Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .dev.vars.example
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
# Local development placeholders only. Never commit real secret values.
# The CEO diagnostic helper does not load this file; it uses LIGHTHOUSE_REPORT_READ_TOKEN or a hidden prompt.
# A real REPORT_READ_TOKEN must be random, 32-128 URL-safe ASCII characters, and differ from ADMIN_TOKEN.
ADMIN_TOKEN=replace-with-local-admin-token
REPORT_READ_TOKEN=replace-with-a-distinct-local-report-read-token
CF_API_TOKEN=replace-with-local-cloudflare-token
TELEMETRY_RATE_LIMIT_SECRET=replace-with-a-long-random-local-secret
12 changes: 9 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@ Authority sources in descending order:
- Any Cloudflare Workers Builds configuration change requires explicit external-change approval and a read-only verification receipt before relying on it.
- When code depends on a D1 schema change, a migration requires explicit approval and remote verification before any Worker deployment.
- Do not print or commit secret values.
- The optional `REPORT_READ_TOKEN` is a secret-binding capability, not repository data. Do not generate, provision, inspect, remove, or rotate its production value without explicit secret-operation approval. It must be independently generated and cryptographically random, contain 32 to 128 URL-safe ASCII characters (`A-Z`, `a-z`, `0-9`, `_`, and `-`), and differ from `ADMIN_TOKEN`; an identical non-empty configuration intentionally fails every protected read and write closed.
- `npm run --silent diagnostic:ceo` is the sole canonical operator helper for a Lighthouse production CEO read. Its fixed, non-echoing behavior does not grant endpoint approval; every invocation still requires explicit production-read scope.
- Cross-repository contracts with Agent Smith, BUS Core, buscore-site, or the leads database must be documented when touched.

## Canonical Analytics Access and Diagnostics
Expand All @@ -45,16 +47,20 @@ For any Lighthouse alert, WATCH, analytics question, report failure, service-hea
1. Read `SOT.md`, then `OPERATIONS.md`, then the relevant `CHANGELOG.md` entry and contract/fixture.
2. Treat `OPERATIONS.md` as the canonical procedure for choosing a diagnostic surface and classifying its side effects. It is subordinate to `SOT.md` and cannot authorize behavior absent from the SOT.
3. Default to local zero-mutation diagnosis. Production, Cloudflare, Discord, GitHub, D1, or other external access requires explicit scope approval.
4. If the approved endpoint, credential source, account context, or tool access is missing, report `ACCESS_BLOCKED`. Do not improvise an endpoint, credential, direct SQL query, or alternate service.
5. Do not fan out across every endpoint. Start with supplied evidence; when live access is approved, use the stored-data `GET /report?view=ceo` diagnostic first and narrow from there.
4. If the approved endpoint, credential source, account context, deployed read-token capability, or tool access is missing, report `ACCESS_BLOCKED`. Do not improvise an endpoint, credential, direct SQL query, raw request command, or alternate service.
5. Do not fan out across every endpoint. Start with supplied evidence; when a production CEO read and its credential mechanism are explicitly approved, run exactly `npm run --silent diagnostic:ceo` and narrow from its validated stored-data result. Do not add arguments, substitute a URL/header, redirect its output to a file, or retry automatically.

Canonical Cloudflare identity: account `eb1a8dd5723031d94e57642e3eaaebda`, Worker `buscore-lighthouse`, primary D1 binding `DB` at database ID `e46f2daa-7e97-45a3-9bf0-49003a42850c` named `lighthouse`, and Production Custom Domain `lighthouse.buscore.ca`. An empty Worker Routes list is expected for this Custom Domain. If another account context lacks the Worker, correct the account rather than diagnosing an outage.

Operational constraints:

