docs(spec): ADR 0002 — Alfred's store moves to Nextcloud (VTODO ≈ §3.2/§3.3.1)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-22 14:51:11 +02:00
commit 378c1f7b23
2 changed files with 89 additions and 7 deletions

View file

@ -0,0 +1,76 @@
# ADR 0002 — Alfred's store is Nextcloud, not the git vault
**Status:** accepted 2026-09-22 (supersedes the "Store" part of ADR 0001)
**Owner:** padreug
**Code:** `~/Work/tries/2026-09-20-alfred-vm/` (`pkgs/vault-*.py`, `vm.nix`, `workspace/AGENTS.md`)
## Context
ADR 0001 started the Alfred trial with the operator's zk vault
(`padreug/brain-chateaudufaune`, git) as the store: tasks as `- [ ]` lines,
journal as daily Markdown, the bot committing and pushing. Two days of live
use showed three things.
1. **The vault is invisible to the community.** It is edited with nvim/zk on
one laptop, synced by git, with no phone, share or web path. "What needs
doing" answered a question nobody but the operator could see, and the
journal (meant as the record newcomers read) was equally hidden.
2. **Free-form file writes were the failure class.** Every Alfred failure came
from `file_write` + `git`: wrong paths, ten tool iterations burnt on a
commit, a task turned into cron reminders, and `contacts.md` invented in
the vault three times (last: `785a9ea`, 2026-09-22) despite explicit
instructions. The CLI verbs with one action each (`vault-cal add`,
`vault-contacts add`) succeeded whenever the model chose them.
3. **The community already lives on Nextcloud.** `cloud.ariege.io` (Nextcloud
33) holds Coco's 2025 Deck boards (seven domain boards, a label taxonomy,
stacks, assignees; archived 2026-01-29), shared calendars, Talk rooms, Notes,
a `chateau` task list. Contacts and appointments had already moved there on
2026-09-21.
## Decision
Nextcloud is the system of record; Alfred's only actions are four commands:
| concern | app / protocol | command | collection |
|---|---|---|---|
| tasks | Tasks (CalDAV VTODO) | `vault-todos` | task list `chateau-1` |
| appointments | Calendar (CalDAV) | `vault-cal` | calendar `chateau` |
| people | Contacts (CardDAV) | `vault-contacts` | address book `Chateau` |
| journal, inbox notes, chat log | Files / Notes app (WebDAV, plain `.md`) | `vault-notes` | folder `Notes/Chateau/{Journal,Inbox,Chatlog}` |
- Tasks (VTODO) over Deck: standard, phone-synced (Tasks.org, DAVx5, Nextcloud
Tasks), shows in the Calendar app, and its fields map onto the spec:
STATUS ↔ §3.2 lifecycle, PRIORITY 1/3/5/7/9 ↔ §3.3.1 levels 1–5, CATEGORIES
↔ domain tags (vocabulary borrowed from the 2025 Deck labels), `X-ALFRED-SRC`
↔ `src:explicit|llm`, `X-ALFRED-BY` ↔ `author`. Deck stays an option if the
group revives its boards.
- Alfred runs as a dedicated Nextcloud user `alfred` that only receives the
four château shares; `file_write`/`file_edit`/`git` are excluded from the
agent; `allowed_commands` is exactly the four verbs; 60 actions/hour.
- No bulk verb exists; every delete takes one uid, and `vault-cal` exposes
`move` instead of delete to the model.
- The git repo `brain-chateaudufaune` is frozen for the bot (final commit
"moved to Nextcloud", deploy key removed); it remains the operator's zk
vault. A daily export backup (ics/vcf/notes) into that repo restores git
history for the community store.
## Consequences
- The whole group sees and edits the same tasks, events, contacts and journal
on phone and web the day they land; the operator syncs `Notes/Chateau` to the
laptop and keeps using zk on it.
- Undo is Nextcloud trash/versions plus the daily backup, weaker than git
history for in-place edits; mitigated by single-uid verbs and the rate cap.
- Still not spec-conformant (no §4 events, no §5 community scoping, no §7
signing), but VTODO is a projection away from NIP-52: a future bridge maps
fields 1:1 instead of parsing Markdown.
- One more account and app password to manage; Nextcloud app passwords are
full-account, hence the dedicated user.
## Revisit when
- The trial holds up: promote to cfaun as a `services.zeroclaw` instance
(sops for env files), and decide whether `tracker` is retired or bridged.
- The agent stays unreliable: the deterministic maubot plugin path from ADR
0001 now has an even simpler shape (four HTTP clients, no git).
- The group revives Deck: add a `vault-deck` verb or mirror VTODOs to cards.

View file

@ -857,13 +857,16 @@ since they filter by community `a`-tag.
### Alternate storage (trial)
Since 2026-09-20 a ZeroClaw-based "Alfred" trial targets a plain-Markdown
zk vault synced over git (`padreug/brain-chateaudufaune`) as its store
instead of the §4 events. It is **not** spec-conformant — no NIP-52
events, no §5 community scoping, no §7 signing — but keeps the §3.1
vocabulary and the §6 rule that capture never blocks on classification
(unsure items go to `inbox/`). Rationale, bounds and revisit criteria in
[`adr-0001-alfred-vault-trial.md`](adr-0001-alfred-vault-trial.md).
The ZeroClaw-based "Alfred" trial (started 2026-09-20 on a git-synced
Markdown vault, [`adr-0001`](adr-0001-alfred-vault-trial.md)) moved its
store to **Nextcloud** on 2026-09-22
([`adr-0002`](adr-0002-alfred-nextcloud-store.md)): tasks are CalDAV
VTODOs whose STATUS and PRIORITY follow §3.2 and §3.3.1 exactly and whose
CATEGORIES carry the domain tags, with `X-ALFRED-SRC` for the §3.3
classification source; appointments are CalDAV events, people CardDAV
contacts, the journal plain Markdown in a shared Notes folder. Still
**not** spec-conformant — no §4 events, no §5 community scoping, no §7
signing — but a NIP-52 bridge from VTODO is a field-for-field projection.
### Reference identity provider — operator-IdP pattern
@ -958,6 +961,9 @@ the bot signing as itself and human attribution carried in the
## Changelog
- **0.4** (2026-09-22) — §12 "Alternate storage": the Alfred trial now
stores tasks as VTODO on Nextcloud with §3.2/§3.3.1 field mapping; see
ADR 0002.
- **0.3** (2026-09-20) — §12 gains "Alternate storage (trial)": the
Alfred / ZeroClaw trial writes a Markdown git vault, not §4 events;
see ADR 0001.