rdmsm4x-changelog-20260827-1632-dev-ecs0-litellm-page
rdmsm4x-changelog-20260827-1632-dev-ecs0-litellm-page
Published the privacy-safe Local AI control-plane document to the
owner-only dev.ecs0.net site and made the parallel Dataroo
capture bridge preserve an explicit ECS0-native overlay without
weakening rollback or source-parity checks.
Scope
- Host:
rdmsm4x - Mode: Production
- Canonical project:
/Users/richh/dev/sites/dev.ecs0.net - Feature worktree:
/Users/richh/dev/_worktrees/dev-ecs0-net/codex-litellm-control-plane-page-20260827 - Branch:
codex/litellm-control-plane-page-20260827 - Published commit:
d4b2abedcb2bffaf20150387d36ab973a984ccd9 - Private remote:
richhdoty/dev-ecs0-net; bothmainand the feature branch contain the commit - Live route:
https://dev.ecs0.net/local-ai-control-planes.html - Explicit exclusions: no Dataroo source/runtime/auth/provider mutation; no hostname redirect or retirement; no LiteLLM, Mem0, Ollama, Qdrant, OpenRouter, database, credential, client-routing, budget, or public-listener change
Provenance
- Neutral source task:
01a040a3-c9f1-7961-936e-b7e4ef029cad - Neutral source commit:
a3beeb0b90c7b58f04c877bc6228bcb11e6178e1 - Accepted artifact SHA-256:
60ffad6d3ef60c72ddff63fa884b1afe7eb6526d3f5e335808fd8303f9d2e354 - Destination integration task:
01a04062-ed77-75a1-86a0-3962ecd97a74
Exact project files changed
ISSUES.mdREADME.mdSESSION-STATE.mdconfig/native-wiki-paths.txtdocs/local-ai-control-planes-publication.mdscripts/sync_wiki.zshscripts/verify_wiki_overlay.pytests/test_dev_ecs0.pytests/test_local_ai_control_planes_page.pytests/test_wiki_overlay.pywiki-manifest.sha256wiki-source-manifest.sha256wiki/amagansett/resume-verification-2026-08-27.htmlwiki/data/status.jsonwiki/directory.htmlwiki/fleet.htmlwiki/index.htmlwiki/local-ai-control-planes.htmlwiki/mem0/index.htmlwiki/monitor/index.htmlwiki/p/ai-architecture.htmlwiki/p/bitroo.htmlwiki/p/dataroo.htmlwiki/p/devmon.htmlwiki/p/devsort.htmlwiki/p/filelabeler.htmlwiki/p/fleet.htmlwiki/p/hyperfile.htmlwiki/p/logtty.htmlwiki/p/onlyroute.htmlwiki/p/rdcontact-rdbookmark.htmlwiki/p/rdworkbench.htmlwiki/p/receiptroo.htmlwiki/p/replicantdb.htmlwiki/p/rtty.htmlwiki/p/scanroo.htmlwiki/p/tyrell.html
Other local state changed
- Added the coordination check-in
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-dev-ecs0-litellm-page-20260827.json. - Refreshed the ignored, mode-0600 verification report at
/Users/richh/dev/sites/dev.ecs0.net/reports/dev-ecs0-verification.json. - No container was restarted or replaced. The existing
ecs0-dev-wiki-1read-only bind mount served the fast-forwarded checkout immediately. - No credential value was written, copied, printed, validated, or retained. Existing approved Cloudflare/GoDaddy secret references were used only by the established read-only verification path and were not emitted.
Commands and verification
python3 -m unittest -v- 55 tests accounted for: 52 passed and three runtime-opt-in tests skipped as designed.
ECS0_RUNTIME_TEST=1 python3 -m unittest -v tests.test_dev_ecs0- 13 of 13 passed against the live loopback origin.
bash scripts/sync_wiki.zsh --apply- Captured 87 read-only Dataroo service files and preserved one declared ECS0-native page.
bash scripts/sync_wiki.zsh --verify- Raw-source, transformed imported content, explicit native overlay, and complete served manifest passed.
bash scripts/verify_dev_ecs0.zsh- All eight production stages passed after publication: content/tests, Compose/nginx, provider resources/tunnel, DNS, TLS, Access boundary, Dataroo rollback, and sanitized report.
- Direct loopback route check with
Host: dev.ecs0.net/local-ai-control-planes.htmlreturned HTTP 200.- Served body SHA-256 exactly matched the accepted artifact.
X-Robots-Tag: noindex, nofollow, noarchivewas present.
- Public unauthenticated route returned HTTP 302 to the owner-only Access boundary.
https://dev.dataroo.net/remained HTTP 401; its local origin remained HTTP 200; its three containers remained running with both content-facing services healthy.- LiteLLM remained alive at its existing loopback endpoint and
/v1/modelsstill exposed exactlyagent-local. - Canonical
main,origin/main, and the live checkout all resolved tod4b2abedcb2bffaf20150387d36ab973a984ccd9; the canonical worktree was clean. git diff --checkand Bash syntax checks passed.- High-confidence raw OpenRouter-key scan of all changed publication files passed with no match.
Backup and rollback
- Remote rollback anchor: private branch
origin/codex/litellm-control-plane-page-20260827atd4b2abedcb2bffaf20150387d36ab973a984ccd9. - Prior ECS0 main:
b7d90ce515eb9cd4e836189f5811a3d521fa571b. - Neutral page source remains independently committed at
a3beeb0b90c7b58f04c877bc6228bcb11e6178e1in its released handoff worktree. - Dataroo was not frozen: its production writer advanced its own
mainindependently during this task. Its Git configuration hash, runtime health, and authentication boundary remained preserved. - Undo with a history-preserving
git revert d4b2abedcb2bffaf20150387d36ab973a984ccd9in the canonical ECS0 repository, then rerun the full repository suite andbash scripts/verify_dev_ecs0.zsh. Do not reset published history, delete Dataroo, or repoint either hostname.
Outstanding owner actions
- Rotate the previously exposed
OPENROUTER_API_KEYbefore any future provider activation; this publication did not use it. - Decide separately when, if ever,
dev.dataroo.netshould redirect or retire. It remains the verified rollback service. - Approve or select a complete destination-native generator to replace the remaining Dataroo capture bridge. The explicit native-page overlay is proven but is not a general generator.
- Keep the optional ECS0 Notes publisher unloaded unless its distinct Automation and data-safety gate is approved.
Recorded at 2026-08-27T16:32:18-0400.