Specify M4a (conversations over Mattermost); propose P15 on secrets

M4 is split into M4a and M4b. The M4a spec rests on facts checked against
the owner's server and Mattermost's source at v11.11.0: the REST and
WebSocket shapes, and that clients will not post a message starting with
'/'. Records the design decisions, proposes P15 (secrets from a systemd
credential, the environment or an owner-only file), and adds the run-time
rows egress.md was missing since M2a and M3b.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-23 17:30:31 -07:00
co-authored by Claude Opus 5.5
parent f0ec0efe9d
commit 7e3783faae
5 changed files with 346 additions and 4 deletions
+2 -1
View File
@@ -12,7 +12,8 @@ M3a (`brokerd`'s decision path, spec `docs/specs/2026-09-18-m3a-decision-path.md
merged, reviewed in `docs/implementer-log.md`; its open findings (17, 18, 20) are listed there; 14 was
closed by M3b task 02. M3b (the container runner and the four tools, `docs/specs/2026-09-22-m3b-runner.md`) is done and
merged: tool containers run from the image `deploy/tools-image.nix` builds, checked on straylight.
M4 (`gatewayd` and Mattermost) is next to design.
M4 is split: M4a (`gatewayd`, conversations over Mattermost) is specified in
`docs/specs/2026-09-23-m4a-gateway.md`, a draft for review; M4b (approvals over Mattermost) follows.
Straylight now serves Ornith as four slots over one 262,144-token pool; see
`docs/inference-contract.md`, "Deployment change, 2026-09-20", before relying on cache behaviour.
`docs/runbook.md` has an entry for every