Commit graph

18 commits

Author SHA1 Message Date
a6e37ccd77 slides(tappaas): swap the cable-pull for a live node-failure demo
All checks were successful
Build docs site / build (push) Successful in 45s
Build slides / build (push) Successful in 1m4s
The cable-pull needs the basement, so it becomes the recorded version and the
live demo is an HA failover instead: tappaas1 carries vm:110 (firewall),
vm:130 (mothership) and vm:140 (identity), all fenced and watchdog armed.
Verified against ha-manager on the cluster.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 15:04:00 +02:00
f4f9b2a81b slides(tappaas): name all three repositories on the receipts slide
All checks were successful
Build docs site / build (push) Successful in 49s
Build slides / build (push) Successful in 1m9s
Was "two public repositories" — the Documentation repo (tappaas.org) was
missing. All three are now listed by their Codeberg path.

"You can check my homework" folds into the lead-in rather than standing as its
own line: with the nine-row table above it, the extra line pushed the last
bullet off the slide.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 13:20:45 +02:00
87650dac86 slides(tappaas): photograph slide, and publish deck images
All checks were successful
Build docs site / build (push) Successful in 44s
Build slides / build (push) Successful in 1m4s
Adds a slide after the hardware diagram showing the two racks side by side —
the MakerFLOSS rack at Orange Makerspace and the one at home — to make the
point that the module contract is what lets those two rooms run the same
system.

build-slides.sh now copies image files from slides/ into the output tree at
the same relative path. Marp keeps relative image URLs, so without this the
images would 404 on the published site. Guarded against the local build,
where OUTPUT_DIR is the source directory and the copy would be a no-op onto
itself. This is the first deck in the repo with images; the convention is
documented in docs/services/slides.md.

Photos resampled to 1200px on the long edge (~300 KB each) from the 3072x4080
originals.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 18:42:11 +02:00
66b20ffc06 slides(tappaas): the predecessor ran five years; 2-3 artefacts before coding
All checks were successful
Build docs site / build (push) Successful in 43s
Build slides / build (push) Successful in 1m5s
Last TODO closed: the pre-TAPPaaS setup ran five years uninterrupted and never
had a name.

Guardrail 1 now says 2-3 artefacts rather than three — the Issue is always
there, the ADR and the plan only when the change warrants them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 18:19:58 +02:00
2e16c4a16b slides(tappaas): restore the commit graph, and small corrections
All checks were successful
Build docs site / build (push) Successful in 44s
Build slides / build (push) Successful in 1m4s
The graph replaces the prose slide that stood in for it — annotated with the
vacation that explains the Sept/Oct 2025 flat spot, and regenerated so August
runs to the 25th (126). Keeps the one line worth saving from the slide it
replaces: the services stayed up through the flat bits.

Also: "every commit" rather than "every line" on the never-push guardrail;
Home Assistant as the suggested first service; evaluation tier calls for two
disks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 18:14:10 +02:00
e1d69309b8 slides(tappaas): correct the rewrite history, note the other instances
All checks were successful
Build docs site / build (push) Successful in 46s
Build slides / build (push) Successful in 1m6s
The ADR-007 rewrite was the move from a flat pile of sequenced scripts to the
manager/controller paradigm — not the dependsOn change. That was an earlier
and separate rewrite, ADR-003: a plain install.sh per module replaced by
dependsOn/provides contracts the platform resolves into an order.

Also: a closing line on the hardware slide that this is one of five known
instances, and the September 2025 gap now answers itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 18:02:55 +02:00
d08e8ad743 slides(tappaas): add the process and test guardrails
All checks were successful
Build docs site / build (push) Successful in 45s
Build slides / build (push) Successful in 1m7s
Guardrail 1 is now the process that runs before the AI is allowed to type:
an Issue with a defined problem and proposed fix, an ADR reviewed by at least
two people for anything non-obvious, then a design and implementation plan
that says how it will be tested. The eight agent roles move here — they are
what "then the AI takes over" means.

