80 lines
3.7 KiB
Markdown
80 lines
3.7 KiB
Markdown
# ADR 004 — Local-Only Production Default
|
|
|
|
**Status:** Accepted; Phase 0B hardening requirements identified; testing consequence strengthened after M1
|
|
|
|
## Decision
|
|
|
|
The production application will operate without Internet access for ordinary v1 story use.
|
|
|
|
## Context
|
|
|
|
The project requires control over story data, imported material, prompts, model outputs, memories, embeddings, and future generated media, with no unintended disclosure to outside services.
|
|
|
|
## Alternatives Considered
|
|
|
|
- hybrid local/cloud,
|
|
- optional cloud providers enabled by default,
|
|
- local-only default with future explicitly enabled extensions.
|
|
|
|
## Reason
|
|
|
|
Local-only operation best matches the privacy and control requirements. For this project, "local-only" means operation on user-controlled local infrastructure without requiring Internet or cloud services; it does not require every component to run on the same physical machine.
|
|
|
|
## Phase 0B Evidence
|
|
|
|
The selected AI-DnD base does **not** satisfy this requirement unchanged:
|
|
|
|
- `tiktoken` attempted a first-use download of its encoding data,
|
|
- the browser requested Google Fonts at runtime,
|
|
- hosted/cloud/auth/analytics/Postgres/provider paths remain present upstream,
|
|
- inherited endpoint guarding is oriented toward hosted deployment rather than enforcing the project's approved-local-infrastructure model boundary.
|
|
|
|
These are bounded production-hardening tasks rather than reasons to reject the fork.
|
|
|
|
## Testing Consequence
|
|
|
|
Strengthened after M1, which confirmed the failure mode this rule exists to catch.
|
|
|
|
**Offline behavior must be tested with a fresh cache/data state on a machine
|
|
with no route to the Internet.** Both inherited violations above were *first-use*
|
|
downloads: `tiktoken` caches its encoding to a temp directory, and the browser
|
|
caches Google's fonts. On any machine that had been online once, both were
|
|
invisible — the application appeared to work offline while depending on an
|
|
artifact an earlier online run had left behind. Neither was findable by static
|
|
analysis; each took an actually isolated run to surface.
|
|
|
|
Therefore an offline claim is only evidence when the test:
|
|
|
|
- runs on a network with **no route out and no external DNS**, verified before
|
|
the test rather than assumed,
|
|
- starts from a **fresh application data directory and a fresh cache**, so
|
|
nothing warmed by a previous run is available,
|
|
- exercises the **first** story turn, which is when a first-use download fires,
|
|
- observes actual network destinations rather than only the absence of an error.
|
|
|
|
## Consequences
|
|
|
|
The production application must avoid or remove:
|
|
|
|
- telemetry,
|
|
- analytics,
|
|
- cloud inference,
|
|
- hosted authentication/accounts,
|
|
- remote vector stores,
|
|
- automatic web retrieval,
|
|
- runtime CDN dependencies,
|
|
- remote fonts/assets,
|
|
- first-use runtime tokenizer/model-support downloads,
|
|
- arbitrary remote model-provider configuration in normal v1 UI.
|
|
|
|
Production packaging must contain all runtime assets required for ordinary story use after the user has installed the intended local Ollama models.
|
|
|
|
Vendored runtime artifacts should be **integrity-verifiable where practical**: a
|
|
recorded source and a digest the application checks when it loads them, rather
|
|
than an opaque blob nobody can re-derive. A substituted or truncated artifact
|
|
should then fail loudly instead of silently changing behavior — a corrupted
|
|
tokenizer table, for instance, would quietly change every token count the
|
|
context budget is computed from.
|
|
|
|
The storyteller application should bind to loopback by default. Ollama should default to same-host loopback but may be explicitly configured to an approved trusted-LAN endpoint for v1. This LAN inference path does not authorize LAN exposure of the storyteller UI/API. Arbitrary public/Internet inference endpoints remain prohibited in normal v1 configuration.
|