- `GET /report?view=source_health` is ingestion-integrity evidence, not service-probe truth.
- `WATCH` is not synonymous with outage; Agent Smith owns WATCH/ALERT/UNAVAILABLE wording, while Lighthouse owns facts and availability.
- The current `ADMIN_TOKEN` is broad: it protects report reads and the mutating `POST /campaign`, `POST /notes`, and `POST /report/snapshot` routes. Possession does not authorize writes.
- `ADMIN_TOKEN` remains broad: it protects report reads and is the only credential accepted by the mutating `POST /campaign`, `POST /notes`, and `POST /report/snapshot` routes. Optional `REPORT_READ_TOKEN`, when separately provisioned, is accepted only through `X-Report-Token` for `GET /report`; the admin credential remains a backward-compatible report fallback and the read credential never authorizes a write.
- The report-read split does not make report requests zero-mutation. Bare/fleet/site reports refresh stored traffic, and every report view—including CEO—can increment `metrics_daily.errors` when assembly fails. The helper is therefore Class 2 and approval-gated.
- Treat the helper's three static failure lines literally: `access blocked` is credential/access evidence, `report unavailable` is application evidence with a possible error-counter increment, and generic `diagnostic failed` is an unclassified transport/safety/contract failure. None authorizes a retry or alternate probe.
- The local 1.30.0 bundle contains no secret value, provisioning, deployment, or production verification. Do not claim production read-token availability until separately approved external activation and readback prove it.
- Agent Smith still carries `LIGHTHOUSE_ADMIN_TOKEN` for report reads and monthly snapshot writes. Do not remove or rotate that credential until an owner-approved snapshot-specific authorization split or write removal is implemented and verified in the owning repositories.
- Many GET/HEAD surfaces change evidence. Bare/fleet/site reports refresh stored traffic; report failures can increment errors; artifact HEAD records raw/HEAD truth; update, redirect, artifact, telemetry, and admin-write routes are not passive probes.
- Git publication is not zero-mutation. The 1.29.3 `main` merge proved that the former Workers Builds production command could promote active traffic independently of the checked-in gate. Durable readback on 2026-08-26 confirmed that both non-production and production publication now use `npx wrangler versions upload`. Pushes still create version or preview state, while active production promotion is reserved for the explicitly approved manual GitHub workflow. Any future external-setting drift reinstates `BLOCKED BEFORE MERGE`.
- Lighthouse, Agent Smith, BUS Core, buscore-site, and tgc-site are separate failure domains. Do not infer a cross-service outage from one unavailable layer.
Expand Down
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# Changelog

## [1.30.0] - 2026-08-26

- Added the optional `REPORT_READ_TOKEN` Worker secret and exact `X-Report-Token` authentication path for every `GET /report` view. The read secret must be independently generated, cryptographically random, contain 32 to 128 URL-safe ASCII characters, and differ from `ADMIN_TOKEN`; existing exact `X-Admin-Token`/`ADMIN_TOKEN` report access remains backward-compatible when the configuration is distinct.
- Kept `POST /campaign`, `POST /notes`, and `POST /report/snapshot` administrative-only. The report-read header is rejected by all three writes, missing/blank/malformed credentials fail closed, and the existing `401 {"ok":false,"error":"unauthorized"}` contract is preserved. An identical non-empty admin/read-secret configuration now fails closed for every protected read and write before database or deferred work instead of silently defeating least privilege.
- Added the fixed `npm run --silent diagnostic:ceo` operator helper for at most one non-echoing request to `https://lighthouse.buscore.ca/report?view=ceo`. It uses `X-Report-Token`, enforces the same credential format, accepts a hidden interactive credential or `LIGHTHOUSE_REPORT_READ_TOKEN` automation input, removes the automation variable from the helper process after capture, rejects arguments, URL overrides, redirects, retries, user-supplied credential/report files, and `.env` loading, and enforces a 15-second timeout plus 1 MiB response cap.
- Made the helper validate the existing strict CEO contract `1.1` before writing pretty-printed JSON plus one newline to stdout. Noninteractive failures use only three static categories: access blocked for missing/invalid credentials and `401`/`403`; report unavailable with an explicit possible-`metrics_daily.errors` warning for `503`; and a generic diagnostic failure for transport, safety, parse, schema, or output failures. Response bodies, numeric HTTP statuses, schema diagnostics, and credentials are suppressed. No browser CORS permission was added for `X-Report-Token`.
- Preserved report payloads, views, schemas, route status semantics, D1 schema and data semantics, retention, cron cadence, integrations, and metric definitions. Stored-data CEO/TGC/source-health/asset/monthly reads still skip the traffic refresh but can best-effort increment `metrics_daily.errors` if report assembly fails; bare/fleet/site reads retain their existing traffic refresh/upsert behavior.
- Documented a rollback-safe phased rollout: keep administrative report fallback intact, separately approve and verify distinct secret provisioning and Worker deployment, verify the read path with one explicitly approved CEO request, and treat a rollback as restoration of the prior admin-only read contract. No secret value, secret provisioning, endpoint request, deployment, migration, or production interaction is part of this local bundle.
- Recorded the remaining cross-service boundary: Agent Smith still holds `LIGHTHOUSE_ADMIN_TOKEN` because it both reads Lighthouse reports and performs the monthly `POST /report/snapshot` write. Full least privilege requires a later owner-approved snapshot-specific authorization split or removal of that write before removing the broad Smith credential or rotating `ADMIN_TOKEN`.

## [1.29.4] - 2026-08-26

- Recorded the owner-approved read-only Cloudflare audit showing that Workers Builds build `793715ef-6123-4d98-a4a7-797634d07812`, sourced from merged `main` commit `59231d09084d0fa4db71012b6f29550886c5b605`, automatically ran `npx wrangler deploy` and promoted Worker version `ba611ac1-653d-47a2-a465-a85f4124b6b6` to 100% of production traffic.
Expand Down
Loading