maubot-plugins/docs/adr-0001-alfred-vault-trial.md
Padreug 96403effd6 docs(spec): record the Alfred vault trial as alternate storage (ADR 0001)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 17:31:30 +02:00

3.8 KiB

ADR 0001 — Alfred: agent-runtime trial writing to a Markdown vault

Status: trial, 2026-09-20 Owner: padreug Code: ~/Work/tries/2026-09-20-alfred-vm/ (bohm), not yet in any aiolabs repo

Context

The community-organizer spec (this repo, docs/community-organizer-spec.md) defines capture as NIP-52 events scoped by NIP-72 communities, produced by the tracker maubot plugin. Phase 1 of tracker shipped rules-only; the LLM tier (§6.1 level 2), Nostr publishing (§4) and per-user signing (§7.2) never landed. The 2026-06-02 pilot review recorded that the community had already named the bot "Alfred" and asked for digests, an LLM fallback and grammar tolerance.

On 2026-09-19 a separate "2nd brain" landed for the operator: plain-Markdown zk vaults, one Forgejo repo per vault, brain todos scanning - [ ] lines in journal/ and projects/, brain sync for git. The chateau vault (padreug/brain-chateaudufaune) is one of them.

The May 2026 planning session had suggested an OpenClaw/ZeroClaw-style agent "running on its own machine" as an alternate runtime (spec §12).

Decision

Run a trial of that alternate runtime, sized to one community and one vault:

  • Runtime: ZeroClaw (0.8.3 from nixpkgs, rebuilt with channel-matrix; upstream NixOS module) in a QEMU VM on bohm. Explicitly not on cfaun.
  • Store: the chateau vault — Markdown + git, main, same repo the operator's laptop syncs. Alfred commits and pushes every write with a repo-scoped write deploy key; force-push is blocked on Forgejo.
  • Inference: the optimus box (http://192.168.0.33:8080/v1, llama-swap: GLM-4.7-Flash for chat, GPT-OSS-120B for the nightly digest).
  • Behaviour: mention-gated replies in one Matrix room; a matrix-nio sidecar logs the whole room per day; a 22:00 Europe/Paris cron job digests the log into journal/YYYY-MM-DD.md (## Chat digest (Alfred)) and proposes tasks; "what needs doing" runs a deterministic port of brain todos so answers match the laptop.
  • Bounds: workspace_only, shell allowlist git + vault-todos, no web/delegation tools, autonomy full (switch to supervised if it misbehaves). Prompt injection from the room is bounded to that repo; git history is the undo.

Consequences

  • Not spec-conformant. Alfred emits no §4 events and knows nothing of §5 communities or §7 signing. Nothing downstream (eink renderer, relays, third-party Nostr clients) sees its output. It shares §3.1 vocabulary (task / journal / done / list) and the §6 rule that capture never blocks on classification (unsure → inbox/).
  • Two writers, one repo. Laptop and bot both pull --rebase before push and stage explicit paths only; the bot never touches hubs/, notes/, README.md, .zk/. Conflicts abort and ask a human.
  • Local-model quality is the unknown. Multi-step tool loops (edit file + git) on GLM-Flash are unproven; the deterministic todos path is immune.
  • Dependency churn. ZeroClaw moves fast; config keys were read from the v0.8.3 source. The upstream v0.8.5 flake did not evaluate (Cargo hash mismatch), hence the nixpkgs rebuild.

Revisit when

  • The trial holds up for a few weeks → promote to cfaun as a services.zeroclaw instance in server-deploy (sops for env + deploy key, networking.hosts for optimus) and decide whether tracker is retired or bridged (a small publisher turning vault commits into §4 events would restore conformance).
  • The agent is unreliable → fall back to a deterministic maubot plugin (dev.aiolabs.alfred): Python vault writers, brain todos port, in-process git under an asyncio lock, model used only to parse JSON. Sketched in the 2026-09-20 planning session; not built.
  • Either way, update spec §12 "Alternate storage (trial)" and this ADR.