feat(poker): bake and supervise the forum poker table's house seat - #14
Merged
Merged
Conversation
…poker_citizen], forum ADR-2020) nostr-bbs-poker-citizen from the kit at the website's KIT_REF (d673708), lib/poker-citizen.nix with the commit's lockfile vendored; [program:poker-citizen] runs config/poker/run-citizen.sh (waits for the sidestr:dreamlab producer) with the key, ledger, relay and daily cap from [poker_citizen]. REBUILD-class: until the image is rebuilt the service runs from a release build in tmux `poker-citizen`. Co-Authored-By: jjohare <github@thedreamlab.uk>
bea1338 added [poker_citizen] to agentbox.toml and the flake, but not to the manifest schema (validator E016 UnknownManifestKey) or the ADR-039 catalogue (check-manifest-catalogue: poker_citizen.enabled uncatalogued). - schema/agentbox.toml.schema.json: poker_citizen object, additionalProperties false, with the five keys the flake reads (enabled, key_file, state, relay, daily_cap). - system-manifest.js: CATALOGUE entry 'poker-citizen', shaped like payments-sidestr, gate poker_citizen.enabled. apply_class is 'rebuild', not payments-sidestr's 'boot': the flake bakes the program and package, so a flip needs an image rebuild. Co-Authored-By: jjohare <github@thedreamlab.uk>
The governed-path changes since each stamp are PR #14's two commits only: [poker_citizen] in agentbox.toml, its schema object and catalogue entry, and the flake's poker-citizen package and program (outbound only, no listener). One dated note per record; earlier notes kept. ADR-2122's note records an open gap instead of closing it here: poker-citizen holds a signing key but is not in secret_bearing_programs, so under [security].role_isolation it would still run as devuser. The flag ships off; a role for it is the owner's follow-up. Co-Authored-By: jjohare <github@thedreamlab.uk>
jjohare
force-pushed
the
feat/poker-citizen-house-seat
branch
from
October 3, 2026 11:55
bea1338 to
2de360f
Compare
The house seat holds a signing key that pays out up to daily_cap DREAM a day, but was not in secret_bearing_programs, so under [security].role_isolation it would have stayed devuser. - config/role-accounts.json: role ab-poker-citizen at 970 (next free after 969; 965 stays reserved), its own group; poker-citizen added to secret_bearing_programs; house.key from the at-rest copy /var/lib/agentbox/secrets/poker-citizen.key, migrated once from the workspace key (legacy), delivered 0400 to /run/secrets/ab-poker-citizen; ledger dir /var/lib/agentbox/events/sidestr/poker-citizen (970:devuser 2750), seeded once. - config/poker/run-citizen.sh: the faucet's custody rule. Under the flag the ledger defaults to the events volume (umask 027); flag off with that ledger ahead of the workspace one, refuse (CUSTODY-STATE-AHEAD) rather than settle hands twice. - agentbox.toml: [poker_citizen].state is no longer pinned (it would point the role at a workspace path it cannot write); the runner's default is the same path flag-off. - tests: role-custody-migrate checks the runner's ledger path and rollback guard (33 cases). isolate on the real program shape gives user=ab-poker-citizen and POKER_CITIZEN_KEY_FILE=/run/secrets/ab-poker-citizen/house.key. - docs: the role tables in SECURITY-profiles and ADR-2122. Co-Authored-By: jjohare <github@thedreamlab.uk>
ADR-2122's note closes the gap its previous note recorded; the other eight see only the [poker_citizen].state line becoming a comment. Earlier notes kept. Co-Authored-By: jjohare <github@thedreamlab.uk>
…iable without a role secret_bearing_programs is an opt-in list, and the poker house seat showed its weakness: the first program added after role isolation landed held a key and was not on it, so the build said nothing. role-accounts isolate now also fails the build when a user=devuser program that is not in secret_bearing_programs has an environment naming - a ROLE-class variable from config/custody/env-classes.json, or its file_var twin (--env-classes; the flake now passes it), or - a variable ending _PRIVKEY_HEX, _SK or _KEY_FILE. Root programs and role programs are exempt; the error names the program and the variable. Red first: against PR #14 before its role (2de360f), isolate over every [program:] block in that flake fails with exactly one error, poker-citizen / POKER_CITIZEN_KEY_FILE. With the role, all 43 programs pass. tests/config/lib/flake-programs.sh renders the flake's programs (user and variable names, no Nix eval); role-isolation-supervisor runs it both ways on every CI run (25 cases), and four Rust unit tests cover each branch (cargo 172). Co-Authored-By: jjohare <github@thedreamlab.uk>
…ds (e3b06d6) Co-Authored-By: jjohare <github@thedreamlab.uk>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Self-contained commit found on the shared checkout (another session, 09:41Z). Pins verified by the repin pass: NAR hash reproduces, vendored lockfile byte-identical to the kit Cargo.lock. Separate from custody PR #12 so each bakes on its own merit.
🤖 Generated by Claude Code