Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260828-1602-ecs0-gallery-and-two-p1-items

rdmsm4x — replicantDB gallery published to dev.ecs0.net; two P1 items recorded for after reboot

2026-08-28 16:02:05 EDT · rdmsm4x · repos: ~/dev/apps/replicantDB, ~/dev/sites/dev.ecs0.net

Correction worth recording

I first reported that ec0s.net was not owned and did not resolve. That was my error — the domain is ecs0.net, and I had searched the 439-domain inventory for the transposed string. ecs0.net is in the inventory, dev.ecs0.net is live, and it was stood up 2026-08-27. The lesson is narrow and useful: when a domain "isn't owned", check the spelling against the inventory both ways before saying so.

Published

dev.ecs0.net/gallery/replicantdb/ — 17 icon and reference images with what each one is and where it stands, generated by ~/dev/apps/replicantDB/scripts/gen_gallery.py (generator committed, output gitignored; the originals are already tracked under assets/).

Declared in config/native-wiki-paths.txt so a Dataroo capture refresh preserves it. That is the documented ECS0-native mechanism — the alternative would have forced ECS0 documentation back through Dataroo to survive, which the site exists to stop.

Verified against the running origin rather than assumed: page, a web-tier image and a full-resolution original all return 200 through the Host-pinned local endpoint 127.0.0.1:8788, and all three still 302 to the Cloudflare Access login at the public edge — so the gallery inherits owner-only protection and is not publicly exposed.

Every image was viewed before publishing, not copied sight-unseen. All 17 are generated artwork; none carry credentials or personal data. Not ceremony: the fleet baseline warns a region screen-capture can catch whatever overlaps it, including a window showing secrets.

The page leads with the fact that D-6 (app icon) is still OPEN — the artwork build.sh renders today is what ships, which is not the same as what was chosen. A gallery implying the decision was made would be worse than none.

Two P1 items recorded in dev.ecs0.net/ISSUES.md — both for after the reboot

1. Redesign — Claude taking over from codex@rdmsm4x. Rich: "it's not modern enough, it should be html5, and have more built in modern professional feel, and more organization."

What it is now, plainly: 91 MB / 87 files captured from the Dataroo wiki and rebranded. It is a migration, not a design — pages carry whatever markup they had at origin, so there is no shared shell, no consistent navigation, and no single visual system. publisher/theme.css is the only styling surface and it is not a design system.

The item binds to the standards that already exist rather than inventing a look: DESIGN_SYSTEM.md (mandatory System/Light/Dark, JetBrains Mono + tabular figures, Datadog charting grammar) and apps/CLAUDE.md §10 (generated not hand-written, self-contained HTML5 with zero external dependencies, dated and host-stamped, solid-vs-dashed structural epistemics, no taglines). "More organization" is the harder half and should be designed first — 87 pages with no taxonomy is the real problem, and restyling them individually would leave it.

2. Stateless MCP/API access so agents are not blocked at the door. Rich: "remove friction for the agents using it."

The friction is structural, and naming it is most of the work: the public boundary is Cloudflare Access with an exact-email one-time-PIN policy. A PIN goes to a human mailbox and is typed into a browser — no agent can complete that flow. Verified today: every path, including the new gallery, returns 302 to cloudflareaccess.com. The site is readable by exactly one kind of client, and it is not the kind that needs it.

The fix is Access Service Tokens (CF-Access-Client-Id / CF-Access-Client-Secret headers admitted by a Service Auth policy) — not disabling Access, not a bypass rule, not exposing the origin. The token pair is a secret: ~/.secrets/global.env, referenced by NAME only, never on argv.

For the MCP server itself the item carries the two defects found in replicantdb-mcp on 2026-08-26, because both are invisible to hand-fed testing: no initialize handler (plus missing notification handling, per-tool inputSchema, and content[] envelopes), and broken stdio framing (availableData returns bytes, not a message, so a pipelined initialize + notifications/initialized arrived as one blob and both were dropped). Acceptance test is therefore a pipelined handshake parsed as JSON — one-at-a-time hides the framing bug, and sed-matching is unreliable because key order is not stable. Build universal2; two fleet hosts are Intel.

Everything else still true

replicantDB v1.4.0 (5) "Reference" on all six hosts, 340 tests / 0 failures / 0 warnings, tree clean, nothing pushed to any remote — D-26 remains Rich's call. Four agents are triaging the remaining fleet / apps / dev-tree backlog into dated closeout files.