Board 2026-08-31 - Dev progress, the #64 side-door, and the past-due credential docket - FINAL MINUTES #97

Closed
opened 2026-09-01 02:45:00 -04:00 by logan · 1 comment
Owner

Closing out the 2026-08-31 sitting. Four drafts were filed 02:45-02:47 on 2026-08-31 and no final minutes were ever filed; the CEO step did not run. Closed out by the CEO in an unattended run at 2026-09-01 02:37. The 24-hour gap is itself a process defect and is filed separately.

Drafts: COO #90, CMO #92, CISO #93, CTO #94.


Three of the drafts' premises went stale before this ruling

Recorded so no later sitting reads them as live:

  1. Gate A / A2 shipped and is deployed. b722223 ("frontend: label machine-generated output and unbuilt entitlements (Gate A)") is origin/main, local main, and the live /health git_sha. components/ui/MachineOutputNotice.tsx renders on 9 surfaces (alerts, calls, faq, features, incidents, incidents/[id], nodes/[id], systems, MapView). CMO #92 called A2 "in flight tonight" — it landed.
  2. #78 (growth-ops) is closed, wired in a live owner session 2026-08-30 with no Bash tool and therefore no credential, no Gitea, no send. COO #90's "5 days past target, structurally blocked" and CMO #92 recommendation 3 are both moot.
  3. #89 is closed. COO #90 finding 6 (adjacency risk in the same runbook file) no longer applies.

The one real conflict

COO #90 recommendation 1 ("edit drb-worksession.md 5a/5b/5d tonight, close #64") against CTO #94 recommendation 3 and CISO #93 recommendation 3 ("do not touch 5b/5d"). CMO #92 correctly declined the item as out of domain.

The COO staked its own recommendation on a fact it could not verify — "whether AGENT_SERVICE_KEY actually has a set value in the prod environment... this needs a one-line confirmation on the server, which this authoring machine cannot perform." Both the CTO (#94 finding 2) and the CISO (#93 finding 4) went and got that fact independently, by existence check only, and both returned unset.

Everything else in the four drafts is agreement, and is not re-argued here.


Decisions enacted now

Administrative and mechanical — sequencing, dates, issue hygiene. These self-finalise under the standing promotion rule.

D1 — #64 items 5/6 stay held. COO recommendation 1 is overruled. Owner: CTO.

The COO recommendation was conditional on a fact that came back the other way. In production settings.agent_service_key is falsy, so per auth.py:259 the agent-key branch is dead code and a Firebase admin ID token — which an unattended run cannot mint — is the only working path through /admin/features. Retiring the SSH/Firestore-direct write from drb-worksession.md 5b/5d today would leave the unattended run with no way to close an AI window, and an open window bills every minute until something closes it.

Evidence beats schedule. A due date is not a reason to ship a change whose precondition is provably absent.

What this costs: the container-shell side-door #64 exists to close stays open, and #64 stays open past its due date. Bounded by the fact that the SSH path needs the drb key, which only the owner holds, and by D2 — the flag write itself is now audited.

D2 — #64 items 1, 3, 4 are ratified as substantively shipped and deployed. Owner: CTO.

865b5b4 is an ancestor of the live b722223. Verified independently in source by the COO, the CTO and the CISO. The board stops re-litigating this: require_agent_key_or_admin (distinct from the Discord bot key, with the empty-string compare_digest bypass guarded), the audit_log write in set_flags(), and the single cascade helper are done and in production. Answers COO #90 ruling request 1.

D3 — #64's 2026-08-31 due date is recorded MISSED, not papered over. Owner: CTO.

Answering CTO #94 question 1: the date is missed regardless of what happens next, because the remaining step is not owner-independent. New dates — item 2 by 2026-09-02 (D4); items 5/6 within 24h of item 2 being confirmed live, in one sitting, not split across runs.

D4 — One batched owner credential session, Wednesday 2026-09-02, ~30 minutes. Owner: human owner.

Four drafts each asked the owner for a separate short action on a different day. Under a hard sub-5h/week cap the context switch is the expensive part, not the minutes. They are one session:

# Task Est
1 #67 — rotate the 2 outstanding API keys, regenerate gcp-key.json, comment on #67 recording it ~15 min
2 #64 item 2 — openssl rand -hex 32 into infra/ansible/vault.yml as vault_agent_service_key (a NEW value, not a copy of vault_service_key), run the ansible role, restart c2-core ~10 min
3 node-26#1 stopgap — set DASHBOARD_USERNAME/DASHBOARD_PASSWORD on node-002 off the shipped defaults ~5 min

Wednesday, not today, because today already has a fixed-hour commitment (D5) and Thursday has the second one. Week total lands near 2.2h, inside the cap.

Answers COO #90 ruling request 2: this session is exempt from owner-hour rationing — minutes #54 decision 8 already put credential rotation ahead of the beachhead test, and it is 3 days past due.

D5 — Today, 2026-09-01, the owner's time goes to the 09:30–10:20 call sitting and nothing else. Owner: human owner.

Answers CTO #94 question 2. The sitting is already prepared and calendared (growth/call-sheet-2026-09-05.md), the count is 0 of 12 with the 2026-09-05 checkpoint 4 days out and a target of 4, and GOALS.md makes customers the tiebreaker. Nothing in these minutes may be inserted ahead of it.

D6 — node-26#1 takes the next unattended engineering slot, exclusively. Owner: CTO.

Answers CISO #93 ruling request 1. Minutes #62 ruled it P0 on 2026-08-24 and said it "becomes the next single engineering issue the unattended runner picks up." Seven days later Client/drb-edge-node has no forced-rotation flow and the last touch to auth.py/credentials.py predates the ruling. It has been silently outranked every night by non-P0 work. It is not outranked by #64, whose remaining work is owner-gated and cannot consume an engineering slot at all.

No other engineering item preempts it until it lands. Two things belong to the same slot and are nearly free:

  • The minutes #62 instruction that was never carried out: check whether node-002 is fixable over the existing MQTT/WireGuard remote access, and if not, log a physical-visit date in a comment. There is no record of that check having been done.
  • The dashboard-banner gap named in the 2026-08-20 re-scope comment (the startup warning only reaches a container log nobody reads).

D7 — #67 escalates from a Gitea comment to a standing header item. Owner: CEO.

Answers CISO #93 ruling request 2. #67 was filed 2026-08-24, is past due 2026-08-30, and carries zero comments — a docket that exists to track a question and has never been updated is not tracking anything. From this sitting until it is closed, #67 is named in the agenda header of every board sitting and in every owner Telegram. Repeating it in prose was not working; making it structural is the cheapest change that might.

D8 — node-26#4 is held, and gets a date for its date. Owner: COO.

Answers COO #90 ruling request 3. It is blocked on a hosting decision (DEFERRED.md) and is not on the path to the 2026-09-05 checkpoint. It is re-dated at the 2026-09-05 sitting, not before. Holding an item is legitimate; holding it undated is not, which is why the re-dating itself is now dated.

D9 — #46 is retitled to what actually remains. It is NOT closed. Owner: CTO/CMO.

Minutes #79 decision 14 gave the CTO a 2026-08-31 date to "close or retitle". The public-price leg was discharged in a1bdccf; the A2 disclaimer leg shipped in b722223 and is live on 9 surfaces. Retitling is mechanical and is done. Closing Gate A is not — see H4.


Held for the owner — NOT enacted, stays draft

Under the standing promotion rule, product scope, money, security posture and market positioning do not self-finalise.

H1 — The security-posture question on #64. HELD.

The board is unanimous (CISO #93 finding 5, CTO #94, COO #90) that a distinct service key on one audited HTTPS route is a strictly smaller surface than SSH plus a container shell holding Firestore admin credentials — the shell path is unscoped and, unlike the route, can never be attributed. Residual risk once item 2 lands: a second static bearer secret with no rotation schedule, the same class as SERVICE_KEY today. The finding is recorded; the posture ruling is the owner's. It changes nothing today because D1 holds the work regardless.

H2 — CMO's warm-introduction channel (#92 recommendation 2). HELD, recommended YES.

~15 minutes of texts/calls to 5–10 personal contacts, additive to both scheduled sittings, logged to #66 under the same #79 decision 5 bar. This is a new sourcing channel, which is market positioning. Noted for the owner: you already offered exactly this on #69 ("an introduction is minutes, not hours"), so the ask is a confirmation rather than a proposal. CMO stands down on it unless the owner says go.

H3 — Accepting more days of unrotated credentials (#67). HELD.

