Files
interactive-story/planning/DECISIONS/004-local-only-production.md
T

52 lines
2.2 KiB
Markdown

# ADR 004 — Local-Only Production Default
**Status:** Accepted; Phase 0B hardening requirements identified
## Decision
The production application will operate without Internet access for ordinary v1 story use.
## Context
The project requires control over story data, imported material, prompts, model outputs, memories, embeddings, and future generated media, with no unintended disclosure to outside services.
## Alternatives Considered
- hybrid local/cloud,
- optional cloud providers enabled by default,
- local-only default with future explicitly enabled extensions.
## Reason
Local-only operation best matches the privacy and control requirements. For this project, "local-only" means operation on user-controlled local infrastructure without requiring Internet or cloud services; it does not require every component to run on the same physical machine.
## Phase 0B Evidence
The selected AI-DnD base does **not** satisfy this requirement unchanged:
- `tiktoken` attempted a first-use download of its encoding data,
- the browser requested Google Fonts at runtime,
- hosted/cloud/auth/analytics/Postgres/provider paths remain present upstream,
- inherited endpoint guarding is oriented toward hosted deployment rather than enforcing the project's approved-local-infrastructure model boundary.
These are bounded production-hardening tasks rather than reasons to reject the fork.
## Consequences
The production application must avoid or remove:
- telemetry,
- analytics,
- cloud inference,
- hosted authentication/accounts,
- remote vector stores,
- automatic web retrieval,
- runtime CDN dependencies,
- remote fonts/assets,
- first-use runtime tokenizer/model-support downloads,
- arbitrary remote model-provider configuration in normal v1 UI.
Production packaging must contain all runtime assets required for ordinary story use after the user has installed the intended local Ollama models.
The storyteller application should bind to loopback by default. Ollama should default to same-host loopback but may be explicitly configured to an approved trusted-LAN endpoint for v1. This LAN inference path does not authorize LAN exposure of the storyteller UI/API. Arbitrary public/Internet inference endpoints remain prohibited in normal v1 configuration.