Guardrail 5 replaces "I stayed the reviewer" with the test regime: quick test
on every change, deep test via test-module.sh --deep, test plan authored in
the ADR, and a full regression across every module after implementation.

Test figures reconciled to one scope across the deck (both repos): 195 suites,
34,490 lines, 27% of source.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 17:50:52 +02:00
a133efe3bf slides(tappaas): recast The Bad around amortisation, not personal cost
All checks were successful
Build docs site / build (push) Successful in 46s
Build slides / build (push) Successful in 1m11s
Drop the commit-graph slide and the two cost slides. Replace all three with
one argument: the platform is expensive to build, but that cost is fixed and
per-site cost is near zero — so it only makes sense shared across many home
labs and SMB sites.

"What I got wrong" becomes "Did I get it all right?" — no, two large rewrites
(ADR-007 numbering to dependsOn, ADR-014 zone tiers to checked state) plus a
predecessor system run for years before this one.

36 slides; the agenda line and the quiet-months slide no longer refer to the
graph that left.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 17:44:40 +02:00
485f53f48d slides(tappaas): real hardware/VM diagrams, and count the Community modules
All checks were successful
Build docs site / build (push) Successful in 49s
Build slides / build (push) Successful in 1m8s
Split the single architecture slide into two: the iron (three nodes, switch,
AP, modem) and the software (foundation band with the AI and productivity
stacks above it). Both read off the running cluster via tappaas-cicd, not
from docs — CPU, RAM, pool topology, link speeds and switch ports are live
values.

The VM layer-cake is inline SVG rather than mermaid: mermaid ignores
`direction LR` inside a subgraph that has a cross-boundary edge, so the bands
came out as a 629x1258 column.

Module slide now counts all three sources — 8 foundation + 12 apps +
21 Community = 41 — and slide 3 is recomputed for today.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 17:33:03 +02:00
Lars Rossen
aab16d8189 slides(tappaas): the session builds the merged podman module
All checks were successful
Build docs site / build (push) Successful in 48s
Build slides / build (push) Successful in 1m8s
Podman and Portainer are one module now — engine plus GUI — so the deck follows:
podman.json, vmid 812, both sockets on the update.sh slide, and the console at
https://lab1.makerfloss.eu because --proxyDomain makes the module the
environment's gateway rather than podman.lab1.makerfloss.eu.

All commands verified against a live install on lab1.
2026-08-25 09:35:35 +02:00
Lars Rossen
2722c89dcb slides(tappaas): correct the demo commands against a real run
All checks were successful
Build docs site / build (push) Successful in 52s
Build slides / build (push) Successful in 1m14s
Installed portainer into lab1 on the live system; several slide commands were
wrong. The verb is 'network-manager add', not 'network-manager zone add', and
there is no 'srv' zone here — the live service zone is 'makerfloss'. Status
verbs need the effective name 'portainer-lab1', while 'module add' takes the
base name. The published host is portainer-lab1.lab1.makerfloss.eu, not
portainer.lab1.makerfloss.eu. Adds the repository registration to Demo 2, which
the deck had never shown.
2026-08-24 21:03:01 +02:00
ef00334f94 slides(tappaas): write the Sommerhack 2026 'one year in' deck
All checks were successful
Build docs site / build (push) Successful in 49s
Build slides / build (push) Successful in 1m10s
Talk announced at pretalx.varum.dk/sommerhack-2026/talk/WD8EVP/ —
27 August, Taler Teltet, 60 minutes.

Figures come from the repo rather than the abstract: commit counts and the
per-month graph from git log, source counts from src/STATISTICS.md as
regenerated 2026-08-23. Twelve TODO markers remain for the personal
material (costs, the autumn 2025 dip, war stories).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 12:58:55 +02:00
Lars Rossen
87d6d83ff3 slides(tappaas): the session builds the portainer module
All checks were successful
Build slides / build (push) Successful in 1m22s
Build docs site / build (push) Successful in 1m26s
Retargets the deck from podman to portainer: the contract, the three script
slides, both demo slides and the repo-location slide. Demo 3 is now an actual
single sign-on — 'no login form, you are already you' — because Portainer is an
OIDC client and Cockpit never could be.