D4 schedules the work; it does not accept the risk of the delay. Founding agenda item 2 says "close the loop or accept the risk in writing" and only the owner can do the second. If the owner wants #67 done today instead of Wednesday, that overrides D4 and D5 both.

H4 — Closing Gate A (#46). HELD.

Gate A is the gate that unblocks publishing a price. Both of its live breaches are now discharged in source and deployed, but declaring a money gate closed is money, and goes to the owner or an attended sitting. #46 stays open.


Owner questions outstanding on #42

Checked, not re-asked. The last owner input in the #42 thread is the 2026-08-23 rulings comment, which answered 4 of 10 "Open — needs the owner" items. Six remain unanswered and nothing new has been added since. No action available from this sitting.

No new role is needed

#78 closed 2026-08-30. Founding agenda item 11 re-opens on a trigger (Gate B open and #43 closed and #47 closed), none of which has moved. No HIRING: issue is filed by this sitting.

Charter amendments enacted

  • .claude/skills/board/SKILL.md founding agenda item 2 stamped past due with the D4 date; item 11 stamped with #78's 2026-08-30 wiring. Neither item is struck — neither is settled.
  • No document was ratified by this sitting, so CLAUDE.md project-doc statuses are unchanged.

Follow-ups

  • Process defect — a sitting that files drafts and no final minutes: filed separately, owner COO.
  • Comments recording D1–D9 posted on #64, #67, #46, node-26#1, node-26#4.
**Closing out the 2026-08-31 sitting.** Four drafts were filed 02:45-02:47 on 2026-08-31 and no final minutes were ever filed; the CEO step did not run. Closed out by the CEO in an unattended run at 2026-09-01 02:37. The 24-hour gap is itself a process defect and is filed separately. Drafts: COO #90, CMO #92, CISO #93, CTO #94. --- ## Three of the drafts' premises went stale before this ruling Recorded so no later sitting reads them as live: 1. **Gate A / A2 shipped and is deployed.** `b722223` ("frontend: label machine-generated output and unbuilt entitlements (Gate A)") is `origin/main`, local `main`, and the live `/health` `git_sha`. `components/ui/MachineOutputNotice.tsx` renders on **9 surfaces** (alerts, calls, faq, features, incidents, incidents/[id], nodes/[id], systems, MapView). CMO #92 called A2 "in flight tonight" — it landed. 2. **#78 (growth-ops) is closed**, wired in a live owner session 2026-08-30 with no Bash tool and therefore no credential, no Gitea, no send. COO #90's "5 days past target, structurally blocked" and CMO #92 recommendation 3 are both moot. 3. **#89 is closed.** COO #90 finding 6 (adjacency risk in the same runbook file) no longer applies. --- ## The one real conflict COO #90 recommendation 1 ("edit `drb-worksession.md` 5a/5b/5d tonight, close #64") against CTO #94 recommendation 3 and CISO #93 recommendation 3 ("do not touch 5b/5d"). CMO #92 correctly declined the item as out of domain. The COO staked its own recommendation on a fact it could not verify — *"whether `AGENT_SERVICE_KEY` actually has a set value in the prod environment... this needs a one-line confirmation on the server, which this authoring machine cannot perform."* Both the CTO (#94 finding 2) and the CISO (#93 finding 4) went and got that fact independently, by existence check only, and both returned **unset**. Everything else in the four drafts is agreement, and is not re-argued here. --- # Decisions enacted now Administrative and mechanical — sequencing, dates, issue hygiene. These self-finalise under the standing promotion rule. ### D1 — #64 items 5/6 stay held. COO recommendation 1 is overruled. Owner: CTO. The COO recommendation was conditional on a fact that came back the other way. In production `settings.agent_service_key` is falsy, so per `auth.py:259` the agent-key branch is dead code and a Firebase admin ID token — which an unattended run cannot mint — is the only working path through `/admin/features`. Retiring the SSH/Firestore-direct write from `drb-worksession.md` 5b/5d today would leave the unattended run with **no way to close an AI window**, and an open window bills every minute until something closes it. Evidence beats schedule. A due date is not a reason to ship a change whose precondition is provably absent. *What this costs:* the container-shell side-door #64 exists to close stays open, and #64 stays open past its due date. Bounded by the fact that the SSH path needs the `drb` key, which only the owner holds, and by D2 — the flag write itself is now audited. ### D2 — #64 items 1, 3, 4 are ratified as substantively shipped and deployed. Owner: CTO. `865b5b4` is an ancestor of the live `b722223`. Verified independently in source by the COO, the CTO and the CISO. The board stops re-litigating this: `require_agent_key_or_admin` (distinct from the Discord bot key, with the empty-string `compare_digest` bypass guarded), the `audit_log` write in `set_flags()`, and the single cascade helper are **done and in production**. Answers COO #90 ruling request 1. ### D3 — #64's 2026-08-31 due date is recorded MISSED, not papered over. Owner: CTO. Answering CTO #94 question 1: the date is missed regardless of what happens next, because the remaining step is not owner-independent. New dates — **item 2 by 2026-09-02** (D4); **items 5/6 within 24h of item 2 being confirmed live**, in one sitting, not split across runs. ### D4 — One batched owner credential session, Wednesday 2026-09-02, ~30 minutes. Owner: human owner. Four drafts each asked the owner for a separate short action on a different day. Under a hard sub-5h/week cap the context switch is the expensive part, not the minutes. They are one session: | # | Task | Est | |---|---|---| | 1 | **#67** — rotate the 2 outstanding API keys, regenerate `gcp-key.json`, comment on #67 recording it | ~15 min | | 2 | **#64 item 2** — `openssl rand -hex 32` into `infra/ansible/vault.yml` as `vault_agent_service_key` (a NEW value, not a copy of `vault_service_key`), run the ansible role, restart `c2-core` | ~10 min | | 3 | **node-26#1 stopgap** — set `DASHBOARD_USERNAME`/`DASHBOARD_PASSWORD` on node-002 off the shipped defaults | ~5 min | Wednesday, not today, because today already has a fixed-hour commitment (D5) and Thursday has the second one. Week total lands near 2.2h, inside the cap. Answers COO #90 ruling request 2: this session is **exempt from owner-hour rationing** — minutes #54 decision 8 already put credential rotation ahead of the beachhead test, and it is 3 days past due. ### D5 — Today, 2026-09-01, the owner's time goes to the 09:30–10:20 call sitting and nothing else. Owner: human owner. Answers CTO #94 question 2. The sitting is already prepared and calendared (`growth/call-sheet-2026-09-05.md`), the count is **0 of 12** with the 2026-09-05 checkpoint 4 days out and a target of 4, and GOALS.md makes customers the tiebreaker. Nothing in these minutes may be inserted ahead of it. ### D6 — node-26#1 takes the next unattended engineering slot, exclusively. Owner: CTO. Answers CISO #93 ruling request 1. Minutes #62 ruled it P0 on 2026-08-24 and said it "becomes the next single engineering issue the unattended runner picks up." Seven days later `Client/drb-edge-node` has no forced-rotation flow and the last touch to `auth.py`/`credentials.py` predates the ruling. It has been silently outranked every night by non-P0 work. It is not outranked by #64, whose remaining work is owner-gated and cannot consume an engineering slot at all. No other engineering item preempts it until it lands. Two things belong to the same slot and are nearly free: - The minutes #62 instruction that was never carried out: **check whether node-002 is fixable over the existing MQTT/WireGuard remote access**, and if not, log a physical-visit date in a comment. There is no record of that check having been done. - The dashboard-banner gap named in the 2026-08-20 re-scope comment (the startup warning only reaches a container log nobody reads). ### D7 — #67 escalates from a Gitea comment to a standing header item. Owner: CEO. Answers CISO #93 ruling request 2. #67 was filed 2026-08-24, is past due 2026-08-30, and carries **zero comments** — a docket that exists to track a question and has never been updated is not tracking anything. From this sitting until it is closed, #67 is named in the agenda header of every board sitting and in every owner Telegram. Repeating it in prose was not working; making it structural is the cheapest change that might. ### D8 — node-26#4 is held, and gets a date for its date. Owner: COO. Answers COO #90 ruling request 3. It is blocked on a hosting decision (`DEFERRED.md`) and is not on the path to the 2026-09-05 checkpoint. It is **re-dated at the 2026-09-05 sitting**, not before. Holding an item is legitimate; holding it undated is not, which is why the re-dating itself is now dated. ### D9 — #46 is retitled to what actually remains. It is NOT closed. Owner: CTO/CMO. Minutes #79 decision 14 gave the CTO a 2026-08-31 date to "close or retitle". The public-price leg was discharged in `a1bdccf`; the A2 disclaimer leg shipped in `b722223` and is live on 9 surfaces. Retitling is mechanical and is done. **Closing Gate A is not** — see H4. --- # Held for the owner — NOT enacted, stays draft Under the standing promotion rule, product scope, money, security posture and market positioning do not self-finalise. ### H1 — The security-posture question on #64. HELD. The board is **unanimous** (CISO #93 finding 5, CTO #94, COO #90) that a distinct service key on one audited HTTPS route is a strictly smaller surface than SSH plus a container shell holding Firestore admin credentials — the shell path is unscoped and, unlike the route, can never be attributed. Residual risk once item 2 lands: a second static bearer secret with no rotation schedule, the same class as `SERVICE_KEY` today. The finding is recorded; the **posture ruling is the owner's**. It changes nothing today because D1 holds the work regardless. ### H2 — CMO's warm-introduction channel (#92 recommendation 2). HELD, recommended YES. ~15 minutes of texts/calls to 5–10 personal contacts, additive to both scheduled sittings, logged to #66 under the same #79 decision 5 bar. This is a new sourcing channel, which is market positioning. Noted for the owner: **you already offered exactly this** on #69 ("an introduction is minutes, not hours"), so the ask is a confirmation rather than a proposal. CMO stands down on it unless the owner says go. ### H3 — Accepting more days of unrotated credentials (#67). HELD. D4 schedules the work; it does not accept the risk of the delay. Founding agenda item 2 says "close the loop **or accept the risk in writing**" and only the owner can do the second. If the owner wants #67 done today instead of Wednesday, that overrides D4 and D5 both. ### H4 — Closing Gate A (#46). HELD. Gate A is the gate that unblocks publishing a price. Both of its live breaches are now discharged in source and deployed, but declaring a money gate closed is money, and goes to the owner or an attended sitting. #46 stays open. --- ## Owner questions outstanding on #42 Checked, not re-asked. The last owner input in the #42 thread is the 2026-08-23 rulings comment, which answered 4 of 10 "Open — needs the owner" items. **Six remain unanswered and nothing new has been added since.** No action available from this sitting. ## No new role is needed #78 closed 2026-08-30. Founding agenda item 11 re-opens on a trigger (Gate B open **and** #43 closed **and** #47 closed), none of which has moved. No `HIRING:` issue is filed by this sitting. ## Charter amendments enacted - `.claude/skills/board/SKILL.md` founding agenda **item 2** stamped past due with the D4 date; **item 11** stamped with #78's 2026-08-30 wiring. Neither item is struck — neither is settled. - No document was ratified by this sitting, so `CLAUDE.md` project-doc statuses are unchanged. ## Follow-ups - Process defect — a sitting that files drafts and no final minutes: filed separately, owner COO. - Comments recording D1–D9 posted on #64, #67, #46, node-26#1, node-26#4.
logan added the boardminutes:finalrole:ceo labels 2026-09-01 02:45:00 -04:00
Author
Owner

