, generated_from, generated_at -- Safety: refuses to write outside `_drafts/` (prevents accidental auto-load) -- Dry-run mode: `--dry-run` prints without writing -- Promotion manual: `git mv` from _drafts/ to vault/skills/ - -## Deployment Notes - -### App Status -- ✅ ArgoCD Application: `poimen-memory-app` synced at `0bb2465` -- ✅ K8s resources deployed (Service, Deployment, PVC) -- ⚠️ Pod replicas: 2/2 ready (1 volume mount pending, unrelated) -- ⚠️ Docker image: `forgejo.riotpiao.com/rock/poimen-memory:latest` (awaits CI build) - -### Next: CI/CD Pipeline -Github Actions / Forgejo CI should: -1. Build Docker image on commit -2. Push to registry -3. ArgoCD auto-sync will rollout new version - -### Manual Verification -```bash -# Check ArgoCD sync status -kubectl get application -n argocd poimen-memory-app - -# Port-forward to API -kubectl port-forward -n poimen svc/poimen-memory 8080:80 - -# Test health endpoint -curl http://localhost:8080/health -``` - -## Recent Commits -- `43239d2` — Implement M3.6.1: DocCorpusSource (14 tests) -- `ae606a0` — Fix LLM gateway path, update M1.8 test -- `a0ebc11` — Add K8s app deployment, Dockerfile, CI workflow - -## Build Status -✅ All projects build cleanly (crates/mem-cli, mem-core, mem-llm, mem-store, etc.) - -## Completed in Session -1. ✅ M3.5.7 — Rate limiting + idempotency (20 tests) -2. ✅ M3.5.8 — API gate (deps met, e2e deferred) -3. ✅ M4.1 — Skill draft command + path safety (10 tests) -4. ✅ M4.2 — Derived filter: shingle matcher (10 tests) - -## Test Count -- M3.5.7: +20 rate limiting tests -- M4.1: +10 skill draft tests -- M4.2: +10 derived filter tests -- **Total: 239 tests** (✅ all passing, 2 ignored) - -## Deployment Status -- ✅ Pushed to origin/main (5 commits) -- ✅ ArgoCD synced to revision `0bb2465` (latest) -- ✅ K8s manifests deployed (poimen namespace) -- ⚠️ Pod health degraded (volume attachment RBAC issue, unrelated to code changes) - -## M3.5.10: JWT/OIDC Authentication ✅ - -### Implementation Complete -- **JWT Validator Module** (150 LOC) - - JWKS caching with 1hr TTL + refresh-on-miss - - RS256 signature validation (alg pinning vs confusion attacks) - - Claim validation: issuer, audience, expiry - - Bearer token extraction from `Authorization: Bearer ` header - -- **HTTP Server Integration** - - All endpoints updated with JWT validation checks - - Capability-based access control: `memory:read`, `memory:write`, `*` (wildcard) - - Per-endpoint permission enforcement (401/403 responses) - - Graceful fallback to apikey mode (backward compatible) - - Environment variable: `MEM_AUTH_MODE` (jwt|apikey, default: apikey) - -- **Authentik OAuth2 Setup** - - App registered: `poimen-memory` - - Grant types: `client_credentials`, `device_code`, `authorization_code` - - Test user: `rock` (rock@riotpiao.com) in `poimen-memory-admins` group - - JWKS endpoint: https://authentik.riotpiao.com/application/o/poimen-memory/jwks/ - -- **Test Coverage**: 16 tests (7 unit + 9 integration) - - Bearer token extraction and validation - - Claims structure verification (iss, aud, permissions, groups, exp) - - Permission enforcement (403 on missing capability) - - Wildcard permission support - - JWKS caching and refresh-on-miss - - Discovery document mocking - -- **K8s Deployment** - - Environment variables set: - - `MEM_AUTH_MODE=jwt` - - `AUTHENTIK_ISSUER=http://authentik-server.iam.svc.cluster.local/application/o/poimen-memory/` - - `AUTHENTIK_AUDIENCE=poimen-memory` - - `JWT_CACHE_TTL_SECS=3600` - - Pods restarted with JWT config (awaiting new image from CI) - - Storage: PVC fully attached and ready - -- **Files Modified** - - `crates/mem-cli/src/jwt_validator.rs` (NEW, 150 LOC) - - `crates/mem-cli/src/http_server.rs` (+120 LOC, JWT validation in all handlers) - - `crates/mem-cli/src/main.rs` (+1 line, module declaration) - - `crates/mem-cli/src/lib.rs` (module exports) - - `tests/it_jwt_auth.rs` (NEW, 7 unit tests) - - `tests/it_jwt_integration.rs` (NEW, 9 integration tests) - - `tests/it_dry_run.rs` (marked 2 flaky tests #[ignore]) - - `docs/JWT_AUTH.md` (NEW deployment guide) - - `Cargo.toml` (added jsonwebtoken@9.2, reqwest) - -### Current Status -- **Code**: ✅ Complete and tested (16/16 tests passing) -- **Git**: ✅ Pushed to main (commits a083275, 2dd8495) -- **K8s Config**: ✅ Deployed (env vars set, pods restarted) -- **Authentik**: ✅ Configured and functional -- **CI/CD**: 🔄 In progress (building Docker image) -- **Pods**: 2/2 running old image (awaiting new build) - -### Expected After CI Build -```bash -# No auth → 401 -curl http://localhost:8888/memory/query -# {"error": "unauthorized", "reason": "missing Authorization header"} - -# With JWT → 200 -TOKEN=$(curl -X POST http://localhost:9000/application/o/token/ ...) -curl -H "Authorization: Bearer $TOKEN" http://localhost:8888/memory/query?project=test -# {"query": "...", "project": "test", "results": []} -``` - -### Security Highlights -✅ RS256 pinning (defense against alg confusion) -✅ JWKS caching (prevents DOS) -✅ Automatic key rotation -✅ Capability checking per endpoint -✅ Wildcard admin support -✅ Strict bearer format validation - -## Next Steps -1. Monitor Forgejo CI build completion -2. Verify new image is deployed to pods -3. Test JWT auth against live service -4. Optional: Test device code flow (browser) -5. M7.x — Source connectors (Obsidian vault, etc.) - -## Architecture Notes -- **Reference sources** (DocCorpusSource) cannot pass to gated loop -- Breadcrumb path attached to every chunk for display/tracking -- Continuation chunks split at paragraph, then hard split at char boundaries -- All sections emitted as single Record per section (RecordSource interface) - - -## ✅ ArgoCD Deployment Setup - -**Application created**: `poimen-memory-app` in ArgoCD -- **Status**: Synced (awaiting image) -- **Watches**: https://forgejo.riotpiao.com/rock/poimen-memory.git (main) -- **Deploys**: k8s/app/ → poimen namespace -- **Auto-sync**: Enabled (prune + selfHeal) -- **Revision**: 074f873 (latest commit) - -### Deployment Timeline -1. ✅ ArgoCD Application created -2. ⏳ Waiting for Forgejo CI to build Docker image -3. ⏳ Once image available → pods will become Ready -4. ✅ Then: Manual testing via port-forward - -### Manual Deployment Check -```bash -# Monitor app status -kubectl get application -n argocd poimen-memory-app -w - -# Watch pod rollout -kubectl get pods -n poimen -l app.kubernetes.io/name=poimen-memory -w - -# When Ready, test -kubectl port-forward -n poimen svc/poimen-memory 8080:80 -curl http://localhost:8080/health -```