rdmsm4x-changelog-20260827-0650-dev-dataroo-live-project-alignment
dev.dataroo.net live project alignment
Aligned the existing dev.dataroo.net project/operations
repository with the actual live Portfolio/Fleet/Agents dashboard so
future work starts from the real generator, runtime, ownership, and
authentication boundaries rather than from a similarly named folder.
Scope
- Host:
rdmsm4x. - Canonical project envelope:
/Users/richh/dev/sites/dev.dataroo.net. - Documentation worktree:
/Users/richh/dev/_worktrees/dev-dataroo-net/codex-live-site-alignment-20260827. - Branch:
codex/live-site-alignment-20260827. - Commit:
efcfd15(docs: align project with live dev.dataroo.net). - Production generator, runtime, containers, routes, authentication, DNS, and Cloudflare state were not changed by this alignment lane.
Files changed
README.md— identifies this repository as the project/operations envelope, maps the split source/runtime architecture, and points agents to the durable project records.AGENTS.md— records Production mode, one-writer rules, source/runtime boundaries, outward-action gates, secret handling, and verification rules.SESSION-STATE.md— captures chronology, latest directive, exact roots, branches, owners, peer messages, evidence, security follow-up, and next gates.docs/live-site-architecture.md— documents the generator, data inputs, scheduled publisher, generated webroot, OrbStack Compose stack, auth proxy, Cloudflare Tunnel, route behavior, rollback, and active writer scope.docs/project-root-reconciliation.md— classifies every candidate folder and records the safe convergence path without moving production files./Users/richh/.agent-coordination/checkins/codex-rdmsm4x-devsite-live-alignment-20260827.json— docs-only writer lease, result, verification, and ownership release.
Peer coordination
- Sent three information-only requests to
claude@rdmsm4x. - Received actual Claude reply
20260827-063850-4E99F5AC, which confirmed:- canonical generator/data roots under
/Users/richh/dev/scriptsand/Users/richh/dev/data; - generated runtime root
/Users/richh/dataroo.net/wiki; - Compose root
/Users/richh/dataroo.net; sites/dev.dataroo.netis the project/ops folder, not live generator source;dataroo.netis a near-empty adjacent repo anddataroo.devis a separate Next.js project;- the loaded launchd interval is 1,800 seconds;
- Claude is the active writer for the generator, product data, and selected nginx/Compose files until it posts a handoff.
- canonical generator/data roots under
- Replied with the docs-only boundary and acknowledged the message.
- Reported a credential-rotation requirement to the active owner without reading or repeating the value.
- The separate
dev.ecs0.nettask has a newer direct user authorization to continue its isolated migration lane; this task did not edit or validate that lane by inference.
Commands and verification
- Created the isolated Git worktree and branch from project commit
4ea83f0a185b1cb7ebb0caa88555e19f86ab270b. - Ran
/usr/bin/python3 -m unittest discover -s tests -v: 30 tests passed, zero failures. - Ran
git diff --cached --check: no whitespace errors after correction. - Ran staged Gitleaks 8.30.1 with full redaction: no leaks found across about 30.76 KB of staged documentation.
- Compared active
gen_site.py,dr_export.py, andpublish_site.zshto the preserved implementation worktree: all three matched at the snapshot. - Recounted the generated webroot: 86 files, 41 HTML files, 95,667,910 bytes.
- Verified
http://127.0.0.1:8787/returned200and unauthenticatedhttps://dev.dataroo.net/returned the expected401. - Verified
dataroo-wiki-server-1anddataroo-auth_proxy-1remained healthy anddataroo-cloudflared-1remained running. - Verified launchd label
com.eastcoastscience.devsiteretained a 1,800-second interval and last exit code0. - Synchronized the fleet check-ins;
rdmpw3265mremained unreachable and no state from that host was inferred.
Security follow-up
A read-only resolved Compose diagnostic expanded the credential named
CLOUDFLARE_TUNNEL_TOKEN into private task/tool output. The
value was not copied into files, check-ins, messages, or this changelog.
The active production owner was notified to rotate it through the
approved credential workflow. No rotation or external security-principal
change was attempted by this task.
Backup and undo
- No production backup was needed because this lane changed documentation only in an isolated worktree.
- The local Git commit is the recoverable record. Before integration,
undo is simply to leave branch
codex/live-site-alignment-20260827unmerged. After integration, revert commitefcfd15rather than deleting unrelated project history. - Existing production rollback remains at
/Users/richh/dev/_backups/devsite-nocontext-nav-20260827-044352; this task did not alter it.
Outstanding owner actions
- Wait for
claude@rdmsm4xto hand off its active production writer scope before changing generator/data/nginx/Compose files. - Reconcile the unreleased prior Codex production check-in with the current Claude writer.
- Choose whether to integrate commit
efcfd15into the project main branch. - Decide the final disposition of preserved generator branch
work/devsite-nocontext-nav-20260827. - Rotate
CLOUDFLARE_TUNNEL_TOKENthrough the approved credential workflow. - Require the separately owned
dev.ecs0.netmigration task to report its own external actions, content parity, rollback, and acceptance evidence.