Author SHA1 Message Date
Jens 0458403e67 Merge pull request 'ci: retire legacy unraid deploy runner workflow' (#11) from codex/runnerless-ci-v1-8-mobilityops into master
Managed validation / full (push) Successful in 4s
2026-09-14 13:18:21 +00:00
ITWorx AppOps Automation 885dff413c ci: retire legacy unraid deploy runner workflow
MobilityOps acceptance / acceptance (pull_request) Successful in 33s
2026-09-14 14:26:23 +02:00
Jens f8a30c0f5c Merge pull request 'hygiene: prepare public release' (#10) from chore/public-release-hygiene-20260902 into master
Unraid autoredeploy / Deploy mobilityops (push) Failing after 3s
2026-09-03 00:58:52 +00:00
NuklearRabbit 2d92084489 test: stabilize browser assertions under CI load
MobilityOps acceptance / acceptance (pull_request) Successful in 8m45s
2026-09-03 01:13:21 +02:00
NuklearRabbit a42012d9c0 hygiene: prepare MobilityOps for public release
MobilityOps acceptance / acceptance (pull_request) Failing after 10m16s
2026-09-02 23:44:03 +02:00
Jens 0de9177e7c Merge pull request 'Use Gitea-compatible canary evidence upload' (#3) from codex/resolve-projectbrain-findings-20260828 into master
Unraid autoredeploy / Deploy mobilityops (push) Failing after 1m11s
Reviewed-on: #3
2026-09-01 20:09:22 +00:00
NuklearRabbit 48147465b5 security: refresh Alpine runtime packages
MobilityOps acceptance / acceptance (pull_request) Successful in 6m28s
2026-09-01 21:19:48 +02:00
NuklearRabbit 92bdfb421b Merge remote-tracking branch 'origin/master' into codex/resolve-projectbrain-findings-20260828
MobilityOps acceptance / acceptance (pull_request) Failing after 2m42s
# Conflicts:
#	.dockerignore
#	.gitea/workflows/ci.yml
#	.gitea/workflows/live-canary.yml
#	.gitea/workflows/release.yml
2026-09-01 20:42:10 +02:00
Jens 4257fea9d6 Merge pull request 'chore: sanitize MobilityOps operational evidence and public boundary' (#8) from chatgpt/repo-hygiene-mobilityops into master
Unraid autoredeploy / Deploy mobilityops (push) Failing after 1h58m50s
Reviewed-on: #8
2026-09-01 14:29:25 +02:00
NuklearRabbit 014caba7d5 test: target data-quality reference in page header
MobilityOps acceptance / acceptance (pull_request) Successful in 5m54s
2026-09-01 01:44:50 +02:00
Jens e531740bb9 docs: record MobilityOps history blocker
MobilityOps acceptance / acceptance (pull_request) Failing after 4m13s
2026-08-31 09:26:15 +02:00
Jens 921c6878a6 repo: prevent generated deployment evidence returning
MobilityOps acceptance / acceptance (pull_request) Canceled after 0s
2026-08-31 09:25:48 +02:00
Jens cd55d6854f build: exclude AI, credential and runtime state
MobilityOps acceptance / acceptance (pull_request) Failing after 4m36s
2026-08-31 07:56:09 +02:00
Jens 70e2648b03 docs: add fleet privacy contribution guidance 2026-08-31 07:53:43 +02:00
Jens f8eff37982 docs: record MobilityOps history sanitation blockers 2026-08-31 07:53:33 +02:00
Jens 25cc7a1b0d chore: remove generated agent handoff entrypoint 2026-08-31 07:53:12 +02:00
Jens 6fd1d5e5e9 chore: remove generated build-agent prompt 2026-08-31 07:53:02 +02:00
Jens 54b7719759 chore: remove generated repository file index 2026-08-31 07:52:54 +02:00
Jens a19613d5e9 chore: remove project-local Claude instructions 2026-08-31 07:52:44 +02:00
Jens b62ecf66d8 chore: remove generated project-state chronology 2026-08-31 07:52:35 +02:00
Jens 97b8cd1c8c docs: generalize demo deployment instructions 2026-08-31 07:51:49 +02:00
Jens 50f9bb471a docs: replace private deployment topology with configuration 2026-08-31 07:51:06 +02:00
Jens 719b710926 chore: exclude internal evidence from source archives 2026-08-31 07:50:44 +02:00
Jens 441b3624e1 chore: block generated evidence and local private state 2026-08-31 07:50:30 +02:00
ChatGPT MCP ccae0538d7 chore: remove generated design-validation screenshot baselines 2026-08-31 05:49:42 +00:00
ChatGPT MCP 7d935c5a7d chore: remove generated deployment and audit evidence 2026-08-31 05:49:16 +00:00
Jens 51c3c90fa1 ci: keep workflow-only pull requests lightweight (#6)
Full acceptance remains mandatory for product and test changes; workflow-only pull requests run checkout and verified-secret scanning without rebuilding every stack.
2026-08-29 09:09:14 +02:00
NuklearRabbit d6a566e1a1 ci: keep workflow-only pull requests lightweight
MobilityOps acceptance / acceptance (pull_request) Successful in 26s
2026-08-29 09:07:38 +02:00
NuklearRabbit 4b727a109f ci: avoid duplicate post-merge acceptance
MobilityOps acceptance / acceptance (pull_request) Canceled after 2m0s
2026-08-29 09:04:25 +02:00
Jens 1bf72c39e3 ci: streamline MobilityOps validation (#5)
MobilityOps acceptance / acceptance (push) Failing after 2s
One bounded PR acceptance job, lightweight hourly probe, daily browser canary, deterministic isolated demo resets, and pinned weekly/release scans.
2026-08-29 09:03:13 +02:00
NuklearRabbit 55e8ebd81e fix(ci): isolate demo resets and keep acceptance deterministic
MobilityOps acceptance / acceptance (pull_request) Successful in 9m46s
2026-08-29 08:48:06 +02:00
NuklearRabbit b2bdb78baa fix(ci): reach DIND services over the compose network
MobilityOps acceptance / acceptance (pull_request) Failing after 6m58s
2026-08-29 08:36:14 +02:00
NuklearRabbit fe92a7f491 ci: consolidate validation and split lightweight probes
MobilityOps acceptance / acceptance (pull_request) Failing after 4m47s
2026-08-29 06:59:02 +02:00
NuklearRabbit 19df5f7508 ci: keep one required pull-request gate
MobilityOps acceptance / backend (pull_request) Failing after 2m18s
MobilityOps acceptance / frontend (pull_request) Successful in 29s
MobilityOps acceptance / e2e (pull_request) Skipped
2026-08-29 05:38:23 +02:00
NuklearRabbit e8eed3e641 fix(ci): package contract fixtures and recover deploy chunk races
MobilityOps acceptance / backend (pull_request) Failing after 2m29s
MobilityOps acceptance / frontend (pull_request) Successful in 1m10s
MobilityOps acceptance / e2e (pull_request) Skipped
Managed validation / full (pull_request) Successful in 3s
2026-08-29 00:40:51 +02:00
NuklearRabbit 2918608240 fix(ci): isolate contract and image scans from host paths
MobilityOps acceptance / backend (pull_request) Failing after 2m20s
MobilityOps acceptance / frontend (pull_request) Successful in 1m24s
MobilityOps acceptance / e2e (pull_request) Skipped
Managed validation / full (pull_request) Canceled after 0s
2026-08-29 00:27:17 +02:00
NuklearRabbit a99aed9a5f perf(ci): deduplicate branch validation
MobilityOps acceptance / backend (pull_request) Canceled after 0s
MobilityOps acceptance / frontend (pull_request) Canceled after 0s
MobilityOps acceptance / e2e (pull_request) Canceled after 0s
Managed validation / full (pull_request) Canceled after 0s
2026-08-28 23:59:30 +02:00
NuklearRabbit 00e8ec001b fix(ci): run secret scan inside isolated workspace
Managed validation / full (pull_request) Canceled after 0s
MobilityOps acceptance / frontend (pull_request) Successful in 1m14s
MobilityOps acceptance / backend (pull_request) Failing after 4m7s
MobilityOps acceptance / e2e (pull_request) Skipped
2026-08-28 23:57:46 +02:00
NuklearRabbit d20ff7a243 fix(ci): upgrade pinned Trivy action
Managed validation / full (pull_request) Canceled after 0s
MobilityOps acceptance / backend (pull_request) Failing after 32s
MobilityOps acceptance / frontend (pull_request) Successful in 1m1s
MobilityOps acceptance / e2e (pull_request) Skipped
2026-08-28 23:42:59 +02:00
NuklearRabbit bc0951115b fix(ci): use Gitea-compatible canary artifacts
Managed validation / full (pull_request) Successful in 10s
MobilityOps acceptance / frontend (pull_request) Successful in 1m17s
MobilityOps acceptance / backend (pull_request) Failing after 1m18s
MobilityOps acceptance / e2e (pull_request) Skipped
2026-08-28 23:11:09 +02:00
Jens 51d488a634 Merge pull request '[skip ci] Centralize Gitea Actions runner' (#2) from codex/centralize-gitea-runner into master 2026-08-27 23:51:14 +02:00
NuklearRabbit da2f0956c9 chore(actions): use central Unraid runner [skip ci] 2026-08-27 23:42:54 +02:00
Jens 13f8db7573 ci: align managed validation contract [skip ci] 2026-08-27 07:40:50 +02:00
Jens e6ec89658e ci: add managed validation contract [skip ci] 2026-08-27 06:28:27 +02:00
NuklearRabbit 9d71555135 ci: add scoped Unraid autoredeploy
MobilityOps acceptance / backend (push) Failing after 33s
MobilityOps acceptance / frontend (push) Successful in 45s
MobilityOps acceptance / e2e (push) Skipped
2026-08-26 02:50:54 +02:00
NuklearRabbit 81de78bd8b M56: make RAGcore sync fail closed
MobilityOps acceptance / backend (push) Failing after 19s
MobilityOps acceptance / frontend (push) Successful in 26s
MobilityOps acceptance / e2e (push) Skipped
2026-08-24 03:58:57 +02:00
NuklearRabbit 444e61253b M55: restore private RAGcore routing
MobilityOps acceptance / backend (push) Failing after 18s
MobilityOps acceptance / frontend (push) Successful in 27s
MobilityOps acceptance / e2e (push) Skipped
2026-08-24 03:45:09 +02:00
NuklearRabbit 81e3fd63bd M54: harden operations and demo resilience
MobilityOps acceptance / backend (push) Failing after 19s
MobilityOps acceptance / frontend (push) Successful in 25s
MobilityOps acceptance / e2e (push) Skipped
2026-08-24 03:31:03 +02:00
NuklearRabbit b0706989db M53: record OneDrive production acceptance
MobilityOps acceptance / backend (push) Failing after 33s
MobilityOps acceptance / frontend (push) Successful in 26s
MobilityOps acceptance / e2e (push) Skipped
2026-08-22 00:00:45 +02:00
NuklearRabbit 2036e8b4ec M52: activate verified OneDrive backups
MobilityOps acceptance / backend (push) Failing after 18s
MobilityOps acceptance / frontend (push) Successful in 26s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 23:57:47 +02:00
NuklearRabbit 51b0ade7e7 M51: record zero-error rollout acceptance
MobilityOps acceptance / backend (push) Failing after 19s
MobilityOps acceptance / frontend (push) Successful in 30s
MobilityOps acceptance / e2e (push) Skipped
MobilityOps release evidence / release-evidence (push) Failing after 2m18s
2026-08-21 22:33:41 +02:00
NuklearRabbit cea0825d60 M50: preserve rollout API compatibility alias
MobilityOps acceptance / backend (push) Failing after 17s
MobilityOps acceptance / frontend (push) Successful in 29s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 22:29:55 +02:00
NuklearRabbit dd3acd872c M49: record resilience production acceptance
MobilityOps acceptance / backend (push) Failing after 20s
MobilityOps acceptance / frontend (push) Successful in 26s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 22:25:48 +02:00
NuklearRabbit 00191e9b54 M48: harden demo operations and offsite recovery
MobilityOps acceptance / backend (push) Failing after 20s
MobilityOps acceptance / frontend (push) Successful in 28s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 22:17:49 +02:00
NuklearRabbit a24098c583 M47: record final production acceptance
MobilityOps acceptance / backend (push) Failing after 15s
MobilityOps acceptance / frontend (push) Successful in 29s
MobilityOps acceptance / e2e (push) Skipped
MobilityOps release evidence / release-evidence (push) Failing after 1m10s
2026-08-21 18:52:23 +02:00
NuklearRabbit 95c91797fa M46: refresh web runtime base
MobilityOps acceptance / backend (push) Failing after 18s
MobilityOps acceptance / frontend (push) Successful in 27s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 18:46:10 +02:00
NuklearRabbit ec02aca0fd M45: authenticate Prometheus scraping
MobilityOps acceptance / backend (push) Failing after 17s
MobilityOps acceptance / frontend (push) Successful in 25s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 18:33:23 +02:00
NuklearRabbit acd8b82b09 M44: harden release integrity and assurance
MobilityOps acceptance / backend (push) Failing after 20s
MobilityOps acceptance / frontend (push) Successful in 26s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 18:32:02 +02:00
NuklearRabbit 9e4fca5708 M43: record production deployment evidence
MobilityOps acceptance / backend (push) Failing after 15s
MobilityOps acceptance / frontend (push) Successful in 25s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 17:25:04 +02:00
NuklearRabbit 0045778dbb M42: calibrate grounded RAGcore fallback
MobilityOps acceptance / backend (push) Failing after 17s
MobilityOps acceptance / frontend (push) Successful in 29s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 17:22:17 +02:00
NuklearRabbit 24dcb3494c M41: harden trust boundaries and delivery
MobilityOps acceptance / backend (push) Failing after 47s
MobilityOps acceptance / frontend (push) Successful in 29s
MobilityOps acceptance / e2e (push) Skipped
2026-08-21 17:06:59 +02:00
JensandClaude Fable 5 a830e8a2d0 ci(security): pin trivy-action to an existing tag (v0.30.0) so the gate can resolve on Gitea Actions
MobilityOps acceptance / backend (push) Failing after 33s
MobilityOps acceptance / frontend (push) Successful in 33s
MobilityOps acceptance / e2e (push) Skipped
The first real platform runs (2026-08-17, new instance runner) failed at
'Unable to resolve 0.30.0: reference not found' - the tag exists only as v0.30.0.
Where present, the trufflehog GitHub Action (which fails under the act runner) is
replaced by the pinned trufflehog binary in filesystem mode next to gitleaks.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 14:13:18 +02:00
NuklearRabbit ca66083c8b M40: record hardening deployment evidence
MobilityOps acceptance / backend (push) Failing after 14s
MobilityOps acceptance / frontend (push) Successful in 37s
MobilityOps acceptance / e2e (push) Skipped
2026-08-17 03:31:10 +02:00
NuklearRabbit ae39a8947f M39: harden application and acceptance gates
MobilityOps acceptance / backend (push) Failing after 45s
MobilityOps acceptance / frontend (push) Successful in 32s
MobilityOps acceptance / e2e (push) Skipped
2026-08-17 03:17:44 +02:00
NuklearRabbit a9f48d6880 fix(security): add secret-scan step to backend CI job
Backend job had static checks (ruff/mypy) and a dependency-vulnerability
gate but no secret scan; frontend had a dependency audit but no secret
scan either. Adds trufflehog once, on the backend job's full checkout,
covering the whole repository - the last gap for this repo to count as
fully-authored.
2026-08-16 14:54:44 +02:00
NuklearRabbit 6859249570 fix(security): add backend dependency vulnerability gate to CI
Backend CI had ruff/mypy static checks and a real pip-audit-equivalent
was missing; frontend already had npm audit, so backend was the only
side of this repo without any dependency-vulnerability gate (partial
coverage). Adds trivy-action fs scoped to backend/, HIGH/CRITICAL only,
consistent with this security programme's gate convention elsewhere.
Verified clean (0 HIGH/CRITICAL) against backend/pyproject.toml before
wiring in, so the gate does not immediately fail CI.
2026-08-16 04:41:07 +02:00
NuklearRabbit 1ca70187a2 M38: record production acceptance evidence
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 23:29:10 +02:00
NuklearRabbit 26819354ee M37: complete production acceptance hardening
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 23:19:26 +02:00
NuklearRabbit 9dfbd7c4bf M36: deepen operational and mobile UX 2026-08-10 22:53:45 +02:00
NuklearRabbit 809ba0ddcc M35: harden the shared public demo 2026-08-10 22:32:58 +02:00
NuklearRabbit c7492bf6ad M34: enforce domain integrity in PostgreSQL 2026-08-10 22:28:38 +02:00
NuklearRabbit 82a933f6cd M33: enforce booking readiness workflow 2026-08-10 22:23:11 +02:00
NuklearRabbit be33b46228 M32: clarify deployment source evidence
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 21:19:27 +02:00
NuklearRabbit b44915ff35 M32: record production integration acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 21:18:50 +02:00
NuklearRabbit eecfcb4b79 M31: cover both knowledge provider title contracts
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 21:10:48 +02:00
NuklearRabbit cb7edb0b84 M31: align RAG verification with provider contract
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 21:02:47 +02:00
NuklearRabbit efab8d816f M31: verify RAG inventory and polish attention queue
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 20:58:26 +02:00
NuklearRabbit cfffb1ce54 M30: record production recruiter acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 18:32:30 +02:00
NuklearRabbit 29325b6c27 M29: polish recruiter engineering story
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 18:13:18 +02:00
NuklearRabbit 6365586e82 M28: complete production acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 16:34:56 +02:00
NuklearRabbit e1b700b10e M27: make backup checksums portable
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 16:19:18 +02:00
NuklearRabbit b00d33af11 M26: harden clean observability acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 16:15:23 +02:00
NuklearRabbit 90cc3cf378 M25: expose provenance-aware knowledge statistics 2026-08-10 16:04:39 +02:00
NuklearRabbit 0935901f11 M24: implement privacy governance 2026-08-10 15:56:03 +02:00
NuklearRabbit f0f1be83ae M23: automate verified database backups 2026-08-10 15:46:06 +02:00
NuklearRabbit 689e499634 M22: implement operational observability 2026-08-10 15:42:26 +02:00
NuklearRabbit c3f1cfc699 M21: add optional organisation identity 2026-08-10 15:35:25 +02:00
NuklearRabbit 509cb95110 M20: complete production acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 13:22:55 +02:00
NuklearRabbit 5dda5742e4 M20: verify reordered work queue by identity
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 13:12:07 +02:00
NuklearRabbit 152d847a26 M20: target guided issue semantically
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 13:06:28 +02:00
NuklearRabbit f715085f65 M20: stabilize production acceptance
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 13:02:03 +02:00
NuklearRabbit 5d7a5e7359 M19: harden performance and recovery
MobilityOps acceptance / backend (push) Canceled after 0s
MobilityOps acceptance / frontend (push) Canceled after 0s
2026-08-10 12:51:41 +02:00
NuklearRabbit fe06ff75a1 M18: implement operational workspaces 2026-08-10 12:41:28 +02:00
NuklearRabbit 8030753dbc M17: ground knowledge and integration evidence 2026-08-10 12:27:17 +02:00
NuklearRabbit 686795a452 M16: isolate acceptance and harden readiness 2026-08-10 12:08:42 +02:00
NuklearRabbit 2ee8b2d82b M15: synchronize contracts and acceptance 2026-08-10 05:39:19 +02:00
NuklearRabbit 58fb515337 M14: add n8n execution health telemetry 2026-08-10 03:41:06 +02:00
NuklearRabbit 218599af7d M13: harden MCP trust boundary 2026-08-10 03:24:17 +02:00
NuklearRabbit 15bdbe40ac M12: complete daily operations cycle 2026-08-10 03:15:46 +02:00
NuklearRabbit 4a3c3bd0a9 M11: implement operational booking lifecycle 2026-08-10 03:06:30 +02:00
NuklearRabbit 3f13912739 test: select an available vehicle for booking creation 2026-08-10 02:54:50 +02:00
NuklearRabbit b2e1ae7f17 test: make booking overlap assertion deterministic 2026-08-10 02:53:40 +02:00
NuklearRabbit de151914b6 M10: harden knowledge trust and telemetry 2026-08-10 02:51:07 +02:00
NuklearRabbit e577c16db5 M9: create validated internal bookings 2026-08-10 02:20:28 +02:00
NuklearRabbit c194c18ca9 docs: record operational mode validation 2026-08-10 02:11:26 +02:00
NuklearRabbit 948d5eb6a6 fix: normalize return risk timestamps 2026-08-10 02:10:02 +02:00
NuklearRabbit 3cd9ddfa66 fix: retain demo sessions across seed resets 2026-08-10 02:08:40 +02:00
NuklearRabbit 0bfcf71ff7 M8: add operational authentication mode 2026-08-10 02:06:50 +02:00
NuklearRabbit 4cdf667dc1 docs: record booking scale-up verification 2026-08-10 01:49:49 +02:00
NuklearRabbit 0ef4a6fa98 UX: paginate booking operations 2026-08-10 01:47:35 +02:00
NuklearRabbit 2648cef8e3 docs: record final roadmap verification 2026-08-10 01:15:16 +02:00
NuklearRabbit aacf0e04bc fix: preserve mobile record status 2026-08-10 01:14:20 +02:00
NuklearRabbit ad1182582d docs: record visual roadmap evidence 2026-08-10 01:05:30 +02:00
NuklearRabbit f2cdad194c UX: implement visual product roadmap 2026-08-10 01:05:07 +02:00
NuklearRabbitandClaude Sonnet 5 13ad2ba6a3 docs: record the MCP Hub URL fix and RAGcore Procedure Sync go-live
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 22:07:41 +02:00
NuklearRabbitandClaude Sonnet 5 086dfed992 fix: publish RAGcore Procedure Sync and derive its evidence for real
MCP_HUB_BASE_URL had the same wrong-hostname bug as RAGCORE_BASE_URL earlier
this session (itworx-mcp-hub:8000 doesn't resolve; the real container is
reachable at the host's own 192.168.10.150:1100) -- fixed live, resolving the
Automation page showing "Operationeel" and "Hub Onbereikbaar" simultaneously.

Went on to actually publish the "Fleet Ops -- RAGcore Procedure Sync" n8n
workflow now that RAGcore is reachable: its own RAGcore Sync Token credential
had gone stale from the same rotation as the earlier one, so minted a fresh,
dedicated, minimally-scoped (sources:sync only) credential, verified a real
manual run (33 synced, 0 failed, result registered) before publishing.

That exposed a real, now-stale bug: derive_n8n_status() hardcoded this
workflow's evidence to None with a comment explaining it was unpublished --
true when written, false now. The workflow's own result-report callback
already writes a real n8n_procedures_synced audit event; wired that in as its
evidence source, the same pattern the scheduled scan and error handler already
use, instead of a value that could never update itself once the workflow went
live.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 22:05:13 +02:00
NuklearRabbitandClaude Sonnet 5 64cc96fa4b docs: record the RAGcore go-live fix and evidence
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 21:22:57 +02:00
NuklearRabbitandClaude Sonnet 5 319f43312e fix: drop RAGcore's opaque version UUID from the fallback answer sentence
document_version_id is an internal UUID, not a human-meaningful version like
the demo corpus's markdown frontmatter -- confirmed live it made the fallback
answer read as "Per \"vehicle-checkout-procedure.md\" (v2e139422-b10b-...)".
Still shown on the source card itself, just not in the composed sentence.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 21:18:58 +02:00
NuklearRabbitandClaude Sonnet 5 a2433d7fa3 fix: fall back to real RAGcore search when /v1/answers is unavailable
RAGcore's /v1/answers (generation + citation validation) is currently returning
a consistent 503 VALIDATION_RETRIES_EXHAUSTED live -- a RAGcore-side bug in its
own generation/validation step, out of scope to fix here (CLAUDE.md forbids
modifying the RAGcore repo). Its retrieval pipeline (/v1/search) is a materially
different, simpler stage with no generation step, and returns real, correctly
cited results right now.

RAGcoreKnowledgeProvider.ask() tries /v1/answers first (unchanged behavior once
RAGcore's generation is fixed), and only when that endpoint itself is
unavailable -- non-2xx or unreachable, never a real 200 classifying the
question as insufficiently answerable -- falls back to /v1/search and builds
the shown "answer" as an extractive citation-wrapped excerpt, mirroring
DemoKnowledgeProvider's own existing template exactly. Never invents an answer
to the question; only ever shows a real, cited excerpt RAGcore's own search
actually found.

Also fixed two real config bugs found while wiring this up live: RAGCORE_BASE_URL
pointed at a non-existent internal hostname (ragcore-api:8000 -- the real
container is reachable at the host's own address on port 1237), and the
previous test credential had been invalidated with nothing to replace it. Minted
a fresh, correctly-scoped service-account credential via RAGcore's own admin
control plane (the documented, legitimate way to obtain one).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 21:11:28 +02:00
NuklearRabbitandClaude Sonnet 5 453c7241fe docs: record the MCP Hub go-live fix and evidence
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 20:19:07 +02:00
NuklearRabbitandClaude Sonnet 5 529e7364a9 fix: pass MCP_HUB_REGISTRATION_ENABLED/MCP_HUB_BASE_URL through to the api container
compose.yaml's api service environment block forwarded MCP_HUB_SERVICE_TOKEN but
never these two -- so .env's value was silently ignored and Settings always fell
back to its Python default (false / empty), no matter what .env said. Found while
flipping the flag live: the container's actual reported registration_enabled
stayed false after a full recreate, even though .env had been updated and two
real mcp_tool_request audit events already existed (itworx-mcp-hub:readiness ->
fleet_ops_get_operations_summary), proving the Hub's connector already reaches
Fleet Ops successfully independent of this flag -- only the status display was
gated, and silently stuck off.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 20:15:17 +02:00
NuklearRabbitandClaude Sonnet 5 7d686ae2aa docs: record polish fixes, merge, and second deploy evidence
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 19:04:42 +02:00
NuklearRabbitandClaude Sonnet 5 c2b8268927 fix: form field alignment, raw maintenance text, and static movements list
- .form-grid labels (missing-field form, odometer-regression correction fields)
  and the odometer/overlap note textareas had no stacked label-above-input
  styling at all -- the shared rule only covered .filters/.return-form, so these
  fell back to default inline browser layout with mismatched input widths.
  Extended the existing rule to cover .form-grid and label:has(> textarea).

- Vehicle maintenance list showed the raw, untranslated seed text
  ("Synthetic scheduled service record") regardless of locale -- purely
  decorative and 1:1 redundant with the (already-translated) category. Replaced
  it with the record's real odometer reading, mirroring the sibling
  Inspections tab's pattern.

- "Today's movements" was always the same fixed 4 bookings (2 returns, 2
  departures) on every reset, reading as a static mockup rather than live
  fleet activity. Added 8 more bookings anchored to land on "today" across 8
  additional vehicles, spread through the day.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 18:29:56 +02:00
NuklearRabbitandClaude Sonnet 5 9e9dd8e0e3 docs: record the three-defect fix, gates, and live verification evidence
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 17:52:13 +02:00
NuklearRabbitandClaude Sonnet 5 4faac24b5a fix: localize dashboard evidence, explain blocked vehicles, clarify pending odometers
Three content defects found by a live reviewer:

- Dashboard attention subtext was raw, untranslated evidence.summary text, and for
  11 of 15 seeded issues that text was literally "Synthetic deterministic seed
  issue". AttentionItem now exposes evidence_signals (stable code + params, same
  shape as the issue detail page) instead of a detail string; the frontend renders
  them through a shared describeEvidenceSignal() used by both the dashboard and the
  issue detail page. Every previously-placeholder seed row now cites a real,
  per-rule-type fact (a genuinely crossed service threshold, a genuinely blank
  field, or a real pair of booking odometer readings) instead of invented prose.

- 5 of 7 blocked vehicles had no quality issue at all and one had only a resolved
  one, so "needs attention" led nowhere. Each now has a real open
  missing_required_field issue backed by a genuinely blank field (no schema change,
  no migration -- reuses the existing data-quality pipeline).

- Booking odometer fields showing a bare "-" for 25 reserved + 1 active booking now
  show a localized explanation ("trip hasn't started yet" / "not yet closed").
  MO-024's rented-but-service-overdue contradiction was already caught by the
  vehicle-status evaluator (DQ-SCAN, vehicle.manual_review_required) -- added a
  regression test rather than new logic.

Also fixed a related bug the above exposed: the vehicle entity_snapshot omitted
registration_number entirely, so the "provide missing fields" form always showed
it blank regardless of the real value.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 17:44:32 +02:00
NuklearRabbitandClaude Sonnet 5 3808bbe132 docs: record push, Unraid deploy, and live verification evidence
Closes out the demo-scenario fix: pushed the two pending commits, deployed
6f77a30 to Unraid, and verified all four live checks (integration status,
failed-workflow listing, retry via API and UI, audit trail, Automation page).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 16:39:41 +02:00
NuklearRabbit 6f77a30dce fix: stop the prepared demo failure from degrading n8n integration health
The demo seed plants exactly one failed delivery (BK-H-0020) to demonstrate
retry and audit. Because derive_n8n_status() counted any failure, every fresh
reset pinned the n8n integration to "degraded" -- the demo showed a warning
about a prop, which tells a viewer something untrue about the automation.

The seeded failure now carries its own error code, demoScenarioTimeout, rather
than the generic connectionError a real timeout produces. No column and no
migration: last_error_code already existed, is already surfaced to the UI and is
already localizable.

- integration status splits failed into unexpected_failed and
  demo_scenario_failed; only unexpected failures may move the state. A staged
  failure alone leaves n8n operational.
- latest_failure_at is a health signal and now ignores the staged failure;
  latest_demo_scenario_at reports it separately.
- /api/v1/workflows exposes is_demo_scenario. The Automation page labels the run
  as a prepared demo scenario, explains that it is a simulated temporary failure
  that does not affect automation health, and offers a distinct "retry demo
  scenario" action. Translated in nl-BE, en-GB and fr-BE.
- the carve-out stays narrow: a real failure still degrades n8n, and a genuine
  later failure of the same event overwrites the demo code with the real one.
- the retry itself is unchanged and real: the event goes back on the outbox and
  the dispatcher delivers it to n8n like any other, so 19+1 becomes 20+0 only on
  an actual round trip. The audit records which kind of failure was retried.

