15 Commits

Author SHA1 Message Date
6a9c18f5a5 fix(taiga-auto-sync): match real Taiga MCP tool names and drop impossible owner/sprint checks
The write-guard's matcher regex never matched the actual tool names
(createUserStory/createTask/createIssue, not user_story_create etc.), so
the metadata guard has never actually fired. It also checked for
assigned_to/milestone fields that don't exist on any create tool's
schema, which would have denied every create once the matcher was fixed.
Guard now validates only the tag contract (area/source/target), covers
the batch-create tools per item, and SKILL.md documents the real
follow-up calls (assignIssue/assignUserStoryToSprint/addIssueToSprint)
needed to set owner and sprint after creation.
2026-09-14 00:31:53 +07:00
98dca237f4 Add infra-ops-toolkit plugin: topology diagram, html-to-pdf, teleport onboarding skills
Distills patterns from the Teleport access topology work: verified-data diagram
building, as-displayed HTML-to-PDF export via headless Chromium, and
container-scoped/host/database onboarding into an existing Teleport cluster.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R3ZTfgQrkR3q8DSEoZAmvs
2026-09-08 16:11:36 +07:00
ed7c1b0a0f fix(openbao-session): always pass -ttl so session tokens stay short-lived
Without an explicit -ttl the role path could mint ~32-day session tokens.
Pass SESSION_TTL in both role and policy modes. Bump 0.1.3.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:37:00 +07:00
ddbdf468e3 docs(openbao-session): creator policy needs auth/token/create/* for role-based minting
Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:35:31 +07:00
0f77ad534e fix(openbao-session): use a token role for entity-alias minting
entity-alias only works with -role; add OPENBAO_SESSION_ROLE so session tokens
can carry the user entity (and read humans/self) via the openbao-session role.
Bump 0.1.2.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:28:38 +07:00
6877bc7202 feat(openbao-session): tie session token to the user entity
Mint the session token with -entity-alias from OPENBAO_SESSION_ENTITY so
{{identity.entity.id}} resolves and the session can read humans/self (read-only)
in addition to shared/*. Document the claude-session policy with humans/self.
Bump 0.1.1.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:19:00 +07:00
6ad7202fdf feat(shared-vault-sync): add commit-driven auto-push script
push-shared-vault.sh pushes the shared vault only when the worktree is clean
and the local branch is ahead of origin (fetch first); never rebases,
force-pushes, or resolves conflicts. Ships with launchd setup docs. Bump 0.1.2.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 10:33:49 +07:00
1bd000e595 feat(shared-vault-sync): sync the nested devops-shared-vault subrepo
Detection order is now SHARED_VAULT_DIR, then $PWD, then $PWD/Areas/DevOps
(the nested shared subrepo inside the personal vault). Bump to 0.1.1.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 10:15:35 +07:00
912e85fbf7 feat: sync shared vault at session start 2026-09-01 09:40:46 +07:00
5166f12775 feat: add openbao-session plugin for interactive agents
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 02:16:01 +07:00
6693213b02 Write Taiga updates in Indonesian 2026-08-29 20:14:23 +07:00
0dbccee979 Activate Taiga tracking only for infra ops work 2026-08-29 20:04:47 +07:00
b56f7def02 Enforce Taiga active item governance 2026-08-29 19:35:45 +07:00
54bbd7c702 Add Claude plugin manifest 2026-08-27 13:12:17 +07:00
1de1479bfa Add Taiga auto-sync Codex plugin 2026-08-27 13:08:07 +07:00