Apply post-M1 corrections to the planning package

This commit is contained in:
JesseMarkowitz
2026-09-02 06:03:10 -04:00
parent 645f07f06d
commit 1a28a9a708
8 changed files with 304 additions and 35 deletions
+36 -3
View File
@@ -1,6 +1,6 @@
# Adventure Storyteller — Production Build Milestones
**Status:** Planning-ready; implementation not yet authorized
**Status:** In implementation. M1 complete (2026-09-02); M2 next
**Base:** AI-DnD `d72f7c1bda0f34fccd84afb7a25c34eb01c901de`
## 1. Purpose
@@ -63,6 +63,15 @@ Create the production fork from the pinned AI-DnD commit and make ordinary local
- verify explicitly configured trusted-LAN Ollama story generation while the storyteller UI/API remains loopback-bound,
- establish baseline regression/test report.
**Added during implementation:** outbound TLS trust. A trusted-LAN Ollama may be
served over HTTPS with a privately issued certificate, which the inherited HTTP
client refused because it verified against a bundled public-CA list only. M1
made outbound HTTPS verify against the operating system's CA store as well,
with verification and hostname checking fully intact and no bypass option
(ADR 002; `backend/app/tlstrust.py`). This was not in the scope list above but
was on M1's critical path: without it the trusted-LAN Definition of Done below
is unreachable against a realistic host.
## Explicit Non-Scope
- no history rewrite yet,
@@ -86,6 +95,22 @@ Must demonstrate:
A clean production build can start, open the browser UI, generate and persist story turns through either same-host Ollama or an explicitly configured trusted-LAN Ollama host, restart, and resume with outbound Internet blocked. The storyteller UI/API remains loopback-bound by default.
## Status: COMPLETE
Accepted 2026-09-02. Evidence: `planning/reports/M1-BASELINE-REPORT.md` (run
logs and packet captures) and `planning/reports/M1-IMPLEMENTATION-REPORT.md`
(review report). A01-A06, H01-H03 and H11 all pass on runtime evidence; 648
backend tests pass, including with no route to the Internet.
**Capabilities M1 delivered, which later milestones inherit rather than build:**
- offline first turn — the tokenizer table is vendored and digest-checked,
- no remote runtime assets — fonts self-hosted, CSP names no remote origin,
- loopback-bound storyteller in every run path, including the published Docker port,
- **working trusted-LAN inference, plain HTTP and HTTPS with a private CA**,
demonstrated against a second physical machine,
- a reproducible environment (`backend/requirements.lock`) and an offline-capable test suite.
---
# M2 — Remove Hosted, Cloud, Scripting, and Unneeded Deployment Surface
@@ -111,7 +136,15 @@ Remove or isolate as appropriate:
Add:
- explicit Ollama endpoint policy: same-host loopback default plus user-configured trusted-LAN inference,
- explicit Ollama endpoint policy. **Trusted-LAN inference already works as of
M1** — same-host loopback default, user-configured LAN endpoint, HTTP or
HTTPS with a privately issued certificate, verified against the machine's CA
store. M2's job is not to invent that capability but to **formalize and
narrow** it: decide and enforce what an endpoint may be in normal v1
configuration, reject or remove what it may not, and keep the endpoint's
configuration from affecting the storyteller's own loopback bind. Do not
regress the TLS behavior while narrowing the surface — the shared
verification context must follow any client the removal work rewrites,
- clear local-model connection diagnostics,
- migration/test instrumentation replacements for any tests that depended on JS hooks or removed hosted paths.
@@ -126,7 +159,7 @@ Add:
- local story play still works,
- existing tree/retry/memory/context behavior remains intact,
- application requires no cloud API keys,
- approved trusted-LAN Ollama endpoints work while arbitrary public/Internet provider endpoints are rejected or absent from normal production configuration,
- approved trusted-LAN Ollama endpoints work — including an HTTPS endpoint with a privately issued certificate, per A06 — while arbitrary public/Internet provider endpoints are rejected or absent from normal production configuration,
- removed provider/auth/analytics/scripting paths are no longer reachable from normal production configuration.
## Definition of Done