Tests that assert on the seeded scenario now reseed first, since earlier test
files legitimately mutate the outbox and the suite shares one database.

Verified locally against a real PostgreSQL 16: 181 passed, ruff clean, mypy
clean (50 files), tsc clean, frontend build clean. Not deployed and not
browser-verified.
2026-08-05 14:07:05 +00:00
NuklearRabbit e5307a7c0f fix: derive demo-manifest MCP Hub status from real tool-call evidence
The demo manifest still reported the MCP Hub integration as operational purely
because MCP_HUB_REGISTRATION_ENABLED was set, while the integration status page
had already moved to evidence-based status in Batch 4. Registration is
catalog-driven on the Hub's side, so the flag alone proves nothing; reuse
derive_mcp_hub_status() so "operational" requires real recorded mcp_tool_request
calls.

No change to the MCP integration contract: the four read-only routes, service
token and client id handling, inbound X-Correlation-Id preservation, the locale
field on search-knowledge and the provider/correlation_id response fields were
verified as already correct at deployed revision 727c19a and left untouched.
2026-08-05 13:28:43 +00:00
NuklearRabbitandClaude Sonnet 5 dee8f2f7e9 docs: record Batch 5 evidence and final session state
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 13:51:11 +02:00
NuklearRabbitandClaude Sonnet 5 57992bf153 M10: AI Operations Brief runbook, full live e2e regression, final evidence
Ran a real AI Operations Brief via the live ITWorx MCP Hub connector's own
MobilityOpsClient against production Fleet Ops: real operations summary, real
most-pressing vehicle, real grounded knowledge answer with citations, real
correlation IDs verified end-to-end in Fleet Ops's own audit log. No write
actions performed. Runbook and full output in
docs/final-integrations/ai-operations-brief-runbook.md.

Ran the full Playwright e2e suite against the live deployed instance and fixed
two pre-existing fragile locators unrelated to this session's feature work
(both broke because Automation now legitimately has two tables sharing the
same generic selectors, exposed by running the full suite rather than
individual files) plus one pre-existing untranslated-loanword false positive.
All specs pass.

artifacts/final-integrations/final-summary.md has the complete evidence
write-up: repository/deployment state, what was fixed vs. handed off, test
results, and known limitations stated plainly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 13:49:23 +02:00
NuklearRabbitandClaude Sonnet 5 727c19a779 M9: MCP Hub locale/correlation propagation, real Hub health check, fix stale test image
Fixed two concrete gaps in the MCP knowledge-search endpoint: no locale field
existed at all (now nl-BE/en-GB/fr-BE, wired to the knowledge provider's
existing language param), and the correlation ID was always freshly minted,
ignoring any inbound X-Correlation-Id header. Added a shared dependency and
applied it to all four MCP endpoints so Fleet Ops's own audit log preserves
the Hub's real correlation ID end to end.

MCP_HUB_BASE_URL/MCP_PROVIDER_ID were declared in .env.example but never read
anywhere. Since the Hub's own registration is catalog-driven (it never needs
Fleet Ops to push a registration call), wired mcp_hub_base_url for a real Hub
reachability health check instead of an unneeded self-registration call.

Renamed Fleet Ops's own internal audit tool labels mobilityops_* -> fleet_ops_*
(mirrored in contracts/mcp-tools.json with mobilityops_* kept as deprecated
aliases); documented that the live Hub connector's own dotted tool namespace
is a separate, Hub-owned naming layer, deliberately not touched.

Automation page's MCP card now shows real evidence (last tool/client/count/
timestamp, honest no-evidence state) instead of just the registration flag.

Also fixed a real methodology gap found mid-session: compose.yaml's api
service has no bind mount, so `docker compose run --rm api` silently tests a
stale image until rebuilt. Re-ran every local gate after rebuilding; fixed one
genuinely stale test assertion and two lint line-length errors surfaced by
that rebuild. 176 tests passing, ruff clean, mypy clean (50 files).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 13:30:24 +02:00
NuklearRabbitandClaude Sonnet 5 2ae2044e3a docs: record Batches 1-3 evidence and exact next action
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 13:05:53 +02:00
NuklearRabbitandClaude Sonnet 5 34df66d28c M8: GUI polish, n8n workflow-3 fixes, RAGcore retrieval root-cause and fix
GUI: dashboard Attention Queue presents a curated severity mix instead of pure
severity-sort (grouped Now/Today/Later headers); Today's Movements seed data
curated so a fresh reset shows a credible day (2+ departures, 2+ returns), with
a new seed-integrity test; About Demo restructured into a compact grid with
progressive disclosure for technical sections; Duplicate Merge shows match/conflict
counts, hides matching fields by default, and previews the final merged record
before confirmation.

Repo hygiene: removed a stray empty `backend;C` directory and an untracked 31MB
zip export; `.gitignore` now excludes future archive exports.

n8n: fixed invalid JSON (a missing `},` between two node objects) in the committed
`fleet-ops-vehicle-return.json` -- the file could not be parsed. Live-validated
workflow 3 (RAGcore Procedure Sync): found and fixed a real defect (three body
parameters had a stray trailing `}}`) and a missing Error Workflow wiring, both
via the safe `n8n import:workflow` CLI path; exported the corrected, still-
inactive workflow as the new source of truth and updated MANIFEST.md/check_drift.py.
Publishing it (starts real daily unattended runs) remains a separate decision.

RAGcore: root-caused and fixed (live, approved) the "zero retrieval candidates"
bug -- a filesystem permission bug (`embedding_profiles.json` unreadable by the
app's own runtime user) that broke every retrieval call before it reached Qdrant.
Every other suspect (grants, scope resolution, Qdrant filters, embeddings) was
verified healthy first. Found a second, deeper gap: the reranker adapter calls
an Ollama HTTP route that does not exist on the deployed Ollama version, so
`/v1/answers` still returns `not_answerable`. `KNOWLEDGE_PROVIDER` stays `demo`
until that is resolved on the RAGcore side. Evidence-based MCP Hub integration
status (real tool-call audit history, not just a boolean flag) replaces the old
`configured`/`not_configured` guess. Full findings in
`docs/final-integrations/current-state-audit.md`.

Backend: 172 tests passing, ruff clean, mypy clean (50 files). Frontend: tsc
clean, production build clean.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 13:05:02 +02:00
NuklearRabbitandClaude Sonnet 5 3ebca9e9b7 feat: replace brand mark with waypoint (pin-on-route) logo
Swaps the peaks-over-a-road glyph for a location pin on a route line
in both the favicon and the BrandMark component, so the mark stays
legible at 16px favicon size and reads more literally as fleet/route
tracking. Palette unchanged (navy #0f172a, teal #2dd4bf).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 11:47:11 +02:00
NuklearRabbitandClaude Sonnet 5 b66521da82 docs: record branch push and Unraid redeploy to 0571a40
Pushed feat/live-n8n-ragcore-integration to origin, then redeployed
the live Fleet Ops instance from 0da5251 to 0571a40 following the
deployment directory's own established source-archive convention.
Verified live: /health OK, the new n8n procedures endpoint (added
this branch) is reachable and correctly auth-gated, KNOWLEDGE_PROVIDER
still demo as intended.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 11:25:30 +02:00
NuklearRabbitandClaude Sonnet 5 0571a40649 docs: record n8n proxy-hops fix and completed workflow-3 build
Root cause found via the live n8n container's own logs: N8N_PROXY_HOPS=0
in the Unraid template didn't match the real reverse-proxy in front of
it, breaking the browserId/CSRF check on every workflow save while
leaving the UI looking fully signed in -- the user's pushback that it
"shows logged in" was correct and prompted digging into server logs
instead of continuing to guess client-side.

Fixed by editing the Unraid template (N8N_PROXY_HOPS 0->1, backed up
first) and recreating the container with every other setting preserved
exactly. Verified by reproducing the exact save action that used to
fail; it now works, and node persistence survives a full reload.

Built and saved both remaining workflow-3 nodes (Summarize sync
result, Report sync result to Fleet Ops) after recovering from an
errant Ctrl+A that deleted a node mid-verification (caught via node
count, restored via n8n's own Version History, redone carefully). Not
published -- that starts real daily production runs and is left for a
separate decision.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 07:12:57 +02:00
NuklearRabbitandClaude Sonnet 5 4227fe4f58 docs: record live /v1/answers verification and a retrieval finding
Issued a fresh scoped credential via the RAGcore admin UI (separate,
working OIDC session, unaffected by the n8n auth problem) and made a
real authenticated /v1/answers call. Got a clean 200 with a real
answer_id/retrieval_run_id, not degraded -- but not_answerable, 0
citations.

Confirmed this isn't a regression: the same query through RAGcore's
own pre-existing Query Lab tool (untouched this session) returns the
identical result down to zero dense/sparse candidates at the raw
retrieval stage. Ruled out the obvious causes via direct Qdrant/
Postgres checks -- workspace_id, space_id, status, and embedding
digest all correctly match real indexed content. Root cause not yet
found; flagged as a follow-up rather than pursued further to avoid
scope creep on what was a deployment-verification task.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 04:01:16 +02:00
NuklearRabbitandClaude Sonnet 5 c790ec99cb docs: record RAGcore search/answer wiring deployment to production
Deployed a2905cc to the live RAGcore instance (approved). Verified
the fix directly: POST /v1/search now returns 401
AUTHENTICATION_REQUIRED instead of the old permanent 503
SEARCH_UNAVAILABLE, proving the endpoint reaches real request
handling. A full authenticated /v1/answers call with a real grounded
answer is still outstanding -- the previously-issued production
credential's raw token was never persisted anywhere retrievable, and
issuing a fresh one needs the RAGcore admin UI, not attempted this
round.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 03:44:39 +02:00
NuklearRabbitandClaude Sonnet 5 fd390df423 docs: record n8n workflow-3 wipe/recovery and the live auth blocker
The live "Fleet Ops -- RAGcore Procedure Sync" workflow's canvas was
found at zero nodes -- the earlier session's abandoned direct n8n
REST API attempt had gone far enough to wipe it before hitting its
401. Recovered via n8n's own Version History "Restore version"
action back to the last good 4-node save; verified via DOM node
count before and after.

Adding the two remaining nodes then hit the same failure mode: n8n's
own first-party autosave reported "Unauthorized" moments after a
fresh, successful interactive sign-in. Stopped deliberately rather
than retrying against a live instance that already caused one data
loss incident this session -- this looks like an n8n-side session/auth
problem, not something fixable from browser automation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 03:38:16 +02:00
NuklearRabbitandClaude Sonnet 5 e5d8466266 knowledge: rewrite RAGcoreKnowledgeProvider to the real search/answers contract
The previous adapter targeted an endpoint shape RAGcore never actually
exposed. health() now checks /health/ready and ask() posts to the real
POST /v1/answers with Bearer auth and requested_space_ids, matching
RAGcore's actual contract after this session's Bearer-auth and
search/answer wiring work.

Adds RAGCORE_SPACE_ID config/env plumbing (a question is meaningless
without a knowledge space to scope it to) and 12 new adapter tests
covering degradation paths: missing space id, connection errors,
non-200 responses, malformed responses, not-answerable, and
answerable-without-citations all fail closed to "insufficient
evidence" rather than fabricating an answer.

KNOWLEDGE_PROVIDER stays "demo" in production for now -- switching
requires RAGcore's own search/answer application to actually be
deployed and live-verified, tracked separately in PROJECT_STATE.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 03:20:55 +02:00
NuklearRabbit 0da5251524 n8n: add backend endpoints for the RAGcore Procedure Sync workflow
GET /api/v1/integrations/n8n/procedures lists every procedure Markdown
file Fleet Ops ships (all languages) with a stable per-document id and
content hash, ready for workflow 3 to push into RAGcore. POST
.../procedures-sync-result records the sync outcome as an idempotent
audit event, matching the existing return-callback/workflow-error
pattern. Extracted frontmatter parsing out of the demo knowledge
provider into a shared module so both read the same source of truth.
2026-08-04 19:47:39 +02:00
NuklearRabbit 2afceea5e4 docs: record root cause and fix for the RAGcore credential-issuance bug
With explicit owner approval, traced the persistent credential-issuance
rejection to a cross-transaction race in RAGcore's own dependency
injection (two independent DB transactions per request instead of one
shared transaction), fixed and deployed it in RAGcore, and verified a
working "RAGcore Sync Token" n8n credential now exists. Unblocks
workflow 3 and the RAGcoreKnowledgeProvider adapter rewrite.
2026-08-04 18:11:34 +02:00
NuklearRabbit cf4d8e3649 docs: write final n8n + RAGcore integration evidence summary
Consolidates this effort's outcome across all four canonical workflows:
WF1/WF2 hardened and live, WF3 blocked on a RAGcore-side credential
rejection (with trace IDs for the operator to investigate), WF4 built
and live-validated with one open non-blocking follow-up. No credential
values or secrets included.
2026-08-04 17:07:54 +02:00
NuklearRabbit aaa1630535 docs: record WF2 retry fix and WF4's n8n-session-expiry blocker 2026-08-04 17:04:33 +02:00
NuklearRabbit 167bf49b6e n8n: add bounded retries to WF2's quality-scan callback
Found during this round's full acceptance pass: WF2 had the same
timeouts/bounded-retries gap as WF1 (timeout was already set, but Retry
On Fail was disabled). Fixed live (3 tries, 1000ms wait), published, and
synced the repo definition + manifest checksum.
2026-08-04 17:03:52 +02:00
NuklearRabbit fd0c55b13b docs: record RAGcore credential re-attempt and its concrete failure evidence
User explicitly authorized issuing the RAGcore credential directly this
round. Retried via the admin UI (Platform Admin role) after the earlier
raw-API attempt; both fail with an opaque server-side rejection carrying
a trace ID. Documents this as a RAGcore-side blocker, not a Fleet Ops gap.
2026-08-04 16:54:02 +02:00
NuklearRabbit 05628936ca n8n: add bounded retries and timeout to WF1's Fleet Ops callback
Vehicle Return Orchestration had no explicit timeout and Retry On Fail
disabled on its outbound HTTP call, a gap against the acceptance
checklist's timeouts/bounded-retries requirement. Fixed live (3 tries,
1000ms wait, 15s timeout, matching WF2's existing convention) and
synced the repo definition + manifest checksum.
2026-08-04 16:46:11 +02:00
NuklearRabbitandClaude Sonnet 5 b341436e77 docs: record integration status page verification and deploy evidence
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 16:32:43 +02:00
NuklearRabbitandClaude Sonnet 5 4049c0c6b1 n8n: surface real per-workflow evidence on the integration status page
Fleet Ops integration status no longer depends only on a config
boolean or the most recent outbox event: N8nIntegrationStatus now
reports per-canonical-workflow evidence (last successful outbox
delivery for the return workflow, latest service-triggered
data_quality_scan_run for the scan workflow, latest
n8n_workflow_failure_registered for the error handler, and "not built"
for the still-blocked RAGcore sync), plus an error-handler summary
(total failures registered, latest failure + which workflow).

Automation page renders this as a localized workflow table (EN/NL/FR)
with technical workflow names tucked under a "Technical details"
disclosure, matching the existing progressive-disclosure pattern.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 16:15:09 +02:00
NuklearRabbitandClaude Sonnet 5 e39c0a1dd6 n8n: build and live-validate the Workflow Error Handler (WF4)
New central "Fleet Ops — Workflow Error Handler" workflow (Error
Trigger -> safe-report Code node -> POST to the new /workflow-error
endpoint), wired as the Error Workflow on both existing workflows with
no recursive loop on itself. Live-validated end-to-end against the
real Fleet Ops server (register + idempotent re-register), and via a
genuine induced failure on the scheduled-scan workflow (broken URL,
confirmed failure, reverted, confirmed healthy).

Fixed two real bugs found during live testing: Code node needed
"Run Once for Each Item" (not "All Items") for $json binding, and
every HTTP body field had a stray trailing space from the n8n
code-editor's bracket auto-close that broke datetime/enum validation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 15:52:17 +02:00
NuklearRabbitandClaude Sonnet 5 bbdb4a9ae8 n8n: add Fleet Ops endpoint to receive workflow error reports
New POST /api/v1/integrations/n8n/workflow-error, service-token
authenticated, for the central "Fleet Ops — Workflow Error Handler"
n8n workflow to report a bounded, secret-free failure (workflow id/
name, execution id, safe error category, trigger context, correlation
id, attempt, retry action). Idempotent on execution_id via the same
audit-event precheck pattern used by /return-callback, so a
redelivered error report is not registered twice.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 13:40:36 +02:00
NuklearRabbitandClaude Sonnet 5 e0c107a94a n8n: store cleaned workflow definitions as repo source of truth
Move the two live-validated workflows into n8n/workflows/ (credential-
based auth referenced by name only, no secret values), add a manifest
covering all 4 canonical workflows and a read-only drift-check script
against n8n's Public API. Retire the pre-integration root-level starter
files that still carried the literal-token pattern, and repoint the
Unraid deploy scripts, Makefile targets and runbook at the new files.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 13:34:51 +02:00
NuklearRabbit 59cb4c062e docs: record n8n corrections applied and failure-history triage
Appends a follow-up section to the current-state audit: both existing
workflows renamed to their canonical Fleet Ops names and republished
(IDs/history preserved), and all 6 error executions in the return-
processing workflow's entire history triaged -- the 4 original ones
were the workflow's own author testing against the local test webhook
during initial setup on 2 August, the 2 newest are this session's own
deliberate auth-fix validation calls. Zero unexplained failures remain.
2026-08-04 09:15:08 +02:00
NuklearRabbit b79d485ef1 docs+fix: audit live n8n state, require auth on the return webhook
Inspected the shared n8n instance (n8n.itworx.tech) live: both existing
Fleet Ops workflows are genuinely active and structurally match the repo,
but the shared X-Service-Token secret was stored as plaintext literal
text in both HTTP Request nodes (exportable in the clear), and the
production return webhook had n8n-level Authentication set to "None"
(publicly callable by anyone who discovered the URL). Findings recorded
in docs/live-ai-integration/n8n-current-state.md.

Fixed on the n8n side (both workflows published): the shared token now
lives in a single Header Auth credential instead of two literal copies;
the return webhook now requires a second, distinct Header Auth
credential.

Fixed on the Fleet Ops side to match: the outbox dispatcher now sends
the new X-Fleet-Ops-Trigger-Token header (new
MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN setting) when calling the webhook.
Live-verified against the real webhook: a request with no header is now
rejected (403); a request with the correct header passes n8n's auth and
reaches Fleet Ops's own business logic.

That same live test also surfaced a real robustness gap: an n8n
execution that errors before its "Respond to Webhook" node runs can
still answer with a 2xx status and an empty body, which made
response.json() raise an uncaught exception, potentially leaving the
outbox event stuck in "delivering". Now treated as an explicit,
retryable failure (error_code=malformedResponse), with a regression
test reproducing the exact case.
2026-08-04 05:03:33 +02:00
NuklearRabbit c0995b762e docs(release): final Fleet Ops localization correction evidence
Final evidence for the small correction round merged in 5f0eaa5:
commits, translation fixes, API-error-localization result, greeting
logic and edge-case evidence, clean-checkout drill, Unraid deployment
evidence, repository/runtime hash comparison, known limitations
(including the transient document.lang anomaly observed during
interactive testing, root-caused as far as possible and not
reproduced in any automated run), and rollback procedure.
2026-08-04 04:01:55 +02:00
NuklearRabbit 5f0eaa59b0 merge: finalize Fleet Ops localization 2026-08-04 03:46:20 +02:00
NuklearRabbit 09173a4740 fix: correct fr-BE audit column label Actor -> Auteur
Caught during live browser validation on Unraid: fr-BE had "Acteur" for
the audit trail's actor column, but the brief's minimum-required French
corrections specify "Actor" -> "Auteur" explicitly.
2026-08-04 03:32:48 +02:00
NuklearRabbit 9468cc3e21 docs: update PROJECT_STATE and README for the final localization round
PROJECT_STATE.md: fix the stale "Product name: MobilityOps."/"PoC only"
locked-decisions lines (predate the Fleet Ops rebrand), fix the "Fleet
Ops correction" section header still reading "IN PROGRESS .../Not yet
merged to master" when it was in fact already merged (de0bdea, evidence
commit f780557), and append a new dated entry for this correction round
with commits and gate evidence so far.

README.md: reference docs/fleet-ops-final-localization/ alongside the
existing docs/fleet-ops-correction/ link, refresh the stale Playwright
test count (113 -> 138).
2026-08-04 03:10:37 +02:00
NuklearRabbit f0d641198c fix: serve the missing Fleet Ops favicon
There was no favicon at all -- index.html never linked one, and the
frontend Dockerfile's build stage never copied the public/ directory
into the build context, so even after adding public/favicon.svg
locally, the containerized build silently dropped it (nginx fell back
to serving index.html for that path). Fixed both: index.html links
/favicon.svg, and the Dockerfile now copies public/ alongside src/.
The favicon reuses the existing BrandMark glyph (petrol background,
teal accent) for visual consistency with the in-app brand mark.
A regression test for this lives in the earlier translation-fix commit
(frontend/e2e/fleet-ops-correction.spec.ts), added together with the
fix at the time.
2026-08-04 03:10:11 +02:00
NuklearRabbit 77208b857a fix: prevent topbar overflow from an unbreakable Dutch role-name translation
Correctly translating auth.json's roleOperationsManager from the old
two-word "Operations Manager" (which could wrap at the space) to the
single Dutch compound word "Operationsmanager" (which cannot) pushed the
topbar's .operator block past its 1024px-breakpoint budget, caught by
the existing responsive-i18n.spec.ts overflow test. Fixed with
overflow-wrap: anywhere on the role/name text and min-width: 0 on their
flex-item wrapper, rather than reverting the correct translation.
2026-08-04 03:09:17 +02:00
NuklearRabbit e427313bce feat: add time-dependent Europe/Brussels dashboard greeting
The dashboard greeting was a fully static "Goedemorgen..." regardless of
actual time of day. New frontend/src/i18n/greeting.ts::getGreetingPeriod
is a pure, clock-injectable function resolving one of 4 periods (05:00-
11:59 morning, 12:00-17:59 afternoon, 18:00-22:59 evening, 23:00-04:59
night) against Europe/Brussels wall-clock time via
Intl.DateTimeFormat({ timeZone, hourCycle: "h23" }), which is DST-safe
by construction.

useGreetingPeriod.ts wires this into React with a 30s poll so the
greeting rolls over live while the app stays open, no reload required.
Each period now has its own greeting word and accompanying sentence in
all 3 languages (dashboard.json), replacing both the fixed "Goedemorgen"
and the fixed "Here's the fleet" follow-up sentence. Night never says
"Goedenacht" (used as a farewell, not a welcome, in Dutch).
2026-08-04 03:08:45 +02:00
NuklearRabbit d17af1c52a feat: centralize API error localization
Replace the err instanceof ApiError ? err.message : t(fallback) anti-
pattern -- which showed raw English backend text for the common case and
only used the localized fallback for the rare network-failure case -- at
all 13 call sites across 7 files.

New frontend/src/api/errorMessages.ts (describeApiError) resolves a
caught error to a localized {title, explanation, nextStep?, technical}
by checking the 32 known AppError codes first, then known HTTP statuses
(401/403/404/409/422/500), then a fully generic fallback. New
ApiErrorNotice (PageChrome.tsx) renders title/explanation/nextStep with
the raw text demoted to a "Technical details"/"Details techniques"
disclosure -- never shown as the primary message.

ApiError itself is split out of client.ts into a standalone
api/apiError.ts with no import.meta.env dependency, so errorMessages.ts
(and its tests) can be loaded outside a Vite/browser context.
2026-08-04 03:08:07 +02:00
NuklearRabbit 94cfb7bcbb test: tighten i18n allowlist, add substring and brand-leak guards
Remove 7 now-stale IDENTICAL_VALUE_ALLOWLIST entries (audit.title,
auth.roleOperationsManager, auth.roleRentalEmployee,
demo.scenarios.startScenario, demo.scenarios.roles.operations_manager/
rental_employee, navigation.items.audit) now that they are genuinely
translated -- their old comments describing them as "deliberately
untranslated" were no longer true.

Add two new checks: one closing the embedded-English/Dutch-substring
blind spot the whole-string identity test structurally cannot catch (a
mid-sentence phrase surviving inside otherwise-translated prose), one
asserting no locale file contains "MobilityOps" or the word "PoC".
2026-08-04 03:04:14 +02:00
NuklearRabbit 37a362c4a0 fix: translate remaining NL/FR interface gaps
Role names, audit/scenario labels, and status text were previously either
left in English or only partially translated:
- auth.json/demo.json role labels actually translated (not just labelled
  as translated): Operationsmanager/Verhuurmedewerker,
  Responsable des operations/Collaborateur de location.
- "Audit trail" -> Auditgeschiedenis/Piste d'audit (title, column header,
  and every mid-sentence occurrence across demo.json, quality.json,
  returns.json -- these embedded leaks were previously invisible to the
  whole-string identity check).
- "Open" (status) -> Openstaand, "Recent" -> Recentste,
  "Start scenario" -> Scenario starten / Demarrer le scenario.

Matching Playwright spec text updated in the same commit so the suite
never regresses through a broken intermediate state.
2026-08-04 03:03:46 +02:00
NuklearRabbit 1fbb20b1ab docs: audit remaining Fleet Ops localization gaps
Documents every remaining untranslated/incorrect NL/FR string, raw-backend-
error call site, over-permissive i18n allowlist entry, the static-greeting
bug, and doc staleness found by a dedicated read-only sweep before any file
was touched, per the Fleet Ops final localization brief.
2026-08-04 03:02:50 +02:00
NuklearRabbitandClaude Sonnet 5 f7805579f7 docs(release): final Fleet Ops correction evidence and screenshots
Full acceptance evidence for the Fleet Ops correction milestone: commits, branding,
translation coverage, status-preview/apply/manual-review/MO-016-ordering results,
knowledge grounding per language, audit/automation localization, backend/frontend
test results, clean-checkout drill, Unraid deployment (both fix-branch and
post-merge master), responsive/accessibility results, known limitations, and
rollback procedure. Includes live screenshots (nl-BE and fr-BE login, and the
localized data-quality evidence summary that live validation caught and fixed).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 01:15:31 +02:00
NuklearRabbit de0bdea84f merge: complete Fleet Ops localization and status resolution 2026-08-04 00:54:31 +02:00
NuklearRabbitandClaude Sonnet 5 284b3c7394 docs: record Unraid deployment evidence (PASS)
Deployed fix/fleet-ops-i18n-status-flow to http://192.168.10.150:1236 and validated
live, which directly caught the evidence-summary localization bug (fixed in 2e4fb43).
Redeployed with the fix and re-verified: full 116-test Playwright suite green against
the live server, no console errors, no container-log errors, both containers healthy,
scenario_integrity.all_ready: true after final reset.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 00:53:31 +02:00
NuklearRabbitandClaude Sonnet 5 2e4fb43f09 fix: localize the primary data-quality evidence summary (live-caught on Unraid)
Live validation on the deployed fix branch caught a real bug: every data-quality
issue's top-of-page "Evidence summary" line rendered the raw, always-English legacy
evidence.summary string unconditionally -- in all three languages -- even though the
backend has been emitting structured, localizable evidence.signals for a while
(app/services/data_quality.py already documented this exact intent). The frontend
side of that conversion was never finished.

- DataQualityIssueDetail.tsx now renders evidence.signals through the operator's
  locale as the primary summary; the raw evidence.summary string is only visible
  inside "Technical details" (via the existing EvidenceDisclosure JSON dump).
- The four DQ-DEMO-* seed rows that anchor the guided demo's scripted scenarios now
  carry real, accurate signals computed at seed time (duplicate-customer's similarity
  score is the actual SequenceMatcher ratio on the seeded names, not invented) instead
  of only a legacy English sentence.
- Rows with no structured signals (generic filler seed data) fall back to the raw
  text rather than showing a blank summary; the one known placeholder string gets its
  own localized rendering so it never displays as English filler either.
- New regression test: the vehicle_status_conflict evidence summary must show
  localized text and must never contain the specific raw English sentence that was
  live-visible before this fix, in all 3 languages.

151 backend tests, Ruff, mypy green; full local Playwright suite green (a couple of
sequential-run-only flakes, both confirmed to pass in isolation and unrelated to this
change).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 00:44:06 +02:00
NuklearRabbitandClaude Sonnet 5 cda2c32bd0 docs: record clean-checkout drill evidence (PASS)
Fresh clone of only committed files into an isolated Compose project (separate ports,
no shared volumes) validated: migration from empty database to head, deterministic
seed (matches the corrected 27-issue count), 151 backend tests + Ruff + mypy, frontend
build, and the full 113-test Playwright suite -- all green. Isolated stack torn down
afterward; working dev environment confirmed untouched. Full detail in
PROJECT_STATE.md; test counts refreshed in README.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 23:57:21 +02:00
NuklearRabbitandClaude Sonnet 5 7851e807fa test: add route matrix (11F) and hardcoded-JSX-text check (11D)
- fleet-ops-correction.spec.ts: opens every main route in all 3 languages, asserting
  no console errors, correct html[lang], and a real non-empty page heading (key parity
  across locale files is already proven structurally elsewhere, so this focuses on what
  only a live render can catch).
- i18n-coverage.spec.ts: a static scan for hardcoded JSX text bypassing t(...). A naive
  `>text<` regex falsely flagged TypeScript generics everywhere (`useState<string |
  null>(null)` was read as a "JSX tag" spanning to the next unrelated `>`) -- fixed by
  requiring the closing tag name to backreference the opening one
  (`<Tag>...</Tag>`), which generics can never satisfy. Verified against both false
  positives (passes clean on the current codebase) and false negatives (deliberately
  injected and reverted a hardcoded string to confirm it's caught).

