docs(spec): record the Alfred vault trial as alternate storage (ADR 0001)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
59a143671d
commit
96403effd6
2 changed files with 88 additions and 0 deletions
75
docs/adr-0001-alfred-vault-trial.md
Normal file
75
docs/adr-0001-alfred-vault-trial.md
Normal file
|
|
@ -0,0 +1,75 @@
|
||||||
|
# ADR 0001 — Alfred: agent-runtime trial writing to a Markdown vault
|
||||||
|
|
||||||
|
**Status:** trial, 2026-09-20
|
||||||
|
**Owner:** padreug
|
||||||
|
**Code:** `~/Work/tries/2026-09-20-alfred-vm/` (bohm), not yet in any aiolabs repo
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
The community-organizer spec (this repo, `docs/community-organizer-spec.md`)
|
||||||
|
defines capture as NIP-52 events scoped by NIP-72 communities, produced by
|
||||||
|
the `tracker` maubot plugin. Phase 1 of `tracker` shipped rules-only; the
|
||||||
|
LLM tier (§6.1 level 2), Nostr publishing (§4) and per-user signing (§7.2)
|
||||||
|
never landed. The 2026-06-02 pilot review recorded that the community had
|
||||||
|
already named the bot "Alfred" and asked for digests, an LLM fallback and
|
||||||
|
grammar tolerance.
|
||||||
|
|
||||||
|
On 2026-09-19 a separate "2nd brain" landed for the operator: plain-Markdown
|
||||||
|
zk vaults, one Forgejo repo per vault, `brain todos` scanning `- [ ]` lines
|
||||||
|
in `journal/` and `projects/`, `brain sync` for git. The chateau vault
|
||||||
|
(`padreug/brain-chateaudufaune`) is one of them.
|
||||||
|
|
||||||
|
The May 2026 planning session had suggested an OpenClaw/ZeroClaw-style
|
||||||
|
agent "running on its own machine" as an alternate runtime (spec §12).
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Run a **trial** of that alternate runtime, sized to one community and one
|
||||||
|
vault:
|
||||||
|
|
||||||
|
- **Runtime:** ZeroClaw (0.8.3 from nixpkgs, rebuilt with `channel-matrix`;
|
||||||
|
upstream NixOS module) in a QEMU VM on bohm. Explicitly **not** on cfaun.
|
||||||
|
- **Store:** the chateau vault — Markdown + git, `main`, same repo the
|
||||||
|
operator's laptop syncs. Alfred commits and pushes every write with a
|
||||||
|
repo-scoped write deploy key; force-push is blocked on Forgejo.
|
||||||
|
- **Inference:** the optimus box (`http://192.168.0.33:8080/v1`, llama-swap:
|
||||||
|
GLM-4.7-Flash for chat, GPT-OSS-120B for the nightly digest).
|
||||||
|
- **Behaviour:** mention-gated replies in one Matrix room; a matrix-nio
|
||||||
|
sidecar logs the whole room per day; a 22:00 Europe/Paris cron job
|
||||||
|
digests the log into `journal/YYYY-MM-DD.md` (`## Chat digest (Alfred)`)
|
||||||
|
and proposes tasks; "what needs doing" runs a deterministic port of
|
||||||
|
`brain todos` so answers match the laptop.
|
||||||
|
- **Bounds:** `workspace_only`, shell allowlist `git` + `vault-todos`, no
|
||||||
|
web/delegation tools, autonomy `full` (switch to `supervised` if it
|
||||||
|
misbehaves). Prompt injection from the room is bounded to that repo;
|
||||||
|
git history is the undo.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
- **Not spec-conformant.** Alfred emits no §4 events and knows nothing of
|
||||||
|
§5 communities or §7 signing. Nothing downstream (eink renderer, relays,
|
||||||
|
third-party Nostr clients) sees its output. It shares §3.1 vocabulary
|
||||||
|
(task / journal / done / list) and the §6 rule that capture never blocks
|
||||||
|
on classification (unsure → `inbox/`).
