f2a12f9fed
v0.4 (Operator Tier — Cohort Dashboard + Auth + Postgres) milestone complete. Phases: ✓ P0 pre-execution (planning) → v0.1.6 ✓ P1 operator foundation (Postgres+auth+VC migration) → v0.1.7 ✓ P2 cohort dashboard + aggregation → v0.1.8 ✓ P3 final review + ship → v0.1.9 (= v0.4 milestone release) Requirements covered (8/8): REQ-MT-01 (Postgres store), REQ-MT-02 (aggregation pipeline), REQ-AUTH-01 (operator auth), REQ-DASH-01 (cohort dashboard), REQ-NFR-AUTH-01 (auth NFRs), REQ-NFR-MT-01 (Postgres-in-LXC), REQ-NFR-DASH-01 (k-anonymity ≥10), REQ-NFR-DASH-02 (freshness ≤24h) Grill MUSTs honored (6/6): G-008, G-011, G-027, G-031, G-038, G-041 Tests: 317 pytest pass, 36 skip (Postgres-requiring), 0 fail; 17/17 vitest pass Review: APPROVE_WITH_NOTES (6/6 personas, 0 P0, 8 P1+ carry-forward) Audit: HEALTHY (reconstruction PASS, 8/8 REQ, 6/6 grill) ---ci--- project: praxis phase: 3 milestone: v0.4 status: complete phase_role: final milestone_complete: true milestone_merged_to_main: true tag: v0.1.9 requirements: covered: [REQ-MT-01, REQ-MT-02, REQ-AUTH-01, REQ-DASH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01, REQ-NFR-DASH-01, REQ-NFR-DASH-02] partial: [] ---/ci---
29 lines
1.2 KiB
Bash
29 lines
1.2 KiB
Bash
# Praxis — Operator-tier secrets template (v0.4, TASK-05-02).
|
|
# Copy to .ciagent/.env.secrets and fill in real values.
|
|
# .env.secrets is gitignored (verified in .gitignore: .env.secrets).
|
|
# This file (.env.secrets.example) is committed as documentation.
|
|
|
|
# ─── Operator tier (v0.4) ───────────────────────────────────────────────────
|
|
# Postgres password. Generate: openssl rand -base64 32
|
|
PRAXIS_PG_PASSWORD=
|
|
|
|
# Full Postgres DSN. host=postgres is the docker-compose service DNS name.
|
|
# postgresql://praxis:${PRAXIS_PG_PASSWORD}@postgres:5432/praxis
|
|
PRAXIS_PG_DSN=
|
|
|
|
# Cookie signing secret (>=32 bytes). Generate: openssl rand -base64 48
|
|
PRAXIS_COOKIE_SECRET=
|
|
|
|
# Bootstrap operator credentials (scripts/create-operator.py).
|
|
PRAXIS_BOOTSTRAP_OPERATOR_USER=
|
|
PRAXIS_BOOTSTRAP_OPERATOR_PASS=
|
|
|
|
# VC issuer root key (nacl.SecretBox, 32 bytes). Generate:
|
|
# python3 -c "import nacl.utils; print(nacl.utils.random(32).hex())"
|
|
PRAXIS_VC_ISSUER_KEY=
|
|
|
|
# Issuer URL (public base for VC identifiers).
|
|
PRAXIS_ISSUER_URL=https://praxis.example/issuers/v0.4
|
|
|
|
# Cookie Secure flag — set false ONLY for the HTTP pilot (R-AUTH-01, G-031).
|
|
PRAXIS_COOKIE_SECURE=true |