Known pre-existing flake (unrelated to this branch, not touched by it): "logout
invalidates the server session so a refresh returns to login" in
interactive-elements.spec.ts occasionally fails only in the full sequential run,
never in isolation -- AuthContext.logout() clears local state and redirects before
awaiting the server-side cookie-clearing POST, a narrow race no human interaction
speed would ever hit. Noted as a known limitation, not fixed (out of this branch's
scope).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 23:30:09 +02:00
NuklearRabbitandClaude Sonnet 5 a7ac5ed9d0 docs: update OpenAPI contract, README branding, and PROJECT_STATE for the correction milestone
- contracts/openapi.yaml: title is now "Fleet Ops API"; documents the new
  status-recommendation preview endpoint and the apply endpoint's request body
  (recommendation_token) and full error-code set; notes the search endpoint's
  code+params response shape.
- README.md: title and intro now say Fleet Ops, with an explicit note on the
  Fleet Ops (visible)/MobilityOps (technical identifier) naming split; refreshed
  stale test counts (151 backend, 108 Playwright).
- PROJECT_STATE.md: full progress record for the in-progress correction milestone,
  including what's done, what bugs were found and fixed, and what's explicitly not
  yet done (i18n test-strengthening 11D/E/F, clean-checkout drill, Unraid deployment,
  merge to master).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 23:14:34 +02:00
NuklearRabbitandClaude Sonnet 5 1e407754e6 test: add accessibility coverage for the status-recommendation panel
Adds aria-live="polite" to the status-conflict panel (matching the existing
resolved-issue success-panel convention) so the applied-status confirmation is
announced to screen readers, and a Playwright test covering: keyboard-only
activation of both the "Review recommendation" and "Change status to X" actions,
reduced-motion emulation, and that status is never conveyed by colour alone (the
badge always carries its own localized text).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 23:08:21 +02:00
NuklearRabbitandClaude Sonnet 5 1fdd2b3ccf test: add targeted E2E coverage for branding, status flow, MO-016, and knowledge; fix two real bugs found along the way
New frontend/e2e/fleet-ops-correction.spec.ts covers section 12 of the brief:
branding (Fleet Ops visible, no MobilityOps/PoC leaks, in all 3 languages), the
language switcher persisting across reload, the full status-recommendation flow
(non-mutating preview, exact-status confirm button, manual review with no apply
button, stale-token rejection), MO-016 order independence at the browser level, the
knowledge base grounding the exact brief question in its own language, and localized
audit/automation content with raw codes only under "Technical details".

Writing these tests surfaced two real bugs:

- DataQualityIssueDetail.tsx conflated "no conflict" with "manual review required"
  because both carry safe_to_apply: false (a no_conflict recommendation has nothing to
  apply, so it's trivially "not safe to apply" without being unsafe). This showed a
  false "manual review required" panel for MO-016 after its overlap was resolved,
  instead of the correct "no change needed" state. Fixed by keying the branch on
  manual_review_required alone.
- test_mo_016_status_conflict_recommendation_is_order_independent never actually
  exercised MO-016: _first_open() returned whichever vehicle_status_conflict issue was
  most recently detected (there are ~14 open after a reset), not necessarily
  DQ-DEMO-STATUS, so the test's MO-016 assertions were trivially true regardless of
  what the code under test did. Added _first_open_for_vehicle() and rewrote the test
  to explicitly target MO-016, and to assert the behaviour order independence actually
  requires: resolving the overlap first must correctly leave nothing to apply (the
  vehicle already matches the facts), not literally the same end status as resolving
  the conflict first.

151 backend tests, Ruff, mypy green; full 108-test Playwright suite green (two
transient, non-reproducible flakes confirmed to pass in isolation and unrelated to
this change).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 22:53:55 +02:00
NuklearRabbitandClaude Sonnet 5 ac4b1636fe test: update Playwright specs for the new status-recommendation flow and localized return reason
Two specs still exercised the old single-button "calculate and apply" flow and asserted
on the raw English return-status reason that is now shown as localized primary text
with the raw code moved behind "Technical details". Updated both to match the new
review/decide/confirm status panel and the reason-code UI.

Full 94-test Playwright suite green against the rebuilt web+api stack.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 22:05:50 +02:00
NuklearRabbitandClaude Sonnet 5 e6539d17b6 fix: knowledge retrieval accuracy and remaining brand/PoC leaks in procedure docs
- Fix the demo knowledge provider's tokenizer: a plain [a-z0-9]+ regex silently
  dropped accented characters, splitting French words like "véhicule" into "v" +
  "hicule" and mangling retrieval for nearly every French query. Now matches the
  Latin-1 accented range too.
- Reweight section scoring so the body match (the actual substance of a section)
  outranks a heading/title match (a shallow structural hint) rather than the reverse
  -- confirmed via the brief's exact validation question that the old weighting
  misranked the damage procedure behind a topically-adjacent document in all three
  languages (nl-BE: a checkout section; en-GB/fr-BE: the return procedure), purely
  because a generic word like "vehicle"/"voertuig" happened to sit in a heading/title.
- Remove leftover "MobilityOps" and "PoC" mentions from 5 English and 4 NL/FR
  procedure documents -- knowledge-base prose is visible UI content and was missed by
  the earlier rebrand.
- Add regression tests: the brief's exact NL/EN/FR damage question must ground on the
  damage procedure as the *primary* source (not just appear in the top 3), and no
  procedure file may contain "MobilityOps" or "PoC".

151 backend tests, Ruff, mypy green.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 21:54:15 +02:00
NuklearRabbitandClaude Sonnet 5 6deb95524d fix: safe status-recommendation flow, MO-016 order independence, brand constant, message codes
- Add a single shared, pure vehicle-status evaluator (app/services/vehicle_status.py)
  used identically by the data-quality scanner, a new non-mutating status-recommendation
  preview endpoint, and a transactional apply endpoint with optimistic-concurrency token
  revalidation -- eliminates the old opaque "calculate and apply" action and the unsafe
  "maintenance + active booking -> auto rented" shortcut. Frontend
  DataQualityIssueDetail.tsx now shows a review/decide/confirm panel with localized
  why/evidence/consequence text in nl-BE/en-GB/fr-BE, with an exact "Change status to
  <status>" confirm action per the brief.
- Fix MO-016 issue-order dependency: resolving the booking-overlap issue before vs.
  after the status-conflict issue now converges on the same final vehicle status,
  proven by test_mo_016_status_conflict_recommendation_is_order_independent.
- Make "Fleet Ops" a non-localizable brand constant (frontend/src/product.ts,
  backend PRODUCT_NAME) via {{productName}} interpolation everywhere the brand name
  appeared in locale prose; add a permanent test guarding against a translation file
  ever defining the brand name or an "appName" key again.
- Convert dynamic backend prose to stable message codes + params: return status
  reasons, audit field/actor-type labels, automation last_error, and search
  section/vehicle/booking/issue results all now carry codes the frontend localizes,
  with raw technical text demoted to a "Technical details" disclosure.
- docs/fleet-ops-correction/: gap audit, i18n inventory, and the vehicle-status
  decision table documenting the evaluator's rules and safe-status principles.

148 backend tests + Ruff + mypy green; Alembic migration verified upgrade/downgrade;
frontend tsc/build and the i18n-coverage Playwright suite green.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 21:37:34 +02:00
NuklearRabbitandClaude Sonnet 5 18344bc8b7 docs(release): final Fleet Ops multilingual-polish evidence and screenshots
Adds artifacts/fleet-ops-release/final-summary.md with the complete evidence trail for
this release: commits, branding, locale/translation/knowledge-base coverage, adaptive
Demo Guide behaviour per breakpoint, Data Quality/Automation/Audit/clickable-row
improvements, full test results (backend, lint, build, 92 Playwright tests) re-run
against the local stack, an isolated clean-checkout drill, and both the feature-branch
and post-merge master deployments to Unraid -- plus 10 screenshots across the three
languages, desktop and mobile. Updates PROJECT_STATE.md with the corresponding summary.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 19:45:57 +02:00
NuklearRabbit 18a765d623 merge: release Fleet Ops multilingual demo 2026-08-03 19:28:30 +02:00
NuklearRabbitandClaude Sonnet 5 845db14e17 fix: mobile topbar overflow at 421-440px and add trilingual responsive coverage
The 420px "compact topbar" breakpoint left a gap: at 421-440px the demo-guide trigger,
badge, operator block and logout button together overflowed the viewport (introduced by
this session's language-switcher addition). Widen the breakpoint to 440px.

Adds a dedicated Playwright spec asserting no horizontal overflow across the brief's full
7-breakpoint matrix (1440x1000 down to 360x800) in all three supported languages.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 18:41:14 +02:00
NuklearRabbitandClaude Sonnet 5 337f8716bb polish: rebrand to Fleet Ops, add trilingual i18n, adaptive demo guide, and UX overhaul
Rebrands the product from MobilityOps to Fleet Ops across the UI, backend defaults and
knowledge base, and makes nl-BE/en-GB/fr-BE full first-class languages: i18next with
eager-bundled per-namespace resources, a persisted accessible language switcher (topbar
and mobile drawer), locale-aware date/number formatting, and a coverage test that fails
the build on any missing or empty translation key.

Backend dynamic content (demo scenarios, blocked-reason text, integration status) moves
from fixed English/Dutch prose to stable message codes + params so the frontend can
localize it; the demo knowledge base gains a fully translated NL/EN/FR procedure corpus
(11 documents each) with per-language retrieval and localized evidence-state messages.

The Demo Guide becomes breakpoint-adaptive: a docked rail on extra-wide desktop, a
floating panel that auto-collapses to a persistent, closable progress chip on standard
desktop/tablet, and a collapsed/half/full bottom sheet on mobile -- with scroll+focus+
highlight on "go to this step", Escape handling, and reduced-motion support.

The Data Quality Workbench gets accessible choice-card decisions with a clear primary/
secondary/tertiary action hierarchy; the Automation ledger groups repeated successes and
uses meaningful short refs; the Audit trail groups events by correlation id with human
action labels and readable before/after diffs. Attention Queue, Today's movements,
Vehicles, Bookings and Data Quality rows are fully clickable (stretched-link pattern)
with independent secondary links, keyboard support and mobile touch targets.

Fixes a topbar overflow on mobile caused by the new language switcher (moved into the
mobile drawer at <=960px) and two dangling aria-labelledby references introduced this
session. Updates all affected Playwright specs for the new nl-BE default and the new
Audit/DemoGuide DOM structure, and adds new i18n-coverage, demo-guide-adaptive and
clickable-rows specs. 131 backend tests, Ruff and mypy, and 71 Playwright tests pass.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-03 18:33:22 +02:00
NuklearRabbit 257a4cf6c0 docs(polish): audit finale demo-afwerking
Verifies the actual branch HEAD against the deployed Unraid revision
(they match) and corrects a one-commit-behind final-commit hash in
artifacts/demo-release/final-summary.md (its own "record the hash"
follow-up commit couldn't self-reference). Catalogues remaining
MobilityOps/PoC mentions (including in knowledge-base procedure prose
that gets quoted in answers), confirms no i18n exists, documents the
Demo Guide's single-behaviour-at-all-desktop-widths gap, the
inconsistent radio-vs-card decision styling in Data Quality, automation/
audit density, and exactly which dashboard rows aren't fully clickable.
Notes the repository's primary branch is `master`, not `main`.
2026-08-03 15:58:48 +02:00
NuklearRabbit 4a268c7351 docs(release): record the final commit hash in the demo-release summary 2026-08-03 15:31:39 +02:00
NuklearRabbit 294a8176d1 docs(release): finalize demo-productization acceptance evidence
Records the clean-checkout drill result (127 backend tests, 56
Playwright tests, all green on an isolated fresh clone), final live
Unraid verification, and the complete required evidence summary for
the demo-productization work on this branch.
2026-08-03 15:31:13 +02:00
NuklearRabbit a5024f7190 docs(demo): add demo-release evidence screenshots and capture tooling
One-off Playwright script (excluded from the regular suite) capturing
the demo entry (desktop+mobile), dashboard with scenarios, Demo Guide,
return preview/result, data-quality resolution, duplicate-customer
merge, knowledge assistant, integration status, automation retry,
audit trail + related-events, About page, demo badge popover, and
reset confirmation -- captured live against the Unraid deployment.
2026-08-03 15:29:53 +02:00
NuklearRabbit 38f654b97a docs(demo): add demo concept, scenarios, data, guide and runbook docs
Documents the demo-productization work from this branch: the Northstar
Mobility fictional concept and scope, the five named scenarios and their
fixed records, the seed/date-anchoring strategy (including the real bug
it fixed), the in-app Demo Guide's design and the English-suggested-
questions decision, and an operational runbook covering 5/10-minute demo
flows, reset, Unraid redeploy and rollback. Updates README with current
test counts and pointers to the new docs.
2026-08-03 15:24:35 +02:00
NuklearRabbit f04a81f6c7 docs: record Unraid deployment evidence for guided-demo test batch 2026-08-03 15:14:20 +02:00
NuklearRabbit 07d5605812 test(demo): add full guided-demo walkthrough and targeted demo tests
Adds one comprehensive Playwright test that walks a fresh Operations
Manager session through all 8 Demo Guide steps performing the real
action at each one, then restores the environment. Writing it surfaced
a real desktop layout bug: the Demo Guide's fixed side panel overlapped
main content with no reflow, making the return form's "Review return"
button unclickable while the guide was open at ordinary viewport widths.
Fixed by reserving layout space via a guide-open class. Also adds mobile
bottom-sheet, keyboard-reachability, and console-error checks.
2026-08-03 15:12:29 +02:00
NuklearRabbit 65835ea40a docs: record Unraid deployment evidence for integration/audit/about batch 2026-08-03 15:02:37 +02:00
NuklearRabbit 5fa4fe0811 feat(demo): plain-language integration status, richer audit, reset integrity
Integration status badges across Dashboard/Automation now show honest
plain-language labels instead of raw backend state strings (and fix a
few states that had no matching CSS colour class at all). Audit trail
gets a "view related events" action reusing the existing correlation_id
filter. About page gains scope/architecture/security/testing sections
and a guided-demo entry point. POST /api/v1/demo/reset now runs and
records a server-side scenario-integrity check. Also fixes a second real
race condition (caught by the return-review e2e test): the odometer
scenario pre-fill now resolves before ReturnForm mounts instead of
patching its value in after the fact.
2026-08-03 15:00:11 +02:00
NuklearRabbit cf9a889547 docs: record Unraid deployment evidence for demo-legibility batch 2026-08-03 14:42:49 +02:00
NuklearRabbit ddc3a98e4b feat(demo): make return, data-quality and knowledge flows demo-legible
Fixes a real honesty bug in Knowledge.tsx (body copy named "RAGcore" while
the active provider is the demo one) and a second real bug discovered
while fixing it: the brief's suggested Dutch questions would silently
return "insufficient evidence" against the English-only demo knowledge
base -- verified empirically and fixed by keeping suggested questions in
English. The return flow now pre-fills the odometer-regression scenario's
suspicious reading instead of asking a visitor to invent one, and links
to automation/audit after committing. Data-quality issues get a shared
plain-language "what's wrong / why it matters" explainer per rule type,
a post-resolution confirmation with audit/vehicle links, and a "demo
scenario's only" list filter. Also fixes a real async race where the
odometer pre-fill could clobber text a visitor had already started typing.
2026-08-03 14:41:02 +02:00
NuklearRabbit 6b864596e0 docs: record Unraid deployment evidence for Demo Guide/scenario overview batch 2026-08-03 14:18:47 +02:00
NuklearRabbit 14c2ad3ee8 fix(demo): wait for post-login redirect before navigating in e2e tests
Two demo-guide.spec.ts tests navigated straight to /scenarios right after
clicking a login button without waiting for the /dashboard redirect to
settle first. This raced harmlessly on localhost but flaked against the
higher-latency Unraid deployment, hitting RequireAuth before the session
was confirmed.
2026-08-03 14:17:44 +02:00
NuklearRabbit 9fff84dc68 feat(demo): add Demo Guide (8-step guided tour) and scenario overview
Adds a compact "Probeer een demonstratiescenario" page listing the 5 named
scenarios with live readiness from the manifest, plus a Demo Guide side
panel (bottom sheet on mobile) that walks an Operations Manager through
all 8 steps with per-step context, live-resolved routes, sessionStorage
progress, and a "Demo opnieuw voorbereiden" restart. Login's guided-demo
CTA now actually opens the guide. Fixes a real mobile topbar overflow the
new guide trigger introduced.
2026-08-03 14:15:15 +02:00
NuklearRabbit c63903cc94 docs: record Unraid deployment evidence for demo entry/manifest/badge batch 2026-08-03 13:48:22 +02:00
NuklearRabbit ac427f4427 feat(demo): add demo manifest, Dutch demo entry, permanent badge and About page
Adds GET /api/v1/demo/manifest as a single source of truth for the demo's
fictional org identity (Northstar Mobility -- surfacing the project's
already-locked tenant name), synthetic-data/reset state, and live scenario
readiness. Rewrites the login screen in Dutch with an honest, no-password
demo entry and a guided-demo entry point, replaces the loud full-width
demo banner with a subtle badge + popover, and adds a compact About page
explaining what's real vs. synthetic vs. not yet connected.
2026-08-03 13:45:55 +02:00
NuklearRabbit 728e380d63 docs: record Unraid deployment evidence for the date-anchoring fix 2026-08-03 13:10:33 +02:00
NuklearRabbit 8989ffb23c fix(demo): anchor seeded dates to the real reset moment
Booking/inspection/maintenance/outbox dates were authored as absolute
timestamps around a fixed 2026-08-01 anchor and never re-anchored at
seed/reset time, so demo scenarios (e.g. BK-DEMO-RETURN) silently drifted
into the past. Every reset now shifts seeded dates by (today - authored
anchor); dashboard's "today" filter uses real wall-clock time instead of
the now-removed frozen demo_today setting. Adds seed-validation tests
proving scenarios S1/S2/S4/S5 are present and internally consistent after
every reset.
2026-08-03 13:08:02 +02:00
NuklearRabbit 7c94eb9e87 docs(demo): audit current demo readiness gaps
Confirms the underlying data/business-logic is already demo-grade (Dutch/
Flemish names, .test emails, believable Belgian towns and RV brands; the
5 requested scenarios already exist as S1/S2/S4/S5/S6 in
docs/13-seed-and-demo-scenarios.md) -- the real gaps are structural: no
guided path, no visible fictional org identity (Northstar Mobility is
already the locked tenant name internally, just never shown), a
reproducible date-anchoring bug (seed dates are absolute and don't move
with reset -- BK-DEMO-RETURN's end date is already in the past as of
today), the knowledge page naming "RAGcore" directly instead of "demo
mode", technical-register integration-status labels, and no About page.
2026-08-03 12:54:27 +02:00
NuklearRabbit e0c7ed6011 docs(release): finalize the recorded commit hash 2026-08-02 07:25:30 +02:00
NuklearRabbit 5b2827eb7e docs(release): record the final commit hash in the evidence summary 2026-08-02 07:24:51 +02:00
NuklearRabbit 8a3a43d4ac docs(release): add final functional-completion acceptance evidence 2026-08-02 07:24:37 +02:00
NuklearRabbit ff118dd66d docs(state): record Batch 5 completion 2026-08-02 07:23:08 +02:00
NuklearRabbit 824048b9d4 fix(deploy): mark setup-scheduled-scan.sh executable
Matches the other deploy/unraid/*.sh scripts; was committed 644 instead
of 755, caught while running it directly against the Unraid deployment.
2026-08-02 07:20:48 +02:00
NuklearRabbit c981aad2a3 docs(release): update contracts and docs for functional-completion changes
Add the new endpoints to contracts/openapi.yaml and docs/05-api-contract.md
(return-preview, the four rule-specific data-quality resolution endpoints,
search, integration status, scheduled-scan), document the role matrix and
the audit before/after exposure in docs/12-security-and-audit.md, document
each rule type's actual resolution flow in docs/07-data-quality.md
(including the deliberate evidence-fingerprint simplification and the
reopened_from/previous_decision recurrence link), document the preview/
commit relationship in docs/08-return-workflow.md, and update README.md's
scope/integration-status/quality-gate sections to match what's actually
implemented and verified now. Also drops docs/05-api-contract.md's mention
of GET /api/v1/system/status, which was never implemented.
2026-08-02 07:10:37 +02:00
NuklearRabbit e115031a57 feat(n8n): add scheduled quality-scan workflow
The original docs described two n8n workflows but the repository only ever
shipped one (return-processing); the sketched second workflow (knowledge
sync) depends on RAGcore, which isn't connected here, so it stays deferred.

Add POST /api/v1/integrations/n8n/scheduled-scan (X-Service-Token
protected, same pattern as the return callback), calling the same
run_scan() the manual "Run quality scan" UI action uses and recording a
service-actor data_quality_scan_run audit event. run_scan() already only
creates an issue for a condition without one open, so overlapping triggers
do no duplicate domain work.

n8n/mobilityops-scheduled-quality-scan.json (hourly schedule + manual test
trigger, both feeding the same HTTP call) ships "active": false so it can't
fire anywhere until deliberately published. Verified live against the
local n8n instance via the Manual test trigger: full green execution, and
the resulting data_quality_scan_run audit event (actor_type=service,
actor_label="n8n scheduled scan") confirms the real round trip, not just a
contract test. deploy/unraid/setup-scheduled-scan.sh mirrors the existing
return-workflow publish script for the shared Unraid n8n.
2026-08-02 06:59:17 +02:00
NuklearRabbit ec8f809497 fix(automation): recover stale outbox delivering leases
_claim_due_events flipped rows to 'delivering' and committed before the
HTTP call; if the process died between that commit and the outcome-
recording transaction, the row stayed 'delivering' forever with no reclaim
path -- a real gap, not previously documented as an accepted limitation.

Give each claim a lease deadline (reusing next_attempt_at, since it's only
otherwise meaningful for pending-status backoff scheduling) and sweep
expired leases back to pending at the start of every dispatch cycle, before
claiming new work. attempts is preserved so the count still reflects true
history. Only leases past their deadline are touched, so a still-alive
worker mid-delivery is never disturbed or double-processed.
2026-08-02 06:59:07 +02:00
NuklearRabbit 4a0a4d1cb4 docs(state): record Batch 4 completion 2026-08-02 06:42:54 +02:00
NuklearRabbit 1867828a9d feat(demo): add reset UI and wire truthful integration status into pages
Add a "Reset demo data" action to the sidebar (Operations Manager only,
explicit confirmation, progress, error handling) -- POST /api/v1/demo/reset
already existed and was already role-gated server-side, but had no UI
trigger. Reset invalidates the acting session server-side, so the flow
signs the user out and returns them to login afterward.

Wire the new GET /api/v1/integrations/status into Automation.tsx and
Dashboard.tsx so both show the aggregate n8n state instead of the most
recent event's status, and the MCP Hub card reflects the actual
registration_enabled setting instead of a hardcoded "not configured" label.
2026-08-02 06:42:27 +02:00
NuklearRabbit 4437b8792a feat(search): add role-aware backend search and truthful n8n status
Two new endpoints. GET /api/v1/search returns bounded typed results
(vehicle, booking, data-quality-issue, application section) instead of the
frontend guessing routes from regex patterns against public-ref prefixes;
data-quality and manager-only sections are filtered server-side by role,
and customers are deliberately never returned since no customer detail
route exists in this PoC.

GET /api/v1/integrations/status aggregates outbox delivery counts
(pending/delivering/succeeded/failed) into a single truthful n8n state
(disabled/unavailable/degraded/operational/no_evidence) instead of the UI
showing whichever status the single most recent event happened to be in --
a vehicle_status_conflict-style bug where one stale failure or one lucky
success could misreport the dispatcher's actual health.

Also fixes a real config gap this surfaced: MCP_HUB_REGISTRATION_ENABLED
was documented in .env.example but had no corresponding Settings field, so
it was silently ignored by pydantic-settings' extra="ignore" and never
actually read anywhere in the codebase.
2026-08-02 06:41:56 +02:00
NuklearRabbit 4bc3e33953 docs(state): record Batch 3 completion 2026-08-02 06:16:50 +02:00
NuklearRabbit 477b5e7ce9 feat(quality): add resolution UI for all five rule types and manual scan
DataQualityIssueDetail showed raw JSON as the primary interface for four of
five rule types, with no resolution surface beyond generic defer/reject.
Add a bounded panel per rule type (provide missing fields, retain/correct
an odometer reading, block one of two overlapping bookings, apply the
recommended vehicle status) wired to the new backend endpoints, and move
raw evidence behind a <details> disclosure. Add a "Run quality scan" action
to the workbench (confirmation, progress, per-rule result counts, auto
refresh) -- the endpoint already existed but had no UI trigger.
2026-08-02 06:16:14 +02:00
NuklearRabbit 6e227a214a feat(quality): complete bounded resolution flows and typed snapshots
Two real gaps here: related-entity snapshots were typed by inferring from
the issue's rule_type (get_issue always resolved related refs as "customer"
for duplicates and "vehicle" for everything else), so a booking_overlap
issue's related bookings silently failed to resolve; and defer/reject were
the only resolution actions for 4 of 5 rule types, leaving
missing_required_field, odometer_regression, booking_overlap and
vehicle_status_conflict with no real path beyond a generic reject.

Type related entities from their own public-reference prefix (CUS-/MO-/
BK-/INSP-) instead of the issue's rule_type, and add typed snapshots for
booking and inspection. Add one bounded resolution endpoint per remaining
rule type: provide-fields (re-runs the missing-field check, resolves only
once nothing required is missing), resolve-odometer-regression (retain
canonical or correct the reading -- never silently lowers canonical
mileage), resolve-overlap (blocks one of the two bookings, re-verifies no
overlap remains), apply-recommended-status (one authoritative
recommendation function shared with re-validation). Manual scan now takes
an actor and audits data_quality_scan_run. Reintroduced evidence after a
non-open decision links the new issue back to the prior one
(evidence.reopened_from / previous_decision) instead of looking like a
fresh, undecided problem.
2026-08-02 06:16:07 +02:00
NuklearRabbit 9bd6bea759 docs(state): record Batch 2 completion 2026-08-02 05:34:03 +02:00
NuklearRabbit 7e34f55005 feat(audit): expose structured before/after evidence
audit_events already stored before_json/after_json, but the API and UI only
ever surfaced metadata -- the audit trail could say something happened but
never show what changed. Add before/after to AuditEventOut, resolve a safe
entity_ref/entity_link for vehicle/booking/data-quality-issue entities
(customer stays label-only; no customer detail route exists in this PoC),
and render a human-readable change summary in the UI with the raw
before/after/metadata JSON kept behind a <details> disclosure rather than
shown by default.
2026-08-02 05:33:23 +02:00
NuklearRabbit f5212959b4 feat(returns): add authoritative return preview
The return-review step predicted operational consequences independently in
the frontend, and got it wrong: damage or a technical warning was described
as routing to "maintenance" when the actual domain rule (returns.py) routes
it to "blocked", and the no-contradiction case was described as becoming
"available" when the vehicle actually always goes to "cleaning" first
(only reaching "maintenance" if the service threshold was crossed).

Extract the evaluation returns.py already performed inline into a pure
evaluate_return() function with no writes -- resulting status (with an
explanation), odometer regression, would-create-quality-issue,
next-booking-risk -- and share it between a new non-mutating
POST /bookings/{ref}/return-preview endpoint and the existing commit path,
so preview and commit can never drift apart again. The result screen also
now distinguishes local commit success from n8n delivery (still queued/
unconfirmed) instead of implying both succeeded, and links to any created
quality issue for Operations Manager.
2026-08-02 05:33:12 +02:00
NuklearRabbit 62ac9f825c docs(state): record Batch 1 completion and server verification 2026-08-02 05:00:50 +02:00
NuklearRabbit bdc58f396e fix(e2e): stop hardcoding localhost:8128 for API resets
demo.spec.ts, ui-redesign.spec.ts and interactive-elements.spec.ts all
hardcoded an absolute http://localhost:8128 base for their demo-reset
helpers, which silently pointed at the local dev API even when the suite
was pointed at a different target via MOBILITYOPS_PUBLIC_URL -- discovered
while running the suite against the actual Unraid deployment, where the
reset call kept hitting the local machine instead of the server and left
BK-DEMO-RETURN in whatever state a prior run had left it. Use relative
paths so the request fixture's configured baseURL is honoured everywhere.
2026-08-02 04:59:02 +02:00
NuklearRabbit e1f0ad8431 test(app): cover Batch 1 functional-completion regressions
Add Playwright coverage for the fixes in this batch: vehicle search actually
changes the rendered rows, booking pagination stays within 25 rows and page
2 differs from page 1, session survives a refresh, logout invalidates the
server session, direct navigation without a session redirects to login, and
Rental Employee is blocked from manager-only pages both in the UI (hidden
nav, restricted message) and directly against the API (403).
2026-08-02 04:52:07 +02:00
NuklearRabbit 760f3b6ee2 fix(auth): enforce role boundaries on data quality and audit
The data-quality workbench (list, detail, defer, reject) and the audit trail
had no role gate at all beyond authentication -- confirmed live, a Rental
Employee session could list and resolve data-quality issues and read the
full audit trail through both the API and the UI, with only merge-customers
and scan already restricted.

Per the role matrix, both areas are Operations-Manager-only. Gate the
remaining data-quality and audit endpoints with require_operations_manager,
hide their nav items for Rental Employee, show the same restricted-message
pattern Automation.tsx already used for direct URL access, and stop the
dashboard from linking into now-restricted areas for that role.
2026-08-02 04:52:01 +02:00
NuklearRabbit ffc88e33b4 feat(auth): add server-backed demo sessions
The browser treated sessionStorage as the source of truth for the logged-in
user and never verified or invalidated the server-side session cookie: no
GET /api/v1/demo/session or POST /api/v1/demo/logout endpoint existed, and a
central 401 handler was defined but never wired up.