|
||||||
|
- **Two writers, one repo.** Laptop and bot both `pull --rebase` before
|
||||||
|
push and stage explicit paths only; the bot never touches `hubs/`,
|
||||||
|
`notes/`, `README.md`, `.zk/`. Conflicts abort and ask a human.
|
||||||
|
- **Local-model quality is the unknown.** Multi-step tool loops (edit
|
||||||
|
file + git) on GLM-Flash are unproven; the deterministic todos path is
|
||||||
|
immune.
|
||||||
|
- **Dependency churn.** ZeroClaw moves fast; config keys were read from the
|
||||||
|
v0.8.3 source. The upstream v0.8.5 flake did not evaluate (Cargo hash
|
||||||
|
mismatch), hence the nixpkgs rebuild.
|
||||||
|
|
||||||
|
## Revisit when
|
||||||
|
|
||||||
|
- The trial holds up for a few weeks → promote to cfaun as a
|
||||||
|
`services.zeroclaw` instance in `server-deploy` (sops for env + deploy
|
||||||
|
key, `networking.hosts` for optimus) and decide whether `tracker` is
|
||||||
|
retired or bridged (a small publisher turning vault commits into §4
|
||||||
|
events would restore conformance).
|
||||||
|
- The agent is unreliable → fall back to a deterministic maubot plugin
|
||||||
|
(`dev.aiolabs.alfred`): Python vault writers, `brain todos` port,
|
||||||
|
in-process git under an asyncio lock, model used only to parse JSON.
|
||||||
|
Sketched in the 2026-09-20 planning session; not built.
|
||||||
|
- Either way, update spec §12 "Alternate storage (trial)" and this ADR.
|
||||||
|
|
@ -855,6 +855,16 @@ scoping in §5. A ZeroClaw-based implementation would carry the
|
||||||
`["client", "maubot-tracker", "..."]`; renderers ignore the difference
|
`["client", "maubot-tracker", "..."]`; renderers ignore the difference
|
||||||
since they filter by community `a`-tag.
|
since they filter by community `a`-tag.
|
||||||
|
|
||||||
|
### Alternate storage (trial)
|
||||||
|
|
||||||
|
Since 2026-09-20 a ZeroClaw-based "Alfred" trial targets a plain-Markdown
|
||||||
|
zk vault synced over git (`padreug/brain-chateaudufaune`) as its store
|
||||||
|
instead of the §4 events. It is **not** spec-conformant — no NIP-52
|
||||||
|
events, no §5 community scoping, no §7 signing — but keeps the §3.1
|
||||||
|
vocabulary and the §6 rule that capture never blocks on classification
|
||||||
|
(unsure items go to `inbox/`). Rationale, bounds and revisit criteria in
|
||||||
|
[`adr-0001-alfred-vault-trial.md`](adr-0001-alfred-vault-trial.md).
|
||||||
|
|
||||||
### Reference identity provider — operator-IdP pattern
|
### Reference identity provider — operator-IdP pattern
|
||||||
|
|
||||||
The aiolabs reference implementation runs the **operator-IdP-with-
|
The aiolabs reference implementation runs the **operator-IdP-with-
|
||||||
|
|
@ -948,6 +958,9 @@ the bot signing as itself and human attribution carried in the
|
||||||
|
|
||||||
## Changelog
|
## Changelog
|
||||||
|
|
||||||
|
- **0.3** (2026-09-20) — §12 gains "Alternate storage (trial)": the
|
||||||
|
Alfred / ZeroClaw trial writes a Markdown git vault, not §4 events;
|
||||||
|
see ADR 0001.
|
||||||
- **0.2** (2026-06-28) — reflect shipped state of the reference IdP +
|
- **0.2** (2026-06-28) — reflect shipped state of the reference IdP +
|
||||||
sidecar bunker. `aiolabs/lnbits#9` and `#18` are no longer
|
sidecar bunker. `aiolabs/lnbits#9` and `#18` are no longer
|
||||||
in-flight; `aiolabs/nsecbunkerd` (deploys from `dev`) is live with
|
in-flight; `aiolabs/nsecbunkerd` (deploys from `dev`) is live with
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue