Skip to content

History / Configuration Advanced

Revisions

  • Reframe Docker-centric wording so the conventional path is a first-class option Deployment-Basics.md's "What a deployment is made of" now opens with the substrate-neutral framing (conventional / Docker / Kubernetes all run the same base image and deployment-config), and "Running a deployment" leads with that same three-way framing before presenting the deploy-mf-<service> / scripts/start workflow as one way to bring a service up under Docker, pointing to the Cookbook and Deployment: Without Docker for the other two. Sweeps the rest of the wiki for the same assumption: Architecture-Advanced mentions systemd alongside Docker/Kubernetes for automatic restart and infra-component restart, and drops "container" as the implied only unit for per-instance role reporting, topology packaging, and the operational instance count. Configuration-Basics, Configuration-Advanced, and Deployment-Advanced add the conventional option alongside Docker/Kubernetes where a mounted-config or single-network example only named Docker. Configuration-Reference notes the Docker-free way to read the annotated defaults from an installation package. Image-Catalog and Cookbook-Enable- Tokens swap a couple of "container"/"in a container" phrasings for substrate-neutral wording. Glossary's Composition entry points at the Demo cookbook page instead of a no-longer-used "consolidated composition" name. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Aug 16, 2026
  • Config: SSO couplings in the page's voice, with concrete defaults Replace the conceptual couplings note with the reviewer's version: pins the issuer/audience defaults (metafluent-sso / metafluent-gateway) so the common case reads as "already agree, no action", and states the signing keypair coupling. No raw property names (page defers those). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Security/Config: fix machine-door bind claim, rest.sso path, SSO couplings Review follow-ups from the SSO/tokens implementation session: - Security: Advanced - the machine door is not private-network-bound by default (all interfaces); the always-on protection is the separate cluster credential, private-network binding is deployment hardening. Reword the listener note and the "can't even reach it" claim so the security guarantee rests on the credential, not the default bind. - Configuration: Advanced - SSO operator files live under the short resources/rest.sso/ (intentional exception to the FQN <component> naming), and include the doorway's own signing keystore + SAML.properties. - Configuration: Advanced - document the two SSO matched-pair couplings (issuer/audience; signing keypair vs verifying certificate) as silent-failure traps. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Split Security into Security: Basics + Advanced; add Config Tokens/SSO Concepts: - Rename Security -> Security: Basics (operational surfaces unchanged). - New Security: Advanced - the mechanisms behind the surfaces: the token model (two kinds, fingerprint storage, the two-question check with cache TTL + write-bypass, admin bootstrap), the machine door (two doors, private-network listener, shared-secret vs mutual certs), and single sign-on (SAML contract, login/refresh flow, offline token validation, pasted-URL browsing), plus ironclad defaults + audit. Configuration: Advanced - two operator sections: - Tokens: store on the primary's /app/data, first-boot bootstrap secret, expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake. - Single sign-on: resources/ drop, entityID / IdP-cert / role settings, gateway signing-cert + allowed-origins. Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced; scope/delegation/network links -> Basics. Sourced from com.metafluent.rest/docs/design.md; property keys deferred to Configuration: Reference pending the shipped implementation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Split Security & Entitlements into Access Control + Security Separate the combined Concepts page into two: - Access Control (Architect) - client authentication, entitlements (authorization), and transitive entitlement for derived content. New lead. Placed after Architecture: Basics in the sidebar. - Security (Architect, Operator) - the operational surfaces: REST/admin access, cluster-internal traffic, transport, and deployment secrets. Keeps the original "Elastic MDS's security..." lead, adapted. Placed after Architecture: Advanced. Drops the "security surfaces" list; re-points all cross-references (Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to Access Control; Deployment-Advanced, API-Token-Administration, REST-API to Security). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Configuration: Advanced - modes to switches; per-component settings assembly Replace the mode-group / includePaths-selection model with switches (plain on/off values at the top of deployment.properties) and the per-component settings files that includePaths now pulls in. Env-var and config-API sections unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 25, 2026
  • Configuration: Advanced - apply review notes - "runs without configuration" -> "in most cases it runs without configuration". - Clarify that deployment.properties overrides are operator-authored and each can be a literal or an env-var reference (forward-ref to the env-var section), rather than implying overrides are always env values. - Selecting modes: show the includePaths list reworked with DACS selected. - Env-var intro: "one deployable image adapts to a deployment" (not "one deployment adapts to each host"). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 17, 2026
  • Configuration: Advanced - author page How a deployment's configuration is assembled (shipped defaults <- deployment.properties + modes + env substitution); selecting modes via includePaths with the (*) default convention (DACS worked example stays in Basics); $(NAME) / $(NAME:default) / $(NAME:) substitution; and deeper effective-config inspection over the config API - fullProperties with default/actual, narrowing by bundleName regex and by container (image= predicate). Customer-facing altitude, no blueprint/tunable internals. All REST examples verified live. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 17, 2026
  • Scaffold Elastic MDS wiki: Home, sidebar, footer, page stubs for the full doc set

    @amacgaffey amacgaffey committed Jul 14, 2026