Add both endpoints; the session-check response is marked Cache-Control:
no-store to avoid the browser serving a stale "authenticated" response right
after logout. AuthProvider now verifies against the server on every mount
(sessionStorage only caches presentation state to avoid a login-screen
flash), subscribes to a central 401 listener on the API client, and
RequireAuth shows a loading state during verification instead of flashing
protected content or the wrong role.
2026-08-02 04:51:54 +02:00
NuklearRabbit 56a65b2364 fix(ui): repair vehicle and booking list filtering and pagination
Vehicles and Bookings both computed a filtered (and, for bookings, paginated)
result but rendered the original unfiltered array in the table body, so
search, status and attention filters had no visible effect and every booking
rendered on every page regardless of the 25-row limit. Render the computed
result instead, and clamp the current booking page when a filter change
shrinks the result set below it.
2026-08-02 04:51:48 +02:00
NuklearRabbit 063a8f9a2d docs(audit): record functional completion findings
Independent audit of the design/mobilityops-premium-ui source and the live
Unraid deployment: confirms the two named list-rendering defects plus
sessionStorage-authoritative auth, a missing role gate on the data-quality
workbench and audit trail, a non-authoritative return preview, raw-JSON
issue evidence, a blind client-side search, single-event integration status,
and an unbounded delivering-lease window in the outbox dispatcher.
2026-08-02 04:51:43 +02:00
NuklearRabbit 938a739dfe docs(deploy): record current Unraid baseline
Capture container topology, deployed revision, migration head, volumes,
network and env-var names on the existing review deployment before any
functional-completion changes, per the audit brief's server-first workflow.
2026-08-02 04:51:43 +02:00
438 changed files with 43697 additions and 4629 deletions
+57
View File
@@ -0,0 +1,57 @@
.git
.gitea
.github
.gitignore
.agents
.codex
.claude
.dyad
.idea
.vscode
.vs
.venv
__pycache__
.pytest_cache
.ruff_cache
.mypy_cache
node_modules
frontend/node_modules
frontend/dist
dist
artifacts
docs
deploy
n8n/**
!n8n/workflows/
!n8n/workflows/**
frontend
*.tgz
*.tar.gz
coverage
playwright-report
test-results
.env
.env.*
!.env.example
*.key
*.pem
*.p12
*.pfx
secrets
credentials
.state
data
backups
*.db
*.db-shm
*.db-wal
*.sqlite
*.sqlite-shm
*.sqlite-wal
*.log
*.tmp
*.zip
*.tar
*.tar.gz
.DS_Store
Thumbs.db
+92 -4
View File
@@ -2,14 +2,82 @@ COMPOSE_PROJECT_NAME=mobilityops
MOBILITYOPS_ENV=development
MOBILITYOPS_DEMO_MODE=true
MOBILITYOPS_PUBLIC_URL=http://localhost:1228
MOBILITYOPS_API_URL=http://localhost:8128
# Build-time API origin baked into the web bundle. Leave empty: the SPA calls its own
# origin and nginx proxies /api to the API (required by the CSP connect-src 'self').
VITE_API_BASE_URL=
DATABASE_URL=postgresql+psycopg://mobilityops:mobilityops@db:5432/mobilityops
POSTGRES_DB=mobilityops
POSTGRES_USER=mobilityops
POSTGRES_PASSWORD=mobilityops
# Signs session cookies. With MOBILITYOPS_ENV=production the API refuses to start while
# this (or MOBILITYOPS_CALLBACK_TOKEN) still holds its placeholder value.
APP_SECRET=replace-in-production
DEMO_TODAY=2026-08-01
TZ=Europe/Brussels
# Session cookie Secure flag. Development on localhost may use false; production startup
# requires both an HTTPS public URL and this value set to true.
SESSION_COOKIE_SECURE=false
# Optional OpenID Connect login. Public demo role buttons remain available when enabled.
OIDC_ENABLED=false
OIDC_PROVIDER_NAME=Organisatieaccount
OIDC_ISSUER_URL=
OIDC_CLIENT_ID=
OIDC_CLIENT_SECRET=
OIDC_REDIRECT_URI=
OIDC_ALLOWED_EMAIL_DOMAINS=
OIDC_AUTO_PROVISION=true
OIDC_DEFAULT_ROLE=rental_employee
# Observability: JSON logs are always enabled. Set a token only if /metrics is exposed
# outside the private Compose network; Prometheus can send it as a bearer token.
LOG_LEVEL=INFO
# Required when the observability profile is enabled. Keep private and high entropy.
METRICS_BEARER_TOKEN=replace-me-private-metrics-token
GRAFANA_ADMIN_USER=admin
GRAFANA_ADMIN_PASSWORD=change-me-before-start
# Alertmanager sends every firing/resolved alert and the continuous watchdog to this
# owner-managed receiver. Production must route it to a channel that is actually watched.
ALERTMANAGER_WEBHOOK_URL=https://n8n.itworx.tech/webhook/mobilityops-alerts
# Verified scheduled PostgreSQL backups (Unraid override).
BACKUP_INTERVAL_SECONDS=86400
BACKUP_RETENTION_DAYS=30
BACKUP_MINIMUM_COPIES=7
# Restore the newest dump into a disposable database at least weekly. Backup health also
# requires a successful drill within eight days.
BACKUP_RESTORE_DRILL_INTERVAL_SECONDS=604800
# Set both values to copy every verified backup to an independently mounted path.
BACKUP_SECONDARY_DESTINATION=
MOBILITYOPS_BACKUP_DIR=./backups/postgres
MOBILITYOPS_BACKUP_SECONDARY_DIR=./backups/offsite
# Optional real off-site copy through the official rclone OneDrive adapter. OAuth state
# lives only in MOBILITYOPS_RCLONE_CONFIG_DIR and must never be committed.
BACKUP_OFFSITE_INTERVAL_SECONDS=900
RCLONE_ONEDRIVE_REMOTE=onedrive
RCLONE_ONEDRIVE_PATH=FleetOps/backups
MOBILITYOPS_RCLONE_CONFIG_DIR=./.secrets/rclone
MOBILITYOPS_OFFSITE_VERIFY_DIR=./backups/offsite-verify
# Privacy governance defaults.
PRIVACY_MINIMUM_BOOKING_RETENTION_DAYS=30
PRIVACY_AUDIT_RETENTION_DAYS=2555
PRIVACY_AUDIT_EXPORT_MAX_ROWS=10000
# Demo presentation (fictional org identity, badge/manifest, reset safety valve).
# DEMO_ALLOW_RESET=false permanently disables POST /api/v1/demo/reset (403), independent
# of role -- a safety valve for any environment where the dataset must not be rebuildable.
DEMO_ORGANIZATION_NAME=Northstar Mobility
DEMO_TIMEZONE=Europe/Brussels
DEMO_ALLOW_RESET=true
# Prevent public visitors from repeatedly rebuilding the shared dataset. Concurrent
# resets are always rejected using both process and PostgreSQL advisory locks.
DEMO_RESET_COOLDOWN_SECONDS=60
# Operational mode: set MOBILITYOPS_DEMO_MODE=false and provide the first manager.
# Keep these values in a secret store or an untracked production .env file.
INITIAL_ADMIN_EMAIL=
INITIAL_ADMIN_PASSWORD=
INITIAL_ADMIN_DISPLAY_NAME=Operations Manager
# n8n
N8N_BASE_URL=http://n8n:5678
@@ -18,18 +86,38 @@ N8N_ENCRYPTION_KEY=replace-me
N8N_BASIC_AUTH_ACTIVE=true
N8N_BASIC_AUTH_USER=admin
N8N_BASIC_AUTH_PASSWORD=change-me
# Recipient and sender used by the importable alert workflow. Configure real,
# monitored addresses in the deployment environment; repository defaults stay synthetic.
MOBILITYOPS_ALERT_RECIPIENT=alerts@example.test
MOBILITYOPS_ALERT_SENDER=n8n@example.test
MOBILITYOPS_CALLBACK_TOKEN=replace-me-n8n-callback-token
# Sent as the X-Fleet-Ops-Trigger-Token header when Fleet Ops calls the n8n return-
# processing webhook, so the webhook trigger can require Header Auth instead of being
# publicly callable by anyone who discovers the URL. Must match the value stored in
# n8n's "Fleet Ops Webhook Trigger Token" Header Auth credential.
MOBILITYOPS_WEBHOOK_TRIGGER_TOKEN=replace-me-n8n-webhook-trigger-token
# RAGcore integration
KNOWLEDGE_PROVIDER=demo
RAGCORE_BASE_URL=http://ragcore-api:8000
# Optional existing Docker network used by hosted deployments to reach RAGcore through
# its private service alias instead of exposing RAGcore on the LAN.
RAGCORE_DOCKER_NETWORK=
RAGCORE_TENANT=northstar-mobility-demo
RAGCORE_WORKSPACE=mobilityops
RAGCORE_COLLECTION=internal-procedures
RAGCORE_API_TOKEN=
# UUID of the RAGcore knowledge space procedures were synced into (see workflow 3).
RAGCORE_SPACE_ID=
# Skip the slower generation endpoint temporarily after a timeout/non-2xx response and
# use the still-grounded extractive search fallback immediately.
RAGCORE_ANSWERS_CIRCUIT_BREAKER_SECONDS=60
# ITWorx MCP Hub integration
# ITWorx MCP Hub integration. Registration itself is catalog-driven on the Hub's own
# side (it reconciles its catalog into the gateway; Fleet Ops never pushes a
# registration call) -- MCP_HUB_BASE_URL is only used here for an honest reachability
# health check surfaced on the integration status page.
MCP_HUB_REGISTRATION_ENABLED=false
MCP_HUB_BASE_URL=http://itworx-mcp-hub:8000
MCP_HUB_SERVICE_TOKEN=replace-me-mcp-hub-token
MCP_PROVIDER_ID=mobilityops
MCP_PROVIDER_ID=fleet-ops
+10
View File
@@ -1,4 +1,14 @@
* text=auto eol=lf
*.sh text eol=lf
*.ps1 text eol=crlf
*.png binary
*.jpg binary
*.jpeg binary
*.webp binary
*.zip binary
# Generated operational evidence is not part of a source release archive.
/artifacts export-ignore
/PROJECT_STATE.md export-ignore
/MASTER_BUILD_PROMPT.md export-ignore
/FILE_INDEX.md export-ignore
+44
View File
@@ -0,0 +1,44 @@
name: MobilityOps browser canary
on:
schedule:
- cron: "37 4 * * *"
workflow_dispatch:
concurrency:
group: mobilityops-browser-canary
cancel-in-progress: true
permissions:
contents: read
jobs:
chromium:
runs-on: linux-validation
timeout-minutes: 15
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: 22
cache: npm
cache-dependency-path: frontend/package-lock.json
- name: Install locked Chromium runtime
working-directory: frontend
run: |
npm ci --no-audit --no-fund
npx playwright install --with-deps chromium
- name: Run non-destructive production canary
working-directory: frontend
env:
MOBILITYOPS_PUBLIC_URL: https://fleetops.itworx.tech
run: npx playwright test --config=playwright.live.config.ts --project=chromium
- name: Upload failure evidence
if: failure()
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3; Gitea-compatible artifact protocol
with:
name: browser-canary-failure
path: |
frontend/playwright-live-report
frontend/test-results
if-no-files-found: ignore
+141
View File
@@ -0,0 +1,141 @@
name: MobilityOps acceptance
on:
pull_request:
concurrency:
group: mobilityops-ci-${{ gitea.repository }}-${{ gitea.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
acceptance:
# Never execute code from an untrusted public fork on the private runner.
if: ${{ gitea.event.pull_request.head.repo.full_name == gitea.repository }}
runs-on: linux-validation
timeout-minutes: 60
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0
- name: Determine validation scope
id: scope
shell: bash
run: |
base_sha="${{ gitea.event.pull_request.base.sha }}"
if git diff --quiet "$base_sha...HEAD" -- . ':(exclude).gitea/workflows/**'; then
echo "full=false" >> "$GITEA_OUTPUT"
echo "Workflow-only change: the protected lightweight gate is sufficient."
else
echo "full=true" >> "$GITEA_OUTPUT"
echo "Product or test change: running the complete acceptance gate."
fi
- name: Secret scan
shell: bash
run: |
set -euo pipefail
repository="$PWD"
source="file:///repo"
workspace=(-v "$repository:/repo" -w /repo)
if docker inspect "${HOSTNAME:-}" >/dev/null 2>&1; then
source="file://$repository"
workspace=(--volumes-from "$HOSTNAME" -w "$repository")
fi
docker run --rm "${workspace[@]}" \
ghcr.io/trufflesecurity/trufflehog@sha256:7104dbb84d1ad2f5f6fa1134e92c6aa6f701f0a4ac2efd5a4c5c96225d899fe3 \
git "$source" --fail --no-update --github-actions --only-verified
- name: Backend tests in isolated PostgreSQL stack
if: steps.scope.outputs.full == 'true'
run: sh scripts/run-isolated-tests.sh
- name: Backend static and contract checks
if: steps.scope.outputs.full == 'true'
run: |
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --build --rm api ruff check app tests
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --rm api mypy app
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --rm \
api python scripts/check-contracts.py
python scripts/check-source-budgets.py
- name: Build production API image for vulnerability scan
if: steps.scope.outputs.full == 'true'
run: |
docker build --target runtime --build-arg VCS_REF="$GITHUB_SHA" \
--tag mobilityops-api-ci --file backend/Dockerfile .
- name: Production API image vulnerability scan (HIGH/CRITICAL)
if: steps.scope.outputs.full == 'true'
run: bash scripts/scan-ci-image.sh mobilityops-api-ci
- name: Build production web image for vulnerability scan
if: steps.scope.outputs.full == 'true'
run: |
docker build --build-arg VCS_REF="$GITHUB_SHA" \
--tag mobilityops-web-ci frontend
- name: Production web image vulnerability scan (HIGH/CRITICAL)
if: steps.scope.outputs.full == 'true'
run: bash scripts/scan-ci-image.sh mobilityops-web-ci
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
if: steps.scope.outputs.full == 'true'
with:
node-version: 22
cache: npm
cache-dependency-path: frontend/package-lock.json
- name: Install frontend dependencies once
if: steps.scope.outputs.full == 'true'
working-directory: frontend
run: npm ci --no-audit --no-fund
- name: Frontend lint, build, budget and dependency audit
if: steps.scope.outputs.full == 'true'
working-directory: frontend
run: |
npm run lint
npm run build
npm run budget
npm audit --audit-level=high
- name: Start the demo stack
if: steps.scope.outputs.full == 'true'
run: |
cp .env.example .env
# Acceptance tests intentionally reset their isolated demo dataset per scenario.
printf '\nDEMO_RESET_COOLDOWN_SECONDS=0\n' >> .env
docker compose -p mobilityops-e2e up --build -d db api web
docker network connect mobilityops-e2e_mobilityops "$HOSTNAME"
for _attempt in $(seq 1 60); do
if curl -fsS http://web/health/ready >/dev/null 2>&1; then break; fi
sleep 2
done
curl -fsS http://web/health/ready
docker compose -p mobilityops-e2e exec -T api python -m app.cli seed --reset
- name: Install acceptance browsers
if: steps.scope.outputs.full == 'true'
working-directory: frontend
run: npx playwright install --with-deps chromium
- name: Run browser acceptance and live smoke suites
if: steps.scope.outputs.full == 'true'
working-directory: frontend
env:
MOBILITYOPS_PUBLIC_URL: http://web
run: |
# Pixel baselines are workstation/rendering specific; keep the PR gate functional.
npx playwright test --grep-invert "visual hierarchy"
npx playwright test --config=playwright.live.config.ts --project=chromium
- name: Run concurrent persisted-read smoke
if: steps.scope.outputs.full == 'true'
run: python scripts/run-readonly-load-smoke.py --base-url http://web
- name: Upload Playwright report
if: failure() && steps.scope.outputs.full == 'true'
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3; Gitea-compatible artifact protocol
with:
name: playwright-report
path: |
frontend/playwright-report
frontend/playwright-live-report
if-no-files-found: ignore
- name: Stack logs on failure
if: failure() && steps.scope.outputs.full == 'true'
run: docker compose -p mobilityops-e2e logs --tail=200 api web
- name: Remove CI stacks
if: always() && steps.scope.outputs.full == 'true'
run: |
docker network disconnect mobilityops-e2e_mobilityops "$HOSTNAME" 2>/dev/null || true
docker compose -p mobilityops-e2e down -v --remove-orphans
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml down -v --remove-orphans
+31
View File
@@ -0,0 +1,31 @@
name: MobilityOps live probe
on:
schedule:
- cron: "7 * * * *"
workflow_dispatch:
concurrency:
group: mobilityops-live-probe
cancel-in-progress: true
permissions:
contents: read
jobs:
public-probe:
runs-on: linux-validation
timeout-minutes: 3
steps:
- name: Verify HTTPS readiness and certificate horizon
run: |
curl --fail --silent --show-error --retry 3 https://fleetops.itworx.tech/health/ready
openssl s_client -servername fleetops.itworx.tech -connect fleetops.itworx.tech:443 </dev/null 2>/dev/null \
| openssl x509 -checkend 1209600 -noout
- name: Report successful external heartbeat
env:
HEARTBEAT_URL: ${{ secrets.LIVE_CANARY_HEARTBEAT_URL }}
run: |
if [ -n "$HEARTBEAT_URL" ]; then
curl --fail --silent --show-error --retry 3 "$HEARTBEAT_URL"
fi
+119
View File
@@ -0,0 +1,119 @@
name: Managed validation
on:
push:
branches: [master]
workflow_dispatch:
inputs:
profile:
description: Allowlisted validation profile
required: true
default: full
type: choice
options: [test, lint, typecheck, build, security, full]
permissions:
contents: read
concurrency:
group: managed-validation-${{ gitea.repository }}-${{ gitea.ref }}
cancel-in-progress: true
jobs:
full:
name: full
runs-on: linux-validation
timeout-minutes: 30
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Validate repository with a bounded profile
shell: bash
env:
REQUESTED_PROFILE: ${{ inputs.profile }}
run: |
set -euo pipefail
profile="${REQUESTED_PROFILE:-full}"
case "${profile}" in
test|lint|typecheck|build|security|full) ;;
*) echo "Profile is not allowlisted" >&2; exit 2 ;;
esac
git diff --check
if git grep -nE '^(<<<<<<< |=======$|>>>>>>> )' -- . ':!*.lock' ':!*.patch'; then
echo "Unresolved merge markers detected" >&2
exit 1
fi
if [[ -f pyproject.toml || -f requirements.txt ]]; then
# Compile only tracked Python sources. Running compileall after a
# Node install would otherwise traverse node_modules and turn a
# lightweight baseline into a large runner workload.
git ls-files -z '*.py' | xargs -0 -r python -m py_compile
if [[ -f uv.lock ]]; then
python -m venv "${RUNNER_TEMP}/managed-uv"
uv_python="${RUNNER_TEMP}/managed-uv/bin/python"
"${uv_python}" -m pip install --disable-pip-version-check uv==0.10.0
managed_uv="${RUNNER_TEMP}/managed-uv/bin/uv"
export UV_PROJECT_ENVIRONMENT="${RUNNER_TEMP}/managed-project-venv"
"${managed_uv}" sync --locked
export PATH="${UV_PROJECT_ENVIRONMENT}/bin:${PATH}"
if [[ "${profile}" == test || "${profile}" == full ]]; then
if "${managed_uv}" run python -c 'import pytest' 2>/dev/null; then
"${managed_uv}" run python -m pytest
fi
fi
if [[ "${profile}" == lint || "${profile}" == full ]]; then
if "${managed_uv}" run python -c 'import ruff' 2>/dev/null; then
"${managed_uv}" run python -m ruff check .
fi
fi
elif [[ -f requirements.txt ]]; then
python -m venv "${RUNNER_TEMP}/managed-python"
managed_python="${RUNNER_TEMP}/managed-python/bin/python"
"${managed_python}" -m pip install --disable-pip-version-check -r requirements.txt
export PATH="${RUNNER_TEMP}/managed-python/bin:${PATH}"
if [[ "${profile}" == test || "${profile}" == full ]]; then
if "${managed_python}" -c 'import pytest' 2>/dev/null; then
"${managed_python}" -m pytest
fi
fi
fi
fi
# Prepare Python before invoking Node scripts. Polyglot repositories
# commonly delegate their test script to Python and need the managed
# virtual environment to be active first.
if [[ -f package.json ]]; then
corepack enable
if [[ -f pnpm-lock.yaml ]]; then
pnpm install --frozen-lockfile
[[ "${profile}" == test || "${profile}" == full ]] && pnpm --if-present test
[[ "${profile}" == lint || "${profile}" == full ]] && pnpm --if-present lint
[[ "${profile}" == typecheck || "${profile}" == full ]] && pnpm --if-present typecheck
[[ "${profile}" == build || "${profile}" == full ]] && pnpm --if-present build
elif [[ -f package-lock.json ]]; then
npm ci
[[ "${profile}" == test || "${profile}" == full ]] && npm run --if-present test
[[ "${profile}" == lint || "${profile}" == full ]] && npm run --if-present lint
if [[ "${profile}" == typecheck || "${profile}" == full ]]; then
npm run --if-present typecheck
fi
[[ "${profile}" == build || "${profile}" == full ]] && npm run --if-present build
fi
fi
if [[ -f go.mod ]]; then
if [[ "${profile}" == test || "${profile}" == build || "${profile}" == full ]]; then
go test ./...
fi
fi
if [[ -f Cargo.toml ]]; then
if [[ "${profile}" == test || "${profile}" == build || "${profile}" == full ]]; then
cargo test --locked
fi
fi
if compgen -G '*.sln' >/dev/null; then
if [[ "${profile}" == test || "${profile}" == build || "${profile}" == full ]]; then
dotnet test --configuration Release
fi
fi
+50
View File
@@ -0,0 +1,50 @@
name: MobilityOps release evidence
on:
push:
tags: ["v*"]
jobs:
release-evidence:
runs-on: linux-validation
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Build commit-labelled release images
run: |
docker build --target runtime --build-arg VCS_REF="$GITHUB_SHA" --tag mobilityops-api-release --file backend/Dockerfile .
docker build --build-arg VCS_REF="$GITHUB_SHA" --tag mobilityops-web-release frontend
docker build --build-arg VCS_REF="$GITHUB_SHA" --tag mobilityops-backup-tools-release --file deploy/unraid/Dockerfile.backup-tools .
- name: Scan all release images
run: |
for image in mobilityops-api-release mobilityops-web-release mobilityops-backup-tools-release; do
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
-v mobilityops-release-trivy:/root/.cache/ \
aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 \
image --scanners vuln --severity HIGH,CRITICAL \
--ignore-unfixed --exit-code 1 "$image"
done
- name: Generate CycloneDX SBOMs with the pinned scanner image
run: |
for component in api web backup-tools; do
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
-v "$PWD:/work" -w /work \
aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 \
image --format cyclonedx --output "mobilityops-${component}-sbom.cdx.json" \
"mobilityops-${component}-release"
done
- name: Record immutable image metadata
run: |
docker image inspect mobilityops-api-release > mobilityops-api-image.json
docker image inspect mobilityops-web-release > mobilityops-web-image.json
docker image inspect mobilityops-backup-tools-release > mobilityops-backup-tools-image.json
python scripts/generate-release-provenance.py
sha256sum mobilityops-*-sbom.cdx.json mobilityops-*-image.json release-provenance.json > SHA256SUMS
- name: Upload release evidence
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3; Gitea-compatible artifact protocol
with:
name: mobilityops-${{ github.ref_name }}-evidence
path: |
mobilityops-*-sbom.cdx.json
mobilityops-*-image.json
release-provenance.json
SHA256SUMS
+42
View File
@@ -0,0 +1,42 @@
name: MobilityOps security
on:
schedule:
- cron: "17 3 * * 1"
workflow_dispatch:
concurrency:
group: mobilityops-security
cancel-in-progress: true
permissions:
contents: read
jobs:
images:
runs-on: linux-validation
timeout-minutes: 30
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0
- name: Build production images once
run: |
docker build --target runtime --build-arg VCS_REF="$GITHUB_SHA" \
--tag mobilityops-api-ci --file backend/Dockerfile .
docker build --build-arg VCS_REF="$GITHUB_SHA" \
--tag mobilityops-web-ci frontend
- name: Scan production images for fixed HIGH and CRITICAL vulnerabilities
run: |
for image in mobilityops-api-ci mobilityops-web-ci; do
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
docker.io/aquasec/trivy@sha256:be1190afcb28352bfddc4ddeb71470835d16462af68d310f9f4bca710961a41e \
image --severity HIGH,CRITICAL --exit-code 1 --ignore-unfixed --no-progress "$image"
done
- name: Scan repository secrets and misconfiguration
uses: docker://docker.io/aquasec/trivy@sha256:be1190afcb28352bfddc4ddeb71470835d16462af68d310f9f4bca710961a41e
with:
args: fs --scanners misconfig,secret --exit-code 1 --no-progress .
- name: Remove temporary image tags
if: always()
run: docker image rm mobilityops-api-ci mobilityops-web-ci || true
+56 -6
View File
@@ -1,16 +1,66 @@
# Secrets and local configuration
.env
.venv/
.env.*
!.env.example
*.pem
*.key
*.p12
*.pfx
secrets/
credentials/
# Python
__pycache__/
*.py[cod]
.pytest_cache/
.mypy_cache/
.ruff_cache/
.mypy_cache/
.venv/
.coverage
htmlcov/
*.egg-info/
# Frontend and test output
node_modules/
dist/
frontend/node_modules/
frontend/dist/
coverage/
playwright-report/
test-results/
*.pyc
.DS_Store
*.tsbuildinfo
# Runtime data and local infrastructure state
.state/
data/
backups/local/
*.db
*.db-shm
*.db-wal
*.sqlite
*.sqlite-shm
*.sqlite-wal
*.log
*.tmp
# Generated release/design evidence. Maintained documentation belongs in docs/.
artifacts/**/final-summary.md
artifacts/deployment/
artifacts/design-validation/current/
artifacts/**/screenshots/generated/
# Local AI/editor state
.codex/
.claude/
.agents/
.dyad/
.idea/
.vscode/
*.tsbuildinfo
.vs/
.DS_Store
Thumbs.db
# Archives and local release bundles
*.zip
*.tar
*.tar.gz
*.tgz
+4
View File
@@ -0,0 +1,4 @@
81e3fd63bdbcb2e9c4ae1d709ea46f40537b6f62:backend/tests/test_data_quality.py:generic-api-key:869
0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:93
0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:122
0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:127
+18
View File
@@ -0,0 +1,18 @@
# Changelog
All notable changes are documented here. The project follows semantic release tags for
the deployable PoC; detailed validation evidence remains in `PROJECT_STATE.md`.
## [Unreleased]
- Added contract-drift, accessibility, Firefox smoke and frontend asset-budget gates.
- Added immutable commit-labelled deployment with automatic application rollback.
- Added real PostgreSQL restore drills and routed Alertmanager notifications.
- Added RAGcore generation circuit breaking and retrieval telemetry.
- Added scheduled dependency maintenance, dual-image vulnerability scans and release SBOMs.
## [1.0.0-poc] - 2026-08-21
- Completed the locked Fleet Ops proof of concept: operational core, transactional returns,
data quality, n8n orchestration, grounded RAGcore knowledge, read-only MCP integration,
privacy governance, observability, backup/recovery and full browser acceptance.
-61
View File
@@ -1,61 +0,0 @@
# Binding instructions for Claude
## Operating mode
Work autonomously. Do not ask the user product, architecture, naming, UI, scope or implementation questions already answered in this repository. Record a reasonable assumption in an ADR only when a genuine gap blocks implementation.
Use normal or medium reasoning for routine work. Reserve high reasoning for an actual cross-service design conflict or a persistent failure after evidence-driven debugging.
Continue from milestone to milestone until every acceptance criterion is satisfied. Do not stop merely because one milestone is complete.
## Token and tool efficiency
1. Read `START_HERE.md`, this file, `PROJECT_STATE.md` and `docs/15-build-plan.md` first.
2. Read only the milestone-specific documents named in the build plan.
3. Do not repeatedly reread all documentation.
4. Keep explanations terse; spend effort on implementation and validation.
5. Update `PROJECT_STATE.md` after each milestone with decisions, commands, evidence and the exact next action.
6. Prefer focused file inspection and targeted tests over broad repository scans.
7. Do not generate large speculative documents after implementation starts.
## Scope discipline
- Build the locked PoC only.
- Do not add accounting, payments, public reservations, a generic CRM, inventory, HR, a second RAG stack, a separate MCP server or autonomous write actions.
- Do not modify the RAGcore or ITWorx MCP Hub repositories. Integrate only through documented contracts and configurable adapters.
- Keep critical business rules in MobilityOps code, not in n8n or prompts.
- No direct MCP Hub or RAGcore access to the MobilityOps database.
## Product quality
- No dead buttons, empty routes, unexplained placeholders or hardcoded dashboard metrics.
- Every visible number must derive from persisted data.
- All important state changes must be audited.
- AI must never invent an answer when RAGcore is unavailable or returns insufficient evidence.
- Vehicle returns must commit locally even when n8n is unavailable; orchestration becomes pending and retryable.
- External dependencies require timeouts, bounded retries, health state and graceful degradation.
- Demo data must be clearly labelled synthetic.
## Engineering rules
- Backend: Python, FastAPI, SQLAlchemy 2, Alembic, PostgreSQL.
- Frontend: React, TypeScript, Vite, accessible responsive UI.
- Validation: Pydantic at API boundaries and database constraints for invariants.
- Use UUID primary keys internally and stable human-readable public references.
- Store UTC timestamps; render Europe/Brussels in the UI.
- API paths start with `/api/v1`.
- Use an outbox record for reliable post-commit n8n delivery.
- Tests must cover domain rules, API contracts and the five-minute Playwright demo.
- Generate and commit dependency lockfiles.
## Git workflow
Create one coherent commit per milestone after its validation passes. Suggested message format:
`M1: implement operational core`
Never rewrite already accepted milestone history unless necessary to fix a regression.
## Definition of done
The project is done only when `docs/14-testing-and-acceptance.md` passes from a clean checkout and `PROJECT_STATE.md` contains the final evidence summary.
+12
View File
@@ -0,0 +1,12 @@
# Contributing
MobilityOps contributions must preserve fleet-data privacy, deterministic demo behaviour and the fail-closed integration boundaries documented in `SECURITY.md`.
- use synthetic vehicles, customers, bookings, returns, telematics events and identity claims in tests and screenshots;
- never commit production databases, exports, operator inventories, private service URLs, tokens, backups or generated browser evidence;
- keep external integrations configurable through environment variables or explicit deployment configuration;
- document new personal-data fields, retention, authorization, audit and deletion/export behaviour;
- add negative tests for authentication, authorization, duplicate handling, webhook validation, path containment and stale/unavailable providers;
- review dependencies, images and browser assets for provenance and redistribution rights.
Run the relevant backend, frontend, migration, integration, Compose and managed-validation gates before review. Security-sensitive findings belong through the private process in `SECURITY.md`.
-72
View File
@@ -1,72 +0,0 @@
# File index
- `.env.example`
- `.gitignore`
- `CLAUDE.md`
- `MASTER_BUILD_PROMPT.md`
- `Makefile`
- `PROJECT_STATE.md`
- `README.md`
- `START_HERE.md`
- `backend/Dockerfile`
- `backend/app/__init__.py`
- `backend/app/core/__init__.py`
- `backend/app/core/config.py`
- `backend/app/main.py`
- `backend/pyproject.toml`
- `backend/tests/test_health.py`
- `compose.yaml`
- `contracts/events.schema.json`
- `contracts/mcp-tools.json`
- `contracts/openapi.yaml`
- `contracts/ragcore-contract-assumptions.md`
- `docs/00-product-brief.md`
- `docs/01-scope-and-non-goals.md`
- `docs/02-user-stories.md`
- `docs/03-architecture.md`
- `docs/04-domain-model.md`
- `docs/05-api-contract.md`
- `docs/06-ui-ux.md`
- `docs/07-data-quality.md`
- `docs/08-return-workflow.md`
- `docs/09-ragcore-integration.md`
- `docs/10-mcp-hub-integration.md`
- `docs/11-n8n-integration.md`
- `docs/12-security-and-audit.md`
- `docs/13-seed-and-demo-scenarios.md`
- `docs/14-testing-and-acceptance.md`
- `docs/15-build-plan.md`
- `docs/16-portfolio-case-study.md`
- `docs/17-runbook.md`
- `docs/deferred.md`
- `frontend/Dockerfile`
- `frontend/index.html`
- `frontend/nginx.conf`
- `frontend/package.json`
- `frontend/src/App.tsx`
- `frontend/src/main.tsx`
- `frontend/src/styles.css`
- `frontend/tsconfig.json`
- `frontend/vite.config.ts`
- `knowledge/manifest.json`
- `knowledge/procedures/01-vehicle-checkout.md`
- `knowledge/procedures/02-vehicle-return.md`
- `knowledge/procedures/03-damage-handling.md`
- `knowledge/procedures/04-odometer-anomalies.md`
- `knowledge/procedures/05-cleaning-checklist.md`
- `knowledge/procedures/06-maintenance-escalation.md`
- `knowledge/procedures/07-customer-documents.md`
- `knowledge/procedures/08-privacy.md`
- `knowledge/procedures/09-booking-conflicts.md`
- `knowledge/procedures/10-roles-and-escalation.md`
- `n8n/README.md`
- `n8n/mobilityops-return-processing.json`
- `seed/README.md`
- `seed/bookings.csv`
- `seed/customers.csv`
- `seed/data_quality_issues.csv`
- `seed/generate_seed.py`
- `seed/inspections.csv`
- `seed/maintenance.csv`
- `seed/vehicles.csv`
- `seed/workflow_runs.csv`
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2026 Jens Caers
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
-21
View File
@@ -1,21 +0,0 @@
# Paste this once into Claude Code
Build MobilityOps autonomously from this repository.
First read `START_HERE.md`, `CLAUDE.md`, `PROJECT_STATE.md` and `docs/15-build-plan.md`. Treat the repository specifications and contracts as binding. Do not ask me questions that the files already answer, do not broaden the PoC, and do not stop after a milestone.
Implement the milestones in order. For each milestone:
1. read only the documents listed for that milestone;
2. implement the smallest complete solution;
3. run the specified validation plus relevant regression tests;
4. fix failures using evidence rather than guesses;
5. update `PROJECT_STATE.md` with concise evidence and the exact next step;
6. commit the completed milestone;
7. continue immediately.
MobilityOps owns operational data and business rules. RAGcore owns retrieval and grounded answers. ITWorx MCP Hub owns MCP publication and policy. n8n only orchestrates post-commit workflows. Use configurable adapters and working degraded modes so the core demo remains usable when any external service is absent.
The finished PoC must be reproducible from a clean checkout, have no dead UI, use deterministic synthetic data, support the documented five-minute demo, and satisfy every criterion in `docs/14-testing-and-acceptance.md`.
Keep chat output brief. Spend the available context on code, tests, validation and final evidence. Begin now and continue until the repository is complete.
+25 -6
View File
@@ -1,4 +1,4 @@
.PHONY: up down logs test lint seed reset n8n-setup demo e2e
.PHONY: up down logs test lint contracts seed reset n8n-setup n8n-setup-scan demo e2e live-smoke
up:
docker compose up --build -d
@@ -10,11 +10,17 @@ logs:
docker compose logs -f --tail=200
test:
docker compose run --rm api pytest
sh scripts/run-isolated-tests.sh
lint:
docker compose run --rm api ruff check .
docker compose run --rm api mypy app
docker compose -f compose.yaml -f compose.test.yaml run --build --rm api ruff check app tests
docker compose -f compose.yaml -f compose.test.yaml run --rm api mypy app
cd frontend && npm run lint
contracts:
docker compose -f compose.yaml -f compose.test.yaml run --build --rm \
-v "$(CURDIR):/repo:ro" api python /repo/scripts/check-contracts.py
python scripts/check-source-budgets.py
seed:
docker compose exec api python -m app.cli seed --reset
@@ -26,15 +32,28 @@ reset:
# One-time per environment: imports and activates the n8n return-processing workflow.
# The n8n owner account itself cannot be scripted safely and must be created once at
# http://localhost:5678/setup (any email/password, no verification required) before
# this target's activation takes effect. See docs/17-runbook.md.
# this target's activation takes effect. The workflow also needs the "Fleet Ops Webhook
# Trigger Token" and "Fleet Ops Service Token" Header Auth credentials created manually in
# the n8n UI before it will actually process a return -- see docs/17-runbook.md.
n8n-setup:
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-return-processing.json
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-vehicle-return.json
docker compose exec n8n n8n publish:workflow --id=mobilityops-return-processing
docker compose restart n8n
# One-time per environment: imports and activates the scheduled quality-scan workflow.
# Same owner-account and credential preconditions as n8n-setup above (this workflow only
# needs "Fleet Ops Service Token").
n8n-setup-scan:
docker compose exec n8n n8n import:workflow --input=//imports/workflows/fleet-ops-data-quality-scan.json
docker compose exec n8n n8n publish:workflow --id=mobilityops-scheduled-quality-scan
docker compose restart n8n
# Full deterministic demo bootstrap: build, migrate (automatic on api startup), seed.
demo: up
docker compose exec api python -m app.cli seed --reset
e2e:
cd frontend && npx playwright test
live-smoke:
cd frontend && npx playwright test --config=playwright.live.config.ts
-322
View File
@@ -1,322 +0,0 @@
# Project state
## Publication and Unraid deployment (2026-08-02)
- Unraid deployment is live at `http://192.168.10.150:1236` from
`/mnt/user/appdata/mobilityops`, Compose project `mobilityops`.
- Deployment config commits: `07ab7a3`, `847cd05`, `e1a1c67`, `1e13943`. The accepted
baseline `4bf9afbeff44088864e0844769d4dd0e4089d85b` remains intact.
- MobilityOps PostgreSQL, API and web services are healthy. Only web port 1236 is exposed
by the MobilityOps Compose project; API and PostgreSQL remain internal. Automation uses
the server's existing shared n8n at `http://192.168.10.150:5678`; no second MobilityOps
n8n container is running.
- Migrations are at `e7b08389f47f (head)` and deterministic seed counts match final
acceptance. A Chrome smoke test covered every requested page and a real return; its n8n
event succeeded on attempt 1. Browser console and recent service log scans were clean.
- RAGcore is disabled in favor of the honest local demo provider. MCP Hub registration is
disabled. The MobilityOps workflow is published in the existing n8n and live-verified.
- Local post-change gates: 66 backend tests, Ruff, mypy (44 files), and frontend production
build all pass. Evidence is in `artifacts/deployment/unraid-summary.md`.
- Published to the private Gitea repository
`https://gitea.itworx.tech/Jens/MobilityOps`. `master` is the default branch; the full
commit history and baseline commit are present; zero tags exist; remote hygiene is
clean. `origin` uses the SSH clone URL supplied by Gitea.
- Exact next action: none — repository publication and Unraid deployment are complete.
## Current milestone
M7 — complete. All milestones (M0M7) done, plus a full post-M7 final-acceptance audit (see below). See `artifacts/final-acceptance/summary.md` for the definitive acceptance evidence (supersedes `artifacts/evidence/final-summary.md`, which is kept as historical M7 evidence).
## Locked decisions
- Product name: MobilityOps.
- Fictitious tenant: Northstar Mobility Demo.
- PoC only; all operational and knowledge data are synthetic.
- Core stack and boundaries are defined in `CLAUDE.md` and `docs/03-architecture.md`.
- RAGcore and ITWorx MCP Hub are external central services.
- n8n receives post-commit events through an outbox dispatcher.
- SQLAlchemy 2 declarative models cover the full domain model (`backend/app/models/`); enums are plain `String` columns validated at the Pydantic/service layer, not native PG enums (simpler migrations).
- `backend/requirements.lock` is compiled inside a `python:3.12-slim` container (matches the Dockerfile base image) via `pip-compile --extra dev`; regenerate the same way if `pyproject.toml` changes.
- Frontend dependencies pinned (no more `"latest"`); `package-lock.json` committed; Docker build uses `npm ci`.
- Demo auth is a lightweight HMAC-signed cookie (`app/core/security.py`), not a real password/JWT flow — matches "Demo role buttons create an authenticated session; they do not bypass authorization middleware." Two fixed demo users (`USR-OPS` operations_manager, `USR-EMP` rental_employee) are created by the seed loader, not from a CSV (no `users.csv` in `seed/`).
- Seed loader (`backend/app/seed_loader.py`) only supports `seed --reset` (always rebuilds); there is no incremental/idempotent-without-reset mode, since the acceptance criteria only require deterministic reset, not partial import.
- `DataQualityIssue.entity_ref`/`related_ref` from the CSVs are resolved to `entity_type`/`entity_id` (UUID) at load time per the domain model; the original human-readable refs are kept in `evidence_json` (`entity_ref`, `related_refs`) since the API and UI need them and re-resolving UUID→public_ref on every read would be wasteful.
- `backend/app/core/config.py` added `app_secret`, `session_cookie_name`, `session_ttl_seconds`, `seed_dir` (`/app/seed` in-container), `cors_allow_origins` (comma-separated string, not a list — simpler with pydantic-settings env parsing), `demo_today` (drives the dashboard's "Today" section against the deterministic anchor date, default `2026-08-01`).
- `compose.yaml` api build context changed from `./backend` to repo root with `dockerfile: backend/Dockerfile`, so the image can `COPY seed ./seed` (seed CSVs are outside `backend/`).
- Frontend: added `react-router-dom@7.18.2` (bumped from 6.x to clear two real advisories — open redirect + arbitrary constructor injection in v6). One residual `npm audit` finding (RSC-mode CSRF, GHSA-qwww-vcr4-c8h2) does not apply — this SPA never uses React Router's RSC/SSR mode.
- Nav/pages built so far: Dashboard, Vehicles (list+detail with tabs), Bookings (list+detail), Audit. Data Quality, Knowledge and Automation nav items are intentionally omitted until M3/M5/M4 build the pages behind them — CLAUDE.md forbids dead routes/placeholders.
- Return workflow (`app/services/returns.py`): the spec's "validate submitted reading against booking start reading" step was dropped as a hard rejection. For the seeded S1 scenario, a booking's `start_odometer_km` can already equal the vehicle's canonical odometer, so any regression-testing value would also be below the booking start, making a hard floor there indistinguishable from — and in conflict with — the documented soft-regression path. Only one odometer check exists now: submitted vs. the vehicle's *canonical* odometer (`vehicle.odometer_km`), matching the domain-model invariant verbatim ("a return with a lower submitted reading is recorded as an inspection and issue, while canonical odometer remains unchanged").
- Idempotency: new `idempotency_records` table (migration `e7b08389f47f`), unique on `idempotency_key`, keyed to `booking_id`. Same key + same booking replays the stored response; same key + different booking → 409 `IDEMPOTENCY_KEY_REUSED`; different key on an already-returned booking → 409 `INVALID_BOOKING_STATE`. Concurrency is enforced by `SELECT ... FOR UPDATE` on the booking row (re-checked for the idempotency record immediately after acquiring the lock, as a safety net for two simultaneous identical-key requests racing the pre-lock check).
- `seed_loader.clear_all()` must delete `idempotency_records` before `bookings` (FK) — easy to forget when adding new booking-referencing tables; the ordering list at the top of `seed_loader.py` is the single place to update.
- Inspection `public_ref` is assigned as `INSP-{count+1:04d}` from a live count query (not gap-safe, fine for a PoC single-writer demo, would need a sequence for real concurrency-safe numbering).
- Found and fixed during browser verification (not caught by pytest, since it's a UI-only defect): `ReturnForm` originally held its own `result` state and was conditionally rendered only when `booking.status === "active"`; once the return succeeded the booking flipped to `returned` and React unmounted the form before the user ever saw the result panel. Fixed by lifting the result into `BookingDetail` (`ReturnResultPanel` is now a sibling, not nested in `ReturnForm`). Also found: `OutboxEvent.event_id`'s Python-side `default=uuid.uuid4` on the mapped_column only applies at flush/commit time, so reading `event.event_id` before `db.commit()` returned `None` (rendered as the literal string "None" in the result panel); fixed by assigning `event_id=uuid.uuid4()` explicitly at construction. Lesson: SQLAlchemy column `default=` callables are not available on the in-memory Python object until flush — never rely on the generated value for a same-transaction response body without an explicit `db.flush()` or an explicit Python-side assignment.
- Operational note for this environment: `docker compose run --rm api ...` (used for tests/lint) only starts a throwaway one-off container — it does **not** update the long-running `api`/`web` service containers. After any code change meant to be verified live (browser, curl), `docker compose up -d --build <service>` is required, not just `docker compose build`.
## Completed evidence
### M0 — Reproducible foundation
- Added `backend/app/core/db.py` (engine/session), `backend/app/models/*` (User, Customer, Vehicle, Booking, Inspection, MaintenanceRecord, DataQualityIssue, OutboxEvent, AuditEvent), Alembic config (`backend/alembic.ini`, `backend/alembic/env.py`) and initial migration `backend/alembic/versions/c9498525abb5_initial_schema.py`.
- Commands run and verified from this checkout:
- `docker compose build api` — OK
- `docker compose run --rm api alembic upgrade head` — applied cleanly to empty DB, created 9 tables + `alembic_version`.
- `docker compose run --rm api pytest -q` — 1 passed.
- `docker compose run --rm api ruff check .` — All checks passed (added `extend-exclude = ["alembic/versions"]` to `backend/pyproject.toml` for autogenerated migration line length).
- `docker compose up -d --build` — all 4 services healthy: `curl http://localhost:8128/health``{"status":"ok",...}`; `curl -o /dev/null -w "%{http_code}" http://localhost:1228/` → 200; `curl http://localhost:5678/healthz` → 200.
- Fixed a real scaffold bug: `frontend/src/App.tsx` used `import.meta.env` without a `vite/client` types reference, which broke `npm run build` in Docker (works fine under plain `vite dev` because Vite injects the global at dev-time but `tsc -b` still type-checks it). Added `frontend/src/vite-env.d.ts`.
- `make` is not installed in this Windows/git-bash shell — validated the underlying `docker compose ...` commands directly instead (Makefile targets are thin wrappers around them and are correct as written for a Linux/CI shell or WSL).
- Known accepted gap: `npm audit` reports 1 moderate/1 high transitive `esbuild` advisory (dev-server-only, fixed only by a Vite 8 major bump); left as-is for the PoC, noted here rather than silently upgrading a major version.
### M1 — Operational core
- Backend additions: `app/core/security.py` (HMAC-signed session cookies), `app/api/deps.py` (`get_current_user`, `require_operations_manager`), `app/core/errors.py` (`AppError` + the documented `{"error": {...}}` shape wired as a FastAPI exception handler for both `AppError` and `HTTPException`), `app/seed_loader.py`, `app/cli.py` (`python -m app.cli seed --reset`), `app/services/audit.py`, `app/schemas.py`, routers under `app/api/routers/` (`demo`, `dashboard`, `vehicles`, `bookings`, `audit`).
- Frontend additions: React Router-based app shell (`src/App.tsx`, `src/components/Layout.tsx`, `src/components/RequireAuth.tsx`), `AuthContext`, typed `api` client (`src/api/client.ts`, `src/api/types.ts`), pages `Login`, `Dashboard`, `Vehicles`/`VehicleDetail`, `Bookings`/`BookingDetail`, `Audit`. Full responsive stylesheet (`src/styles.css`) covering nav collapse and table→card layout under 700px, visible focus states, no hover-only actions.
- Commands run and verified from this checkout (container rebuilt each time to pick up code changes):
- `docker compose run --rm api pytest -q`**19 passed** (new: `test_seed.py`, `test_auth.py`, `test_dashboard.py`, `test_vehicles.py`, `test_bookings.py`, `test_audit.py`; tests seed the real Postgres via `reset_and_seed` in a session fixture, then exercise the FastAPI app through `TestClient`, not mocks).
- `docker compose run --rm api ruff check .` — All checks passed (added `ignore = ["B008"]` — FastAPI's `Depends()`-as-default is idiomatic, not a real bug).
- `npm run build` (local, Node 24) — clean `tsc -b && vite build`.
- `docker compose up -d --build` then `docker compose exec api python -m app.cli seed --reset` — counts: `users:2 customers:180 vehicles:50 bookings:246 inspections:75 maintenance:40 data_quality_issues:15 workflow_runs:20`.
- `curl` end-to-end: `POST /api/v1/demo/login` sets cookie and returns the user; unauthenticated `GET /api/v1/dashboard` → 401 with the documented error shape; authenticated dashboard/vehicle-detail return real seeded data (verified metrics `available:21 rented:11 cleaning:6 maintenance:5 blocked:7`, matching the 50 seeded vehicles).
- Browser smoke test (Chrome via MCP) at desktop width: login page → Operations Manager login → Dashboard (metrics + attention items + today + recent automation all populated) → Vehicle detail `MO-016` (tabs render, "Needs attention" badge correct — it's `DQ-DEMO-OVERLAP`/`DQ-DEMO-STATUS`) → Booking detail `BK-DEMO-RETURN` (matches S1 scenario: vehicle `MO-024`, status `active`, start odometer `53610`). Responsive CSS (`@media max-width:700px`) was written and code-reviewed but the automated resize during this session didn't visibly reflect in the captured screenshot (likely a screenshot-timing quirk of the browser tool, not necessarily a real bug) — **treat the ≤360px layout as visually unverified** and re-check with a real device/DevTools emulation before final acceptance (M7).
- Known accepted gap carried over from M0: `npm audit` residual `esbuild`/Vite-8 dev-server-only advisory.
### M2 — Vehicle return vertical slice
- Backend additions: `app/models/idempotency.py` (`IdempotencyRecord`), migration `e7b08389f47f_idempotency_records`, `app/services/returns.py` (`register_vehicle_return` — full transaction: row locks, idempotency replay, inspection, canonical-odometer update or regression issue, vehicle status derivation, two audit events, `vehicle.returned.v1` outbox event matching `contracts/events.schema.json`, next-booking-risk lookup), `POST /api/v1/bookings/{public_ref}/return` wired in `app/api/routers/bookings.py` with required `Idempotency-Key` header.
- Frontend additions: `components/ReturnForm.tsx` (form + `ReturnResultPanel`), wired into `pages/BookingDetail.tsx` (shown only when `booking.status === "active"`; result persists via lifted state after the booking flips to `returned`).
- Commands run and verified from this checkout:
- `docker compose run --rm api pytest -q`**26 passed**, including `tests/test_return.py` (success/canonical-update, S1 regression scenario by name, damage→blocked, idempotent replay, reject-already-returned, missing-header validation, and a real multi-threaded concurrent-submission test against Postgres asserting exactly 1×201 + 2×409).
- `docker compose run --rm api ruff check .` — All checks passed.
- `npm run build` — clean.
- `docker compose up -d --build` (all services) then `docker compose exec api python -m app.cli seed --reset`, then a full browser run of the S1 demo scenario against `BK-DEMO-RETURN`/`MO-024`: submitted 53000 km (below canonical 54820) → result panel showed `INSP-0076`, `resulting_vehicle_status: maintenance` (correctly derived, since canonical 54820 ≥ `next_service_km` 40000), `DQ-RET-0076` created, automation event queued with a real UUID, "no upcoming booking" risk; vehicle detail page confirmed odometer unchanged at 54,820 km and a "Needs attention" badge.
- Both real defects listed above (form disappearing before showing its result; `event_id` reading as `None`) were **found via the browser run, not by pytest** — the test suite asserted on API response shape/values, not on what the UI actually rendered after a status transition. Worth remembering for M3+: UI state-after-mutation bugs need a browser check, not just API tests.
### M3 — Data Quality Workbench
- `app/services/data_quality.py`: `run_scan()` implements all five rules and is called automatically at the end of `seed_loader.reset_and_seed()` (after `db.commit()` of the base seed), plus exposed as `POST /api/v1/data-quality/scan` (Operations Manager only). Idempotency is simplified from the doc's literal `(rule_type, entity_type, entity_id, evidence fingerprint)` to just `(rule_type, entity_type, entity_id)` while an issue is open — see rationale below.
- Router `app/api/routers/data_quality.py`: `GET /issues` (filters status/rule_type/severity), `GET /issues/{ref}` (adds `entity_snapshot`/`related_snapshots` for the UI), `POST /issues/{ref}/defer`, `/reject`, `/merge-customers` (Operations Manager only — enforced via `require_operations_manager`), `POST /scan`.
- **Real bug found and fixed during this milestone, before any browser check**: the first cut of DQ-03 (odometer regression) compared every historical *returned* booking's `end_odometer_km` against the vehicle's *current* `odometer_km`. Since the seed generator assigns `vehicle.odometer_km` independently of booking history (see `seed/generate_seed.py`), this is true for nearly every historical booking by construction (odometer is monotonically increasing over time, so all-but-the-latest reading is "below current") — it produced 51 false-positive issues out of 50 vehicles on first run. Fixed twice: first attempt (compare only the single most-recent booking against canonical) still produced the same problem because canonical itself is disconnected from booking history in this dataset; the working fix compares each vehicle's *own returned-booking sequence* against itself (each booking's end reading vs. the immediately preceding one, chronologically) — a self-consistency check that doesn't depend on the unrelated `vehicle.odometer_km` field at all. Final deterministic seed+scan totals: 15 CSV-seeded + 11 scan-discovered = **26** open/resolved `data_quality_issues` (breakdown: 14 vehicle_status_conflict, 5 missing_required_field, 3 possible_duplicate_customer, 3 odometer_regression, 1 booking_overlap). `tests/test_seed.py`'s exact-count assertion was updated from 15 to 26 accordingly — if the scan logic changes again, update that count.
- Idempotency simplification rationale: the doc's fingerprint-based key would make the scan blind to issues it structurally can't compute a matching fingerprint for against the CSV-seeded rows (which don't carry a fingerprint field), producing duplicate issues for the same real-world problem (e.g. a second `MO-016` overlap issue next to the seeded `DQ-DEMO-OVERLAP`). Using `(rule_type, entity_type, entity_id)` alone while open is a stricter, safe simplification: it can never falsely suppress an issue for a *different* entity, and per-entity there's realistically only one meaningful open issue of a given rule type at a time for this PoC's scope.
- Merge UI intentionally does **not** use `window.confirm()` — a native dialog blocks further automation/testing and isn't screen-reader-distinguishable from page content the same way a rendered `role="alertdialog"` panel is. Built an inline two-step confirm instead (`ReturnForm`-style pattern reused).
- `AttentionItem` gained an `issue_ref` field (dashboard now links attention items straight to `/data-quality/{issue_ref}` instead of only to vehicles); dashboard attention list capped at 8 items (was unbounded, would have shown up to 26 with the richer scan).
- Commands run and verified from this checkout:
- `docker compose run --rm api pytest -q`**35 passed** (new `tests/test_data_quality.py`: all five rule types present, scan idempotent on rerun, scan requires Operations Manager, S2/S4 issue-detail snapshots correct, defer→reject-on-closed 409, merge requires Operations Manager, merge rejects an unrelated survivor ref, full S2 merge scenario asserting rewiring + audit + replay-is-409).
- `docker compose run --rm api ruff check .` — All checks passed.
- `npm run build` — clean (had to fix two `possibly 'null'` TS errors from a closure-narrowing limitation — TS doesn't narrow `const` captured-by-closure across nested function boundaries when the value comes from an index/property expression; fixed by re-binding to explicitly-typed local consts right after the guard).
- Full browser run: Data Quality list (26 open issues, filterable) → `DQ-DEMO-DUPLICATE` two-column compare (CUS-0012 vs CUS-0178, per-field diff highlighting only where they differ) → merge with inline confirm → issue flips to `resolved` → confirmed `customer_merged` audit event with correct actor/entity/correlation → `DQ-DEMO-OVERLAP` (non-duplicate type) renders evidence JSON + defer/reject, no dead compare UI shown for a rule type it doesn't apply to.
### M4 — n8n automation
- `app/services/dispatcher.py`: background daemon thread (started/stopped via FastAPI `lifespan`, not an `on_event` hook) polling every `N8N_DISPATCH_INTERVAL_SECONDS` (default 3s). Claim step (`_claim_due_events`) is a short transaction using `SELECT ... FOR UPDATE SKIP LOCKED` that only flips `pending``delivering` and commits immediately; the HTTP call to n8n happens with **no open transaction**; the outcome is recorded in a separate short transaction. Exponential backoff `min(2**attempts, 60)` seconds, `N8N_MAX_ATTEMPTS=5` before a permanent `failed`.
- Dispatcher reconstructs the wire event from `contracts/events.schema.json`'s exact fields (`event_id`, `event_type`, `occurred_at`, `correlation_id`, `aggregate`, `data`) rather than forwarding `OutboxEvent.payload_json` wholesale — that column also carries an internal `aggregate_ref` convenience key (used by dashboard/workflows list rendering) that the schema's `additionalProperties: false` would reject.
- `POST /api/v1/integrations/n8n/return-callback` (`app/api/routers/integrations.py`): shared-secret auth via `X-Service-Token` header (`N8N_CALLBACK_TOKEN`, propagated to both `api` and `n8n` containers as `MOBILITYOPS_CALLBACK_TOKEN`); idempotent by `Idempotency-Key` (the event UUID) — checked by querying for an existing `AuditEvent` with that event ID in its metadata, **not** by `OutboxEvent.external_run_id`, because the dispatcher only sets that field *after* it gets n8n's final response, which happens *after* n8n has already called this callback mid-workflow — using `external_run_id` as the idempotency guard would have missed the exact redelivery case it's meant to catch.
- `GET /api/v1/workflows` + `POST /api/v1/workflows/{event_id}/retry` (`app/api/routers/workflows.py`), both Operations Manager only. Retry only allowed from `failed`; sets `pending` + clears `next_attempt_at` so the live dispatcher picks it up on its next cycle (does not reset `attempts`, so the counter reflects true delivery history).
- Automation nav + page (`pages/Automation.tsx`): table of all runs with status/attempts/last error, Retry button for `failed` rows, visible only to Operations Manager (matches backend authorization rather than just hiding a link).
- **Two real bugs found and fixed, the second only by testing the actual live n8n round-trip, not by pytest**:
1. Seed-loaded `workflow_runs.csv` rows only ever got `payload_json = {"aggregate_ref": ...}` (no `correlation_id`/`aggregate`/`data`) — fine for M1M3 since nothing read those keys yet, but once the dispatcher tried to *redeliver* a seeded row (i.e. the S5 manual-retry demo scenario) it crashed with `KeyError: 'correlation_id'`, leaving that event stuck in `delivering` forever (the crash happened before the outcome-recording transaction). Fixed in two places: `seed_loader.py` now builds the full schema-compliant envelope for every `workflow_runs.csv` row (matching what the live M2 return flow produces), and `dispatcher._deliver_one` now catches malformed-payload `KeyError`s defensively and resolves the row to `pending`/`failed` instead of leaving it orphaned — added `test_deliver_one_handles_malformed_payload_without_getting_stuck` as a regression test for the latter.
2. This n8n image (2.32.7) has dropped `N8N_BASIC_AUTH_ACTIVE` as a UI/API gate — it requires an actual owner account via the `/setup` flow before anything (including webhook registration reliability) works correctly. Also: `n8n import:workflow` requires the workflow JSON to have a top-level `"id"` field (added `"id": "mobilityops-return-processing"`) and **always deactivates** the imported workflow regardless of its `"active"` field — activation requires `n8n publish:workflow --id=<id>` followed by a full n8n restart (documented in n8n 2.x CLI, not obvious from the docs pack). Did this manually this session via the CLI + browser setup wizard; **this is a one-time operational step that is not automated** — a truly clean checkout still needs someone to run `docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-return-processing.json`, `docker compose exec n8n n8n publish:workflow --id=mobilityops-return-processing`, `docker compose restart n8n`, and complete the one-time owner setup at `http://localhost:5678/setup` (any email/password, no verification required) before the automation demo will work. `docs/17-runbook.md` should get this exact sequence in M7.
- Commands run and verified from this checkout:
- `docker compose run --rm api pytest -q`**49 passed** (new `tests/test_dispatcher.py` — claim/deliver success/failure/backoff/exhaustion-to-failed/malformed-payload, all via `monkeypatch.setattr(dispatcher.httpx, "post", ...)`, no real network calls in tests; `tests/test_integrations.py` — callback auth, unknown-event 404, idempotent-by-event-ID with a real duplicate-call assertion; `tests/test_workflows.py` — role gating, retry-only-from-failed, S5 retry-and-audit).
- `docker compose run --rm api ruff check .` — All checks passed.
- `npm run build` — clean.
- Full live round trip (not mocked): registered a real return on `BK-DEMO-RETURN` → outbox event queued → background dispatcher delivered it to the now-activated n8n workflow within its 3s poll interval → n8n called back into `/api/v1/integrations/n8n/return-callback` (200 OK, confirmed in `docker compose logs api`) → dispatcher's original POST received n8n's success response → event flipped to `succeeded` on attempt 1, visible on `/automation`.
- S5 scenario end-to-end in the browser: seeded `BK-H-0020` (`failed`, 3 attempts, "Synthetic connection timeout to n8n") → clicked Retry → `pending` → within ~3s, live dispatcher delivered it through the real n8n instance → `succeeded`, 4 attempts. This is the full documented S5 scenario working for real, not simulated.
### M5 — RAGcore knowledge integration
- `app/services/knowledge/__init__.py`: `KnowledgeProvider` Protocol (sync, not async — the rest of the backend is sync SQLAlchemy/FastAPI, so an async provider interface would have meant bridging paradigms for no benefit) with `health()`/`ask()`, plus `GroundedAnswer`/`SourceCard`/`KnowledgeHealth` Pydantic models matching `contracts/openapi.yaml`'s `GroundedAnswer` schema exactly. `get_knowledge_provider()` factory switches on `settings.knowledge_provider` ("demo" default, "ragcore" opt-in).
- `app/services/knowledge/demo.py``DemoKnowledgeProvider`: parses the 10 `knowledge/procedures/*.md` files' YAML frontmatter (hand-rolled flat parser, not PyYAML — avoided adding a dependency for a 6-key flat block) and `## `-delimited sections at startup, then does **TF-IDF-weighted keyword retrieval** (not naive keyword counting) with light suffix-stripping stemming (`returns``return`, `damaged``damage`). This is extractive, not generative: it returns real excerpts and a templated answer sentence, never invented text.
- **Real bug found and fixed by testing the actual S6 question, not by inspection**: naive flat keyword-overlap scoring (first cut) let the word "vehicle" — present in nearly every document's title — crowd out the actually-relevant `damage-procedure` document from the top-3 results for "What must I do when a vehicle returns with damage?", because generic words scored the same as distinctive ones. Fixed by computing corpus-wide IDF per token (`log((N+1)/(df+1)) + 1`) and weighting matches by it, so common terms contribute little and rare/distinctive terms (like "damage") dominate the ranking. Verified: the S6 question now returns `damage-procedure` and `vehicle-return-procedure` in the top 3, matching the documented expectation exactly.
- `app/services/knowledge/ragcore.py``RAGcoreKnowledgeProvider`: real `httpx` adapter guessing a plausible REST contract (`GET /health`, `POST /api/v1/ask`) per `contracts/ragcore-contract-assumptions.md` (RAGcore is built separately; no live instance was reachable this session to verify against). Any connection error, timeout, or malformed response degrades to `evidence_state: "unavailable"` rather than raising — this is the adapter that actually exercises the architecture's "RAGcore failure disables knowledge answers only" reliability boundary. Not wired as the active provider by default; `KNOWLEDGE_PROVIDER=ragcore` would need a real, verified base URL to turn on.
- `POST /api/v1/knowledge/questions` + `GET /api/v1/knowledge/status` (`app/api/routers/knowledge.py`). Audit event `knowledge_question_asked` logs `evidence_state`, `provider`, `source_ids`, and `question_length` only — **not** the question text itself, per `docs/12-security-and-audit.md` ("log question metadata and source IDs, not unnecessary full prompts").
- Knowledge nav + page (`pages/Knowledge.tsx`): chat-style question box, source cards (title/version/section/excerpt) prioritized over the answer text per `docs/06-ui-ux.md`, explicit `grounded`/`insufficient`/`unavailable` states with distinct visual treatment — never a fabricated-looking answer for the latter two.
- Dockerfile now also `COPY knowledge ./knowledge`; added `KNOWLEDGE_DIR` setting (`/app/knowledge/procedures` in-container, same pattern as `SEED_DIR`) rather than deriving the path from `__file__` — simpler and doesn't break if the module moves.
- Commands run and verified from this checkout:
- `docker compose run --rm api pytest -q`**57 passed** (new `tests/test_knowledge.py`: S6 grounded-with-expected-sources, unrelated question is honestly insufficient with no fabrication, demo provider health/document count, endpoint auth required, audit doesn't leak question text, RAGcore adapter degrades to unavailable on a simulated connection error).
- `docker compose run --rm api ruff check .` — All checks passed.
- `npm run build` — clean.
- Full browser run of S6 end-to-end: asked "What must I do when a vehicle returns with damage?" on `/knowledge` → grounded answer citing "Vehicle return procedure" (2 sections) and "Damage handling procedure" with real excerpts. Also asked an unrelated question ("What is the weather forecast for tomorrow?") → correctly returned "Insufficient evidence" / "No matching procedure was found" with zero sources, confirming no fabrication.
### M6 — ITWorx MCP Hub publication
- `app/api/routers/mcp_integrations.py`: four read-only endpoints under `/api/v1/integrations/mcp/``GET operations-summary`, `GET attention-vehicles` (query params `minimum_severity`/`date`/`limit` matching `contracts/mcp-tools.json`'s `inputSchema` exactly), `GET vehicles/{vehicle_ref}`, `POST search-knowledge` (the "narrow façade" the doc calls for — wraps M5's `get_knowledge_provider()` rather than re-implementing retrieval; the contract's tool has no MobilityOps `endpoint` field, only `routing.preferred: ragcore`, so this façade path is MobilityOps's own addition for when the Hub needs a single provider boundary, not literally specified by the contract).
