Deployment-Advanced: Conventional host install replaces the Eclipse bullet
The "Deployment topologies" networking breakdown named an Eclipse/developer
mode, an internal dev-build concern with no place in customer docs. Replaces
it with a Conventional (host install) bullet - the primary run method - and
rebalances the section's opening line so conventional, Docker, and
Kubernetes read as peer run methods rather than positioning Docker
compositions as the templates. The new bullet folds in the local/same-host
case the Eclipse bullet used to cover.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Reframe Docker-centric wording so the conventional path is a first-class option
Deployment-Basics.md's "What a deployment is made of" now opens with the
substrate-neutral framing (conventional / Docker / Kubernetes all run the
same base image and deployment-config), and "Running a deployment" leads
with that same three-way framing before presenting the deploy-mf-<service>
/ scripts/start workflow as one way to bring a service up under Docker,
pointing to the Cookbook and Deployment: Without Docker for the other two.
Sweeps the rest of the wiki for the same assumption: Architecture-Advanced
mentions systemd alongside Docker/Kubernetes for automatic restart and
infra-component restart, and drops "container" as the implied only unit
for per-instance role reporting, topology packaging, and the operational
instance count. Configuration-Basics, Configuration-Advanced, and
Deployment-Advanced add the conventional option alongside Docker/Kubernetes
where a mounted-config or single-network example only named Docker.
Configuration-Reference notes the Docker-free way to read the annotated
defaults from an installation package. Image-Catalog and Cookbook-Enable-
Tokens swap a couple of "container"/"in a container" phrasings for
substrate-neutral wording. Glossary's Composition entry points at the
Demo cookbook page instead of a no-longer-used "consolidated composition"
name.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Wiki-wide: fix cross-page and same-page section links
Same mis-placed-anchor pattern as the Cookbook fix, swept across the
whole wiki: 19 links across 8 pages carried the #anchor on the display
side of the [[...]] pipe (or as a bare [[Section Title]]), so they landed
on the page top instead of the section. Convert each to a markdown link
that honors the fragment, e.g.
[[Architecture: Advanced#high-availability-activestandby|active/standby]]
-> [active/standby](Architecture-Advanced#high-availability-activestandby)
and same-page ones to [text](#anchor). One swapped plain link
([[Configuration: Basics|setting values]]) corrected to
[[setting values|Configuration-Basics]].
Every target anchor verified against a real heading. Not touched: two
double-bracket JSON/SQL examples inside code fences (a separate typo,
flagged for review).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security into Security: Basics + Advanced; add Config Tokens/SSO
Concepts:
- Rename Security -> Security: Basics (operational surfaces unchanged).
- New Security: Advanced - the mechanisms behind the surfaces: the token
model (two kinds, fingerprint storage, the two-question check with cache
TTL + write-bypass, admin bootstrap), the machine door (two doors,
private-network listener, shared-secret vs mutual certs), and single
sign-on (SAML contract, login/refresh flow, offline token validation,
pasted-URL browsing), plus ironclad defaults + audit.
Configuration: Advanced - two operator sections:
- Tokens: store on the primary's /app/data, first-boot bootstrap secret,
expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake.
- Single sign-on: resources/ drop, entityID / IdP-cert / role settings,
gateway signing-cert + allowed-origins.
Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced;
scope/delegation/network links -> Basics.
Sourced from com.metafluent.rest/docs/design.md; property keys deferred to
Configuration: Reference pending the shipped implementation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security & Entitlements into Access Control + Security
Separate the combined Concepts page into two:
- Access Control (Architect) - client authentication, entitlements
(authorization), and transitive entitlement for derived content. New
lead. Placed after Architecture: Basics in the sidebar.
- Security (Architect, Operator) - the operational surfaces: REST/admin
access, cluster-internal traffic, transport, and deployment secrets.
Keeps the original "Elastic MDS's security..." lead, adapted. Placed
after Architecture: Advanced.
Drops the "security surfaces" list; re-points all cross-references
(Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to
Access Control; Deployment-Advanced, API-Token-Administration, REST-API
to Security).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Architecture: add "Isolating access by deployment topology"; slow-consumer first
Add a new Architecture: Advanced section on using network segmentation +
reachability-aware orchestration as a per-business-unit isolation and cost
boundary: containment by construction (a compromised BU-network actor has no
route to the data tier, control plane, or other BUs), one central coordinator
with per-tier policies, and a scalable projector tier as the BU's cost
envelope. Order slow-consumer protection ahead of it. Add the reciprocal
pointer from Deployment: Advanced (Flat vs segmented).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Wiki-wide: replace the AI-tell "shape" with topology/arrangement/etc.
"deployment shape(s)" -> "topology"/"arrangement"; "two shapes of API" ->
"kinds"; "the shape your script expects" -> "structure"; "canonical shape
of a subscriber" -> "form"; "production-shaped" -> "production-grade".
Spans Architecture: Advanced, Deployment: Advanced/Basics/Without-Docker,
Glossary, REST API, and the SimpleSubscriber example.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Deployment: Advanced - author from the networking architecture doc
Networking-centered: bind vs advertise and the three host moments; "no
single public host" (advertisement is per-network - retires PUBLIC_HOST);
flat vs segmented (opt-in via *_NETWORKS); the network variables +
NetworkDefinition descriptor (Cidr / AdvertiseHost) + fail-loud; the
gateway's separate host model; and deployment shapes by substrate (Eclipse,
Docker host / bridged / macvlan-multihomed, Kubernetes) with a decision
guide. Distilled to client-facing altitude from
docker-compositions/docs/host-resolution-and-networking.md.
Reconcile composition framing (Glossary + Basics) to "worked templates;
Kubernetes is the production substrate" - drops the "not a production
deployment" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Scaffold Elastic MDS wiki: Home, sidebar, footer, page stubs for the full doc set