The test.sh slide keeps the check worth stealing: /api/settings/public reporting
method 3, which catches identity silently falling back to local accounts.
2026-08-23 09:46:59 +02:00
Lars Rossen
33e783efb5 slides(tappaas): a slide per lifecycle script; correct the identity claim
All checks were successful
Build docs site / build (push) Successful in 48s
Build slides / build (push) Successful in 1m6s
install.sh, update.sh and test.sh get one slide each, with the real content of
each — including why a 401 from Cockpit is a passing test and why test.sh uses
curl -s rather than --fail.

Corrects the identity story: Cockpit is not an OIDC client and cannot be
configured into one, so the contract shows identity:accessControl and the demo
slide is honest that Authentik gates the URL while Cockpit still asks for a
local account. Full analysis in the module's DESIGN.md.
2026-08-22 20:42:04 +02:00
Lars Rossen
f02c4f878f slides(tappaas): participants land in the devops group
All checks were successful
Build docs site / build (push) Successful in 46s
Build slides / build (push) Successful in 1m5s
2026-08-22 18:38:19 +02:00
Lars Rossen
834bd406f2 slides(tappaas): session details, dev-topology slide, identity login
All checks were successful
Build docs site / build (push) Successful in 48s
Build slides / build (push) Successful in 1m6s
Date 24 August; the demo environment is lab1 (zone lab1, lab1.makerfloss.eu
outside / lab1.internal inside). Adds the upstream 'developing TAPPaaS modules'
topology from tappaas.org ahead of our own repo picture, which now carries
forgejo.makerfloss.eu and highlights that this site tracks main, not stable.
Drops the manager-verbs slide; the demo slides carry the verbs where they are
actually used, with network/environment/module status commands.

Cockpit now logs in via identity:identity rather than a local PAM password, and
identity hand-out uses 'authentik-manager user-recovery-link' so no password is
ever read aloud. NOTE: podman.json in Community does not yet declare
identity:identity — the module needs that change before the session.
2026-08-22 18:03:06 +02:00
Lars Rossen
f1c1c79b63 slides(tappaas): write the OrangeMaker podman session deck
All checks were successful
Build docs site / build (push) Successful in 44s
Build slides / build (push) Successful in 1m2s
Sixteen slides built around the live demo: two orientation diagrams (site
shape with environments/zones/satellite, and the pull-based GitOps repo
topology), a condensed module anatomy anchored on the real podman.json from
Community/src/larsrossen/containers/podman, the three demo beats (test
environment, module add, prove it), and the identity hand-out.

Mermaid subgraph titles collide with the node row under flowchart TB, so both
diagrams use LR; _class directives repeat 'invert' because a local _class
replaces the deck-level one rather than adding to it.
2026-08-22 16:47:53 +02:00
Lars Rossen
91f53f1f62 slides: frame a 'How to implement a TAPPaaS module' deck
All checks were successful
Build docs site / build (push) Successful in 49s
Build slides / build (push) Successful in 1m16s
Adds a second Marp source root. Decks under slides/ build to an output path
mirroring their repo path, so slides/TAPPaaS/HOW-TO/NewModule/index.md is
served at slides.makerfloss.eu/TAPPaaS/HOW-TO/NewModule/. Decks in
docs/presentations/ keep their flat URLs.

The deck itself is a frame: structure and headings from the real
src/apps/00-Template anatomy, content still to be written. Unfinished spots
are written as inline `TODO: ...` and rendered in red so a half-finished
deck cannot be presented by accident.

Also fixes the Docker fallback, which could not write to a mktemp directory
on macOS (not shared with Docker Desktop) and must not be passed --user.
2026-08-22 16:01:50 +02:00