- Auth: new `require_mcp_service_token` dependency in `app/api/deps.py`, same shared-secret-header shape as the M4 n8n callback (`X-Service-Token` against `MCP_HUB_SERVICE_TOKEN`) plus an optional `X-Client-Id` header (defaults to `"unknown-mcp-client"`) used as the audit actor label — the Hub's actual client-identity header name is unknown (no live Hub to confirm against), so this is a reasonable guess documented here rather than assumed silently.
- `McpVehicleDetailOut` deliberately omits `registration_number` and all customer data — narrower than the browser-facing `VehicleOut`/`VehicleDetailOut`, matching "no customer or vehicle database access" and the read-only/summary intent of an AI-facing tool. Test `test_vehicle_details_known_ref` asserts the field's absence explicitly so a future change can't silently widen the exposed surface.
- Extracted `app/services/operations.py` (`compute_metrics`, `list_attention_vehicles`) out of `app/api/routers/dashboard.py` so the MCP operations-summary/attention-vehicles endpoints and the human dashboard share one query implementation instead of two copies that could drift — the same "do not duplicate retrieval logic" principle the doc states for the knowledge tool, applied here to the operational-summary tools too.
- Every provider call writes an `AuditEvent` (`actor_type="service"`, `actor_label=X-Client-Id`, `action="mcp_tool_request"`, `metadata={tool, status}`) — MobilityOps's own record that its provider APIs were reached, independent of whatever central tool-call audit the Hub itself keeps (per `docs/10-mcp-hub-integration.md`'s audit section, the Hub owns the central log; this is the local corroborating one).
- No write/mutation endpoints exist under the `/api/v1/integrations/mcp/` namespace at all (verified by `test_no_write_endpoints_exist_under_mcp_namespace` — POST/PUT/DELETE against the vehicle-details path all 404/405) — return registration, customer merge, and any booking/vehicle mutation are correctly absent, per the doc's explicit restriction list.
- Commands run and verified from this checkout:
- `docker compose run --rm api pytest -q`**66 passed** (new `tests/test_mcp_integrations.py`: token-required, wrong-token 401, all four tools' happy paths, severity/limit filtering, 404 for unknown vehicle, `max_sources` respected, audit actor/action verified, write-method rejection).
- `docker compose run --rm api ruff check .` — All checks passed.
- Live `curl` verification against the running stack (no browser needed — these are service-to-service endpoints, not UI): missing header → 422; wrong token → 401; correct token → all four endpoints return correct data (`operations-summary` metrics match the dashboard; `attention-vehicles?minimum_severity=high` returned `MO-016`×2 and `MO-031`, all severity `high`; `vehicles/MO-016` returned the narrow read-only shape; `search-knowledge` with `max_sources=2` returned exactly 2 grounded sources for the S6 question). Confirmed via `GET /api/v1/audit?action=mcp_tool_request` that all four calls were recorded with correct `actor_type=service`, tool name, and status.
### M7 — Portfolio polish and final acceptance
- **Automated clean-checkout migrations**: `backend/entrypoint.sh` now runs `alembic upgrade head` before starting uvicorn (Dockerfile `CMD` changed from `uvicorn ...` to `./entrypoint.sh`). Verified with a true `docker compose down -v` (all volumes wiped) → `docker compose up --build -d` → all 11 tables present, `/health` and web both green, all 66 backend tests pass, with zero manual migration step.
- **n8n one-time setup scripted where it can be**: `make n8n-setup` runs the import/publish/restart sequence (previously three manual commands discovered ad hoc in M4). The owner-account creation itself cannot be scripted safely (it's an interactive one-time step in n8n 2.x's own onboarding, not a MobilityOps concern) — documented precisely in the rewritten `docs/17-runbook.md`, including the exact URL and that no email verification is required. Re-ran this full sequence from the wiped-volumes state this session and confirmed the S1 return → outbox → live n8n → callback → `succeeded` round trip works on a genuinely clean checkout, not just the already-provisioned stack from M0M6.
- **Playwright E2E** (`frontend/e2e/demo.spec.ts`, `frontend/playwright.config.ts`): one test automating the full 9-step documented demo script end-to-end against the live stack — login, dashboard metrics, open `BK-DEMO-RETURN`, register an odometer-regression return (S1), verify the quality issue + queued automation event, merge the duplicate-customer scenario (S2), ask the damage question and verify both expected source citations (S6), inspect audit entries, and verify responsive nav + no horizontal overflow at 360px width. **Passing.** This also resolves the "≤360px layout visually unverified" gap flagged back in M1 — verified both by this test's overflow assertion and by the `9-mobile-dashboard.png` screenshot (nav wraps into rows, metric tiles collapse to a 2-column grid, no horizontal scroll).
- Added `frontend/e2e/_capture-screenshots.spec.ts` as evidence-generation tooling (underscore-prefixed, excluded from the default `playwright test` / `make e2e` run via `testIgnore` in the config — it calls `demo/reset`, which a real regression test shouldn't do as a side effect). Captured all 9 screenshots into `artifacts/evidence/screenshots/`.
- Wrote `artifacts/evidence/architecture.md` (mermaid, as-built — distinguishes verified-live components from implemented-but-never-reached-a-real-instance ones, i.e. RAGcore and the MCP Hub) and `artifacts/evidence/final-summary.md` (commit, exact commands, test counts, screenshot index, RAGcore success/unavailable evidence — including a live-demonstrated unavailable case against an unreachable host, not just the unit test — n8n success/retry evidence, MCP sample calls, known limitations, truthful portfolio wording per `docs/16-portfolio-case-study.md`'s template).
- Updated `README.md` (dropped stale "minimal bootable scaffold, not the finished application" wording and the old two-line quickstart in favor of `make demo` + a pointer to the runbook) and `docs/17-runbook.md` (full rewrite: exact bootstrap, n8n one-time setup, verification commands, required operational checks, recovery expectations).
- Final placeholder/dead-UI sweep: `grep`'d the full `frontend/src` and `backend/app` trees for scaffold/TODO/FIXME/"must be replaced" markers — none found. `FILE_INDEX.md` was left as-is; it's the original build-pack's archive-completeness manifest (a historical snapshot), not a living index that needs to track every file added since — updating it would misrepresent what it's for.
- Commands run and verified from this checkout (this milestone, cumulative across the whole build):
- `docker compose run --rm api pytest -q`**66 passed**, ruff clean.
- `cd frontend && npm run build` — clean.
- `cd frontend && npx playwright test`**1 passed** (full demo script, live stack).
- Full clean-checkout drill: `docker compose down -v``docker compose up --build -d``docker compose exec api python -m app.cli seed --reset``docker compose run --rm api pytest -q` (66 passed) → n8n owner setup + `make n8n-setup` → live S1 return round-tripped through the real n8n instance to `succeeded`.
### Final acceptance audit (post-M7)
A dedicated release-readiness audit was run after M7 claimed completion, specifically to
catch anything the milestone-by-milestone build might have missed by only ever validating
each piece in isolation.
- **Real gap found: `mypy` had never been run.** `mypy` is a declared dev dependency
(`backend/pyproject.toml`) but was never wired into any milestone's validation loop —
only `ruff` was. Running it cold surfaced **43 real type errors across 10 files**, all
pre-existing (not introduced by this audit). Triaged and fixed all of them rather than
suppressing:
- `services/returns.py`: the vehicle lookup after acquiring `FOR UPDATE` could type as
`Vehicle | None` with no runtime guard — added an explicit `if vehicle is None: raise
AppError(..., 404)`. This was a genuine defensive-programming gap (a dangling FK would
have crashed with an unhandled `AttributeError`/500 instead of a clean 404), not just
a type annotation issue.
- `api/routers/bookings.py`: same pattern for `db.get(Customer, ...)` /
`db.get(Vehicle, ...)` in `get_booking` — added a guard raising 500 with a clear
message instead of crashing on `None.public_ref`.
- `api/deps.py` + `api/routers/demo.py`: `CurrentUser.role` is a `Literal[...]`, but
`SessionPayload.role` (decoded from an HMAC-signed cookie) and `User.role` (a DB
column) are both plain `str`. Pydantic validates this at runtime already (so it was
never exploitable), but `get_current_user` now explicitly checks membership before
constructing `CurrentUser`, turning a would-be unhandled `ValidationError` (500) into
a clean 401 for a corrupted/tampered cookie — another real defensive improvement, not
just a type-checker appeasement.
- `api/routers/dashboard.py`, `api/routers/data_quality.py`: two instances of reusing
one variable name for both a `Vehicle` and a `Customer` across an if/else branch,
which is genuinely confusing to read regardless of what mypy thinks — renamed to
distinct variables (`entity`/typed union in dashboard, `customer`/`vehicle` in the
data-quality snapshot helper).
- `services/data_quality.py`, `seed_loader.py`: `Booking.__table__.update()` /
`Customer.__table__.update()` don't typecheck against SQLAlchemy 2.0's stubs (the
`.__table__` accessor is typed as the more general `FromClause`, which doesn't
declare `.update()`) — switched to the idiomatic `sqlalchemy.update(Model)` construct,
which is both correctly typed and the more modern SQLAlchemy 2.0 style anyway.
- Remaining handful (schemas.py's deprecated `conint()``Annotated[int, Field(...)]`,
a `Sequence` vs `list` `.sort()` call, an `assert`-guarded None-narrowing after a
`WHERE ... IS NOT NULL` filter mypy can't see through, `Result.rowcount` typing gaps)
were either latent pydantic-v1-style API usage or genuine SQLAlchemy stub limitations
— fixed with the idiomatic modern equivalent or a narrowly-scoped, commented
`# type: ignore[...]` at the exact line, never a blanket suppression.
- `make lint` now runs both `ruff check .` and `mypy app`; `mypy app` reports
**zero errors across 44 source files**.
- **No other defects found.** Re-ran the full journey matrix end-to-end against a
genuinely wiped-volumes (`docker compose down -v`) clean checkout: all 66 backend
tests, ruff, ✅; ran the demo login → dashboard → vehicle/booking detail → return
workflow → invalid-mileage rejection (422, both a negative value and a non-numeric
string) → data-quality issue review → duplicate-customer merge → audit trail →
Knowledge Assistant → live n8n round trip → MCP Hub endpoint journeys directly via
`curl` against the running stack, all correct.
- **Degraded-mode behavior explicitly re-verified live** (not just unit-tested):
stopped n8n with `docker compose stop n8n`, registered a return — it committed
(`201`, booking flipped to `returned`) exactly as required; the outbox event stayed
`pending` with real `ConnectError`s logged and exponential backoff (2 attempts over
~8s); restarted n8n and the dispatcher **self-healed** without any manual
intervention, delivering the event to `succeeded` on attempt 5. RAGcore unavailable
mode re-verified live against an unreachable host (`ConnectError``evidence_state:
"unavailable"`, empty answer, no fabrication). MCP Hub unavailability is
architecturally moot for MobilityOps — the Hub only ever calls *into* MobilityOps, so
there is nothing on the MobilityOps side that can degrade if the Hub is down (only the
reverse, "does an unavailable Hub break MobilityOps," which is trivially no since
nothing here calls out to it).
- **New test coverage added, no existing tests weakened**: `frontend/e2e/interactive-elements.spec.ts`
(11 Playwright tests — all seven nav items, every filter on every list page, vehicle
detail tabs, defer/reject, automation retry, knowledge form, role-switching, and
role-based page restriction) plus the existing `demo.spec.ts` — **12/12 e2e tests
passing** against the live stack.
- Verified `.env` is `.gitignore`d and was never committed (`git ls-files` /
`git log --all -p -- '*.env'` both empty); scanned full git history for AWS keys,
private-key headers, and `sk-...`-style tokens — none found. Every `Settings` field in
`backend/app/core/config.py` has a corresponding entry either directly in
`.env.example` or is derived/wired through `compose.yaml` (a few purely-internal
container-path constants like `SEED_DIR`/`KNOWLEDGE_DIR` are intentionally not
operator-configurable and correctly absent from `.env.example`).
- Grepped the full `frontend/src` and `backend/app` trees for TODO/FIXME/placeholder/
fake/stub/mock/"not implemented" markers — zero real hits (the two `placeholder=`
matches are legitimate HTML input placeholder attributes). Confirmed dashboard metrics
and all list-page data are 100% DB-backed (`compute_metrics` in
`services/operations.py`, never a literal in frontend JSX). Confirmed every frontend
route in `App.tsx` maps to an implemented page and every nav item maps to a real route
— no dead routes.
- Commands run and verified from this audit:
- `docker compose run --rm api pytest -q`**66 passed**.
- `docker compose run --rm api ruff check .` — All checks passed.
- `docker compose run --rm api mypy app`**Success: no issues found in 44 source files** (0 errors, down from 43).
- `cd frontend && npm run build` — clean (`tsc -b && vite build`).
- `cd frontend && npx playwright test`**12 passed** (`demo.spec.ts` + `interactive-elements.spec.ts`).
- Full clean-checkout drill repeated from a fresh `docker compose down -v`: automatic migrations, seed, 66/66 tests, n8n owner setup + `make n8n-setup`, live return round-tripped through n8n to `succeeded`.
- See `artifacts/final-acceptance/summary.md` for the complete evidence write-up (commands, exact outputs, demo access, deployment instructions, five-minute demo flow).
## Definition of done
All eight milestones (M0M7) are complete, and a dedicated post-M7 final-acceptance audit
found and fixed one real category of gap (`mypy` never having been run) with zero
regressions. `docs/14-testing-and-acceptance.md`'s clean-checkout acceptance list has been
walked item by item against a genuinely wiped-volumes checkout, twice (once in M7, once in
this audit), and `artifacts/final-acceptance/summary.md` is the authoritative final
evidence document. The two items not fully closed — a live RAGcore instance and a live
ITWorx MCP Hub instance — were never reachable in this environment; both integrations are
implemented, unit/contract-tested, directly verified against MobilityOps's own API, and
their unavailable-degradation paths are live-verified, but an actual round trip against
real RAGcore/Hub instances remains unconfirmed and is documented as such rather than
claimed.
## Known blockers
None. External service credentials may be absent; use the documented demo/degraded providers. The n8n workflow-activation steps are a one-time manual setup requirement in this environment (owner-account creation via n8n's own `/setup` UI cannot be scripted safely), fully documented in `docs/17-runbook.md` and scripted where possible (`make n8n-setup`). RAGcore and the ITWorx MCP Hub itself were never reachable in this environment — both integrations are implemented and directly tested/curl-verified against MobilityOps's own API, but neither a real RAGcore instance nor a real Hub round trip was available to confirm end-to-end.
## Premium Control Rail UI transformation (2026-08-02)
- Branch: `design/mobilityops-premium-ui`, branched from verified deployed revision
`dfabb41582e302f45a3de826f85f531bf23dfc8b`; master history was not rewritten.
- Audited every route at 1440, 1280, 768 and 390 px. Baseline findings and captures are
in `docs/design/current-ux-audit.md` and `artifacts/design-validation/current/`.
- Authored three twelve-screen product directions and generated representative Stitch
anchors in project `17018847755558569017`: Control Rail, Dispatch Ledger and Service
Atelier. Control Rail was selected and refined twice for hierarchy, accessibility and
responsive implementation. Decision, screen inventory, tokens and exact Stitch IDs
are in `docs/design/design-directions.md`, `docs/design/design-system.md` and
`docs/design/stitch-manifest.md`.
- Rebuilt the complete React interface around a responsive Control Rail shell: inline SVG
icon/brand system, desktop rail, named landmarks, skip link, top bar, mobile bottom
navigation, shared loading/error/empty states and reduced-motion support.
- Redesigned all shipped pages. The dashboard now prioritizes persisted readiness,
Attention and today's movements; booking results paginate at 25 rows; every responsive
table retains field labels; integrations distinguish n8n evidence, live RAGcore health
and the unconfigured MCP adapter without inventing status.
- Return registration is now capture → review → result. A regression test proves the
return endpoint is not called before confirmation; the existing idempotency and local
commit/outbox contract is unchanged.
- Final browser captures are in `artifacts/design-validation/implementation/`. DOM
measurements and Playwright both prove no horizontal overflow at 390, 768, 1280 and
1440 px. See `docs/design/implementation-validation.md`.
- Final validation commands from this branch:
- `docker compose run --rm api pytest -q`**66 passed**.
- `docker compose run --rm api ruff check .`**All checks passed**.
- `docker compose run --rm api mypy app`**0 issues in 44 files**.
- `cd frontend && npm run lint` — clean TypeScript check.
- `cd frontend && npm run build` — production build succeeded (59 modules; 240.24 kB JS,
36.63 kB CSS before gzip).
- `cd frontend && playwright test --reporter=line`**19 passed** including the full
five-minute demo, every interactive route, return review semantics and four viewport
overflow checks.
- Review deployment updated at `http://192.168.10.150:1236` with persistent PostgreSQL
data preserved. Deployed smoke: all ten authenticated routes plus login at
desktop and mobile sizes rendered without alert state or horizontal overflow; browser console had zero
warnings/errors; seven authenticated API paths returned 200; PostgreSQL/API were
healthy and the shared n8n `/healthz` returned `{"status":"ok"}`.
- Corrected the review topology after confirming the host already runs n8n on port 5678:
the temporary `mobilityops-n8n-1` container was removed without deleting its retained
volume; the bundled service is now opt-in through the `bundled-n8n` profile; the API
points to the shared n8n; and the return workflow is imported and published there.
- The existing n8n's previously empty `N8N_HOST` and `N8N_EDITOR_BASE_URL` values were
persistently set in its Unraid template. A synthetic return then completed the full
MobilityOps → shared n8n → callback round trip as `succeeded` on attempt 1, after which
deterministic demo state was restored (`BK-DEMO-RETURN` is `active`).
- Global search is now live for Control Rail sections and `MO-*`, `BK-*`, `DQ-*` public
references, including Ctrl/Cmd+K focus and a tested not-found announcement. Final local
Playwright result is **19 passed**.
- Exact next action: hand off `design/mobilityops-premium-ui` for review. The final code,
shared-n8n topology and evidence are committed, pushed and deployed; do not merge master
automatically.
+67 -63
View File
@@ -1,91 +1,95 @@
# MobilityOps
# Fleet Ops
**Connected operations for vehicle rental and service teams.**
**A recruiter-ready operations platform for vehicle rental and service teams.**
MobilityOps is a working proof of concept for a fictitious mobility company. It combines vehicle and booking operations, a controlled vehicle-return workflow, data-quality review, RAGcore-backed internal knowledge, n8n orchestration and read-only tools published through ITWorx MCP Hub.
**Try it in two commands** (`cp .env.example .env && make demo`, then open `http://localhost:1228`) · no password required · choose **Highlights in 90 seconds** for the shortest tour. The reference deployment runs on a private LAN (see [deploy/unraid/README.md](deploy/unraid/README.md)); ask for a link if you want the hosted version.
The web application uses the premium responsive **Control Rail** interface: a compact
operations-first workspace with persisted readiness metrics, evidence-led exceptions,
review-before-commit return handling and mobile navigation designed down to 390 px. See
`docs/design/design-directions.md` and `docs/design/implementation-validation.md` for the
design decision and visual evidence.
Fleet Ops turns fragmented vehicle, booking and procedure data into one controlled operational workspace. It is a complete synthetic-data product demo: the company and records are fictional, while the workflows, persistence, validation, authorization, audit trail and integration boundaries are implemented.
All people, companies, vehicles, bookings and documents are synthetic. The workflows, validation, integrations, audit logging and access boundaries are intended to be real.
![Fleet Ops engineering overview](frontend/public/og-fleet-ops.svg)
## Scope
## The 90-second tour
The PoC implements:
1. Open **Highlights** from the login screen.
2. Follow a vehicle return from review to atomic commit, quality issue, outbox and correlated audit trace.
3. Compare and merge a duplicate customer with explicit human confirmation.
4. Ask the Knowledge Hub a damage question and inspect its cited procedure evidence.
5. Open **Engineering** for the architecture, reliability guarantees, test evidence and honest scope boundary.
- operations dashboard;
- vehicle and booking views;
- one complete vehicle-return workflow;
- five deterministic data-quality checks;
- human review and customer merge;
- audit trail;
- RAGcore-backed knowledge assistant with citations;
- one n8n return-processing workflow;
- four read-only MCP tools through ITWorx MCP Hub;
- deterministic demo reset and five-minute showcase.
## What makes it more than a mock-up
It is not an ERP, CRM, accounting package, public booking site, payment system or autonomous agent.
- **Transactional operations:** a return writes the inspection, vehicle/booking state, audit events and outbox record atomically. n8n downtime never rolls back the local business transaction.
- **Explainable data quality:** five persisted rule types, SLA deadlines, assignment, bulk queue controls and bounded resolution flows—not decorative warning cards.
- **Grounded knowledge:** the live deployment uses RAGcore; insufficient or unavailable evidence produces no invented answer. Citations and provider provenance remain inspectable.
- **Safe AI exposure:** four tenant-bound, service-authenticated, read-only Fleet Ops tools are published through ITWorx MCP Hub and audited with correlation IDs.
- **Operational reliability:** bounded retries, delivery leases, health/readiness, Prometheus metrics, Grafana, scheduled verified backups and graceful external-dependency degradation.
- **Real product ergonomics:** nl-BE, en-GB and fr-BE; responsive from 360 px; keyboard-accessible navigation; role-aware global search; route-level lazy loading; server-enforced permissions.
## Integration status
## Architecture
- **n8n**: fully implemented and verified against a real n8n instance, including
degraded mode (n8n stopped mid-flow → return still commits, event stays `pending`
with backoff, self-heals once n8n returns) and the failed-delivery manual-retry path.
- **RAGcore**: the demo `KnowledgeProvider` (deterministic TF-IDF extractive retrieval
over the local procedure documents) is what satisfies the knowledge-assistant
acceptance criteria and is fully verified. A `RAGcoreKnowledgeProvider` HTTP adapter is
implemented and unit-tested, including its unavailable-degradation path, but was never
exercised against a live RAGcore instance in this environment.
- **ITWorx MCP Hub**: the four read-only provider endpoints are implemented, tested, and
directly `curl`-verified with correct auth enforcement and audit logging. No live Hub
instance was reachable in this environment to verify an actual Hub round trip.
```mermaid
flowchart LR
UI["React + TypeScript\nresponsive operations UI"] -->|session cookie| API["FastAPI\nbusiness rules + RBAC"]
API --> DB[(PostgreSQL)]
API -->|grounded retrieval| RAG[RAGcore]
DB --> OUT["Transactional outbox"]
OUT -->|bounded retry| N8N["Existing central n8n"]
N8N -->|authenticated callback| API
HUB["ITWorx MCP Hub"] -->|4 read-only tools| API
```
See `artifacts/final-acceptance/summary.md` for full verification evidence and exact
commands.
Fleet Ops owns operational truth. RAGcore owns retrieval, n8n performs post-commit orchestration, and MCP Hub owns tool transport/publication. Neither RAGcore nor MCP Hub accesses the Fleet Ops database directly. See [the as-built architecture](artifacts/evidence/architecture.md).
## Repository map
## Demonstrable scope
- `CLAUDE.md` — binding implementation rules.
- `MASTER_BUILD_PROMPT.md` — prompt to start an autonomous Claude run.
- `PROJECT_STATE.md` — short persistent project memory.
- `docs/` — product, architecture, UX and acceptance specification.
- `contracts/` — OpenAPI, event and MCP contracts.
- `knowledge/` — fictitious source documents for the MobilityOps RAGcore workspace.
- `seed/` deterministic synthetic dataset and generator.
- `n8n/` — importable workflow definitions.
- `backend/` — FastAPI/SQLAlchemy/Alembic API.
- `frontend/` — React/TypeScript/Vite web app, including the Playwright end-to-end suite (`frontend/e2e/`).
- `artifacts/evidence/` — final acceptance evidence (screenshots, architecture, `final-summary.md`).
- `artifacts/design-validation/` — baseline audit, Stitch direction references and implemented responsive captures.
- dashboard, vehicle fleet, booking lifecycle and controlled returns;
- data-quality queue, assignment, review, merge and resolution;
- correlated human-readable audit history;
- cited Knowledge Hub with honest provider state;
- n8n delivery monitoring and manual retry;
- user administration, privacy export/anonymisation and retention guards;
- deterministic reset with 2 users, 180 customers, 50 vehicles, 254 bookings, 75 inspections, 40 maintenance records, 33 quality issues and 20 workflow runs.
## Quickstart
This is deliberately not accounting, payments, a public reservation site, generic CRM, inventory, HR or an autonomous write agent.
## Stack
React, TypeScript, Vite, FastAPI, SQLAlchemy 2, PostgreSQL, Alembic, n8n, RAGcore, ITWorx MCP Hub, Docker Compose, Prometheus, Grafana and Playwright.
## Run locally
```bash
cp .env.example .env
make demo
```
This builds and starts the full stack (migrations run automatically) and loads the
deterministic demo dataset. See `docs/17-runbook.md` for the one-time n8n workflow setup
required for the automation demo, and the full operational runbook.
Endpoints:
- Web: `http://localhost:1228`
- API health: `http://localhost:8128/health`
- n8n: `http://localhost:5678`
- API readiness: `http://localhost:8128/health/ready`
- Existing n8n server: point `N8N_WEBHOOK_URL` at its return-processing webhook (see `.env.example`). The bundled `n8n` service in `compose.yaml` is a local fallback only; production reuses the server's central n8n (`compose.unraid.yaml` disables the bundled one).
All defaults are configurable via `.env` (see `.env.example`).
The deterministic local knowledge provider supports clean-checkout acceptance without pretending to be the live RAGcore integration. Configuration is documented in `.env.example`; operations and recovery are in [docs/17-runbook.md](docs/17-runbook.md).
## Quality gates
```bash
make test # backend: pytest (66 tests)
make lint # backend: ruff + mypy (strict, zero errors)
make e2e # frontend: Playwright end-to-end (18 tests, live stack required)
make test # isolated PostgreSQL backend suite
make lint # Ruff + strict mypy
make e2e # complete Playwright browser acceptance
cd frontend && npm run build
python scripts/run-readonly-load-smoke.py # while the demo stack is running
```
Frontend build/typecheck: `cd frontend && npm run build` (`tsc -b && vite build`).
Release-scoped results and production evidence are recorded in [artifacts/final-acceptance/summary.md](artifacts/final-acceptance/summary.md); older milestone evidence remains explicitly historical. [PROJECT_STATE.md](PROJECT_STATE.md) records the commands and exact deployment revision.
## Repository map
- `backend/` — FastAPI domain, API, migrations and tests
- `frontend/` — React app and Playwright acceptance suite
- `contracts/` — OpenAPI, event and MCP contracts
- `knowledge/` — versioned fictional procedures
- `n8n/` — importable workflow definitions for the existing server
- `seed/` — deterministic synthetic dataset
- `docs/` — architecture, security, UX, testing and runbooks
- `artifacts/` — dated, release-scoped acceptance evidence and screenshots
“MobilityOps” remains the repository/deployment identifier; **Fleet Ops** is the product name shown to users.
+56
View File
@@ -0,0 +1,56 @@
# Security Policy
## Supported versions
| Version | Security support |
|---|---|
| Latest tagged PoC release and current `master` | Supported |
| Older commits, branches and untagged deployments | Not supported |
MobilityOps is a synthetic-data proof of concept, not a production identity,
payments or public reservation platform. Security fixes target the current
release line only.
## Reporting a vulnerability
Do not disclose suspected vulnerabilities through a public issue.
Report them privately to `security@itworx.tech` with:
- the affected revision, endpoint or component;
- reproduction steps and prerequisites;
- the observed and expected behaviour;
- the security impact;
- a minimal proof of concept, without unnecessary personal or secret data.
Receipt should be acknowledged within three business days. An initial
assessment or request for additional evidence should follow within ten
business days. Remediation timing depends on severity and reproducibility.
## Scope
In scope:
- MobilityOps backend, frontend, container and deployment code;
- authentication, authorization, tenant boundaries and audit integrity;
- database, outbox, backup and restore behaviour;
- MobilityOps-owned n8n workflow definitions;
- RAGcore and MCP Hub integration boundaries implemented in this repository.
Out of scope:
- denial-of-service or destructive testing against the hosted demo;
- social engineering, credential stuffing or physical attacks;
- synthetic demo-data exposure without a security-boundary failure;
- vulnerabilities solely inside RAGcore, ITWorx MCP Hub, n8n or another
third-party service. Report those to their respective owners.
Do not access data beyond what is required to demonstrate the issue, modify
shared infrastructure, interrupt other services or retain obtained secrets.
## Coordinated disclosure
Good-faith research that respects this policy and applicable law will be
handled constructively. Allow a reasonable remediation period before public
disclosure. Submitted reports and evidence are used only for investigation,
remediation and verification.
-39
View File
@@ -1,39 +0,0 @@
# MobilityOps — Claude build pack
MobilityOps is a deliberately scoped, working proof of concept for a fictitious Belgian mobility-rental company. It demonstrates how operational data, workflow automation, data-quality review, a central RAG service and a central MCP hub can work together without pretending to be a full ERP.
## Use this pack efficiently
1. Extract this archive into a new repository.
2. Open the repository in Claude Code.
3. Paste the contents of `MASTER_BUILD_PROMPT.md` once.
4. Let Claude continue autonomously through the milestones in `docs/15-build-plan.md`.
5. Only intervene if the environment itself is unavailable or credentials for an external service are required.
Claude must use `PROJECT_STATE.md` as its compact memory between sessions. Do not restate the full project in later prompts.
## What is included
- locked product scope and non-goals;
- architecture and domain decisions;
- API and event contracts;
- realistic deterministic synthetic seed data;
- ten fictitious procedures for RAGcore;
- an initial n8n workflow export;
- MCP tool definitions for ITWorx MCP Hub;
- a minimal bootable frontend/API scaffold;
- acceptance criteria and a five-minute demo script;
- a master prompt optimized for one autonomous build run.
## Core responsibilities
| Component | Responsibility |
|---|---|
| MobilityOps | Operational data, business rules, UI, audit and data-quality review |
| RAGcore | Document ingestion, retrieval and source-grounded answers |
| ITWorx MCP Hub | Controlled AI access to MobilityOps tools and MobilityOps knowledge |
| n8n | Cross-system orchestration after committed domain events |
## Build principle
Finish a small vertical slice completely. No placeholder pages, fake buttons, invented production claims or scope expansion.
+14
View File
@@ -0,0 +1,14 @@
# Generated live deployment and demo evidence must stay outside source control.
demo-release/
deployment/
screenshots/
*.log
*.db
*.db-wal
*.db-shm
*.zip
*.tar
*.tar.gz
# Keep this policy file.
!.gitignore
Binary file not shown.

