# ADR 004 — Local-Only Production Default **Status:** Accepted; Phase 0B hardening requirements identified; testing consequence strengthened after M1 ## Decision The production application will operate without Internet access for ordinary v1 story use. ## Context The project requires control over story data, imported material, prompts, model outputs, memories, embeddings, and future generated media, with no unintended disclosure to outside services. ## Alternatives Considered - hybrid local/cloud, - optional cloud providers enabled by default, - local-only default with future explicitly enabled extensions. ## Reason Local-only operation best matches the privacy and control requirements. For this project, "local-only" means operation on user-controlled local infrastructure without requiring Internet or cloud services; it does not require every component to run on the same physical machine. ## Phase 0B Evidence The selected AI-DnD base does **not** satisfy this requirement unchanged: - `tiktoken` attempted a first-use download of its encoding data, - the browser requested Google Fonts at runtime, - hosted/cloud/auth/analytics/Postgres/provider paths remain present upstream, - inherited endpoint guarding is oriented toward hosted deployment rather than enforcing the project's approved-local-infrastructure model boundary. These are bounded production-hardening tasks rather than reasons to reject the fork. ## Testing Consequence Strengthened after M1, which confirmed the failure mode this rule exists to catch. **Offline behavior must be tested with a fresh cache/data state on a machine with no route to the Internet.** Both inherited violations above were *first-use* downloads: `tiktoken` caches its encoding to a temp directory, and the browser caches Google's fonts. On any machine that had been online once, both were invisible — the application appeared to work offline while depending on an artifact an earlier online run had left behind. Neither was findable by static analysis; each took an actually isolated run to surface. Therefore an offline claim is only evidence when the test: - runs on a network with **no route out and no external DNS**, verified before the test rather than assumed, - starts from a **fresh application data directory and a fresh cache**, so nothing warmed by a previous run is available, - exercises the **first** story turn, which is when a first-use download fires, - observes actual network destinations rather than only the absence of an error. ## Consequences The production application must avoid or remove: - telemetry, - analytics, - cloud inference, - hosted authentication/accounts, - remote vector stores, - automatic web retrieval, - runtime CDN dependencies, - remote fonts/assets, - first-use runtime tokenizer/model-support downloads, - arbitrary remote model-provider configuration in normal v1 UI. Production packaging must contain all runtime assets required for ordinary story use after the user has installed the intended local Ollama models. Vendored runtime artifacts should be **integrity-verifiable where practical**: a recorded source and a digest the application checks when it loads them, rather than an opaque blob nobody can re-derive. A substituted or truncated artifact should then fail loudly instead of silently changing behavior — a corrupted tokenizer table, for instance, would quietly change every token count the context budget is computed from. The storyteller application should bind to loopback by default. Ollama should default to same-host loopback but may be explicitly configured to an approved trusted-LAN endpoint for v1. This LAN inference path does not authorize LAN exposure of the storyteller UI/API. Arbitrary public/Internet inference endpoints remain prohibited in normal v1 configuration.