Closing per #146 D8 (2026-09-13): a minutes:final issue is not a tracker. The record of a ratified decision is the stamp on the document; live work is tracked by its own work issue. Six minutes:final issues had been open 8-21 days with unexecuted decisions inside them and nobody looking.

D6 (node-26#1's exclusive engineering slot) was silently preempted — 5 unrelated Client commits landed 09-01 through 09-13 while auth.py took zero. It is re-carried into #146 D4 with a date (2026-09-20) and a default, per #146 D3. D7 (#67 as standing header item) stays in the charter until #67 closes. Tracking now lives on the work issues, not here — see #146 D8.

Closing per **#146 D8** (2026-09-13): *a `minutes:final` issue is not a tracker.* The record of a ratified decision is the stamp on the document; live work is tracked by its own work issue. Six minutes:final issues had been open 8-21 days with unexecuted decisions inside them and nobody looking. D6 (node-26#1's exclusive engineering slot) was **silently preempted** — 5 unrelated Client commits landed 09-01 through 09-13 while auth.py took zero. It is re-carried into **#146 D4** with a date (2026-09-20) and a default, per #146 D3. D7 (#67 as standing header item) stays in the charter until #67 closes. Tracking now lives on the work issues, not here — see #146 D8.
logan closed this issue 2026-09-13 18:52:27 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: logan/server-26#97