After

Width:  |  Height:  |  Size: 79 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 44 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 189 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 117 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 104 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 85 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 107 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 135 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 111 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 211 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 157 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 159 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 173 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 59 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 266 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 145 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 102 KiB

-145
View File
@@ -1,145 +0,0 @@
# MobilityOps Unraid deployment evidence
## Outcome
- Deployment: **PASS**
- Gitea publication: **PASS**
- Gitea URL: `https://gitea.itworx.tech/Jens/MobilityOps`
- Visibility: private (verified in the Gitea web UI)
- Branch: `master`
- Verified baseline commit: `4bf9afbeff44088864e0844769d4dd0e4089d85b`
- Deployment implementation commit: `1e13943cffb2da8a328b5b1ea5e9b1fe73fdd774`
- Server: `192.168.10.150`
- Server directory: `/mnt/user/appdata/mobilityops`
- Compose project: `mobilityops`
- Application URL: `http://192.168.10.150:1236`
- Port mapping: LAN `0.0.0.0:1236` / `[::]:1236` to `web:80`
## Services and health
| Service | Runtime state | Health | Host exposure |
|---|---|---|---|
| `db` | running, 0 restarts | healthy | none (`5432/tcp` internal) |
| `api` | running, 0 restarts | healthy | none (`8000/tcp` internal) |
| `web` | running, 0 restarts | healthy | `1236:80` on LAN |
| shared host `n8n` | running | healthy | `5678:5678` on LAN; outside MobilityOps Compose |
The final review topology reuses the n8n container that was already running on the host.
Its empty public-host/editor URL settings were corrected in the persistent Unraid template
so workflow execution URLs are valid. The temporary Compose-owned n8n container was
removed without deleting its retained volume. Port `1236` was confirmed unused before the
original deployment; the application directory was created specifically for MobilityOps.
## Deployment commands
The existing SSH aliases resolve to the requested hosts and keys (`gitea.itworx.tech`
for Gitea SSH and `unraid` for root access). No key was created, copied, or replaced.
The committed source was transferred from the workstation; Unraid has no Gitea key.
Repository publication used the SSH clone URL supplied by Gitea:
```bash
git remote add origin ssh://git@192.168.10.150:222/Jens/MobilityOps.git
git push -u origin master
git push origin --tags
```
Git and the Gitea web UI both verified `master` as the default branch, the full commit
history, baseline commit `4bf9afbeff44088864e0844769d4dd0e4089d85b`, and zero tags.
The remote tree contains no `.env`, local database, `node_modules`, virtual environment,
test cache, build cache, Playwright output, or browser binaries.
```bash
git archive --format=tar.gz --output=<temporary-archive> <commit>
scp <temporary-archive> unraid:/mnt/user/appdata/mobilityops/.deploy/source.tar.gz
ssh unraid
cd /mnt/user/appdata/mobilityops
tar -xzf .deploy/source.tar.gz
./deploy/unraid/configure-env.sh http://192.168.10.150:1236
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d db api web
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml exec -T api \
python -m app.cli seed --reset
./deploy/unraid/setup-existing-n8n.sh \
n8n \
http://192.168.10.150:1236/api/v1/integrations/n8n/return-callback
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up -d db api web
```
The server `.env` was created from `.env.example`, is mode `0600`, and contains generated
runtime secrets. Secret values and n8n owner credentials remain server-only and are not
included here or in Git.
## Validation evidence
- Migration: `e7b08389f47f (head)`.
- Deterministic seed: users 2, customers 180, vehicles 50, bookings 246, inspections 75,
maintenance 40, data-quality issues 26, workflow runs 20.
- HTTP: `GET /` returned 200; `GET /health` returned
`{"status":"ok","service":"mobilityops-api"}` through the web proxy.
- Backend gates in an isolated local Compose project: 66 tests passed, Ruff clean, mypy
clean across 44 files.
- Frontend: `npm ci && npm run build` completed (`tsc -b && vite build`).
- Logs: no traceback, fatal, uncaught, or unresolved startup error in the deployment log
scan. Browser console had no warnings or errors during the smoke test.
- Browser smoke test in Chrome: Operations Manager demo login, Dashboard, Vehicles,
Bookings, Data Quality, Knowledge, Automation, and Audit all loaded from the LAN URL.
- Dashboard showed persisted seed metrics (21 available, 11 rented, 6 cleaning,
5 maintenance, 7 blocked, 22 open issues, 1 pending/failed workflow).
- Return workflow: `BK-DEMO-RETURN` accepted 54,700 km, created `INSP-0076` and
`DQ-RET-0076`, preserved the 54,820 km canonical odometer, and changed the booking to
returned.
- Shared-n8n round trip: final post-deploy event `98eb06dc-0bcc-4e3d-96ec-c23b2d266293`
reached `succeeded` on attempt 1 with no last error; the deterministic reset afterwards
restored `BK-DEMO-RETURN` to `active`.
- Data quality: `DQ-RET-0076` displayed the persisted regression evidence and related
booking/inspection references.
- Knowledge: UI truthfully showed `Provider: demo · available · 10 procedures indexed`;
the damage question returned grounded excerpts and citations from the local procedures.
## Integration status
- RAGcore: disabled for this deployment; `KNOWLEDGE_PROVIDER=demo`. No claim of a live
RAGcore connection is shown. Operational functionality is unaffected.
- ITWorx MCP Hub: registration disabled with `MCP_HUB_REGISTRATION_ENABLED=false`; the
independently authenticated provider endpoints remain available internally to the web
proxy/API boundary, but no live Hub connection is claimed.
- n8n: the existing server instance at `http://192.168.10.150:5678` is healthy; the
MobilityOps workflow is imported/published there and a real return delivery succeeded.
The bundled MobilityOps service is disabled by default in the Unraid overlay.
## Known limitations
- RAGcore and ITWorx MCP Hub are intentionally not connected yet.
- Demo authentication remains the accepted HMAC-cookie PoC mechanism.
- The dependency advisories already documented in final acceptance remain unchanged.
## Redeploy
From the workstation, create an archive of the desired committed revision and transfer it
to `.deploy/source.tar.gz`. On Unraid, preserve `.env` and the named volumes, then run:
```bash
cd /mnt/user/appdata/mobilityops
tar -xzf .deploy/source.tar.gz
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml up --build -d db api web
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml exec -T api alembic current
curl -fsS http://127.0.0.1:1236/health
```
## Logs
```bash
cd /mnt/user/appdata/mobilityops
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml ps
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml logs --tail=200
docker compose -p mobilityops -f compose.yaml -f compose.unraid.yaml logs -f api web
docker logs -f n8n
```
## Safe rollback
Choose a known-good commit on the workstation, archive and transfer it as above, then on
Unraid extract it over the identifiable MobilityOps source directory and run the same
`up --build -d` command. Preserve `.env` and both named volumes; do not use `down -v`,
remove volumes, prune Docker, or modify unrelated containers. Check the target commit's
Alembic compatibility before rolling application code behind the current database schema.
Binary file not shown.

Before

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 68 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 64 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 63 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 110 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 80 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 52 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 50 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 51 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 29 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 35 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 28 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 51 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 68 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

@@ -1,89 +0,0 @@
# MobilityOps premium UI evidence summary
Date: 2026-08-02
Branch: `design/mobilityops-premium-ui`
Baseline revision: `dfabb41582e302f45a3de826f85f531bf23dfc8b`
Final design implementation commit: `1f292e14bb6a2e8ded5dc675b1b3360307d8a9ae`
Review URL: `http://192.168.10.150:1236`
## Outcome
The working PoC was transformed into the Control Rail operational interface without
changing backend contracts or adding scope. All existing journeys remain functional;
return registration gained an evidence-based review boundary before commit.
## Evidence index
- Baseline audit: `docs/design/current-ux-audit.md`
- Three directions and decision: `docs/design/design-directions.md`
- Design tokens and component rules: `docs/design/design-system.md`
- Stitch resource IDs: `docs/design/stitch-manifest.md`
- Implemented visual validation: `docs/design/implementation-validation.md`
- Baseline captures: `artifacts/design-validation/current/`
- Stitch captures: `artifacts/design-validation/stitch/`
- Final responsive captures: `artifacts/design-validation/implementation/`
## Major implementation changes
- Responsive Control Rail shell with compact top bar, desktop rail, off-canvas menu and
labelled mobile bottom navigation.
- Live readiness band, filterable Attention queue, movement timeline, honest integration
pulse and persisted activity on the operations dashboard.
- Searchable fleet and booking registries; booking client pagination limits the DOM to 25
operational rows; responsive tables retain field labels.
- Capture → review → result return workflow with calculated consequence preview and no
write request before confirmation.
- Match/conflict duplicate comparison, evidence-first knowledge, system-health cards and
expandable audit metadata.
- Inline SVG product mark, Feather-like line icon set, CSS control-centre illustration,
timeline/status motion and reduced-motion fallback; no image or motion dependency.
## Validation
| Gate | Result |
|---|---|
| Backend tests | 66 passed |
| Backend lint | ruff passed |
| Backend types | mypy: 0 issues in 44 files |
| Frontend types/build | passed; 59 modules; 240.24 kB JS and 36.63 kB CSS before gzip |
| Browser journeys | 19 passed locally |
| Horizontal overflow | none at 390/768/1280/1440 px |
| Accessibility | named landmarks, skip link, visible focus, text-plus-shape status, labelled mobile rows, reduced-motion support |
| Deployed browser smoke | passed on all 10 authenticated routes plus login at desktop and mobile sizes |
| Console/network | 0 browser warnings/errors; 7 authenticated API paths returned HTTP 200 |
| Deployed global search | Ctrl+K plus `MO-024` navigation passed against the review URL |
All displayed operational counts remain derived from the existing persisted API data.
Synthetic-data labelling is persistent on login and authenticated surfaces.
Deployed evidence is stored in `artifacts/design-validation/implementation/deployed/`.
The review stack reports healthy PostgreSQL/API state, HTTP 200 from the web application,
and healthy state from the server's existing n8n at port 5678. A synthetic return reached
`succeeded` on attempt 1 through that shared n8n and its MobilityOps callback; the demo was
then reset to its deterministic state.
## Performance observations
No runtime font, image or animation dependency was added. The application uses inline SVG
and CSS visuals, and the production bundle remains appropriate for this internal PoC.
## Known limitations
- Global search resolves Control Rail sections and `MO-*`, `BK-*`, `DQ-*` public
references. It intentionally does not offer customer lookup because the locked PoC has
no customer detail route or cross-entity search API.
- The repository retains a bundled n8n service for standalone local clean-checkout demos.
The Unraid overlay keeps it behind the opt-in `bundled-n8n` profile; the live review
deployment uses the server's existing shared n8n instead.
- The MCP Hub state is correctly shown as not configured in the current PoC rather than
simulated as healthy.
- Live RAGcore and MCP Hub round trips remain subject to the existing environment limits
documented in `PROJECT_STATE.md`; their degradation behavior is unchanged.
## Rollback
The accepted baseline remains reachable at commit
`dfabb41582e302f45a3de826f85f531bf23dfc8b`. To roll back the review deployment without
rewriting git history, archive that revision, extract it over the application source on
Unraid while preserving `.env` and Docker volumes, and run
`docker compose -p mobilityops up -d --build`. Verify `/health` and port 1236 afterwards.
+52 -47
View File
@@ -1,63 +1,68 @@
# MobilityOps — as-built architecture
# Fleet Ops — as-built architecture
```mermaid
flowchart TB
subgraph Browser
UI["MobilityOps Web<br/>React + TypeScript"]
end
UI["Fleet Ops Web\nReact + TypeScript + Vite"]
subgraph MobilityOps["MobilityOps (this repo)"]
API["FastAPI backend<br/>/api/v1/*"]
DISPATCH["Outbox dispatcher<br/>background thread"]
subgraph CORE["Fleet Ops this repository"]
API["FastAPI /api/v1\nRBAC + domain rules"]
OUT["Outbox dispatcher\nleases + bounded retry"]
DB[(PostgreSQL)]
OBS["Prometheus metrics\nGrafana dashboards"]
API --> DB
DISPATCH --> DB
OUT --> DB
API --> OBS
end
subgraph External["External central services"]
N8N["n8n<br/>return-processing workflow"]
RAGDEMO["Demo KnowledgeProvider<br/>TF-IDF extractive, local files"]
RAGCORE["RAGcore<br/>(adapter built, no live instance)"]
HUB["ITWorx MCP Hub<br/>(endpoints built, no live instance)"]
subgraph EXT["Existing external platforms"]
N8N["Central n8n\nsecondary orchestration"]
RAG["RAGcore\ngrounded procedure retrieval"]
HUB["ITWorx MCP Hub\ntool transport + publication"]
end
UI -->|session cookie| API
API -->|GroundedAnswer| RAGDEMO
API -.->|configurable, unavailable-safe| RAGCORE
DISPATCH -->|POST vehicle.returned.v1| N8N
N8N -->|callback, X-Service-Token| API
HUB -.->|X-Service-Token, read-only| API
classDef unverified stroke-dasharray: 5 5;
class RAGCORE,HUB unverified;
UI -->|secure session cookie| API
API -->|tenant/workspace adapter| RAG
OUT -->|vehicle.returned.v1| N8N
N8N -->|service-authenticated callback| API
HUB -->|service-authenticated read-only tools| API
```
Dashed boxes/arrows are implemented and unit/contract-tested but were never exercised
against a live instance in this environment (no reachable RAGcore or ITWorx MCP Hub).
Solid boxes were verified end-to-end, including a real n8n instance.
## Ownership and trust boundaries
## Component responsibility (unchanged from `docs/03-architecture.md`)
| Component | Owns | Explicitly does not own |
|---|---|---|
| Fleet Ops | vehicles, customers, bookings, inspections, quality issues, audit, permissions, outbox state | external workflow execution or procedure retrieval |
| RAGcore | indexing/retrieval and grounded procedure evidence | Fleet Ops database or business state |
| ITWorx MCP Hub | MCP transport, connector publication and central tool-call audit | Fleet Ops database or write actions |
| n8n | post-commit workflow orchestration | critical business rules or the source-of-truth transaction |
| Component | Owns |
|---|---|
| MobilityOps | vehicles, customers, bookings, inspections, data-quality issues, audit, outbox/delivery state |
| RAGcore | procedure retrieval and grounded answers (demo provider substitutes locally) |
| ITWorx MCP Hub | MCP transport, tool publication, central tool-call audit |
| n8n | post-commit secondary orchestration only — never the source of truth for vehicle state |
## End-to-end return trace
## Reliability boundaries verified in this build
```mermaid
sequenceDiagram
actor Operator
participant Web
participant API
participant DB
participant n8n
Operator->>Web: Review and confirm return
Web->>API: POST return with idempotency key
API->>DB: Lock booking and validate invariants
API->>DB: Commit inspection, state, audit and outbox atomically
API-->>Web: Result + correlation ID
Web-->>Operator: Human result and full processing trace
API->>n8n: Deliver persisted outbox event
n8n->>API: Authenticated status callback
API->>DB: Persist delivery/audit evidence
```
1. **Return commits atomically with its outbox event**`app/services/returns.py`, one
transaction; verified by `test_concurrent_returns_only_one_succeeds` (real Postgres row
locking, not mocked).
2. **Outbox delivery is at-least-once, idempotent by event ID** — verified live: the n8n
callback checks for an existing `AuditEvent` by event ID before recording a second time.
3. **RAGcore failure disables knowledge answers only**`RAGcoreKnowledgeProvider` degrades
to `unavailable`; the rest of the app is unaffected because the knowledge router is the
only consumer.
4. **MCP Hub failure does not affect the web application** — the four MCP provider
endpoints are a separate authenticated surface (`X-Service-Token`), invisible to the
browser-facing API/UI.
5. **n8n failure leaves events pending with bounded retries** — verified live: a seeded
`failed` event, retried through the UI, was picked up by the background dispatcher and
delivered through the real n8n instance within one poll cycle.
## Verified reliability properties
1. Concurrent returns serialize through PostgreSQL row locking; only one can commit.
2. Local return success is independent of n8n availability. Pending delivery remains persisted and retryable.
3. Outbox delivery is at-least-once and idempotent by event ID, with crash-recoverable leases and bounded backoff.
4. RAGcore failure affects knowledge answers only. The UI reports unavailable/insufficient evidence and does not invent an answer.
5. MCP endpoints are a separate tenant-bound, client-identity-validated, read-only surface; every call is audited with a correlation ID.
6. Browser authorization is enforced again on the API. Hiding a navigation item is never the security boundary.
The live deployment has exercised all three external boundaries. Local clean-checkout acceptance can use the deterministic extractive knowledge provider while reporting that mode honestly.
-177
View File
@@ -1,177 +0,0 @@
# MobilityOps — final acceptance evidence
## Commit
Built on top of commit `c5b7e21f81694f0339ad31e3bf044db952d0fbe0` (M6, "implement ITWorx
MCP Hub publication"). This evidence file and the rest of M7's polish are committed as
`M7: portfolio polish and final acceptance` — run `git log --oneline` for the exact hash.
## Exact commands (clean checkout)
```bash
git clone <repo> && cd MobilityOps
cp .env.example .env
make demo # docker compose up --build -d ; migrations run automatically ; seed --reset
```
One-time n8n setup (see `docs/17-runbook.md` for full detail — this cannot be scripted
end-to-end because it requires a one-time owner account created through n8n's web UI):
```bash
# open http://localhost:5678/setup in a browser, create any owner account
make n8n-setup
```
Verification:
```bash
docker compose run --rm api pytest -q # 66 passed
docker compose run --rm api ruff check . # All checks passed
cd frontend && npm run build # clean tsc + vite build
cd frontend && npx playwright test # 1 passed (full 5-minute demo script)
```
## Test counts
- **Backend**: 66 tests passing (`pytest`), 0 skipped, 0 failed. Ruff clean. Coverage by
area: seed determinism (2), auth/roles (4), dashboard (3), vehicles (4), bookings (3),
return workflow incl. real concurrent-submission test (9), data quality incl. S2/S4
scenarios (10), audit (2), n8n dispatcher incl. malformed-payload regression (6),
n8n callback idempotency (3), workflows/retry (4), knowledge incl. S6 scenario (7),
MCP provider endpoints (8), health (1).
- **Frontend**: `npm run build` — clean TypeScript + Vite build, zero errors.
- **End-to-end**: 1 Playwright test (`frontend/e2e/demo.spec.ts`) automating the full
documented 5-minute demo script (login → dashboard → S1 return → S2 merge → S6 knowledge
question → audit → 360px responsive check) — **passing** against the live stack.
## Screenshots of the seven main pages
Captured live against the deterministic seed (`artifacts/evidence/screenshots/`,
via `frontend/e2e/_capture-screenshots.spec.ts`):
| # | Page | File |
|---|---|---|
| 1 | Login | `1-login.png` |
| 2 | Dashboard | `2-dashboard.png` |
| 3 | Vehicles | `3-vehicles.png` |
| 4 | Bookings | `4-bookings.png` |
| 5 | Data Quality | `5-data-quality.png` |
| 6 | Knowledge (grounded S6 answer) | `6-knowledge.png` |
| 7 | Automation | `7-automation.png` |
| — | Audit (bonus, 8th nav item) | `8-audit.png` |
| — | Dashboard at 360px (responsive proof) | `9-mobile-dashboard.png` |
## RAGcore evidence
**Success (demo provider, the one actually satisfying acceptance in this environment)**
S6 question against the real `/api/v1/knowledge/questions` endpoint:
```json
{
"answer": "Per \"Vehicle return procedure\" (v2.0), section \"1. Register the return\": Open the active booking and record the ending odometer, fuel level, cleanliness, visible damage, technical warnings and relevant notes.",
"evidence_state": "grounded",
"sources": [
{"document_id": "vehicle-return-procedure", "title": "Vehicle return procedure", "version": "2.0", "section": "1. Register the return", "excerpt": "..."},
{"document_id": "vehicle-return-procedure", "title": "Vehicle return procedure", "version": "2.0", "section": "3. Determine next state", "excerpt": "..."},
{"document_id": "damage-procedure", "title": "Damage handling procedure", "version": "1.3", "section": "1. Immediate actions", "excerpt": "..."}
],
"provider": "demo",
"correlation_id": "b50094b7-1c84-4e39-9055-1dc03e8fd1f8"
}
```
**Unavailable (RAGcore adapter, live-demonstrated against an unreachable host)**
`KNOWLEDGE_PROVIDER=ragcore`, `RAGCORE_BASE_URL=http://ragcore-not-reachable:9999`:
```
health: {'provider': 'ragcore', 'available': False, 'detail': 'RAGcore unavailable: ConnectError: ...', 'document_count': 0}
ask: {'answer': '', 'evidence_state': 'unavailable', 'sources': [], 'provider': 'ragcore', 'correlation_id': 'demo-correlation'}
```
No live RAGcore instance was reachable in this environment, so the adapter's actual
request/response contract against a real RAGcore is unverified beyond this
degrade-safely behavior — see `contracts/ragcore-contract-assumptions.md` and
`PROJECT_STATE.md`'s M5 notes.
## n8n evidence
**Success** — a real return registered on `BK-DEMO-RETURN`, delivered through the actual
n8n instance (not mocked), confirmed via `GET /api/v1/workflows`:
```json
{"event_id": "aa5dfeee-90ca-452a-bdd1-0a0b6d3dd63f", "event_type": "vehicle.returned.v1", "aggregate_ref": "BK-DEMO-RETURN", "status": "succeeded", "attempts": 2, "last_error": null}
```
(`attempts: 2` because the first delivery attempt landed while n8n was mid-restart from
the one-time workflow-activation step — the dispatcher's backoff-and-retry handled it
without any manual intervention, which is itself evidence of the retry behavior working.)
**Retry (S5 scenario)** — seeded `BK-H-0020` (event `00000000-...-0020`), initially
`failed` after 3 attempts with `"Synthetic connection timeout to n8n"`:
1. Before: `{"status": "failed", "attempts": 3, "last_error": "Synthetic connection timeout to n8n"}`
2. Operations Manager clicks Retry on `/automation`.
3. Within one ~3s dispatcher poll cycle, delivered through the live n8n instance.
4. After: `{"status": "succeeded", "attempts": 4, "last_error": null}`
## MCP tool sample calls
All four provider endpoints, authenticated with `X-Service-Token`:
```
$ curl -H "X-Service-Token: <token>" http://localhost:8128/api/v1/integrations/mcp/operations-summary
{"tenant":"northstar-mobility-demo","metrics":{"available":21,"rented":11,"cleaning":6,"maintenance":5,"blocked":7,"open_quality_issues":22,"pending_or_failed_workflows":1}}
$ curl -H "X-Service-Token: <token>" "http://localhost:8128/api/v1/integrations/mcp/attention-vehicles?minimum_severity=high&limit=3"
[{"vehicle_ref":"MO-016","severity":"high","rule_type":"booking_overlap",...},
{"vehicle_ref":"MO-016","severity":"high","rule_type":"vehicle_status_conflict",...},
{"vehicle_ref":"MO-031","severity":"high","rule_type":"missing_required_field",...}]
$ curl -H "X-Service-Token: <token>" http://localhost:8128/api/v1/integrations/mcp/vehicles/MO-016
{"public_ref":"MO-016","make":"Hymer","model":"Exsis","model_year":2021,"location":"Geel","operational_status":"available","odometer_km":30497,"next_service_km":40000,"open_quality_issue_count":2,"current_booking_ref":null}
$ curl -H "X-Service-Token: <token>" -X POST -d '{"question":"What must I do when a vehicle returns with damage?","max_sources":2}' http://localhost:8128/api/v1/integrations/mcp/search-knowledge
{"answer":"Per \"Vehicle return procedure\" ...","evidence_state":"grounded","sources":[...2 items...],"provider":"demo",...}
```
Auth verified: missing header → `422`; wrong token → `401`. All four calls confirmed
recorded in `GET /api/v1/audit?action=mcp_tool_request` with `actor_type: "service"`.
No live ITWorx MCP Hub instance was reachable in this environment — these are direct
calls to MobilityOps's own provider endpoints, not a Hub round trip.
## Known PoC limitations
- **RAGcore and ITWorx MCP Hub were never reachable in this build environment.** Both
integrations are implemented against best-effort/documented contracts and are
unit/contract-tested (including their failure-degradation paths), but neither was
verified against a real counterpart service. The demo `KnowledgeProvider` is what
actually satisfies the knowledge-assistant acceptance criteria here.
- **n8n requires a one-time manual owner-account setup** per fresh environment
(`docker compose down -v` wipes it) — this is a property of the n8n 2.x image itself
(`N8N_BASIC_AUTH_ACTIVE` no longer gates the UI), not something MobilityOps can bypass.
Documented precisely in `docs/17-runbook.md`; the workflow import/activation itself
*is* scripted (`make n8n-setup`).
- **Inspection public refs are a simple `count+1` sequence**, not gap-safe under true
concurrent writers — acceptable for this single-tenant demo, would need a DB sequence
for a multi-writer production system.
- **The five data-quality rules use simplified idempotency** — `(rule_type, entity_type,
entity_id)` while open, rather than the doc's literal evidence-fingerprint scheme — see
`PROJECT_STATE.md`'s M3 notes for the reasoning (the fingerprint scheme would have let
the scan double-report issues already present in the seeded CSV).
- **No production authentication** — demo login is an HMAC-signed session cookie tied to
two fixed seeded users, appropriate for a PoC, not a real identity provider.
## Portfolio wording (truthful)
MobilityOps is a working proof of concept, not a production system and not deployed for
any real company. All customers, vehicles, bookings, and documents are synthetic
(deterministically generated). The application logic it demonstrates is real: a
transactional vehicle-return workflow with idempotency and concurrency control tested
against real concurrent database transactions; five explainable, deterministic
data-quality rules with a working customer-merge UI; a background outbox dispatcher
verified end-to-end against a real n8n instance including failure/retry; a
TF-IDF-weighted extractive knowledge assistant that never fabricates answers; and four
read-only, audited, service-authenticated integration endpoints. RAGcore and the ITWorx
MCP Hub integrations are implemented and tested in isolation but were not verified
against live instances of those systems in this environment.
Binary file not shown.

Before

Width:  |  Height:  |  Size: 34 KiB

After

Width:  |  Height:  |  Size: 81 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 103 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 304 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 194 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 122 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

+66 -254
View File
@@ -1,265 +1,77 @@
# MobilityOps — final acceptance audit summary
# Fleet Ops release acceptance
This audit was run after M0M7 had already been implemented and committed, specifically
to independently re-verify the finished system end to end rather than trust the
milestone-by-milestone build log. It found and fixed one real category of defect
(`mypy` had never been run across the whole build) and confirmed everything else — every
user journey, every button/filter/form, both external-dependency degraded modes, secret
hygiene, and the clean-checkout path — works as documented.
This file is release-scoped evidence, not a timeless claim. Older evidence under
`artifacts/evidence/` is historical. Exact commands and production revisions are recorded
in `PROJECT_STATE.md`.
## Final commit
## 2026-08-21 release candidate
This audit's fixes are committed as the commit immediately following
`108b5d04fc6f7c5ff9c47009032d6469df29cf3c` ("M7: portfolio polish and final acceptance").
Run `git log -1 --format="%H %s"` for the exact hash.
- Backend: **271/271** tests passed against an isolated clean PostgreSQL database.
- Browser acceptance: **155/155** Chromium tests passed in 6.0 minutes.
- Live-safe browser canary: **4/4** passed across Chromium and Firefox against the local
deployed stack; unlike the acceptance suite, it never resets or mutates demo records.
- Accessibility: the principal login, dashboard, data-quality, knowledge, automation and
audit routes have no automated critical/serious WCAG 2 A/AA/2.1 AA violations.
- Frontend: TypeScript, ESLint, production build, dependency audit and per-asset JS/CSS
budgets passed; committed visual baselines cover the public entry and engineering story.
- Contracts: committed OpenAPI, event schema, MCP tools and all five n8n definitions match
their code/manifest sources.
- Recovery: a custom-format PostgreSQL dump was restored into a disposable database; the
Alembic revision and non-zero canonical table counts matched the source database.
- Operations: Prometheus/Alertmanager configuration validation passed, including the
watchdog and authenticated n8n receiver route.
## Exact commands executed
## 2026-08-21 production verification
Clean-checkout drill (run twice during this audit, most recently against fully wiped
Docker volumes):
- Immutable application revision `95c91797fa2c599443d69d9c96d83a85ee0711f7` was promoted
from a checksum-verified source archive after a fresh production backup.
- Source revision and both OCI revision labels matched. Public readiness was green,
Alembic was at head, all health-gated services were healthy and persisted demo data was
retained without a deployment reset.
- Trivy found zero fixed HIGH/CRITICAL vulnerabilities in each exact production image.
- Prometheus successfully scraped the bearer-protected API target, Alertmanager carried
the active delivery watchdog, and the authenticated n8n alert receiver remained active.
- The final non-destructive HTTPS canary passed **4/4** across Chromium and Firefox,
including the core operator routes and a grounded answer from the real knowledge stack.
```bash
git status # working tree clean before starting
docker compose down -v # wipe all volumes — genuinely clean state
cp .env.example .env
docker compose up --build -d # migrations run automatically (backend/entrypoint.sh)
docker compose exec api python -m app.cli seed --reset
docker compose run --rm api pytest -q
docker compose run --rm api ruff check .
docker compose run --rm api mypy app
cd frontend && npm run build
cd frontend && npx playwright test
```
## 2026-08-21 resilience upgrade verification
n8n one-time setup (owner account via browser at `http://localhost:5678/setup`, then):
- Immutable revision `00191e9b54ee6b961648a6e02abbb3a57957dba0` was promoted from a
checksum-verified archive after a verified production dump. A stable gateway now routes
to two revision-specific API and two web replicas; stateful services are no longer
restarted by routine application releases.
- Moving host port 1236 from the legacy web container to the gateway was a one-time
migration hand-off and produced 14 failures across 1,200 rapid probes. Future releases
do not move that port; their acceptance gate is the zero-error versioned gateway reload.
- The subsequent M50 release exercised that steady-state path: the gateway remained online,
atomically switched revision-specific API/web aliases and sustained **700/700** external
readiness probes without interruption. Post-promotion Chromium/Firefox acceptance passed
**4/4** and 360 concurrent authenticated reads had zero errors at p95 **116.4 ms**.
- The versioned gateway switch sustained **300/300** local rollout probes without an error.
Production's non-destructive Chromium/Firefox canary passed **4/4**, and 360 authenticated
concurrent reads returned zero errors at p95 **137.2 ms**.
- PostgreSQL, backup, Prometheus, Alertmanager, Grafana and the gateway all reported healthy;
Alembic was at head, the protected Prometheus target was present, and backup plus real
restore-drill evidence remained current.
- Trivy 0.74 found zero fixed HIGH/CRITICAL vulnerabilities in the exact production API,
web and gateway images. The separately built rclone/PostgreSQL backup-tools image is also
clean after rebuilding rclone 1.75.0 with Go 1.26.6.
- The OneDrive worker is deployed as an opt-in profile but is not represented as active:
it requires the owner's one-time interactive Microsoft OAuth authorization. Until that
happens, verified local backups remain the active recovery source.
```bash
docker compose exec n8n n8n import:workflow --input=//imports/mobilityops-return-processing.json
docker compose exec n8n n8n publish:workflow --id=mobilityops-return-processing
docker compose restart n8n
```
## Evidence boundary
Degraded-mode drills:
The complete local suite uses the deterministic provider and an isolated database so it is
repeatable and safely destructive. Production verification is deliberately smaller and
non-destructive; it verifies the real RAGcore/MCP/n8n health surfaces without resetting the
shared demo. A successful local result is never presented as proof that an external service
was live. The production subsection is added only after the exact committed release is
deployed and observed.
```bash
docker compose stop n8n # then register a return via the API — commits, event stays pending
docker compose start n8n # dispatcher self-heals, no manual intervention
docker compose run --rm -e KNOWLEDGE_PROVIDER=ragcore -e RAGCORE_BASE_URL=http://ragcore-not-reachable:9999 \
api python -c "from app.services.knowledge import get_knowledge_provider; ..."
```
## Remaining product boundary
## Test and validation results
| Check | Command | Result |
|---|---|---|
| Backend unit/integration tests | `docker compose run --rm api pytest -q` | **66 passed**, 0 failed, 0 skipped |
| Backend lint | `docker compose run --rm api ruff check .` | **All checks passed** |
| Backend type check | `docker compose run --rm api mypy app` | **Success: no issues found in 44 source files** (found and fixed 43 pre-existing errors this audit — see below) |
| Frontend build + typecheck | `cd frontend && npm run build` | Clean (`tsc -b && vite build`, zero errors) |
| End-to-end (Playwright) | `cd frontend && npx playwright test` | **12 passed** (`demo.spec.ts` — full 9-step demo script; `interactive-elements.spec.ts` — 11 tests covering every nav item, filter, tab, and role boundary) |
| Clean-checkout migrations | `docker compose down -v && docker compose up --build -d` | 11 tables created automatically, `alembic current``e7b08389f47f (head)`, zero manual step |
| Deterministic seed | `docker compose exec api python -m app.cli seed --reset` | `users:2 customers:180 vehicles:50 bookings:246 inspections:75 maintenance:40 data_quality_issues:26 workflow_runs:20` — identical across every reseed this session |
| Secret scan | `git ls-files \| grep -x .env`; `git log --all -p -- '*.env'`; history grep for AWS/private-key/`sk-` patterns | No `.env` ever committed; no secrets found in history |
### mypy defects found and fixed (the one real gap this audit uncovered)
`mypy` is a declared dev dependency (`backend/pyproject.toml`) but was never added to any
milestone's validation loop — only `ruff` was run throughout M0M7. Running it cold
surfaced 43 errors across 10 files. All were triaged and fixed (not suppressed):
- **Two genuine defensive-programming gaps**, not just type-annotation issues:
- `app/services/returns.py`: the vehicle lookup after acquiring the row lock had no
`None` guard; a dangling FK would have crashed with an unhandled 500 instead of a
clean `404 VEHICLE_NOT_FOUND`. Fixed.
- `app/api/routers/bookings.py`: same pattern in `get_booking` for the customer/vehicle
lookups — now returns a clean `500` with a message instead of an `AttributeError`.
- `app/api/deps.py` / `app/api/routers/demo.py`: `CurrentUser.role` is validated by
Pydantic at runtime already, but `get_current_user` now explicitly checks role
membership before construction, turning a would-be unhandled `ValidationError` into a
clean `401` for a corrupted/tampered session cookie.
- Two instances of reusing one variable name for both a `Vehicle` and a `Customer` across
branches (`dashboard.py`, `data_quality.py`) — renamed for clarity, not just to satisfy
mypy.
- `Booking.__table__.update()` / `Customer.__table__.update()` switched to the idiomatic
`sqlalchemy.update(Model)` construct (also fixes the type error).
- Remainder: deprecated `conint()``Annotated[int, Field(...)]`, a `Sequence` vs `list`
`.sort()` call, an `assert`-guarded None-narrow after a `WHERE ... IS NOT NULL` filter
mypy can't see through, and a couple of narrowly-scoped `# type: ignore[...]` comments
for known SQLAlchemy stub gaps (`Result.rowcount`).
`make lint` now runs `ruff check .` **and** `mypy app`.
## Application URLs and ports
| Service | URL | Notes |
|---|---|---|
| Web (React SPA) | `http://localhost:1228` | nginx-served static build |
| API | `http://localhost:8128` | FastAPI, `/health` for liveness |
| API docs | `http://localhost:8128/docs` | auto-generated OpenAPI/Swagger UI |
| n8n | `http://localhost:5678` | requires one-time owner setup, see below |
| PostgreSQL | `localhost:5432` (container-internal only, no host port published) | |
## Demo users and access method
No passwords. Two demo-role buttons on `http://localhost:1228/login`:
- **Open as Operations Manager** → `USR-OPS`, "Amelie De Ridder". Full access: dashboard,
data-quality resolution/merge, automation retry, demo reset, MCP/service-token routes
are separate (not user-facing).
- **Open as Rental Employee** → `USR-EMP`, "Karim Boujaddaine". Can register returns and
browse vehicles/bookings/knowledge; Automation page is visible but shows a
role-restricted message instead of the delivery table (enforced both in the UI and by
the backend's `require_operations_manager` dependency — verified by
`test_retry_requires_operations_manager` and the e2e role-restriction test).
Session is an HMAC-signed, `HttpOnly` cookie (`app/core/security.py`) — a demo mechanism,
not a real identity provider (documented as a known limitation).
## Implemented functionality
- Operations dashboard with 100% database-backed metrics, attention items linking to the
underlying data-quality issue, "today" departures/returns, and recent automation runs.
- Vehicle and booking list/detail pages with working filters (status, attention-only) and
a tabbed vehicle detail view (overview/bookings/inspections/maintenance/quality).
- Full transactional vehicle-return workflow: row-locked, idempotent by
`Idempotency-Key`, canonical-odometer regression handling (never silently lowers the
canonical value), vehicle status derivation, two audit events, and a schema-compliant
outbox event — verified against real concurrent submissions (1×201 + 2×409).
- Invalid-mileage rejection: negative values and non-numeric input both correctly
rejected with `422` and a precise Pydantic validation message.
- Data Quality Workbench: five deterministic rules (duplicate customer via TF-IDF-style
weighted signal scoring, missing required field, odometer regression, booking overlap,
vehicle status conflict), issue list/detail/defer/reject, and a two-column
duplicate-customer compare-and-merge UI with an inline (non-native-dialog) confirmation
step, transactional booking rewiring, and audit logging.
- Full audit trail: every significant action (login, return, vehicle status change,
data-quality issue lifecycle, customer merge, workflow retry, demo reset, n8n
callback, MCP tool request, knowledge question) is recorded with actor, correlation ID,
and before/after state; filterable by action.
- Knowledge Assistant: deterministic TF-IDF-weighted extractive retrieval over the 10
procedure documents — never generative, always cites real excerpts, and honestly
reports `insufficient`/`unavailable` states rather than fabricating an answer.
- n8n automation: background outbox dispatcher (`FOR UPDATE SKIP LOCKED` claim,
exponential backoff, no DB transaction held during the HTTP call), a live-verified
round trip through an actual n8n workflow, manual retry for failed deliveries, and an
Automation page (Operations Manager only) showing all runs with filtering.
- Four read-only, service-token-authenticated MCP Hub provider endpoints, each recording
its own service-request audit event, with zero write/mutation endpoints anywhere in
that namespace.
- Responsive UI verified down to 360px width (nav wraps, tables become cards, metric
tiles reflow to a 2-column grid, no horizontal overflow) — both by an automated
Playwright viewport/overflow assertion and by a captured screenshot.
## RAGcore integration status: implemented, not live-verified
The active `KnowledgeProvider` in this environment is `DemoKnowledgeProvider` — fully
implemented, fully tested, fully live-verified, and what actually satisfies the
knowledge-assistant acceptance criteria. A `RAGcoreKnowledgeProvider` HTTP adapter also
exists (`app/services/knowledge/ragcore.py`), targeting a best-effort contract inferred
from `contracts/ragcore-contract-assumptions.md` (no live RAGcore API spec was available).
Its **unavailable-degradation path is live-verified this audit**: pointed at an
unreachable host, it returns `{"evidence_state": "unavailable", "answer": "", "sources":
[]}` with no fabrication, exactly as required — but an actual successful round trip
against a real RAGcore instance has never been performed, because no such instance was
reachable in this environment.
## MCP Hub integration status: implemented, not live-verified
All four contracted read-only tools (`mobilityops_get_operations_summary`,
`mobilityops_list_attention_vehicles`, `mobilityops_get_vehicle_details`,
`mobilityops_search_knowledge`) are implemented as service-token-protected endpoints under
`/api/v1/integrations/mcp/`, directly `curl`-verified this audit (auth enforcement,
correct data shape, no write methods, service-request audit logging). No live ITWorx MCP
Hub instance was reachable in this environment, so an actual Hub-mediated tool call was
never performed — only direct calls to MobilityOps's own provider API.
## n8n integration status: implemented and fully live-verified
The only external integration with a real, running counterpart service available in this
environment. Fully verified this audit, including both success and degraded paths:
- **Success**: a real return registered via the API was delivered by the background
dispatcher to an actual n8n instance (owner account + imported/activated workflow),
which called back into MobilityOps and was recorded `succeeded`.
- **Degraded mode**: `docker compose stop n8n`, then a return was registered — it
**committed successfully** (`201`, booking `status: returned` persisted) exactly as
required by the architecture's reliability boundary ("a return command and its outbox
event commit in one transaction" and "n8n failure leaves events pending with bounded
retries"). The outbox event stayed `pending` with two real `ConnectError`s logged and
exponential backoff.
- **Self-healing**: restarting n8n required no manual intervention — the background
dispatcher picked the pending event back up on its next poll cycle and delivered it to
`succeeded` (5 total attempts across the outage).
- **Manual retry (S5 scenario)**: a seeded `failed` delivery, retried from the Automation
page, moved to `pending` and was delivered to `succeeded` by the live dispatcher within
one poll cycle.
## Known limitations
- RAGcore and the ITWorx MCP Hub were never reachable in this build/audit environment;
both integrations are implemented and tested against inferred/documented contracts but
not verified against real instances of those systems (see above).
- n8n requires a one-time, per-fresh-environment manual owner-account setup through its
own web UI (`http://localhost:5678/setup`) — a property of the n8n 2.x image itself
(`N8N_BASIC_AUTH_ACTIVE` no longer gates the UI), not something MobilityOps can bypass.
The workflow import/activation itself *is* scripted (`make n8n-setup`).
- Demo authentication is an HMAC-signed session cookie tied to two fixed seeded users —
appropriate for a PoC, not a production identity provider.
- Inspection public references are assigned via a simple `count + 1` sequence, not
gap-safe under true concurrent writers (acceptable for this single-tenant demo).
- The five data-quality rules use a simplified idempotency key
(`rule_type, entity_type, entity_id` while open) rather than the spec's literal
evidence-fingerprint scheme — documented rationale in `PROJECT_STATE.md`'s M3 notes.
- `npm audit` reports one residual moderate `esbuild`/Vite-8 dev-server-only advisory
(fixable only by a Vite major version bump) and one high `react-router` RSC-mode
advisory that does not apply to this app (it never uses React Router's RSC/SSR mode).
## Clean deployment instructions
```bash
git clone <repo> && cd MobilityOps
cp .env.example .env
make demo # build, start, migrate (automatic), seed
```
One-time n8n setup (only needed for the automation demo path; everything else works
without it):
```bash
# open http://localhost:5678/setup in a browser, create any owner account
# (8+ chars, 1 number, 1 capital letter — no email verification required)
make n8n-setup
```
Verify:
```bash
curl http://localhost:8128/health # {"status":"ok",...}
curl -o /dev/null -w "%{http_code}\n" http://localhost:1228/ # 200
make test # 66 backend tests
make lint # ruff + mypy, zero errors
make e2e # 12 Playwright tests (stack must be running)
```
Full detail, recovery expectations, and required operational checks: `docs/17-runbook.md`.
## Five-minute demonstration flow
1. Open `http://localhost:1228`**Open as Operations Manager**.
2. **Dashboard**: point out the metrics are live counts (available/rented/cleaning/
maintenance/blocked vehicles, open quality issues, pending/failed workflows), and the
Attention Required list linking straight to the underlying issues.
3. **Vehicles → MO-024** → open the active booking `BK-DEMO-RETURN`, register a return
with an odometer reading below MO-024's canonical value → the result panel shows the
inspection, the derived vehicle status, the automatically-created data-quality issue,
and the queued automation event — canonical odometer is confirmed unchanged.
4. **Data Quality → DQ-DEMO-DUPLICATE**: the two-column CUS-0012/CUS-0178 comparison,
merge with the inline confirmation step, issue flips to `resolved`.
5. **Knowledge**: ask "What must I do when a vehicle returns with damage?" → grounded
answer citing both the return and damage-handling procedures with real excerpts.
6. **Automation**: filter to `failed`, retry the seeded delivery, watch it succeed within
a few seconds via the live n8n instance.
7. **Audit**: filter by `return_registered` or `customer_merged` to show every action from
this walkthrough is recorded with actor, timestamp, and correlation ID.
8. Resize the browser to 360px width to show the responsive layout (nav wraps, tables
become cards) — or run `make e2e` and point at the passing responsive assertion.
Fleet Ops remains a synthetic single-tenant PoC. It is not a production identity provider,
payment system, accounting package or public reservation platform. External RAGcore, MCP
Hub and n8n services remain independently operated dependencies and are accessed only
through their documented adapters.
Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 42 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 30 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 30 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 30 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 29 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 42 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 44 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 40 KiB

+25 -5
View File
@@ -1,16 +1,36 @@
FROM python:3.12-slim
FROM python:3.12-slim-bookworm@sha256:a116514e19457bcb7af7efe9c3dd0b9b71e85b317694e7882a1c52aa15a78134 AS runtime-base
ARG VCS_REF=development
ARG BUILD_DATE=unknown
LABEL org.opencontainers.image.title="Fleet Ops API" \
org.opencontainers.image.revision="$VCS_REF" \
org.opencontainers.image.created="$BUILD_DATE" \
org.opencontainers.image.source="https://fleetops.itworx.tech"
ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1
WORKDIR /app
COPY backend/requirements.lock ./
RUN pip install --no-cache-dir -r requirements.lock
COPY backend/requirements-prod.lock ./
RUN pip install --no-cache-dir -r requirements-prod.lock
COPY backend/pyproject.toml ./
COPY backend/app ./app
COPY backend/alembic ./alembic
COPY backend/alembic.ini ./
COPY backend/tests ./tests
COPY seed ./seed
COPY knowledge ./knowledge
COPY backend/entrypoint.sh ./entrypoint.sh
RUN pip install --no-cache-dir --no-deps -e . && chmod +x ./entrypoint.sh
RUN pip install --no-cache-dir --no-deps -e . && chmod +x ./entrypoint.sh \
&& addgroup --system app && adduser --system --ingroup app --home /app app \
&& chown -R app:app /app
FROM runtime-base AS test
COPY backend/requirements.lock ./requirements.lock
RUN pip install --no-cache-dir -r requirements.lock
COPY backend/tests ./tests
COPY contracts ./contracts
COPY scripts/check-contracts.py ./scripts/check-contracts.py
COPY n8n/workflows ./n8n/workflows
USER app
FROM runtime-base AS runtime
# Run migrations and the API as an unprivileged user; nothing here needs root.
USER app
EXPOSE 8000
CMD ["./entrypoint.sh"]
+1 -1
View File
@@ -1,7 +1,7 @@
[alembic]
script_location = alembic
prepend_sys_path = .
version_path_separator = os
path_separator = os
[loggers]
keys = root,sqlalchemy,alembic
@@ -0,0 +1,28 @@
"""idempotency request fingerprint
Revision ID: 0a4c1d2e3f5b
Revises: c24f6a9d013e
Create Date: 2026-08-16 22:00:00.000000
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = "0a4c1d2e3f5b"
down_revision: Union[str, None] = "c24f6a9d013e"
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
op.add_column(
"idempotency_records",
sa.Column("request_fingerprint", sa.String(length=64), nullable=True),
)
def downgrade() -> None:
op.drop_column("idempotency_records", "request_fingerprint")
@@ -0,0 +1,27 @@
"""enforce one open issue per detected condition
Revision ID: 4f2b9c8d7e61
Revises: 0a4c1d2e3f5b
"""
from alembic import op
import sqlalchemy as sa
revision = "4f2b9c8d7e61"
down_revision = "0a4c1d2e3f5b"
branch_labels = None
depends_on = None
def upgrade() -> None:
op.create_index(
"uq_data_quality_one_open_condition",
"data_quality_issues",
["rule_type", "entity_type", "entity_id"],
unique=True,
postgresql_where=sa.text("status = 'open'"),
)
def downgrade() -> None:
op.drop_index("uq_data_quality_one_open_condition", table_name="data_quality_issues")
@@ -0,0 +1,25 @@
"""outbox last_error_code
Revision ID: 799d8800e241
Revises: e7b08389f47f
Create Date: 2026-08-03 10:00:00.000000
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '799d8800e241'
down_revision: Union[str, None] = 'e7b08389f47f'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
op.add_column('outbox_events', sa.Column('last_error_code', sa.String(length=60), nullable=True))
def downgrade() -> None:
op.drop_column('outbox_events', 'last_error_code')
@@ -0,0 +1,28 @@
"""add optional external OIDC identity
Revision ID: a81d0ce9f662
Revises: f43d829ab610
"""
import sqlalchemy as sa
from alembic import op
revision = "a81d0ce9f662"
down_revision = "f43d829ab610"
branch_labels = None
depends_on = None
def upgrade() -> None:
op.add_column("users", sa.Column("identity_provider", sa.String(80), nullable=True))
op.add_column("users", sa.Column("external_subject", sa.String(255), nullable=True))
op.create_unique_constraint(
"uq_user_external_identity", "users", ["identity_provider", "external_subject"]
)
def downgrade() -> None:
op.drop_constraint("uq_user_external_identity", "users", type_="unique")
op.drop_column("users", "external_subject")
op.drop_column("users", "identity_provider")
@@ -0,0 +1,25 @@
"""operational user credentials
Revision ID: b7c7b536df85
Revises: 799d8800e241
"""
from alembic import op
import sqlalchemy as sa
revision = "b7c7b536df85"
down_revision = "799d8800e241"
branch_labels = None
depends_on = None
def upgrade() -> None:
op.add_column("users", sa.Column("email", sa.String(length=320), nullable=True))
op.add_column("users", sa.Column("password_hash", sa.String(length=512), nullable=True))
op.create_unique_constraint("uq_users_email", "users", ["email"])
def downgrade() -> None:
op.drop_constraint("uq_users_email", "users", type_="unique")
op.drop_column("users", "password_hash")
op.drop_column("users", "email")
@@ -0,0 +1,24 @@
"""add explicit customer anonymisation state
Revision ID: b913a72e8c14
Revises: a81d0ce9f662
"""
import sqlalchemy as sa
from alembic import op
revision = "b913a72e8c14"
down_revision = "a81d0ce9f662"
branch_labels = None
depends_on = None
def upgrade() -> None:
op.add_column("customers", sa.Column("anonymized_at", sa.DateTime(timezone=True)))
op.create_index("ix_customers_anonymized_at", "customers", ["anonymized_at"])
def downgrade() -> None:
op.drop_index("ix_customers_anonymized_at", table_name="customers")
op.drop_column("customers", "anonymized_at")
@@ -0,0 +1,68 @@
"""add domain constraints and operational indexes
Revision ID: c24f6a9d013e
Revises: b913a72e8c14
"""
import sqlalchemy as sa
from alembic import op
revision = "c24f6a9d013e"
down_revision = "b913a72e8c14"
branch_labels = None
depends_on = None
def upgrade() -> None:
checks = (
("bookings", "ck_bookings_status", "status IN ('reserved','active','returned','cancelled','blocked')"),
("bookings", "ck_bookings_time_window", "ends_at > starts_at"),
("bookings", "ck_bookings_start_odometer", "start_odometer_km IS NULL OR start_odometer_km >= 0"),
("bookings", "ck_bookings_end_odometer", "end_odometer_km IS NULL OR end_odometer_km >= 0"),
("vehicles", "ck_vehicles_operational_status", "operational_status IN ('available','rented','cleaning','maintenance','blocked')"),
("vehicles", "ck_vehicles_model_year", "model_year BETWEEN 1900 AND 2100"),
("vehicles", "ck_vehicles_odometer", "odometer_km >= 0"),
("vehicles", "ck_vehicles_next_service", "next_service_km >= 0"),
("vehicles", "ck_vehicles_version", "version >= 1"),
("data_quality_issues", "ck_data_quality_rule_type", "rule_type IN ('possible_duplicate_customer','missing_required_field','odometer_regression','booking_overlap','vehicle_status_conflict')"),
("data_quality_issues", "ck_data_quality_severity", "severity IN ('low','medium','high')"),
("data_quality_issues", "ck_data_quality_status", "status IN ('open','deferred','resolved','rejected')"),
("outbox_events", "ck_outbox_delivery_status", "delivery_status IN ('pending','delivering','succeeded','failed')"),
("outbox_events", "ck_outbox_attempts", "attempts >= 0"),
("audit_events", "ck_audit_actor_type", "actor_type IN ('user','service','system')"),
)
for table, name, condition in checks:
op.create_check_constraint(name, table, condition)
op.create_index("ix_bookings_vehicle_status_window", "bookings", ["vehicle_id", "status", "starts_at", "ends_at"])
op.create_index("ix_data_quality_work_queue", "data_quality_issues", ["status", "due_at", "severity"])
op.create_index("ix_outbox_delivery_next_attempt", "outbox_events", ["delivery_status", "next_attempt_at"])
op.create_index("ix_audit_action_occurred", "audit_events", ["action", "occurred_at"])
op.create_index("ix_audit_entity", "audit_events", ["entity_type", "entity_id"])
def downgrade() -> None:
op.drop_index("ix_audit_entity", table_name="audit_events")
op.drop_index("ix_audit_action_occurred", table_name="audit_events")
op.drop_index("ix_outbox_delivery_next_attempt", table_name="outbox_events")
op.drop_index("ix_data_quality_work_queue", table_name="data_quality_issues")
op.drop_index("ix_bookings_vehicle_status_window", table_name="bookings")
for table, name in (
("audit_events", "ck_audit_actor_type"),
("outbox_events", "ck_outbox_attempts"),
("outbox_events", "ck_outbox_delivery_status"),
("data_quality_issues", "ck_data_quality_status"),
("data_quality_issues", "ck_data_quality_severity"),
("data_quality_issues", "ck_data_quality_rule_type"),
("vehicles", "ck_vehicles_version"),
("vehicles", "ck_vehicles_next_service"),
("vehicles", "ck_vehicles_odometer"),
("vehicles", "ck_vehicles_model_year"),
("vehicles", "ck_vehicles_operational_status"),
("bookings", "ck_bookings_end_odometer"),
("bookings", "ck_bookings_start_odometer"),
("bookings", "ck_bookings_time_window"),
("bookings", "ck_bookings_status"),
):
op.drop_constraint(name, table, type_="check")
@@ -0,0 +1,49 @@
"""persist revoked sessions
Revision ID: d1f83bc64170
Revises: b7c7b536df85
"""
import sqlalchemy as sa
from alembic import op
revision = "d1f83bc64170"
down_revision = "b7c7b536df85"
branch_labels = None
depends_on = None
def upgrade() -> None:
op.create_table(
"revoked_sessions",
sa.Column("token_hash", sa.String(length=64), nullable=False),
sa.Column("expires_at", sa.DateTime(timezone=True), nullable=False),
sa.Column("id", sa.Uuid(), nullable=False),
sa.Column(
"created_at",
sa.DateTime(timezone=True),
server_default=sa.text("now()"),
nullable=False,
),
sa.Column(
"updated_at",
sa.DateTime(timezone=True),
server_default=sa.text("now()"),
nullable=False,
),
sa.PrimaryKeyConstraint("id"),
)
op.create_index("ix_revoked_sessions_expires_at", "revoked_sessions", ["expires_at"])
op.create_index(
"ix_revoked_sessions_token_hash",
"revoked_sessions",
["token_hash"],
unique=True,
)
def downgrade() -> None:
op.drop_index("ix_revoked_sessions_token_hash", table_name="revoked_sessions")
op.drop_index("ix_revoked_sessions_expires_at", table_name="revoked_sessions")
op.drop_table("revoked_sessions")

Some files were not shown because too many files have changed in this diff Show More