Reframe Docker-centric wording so the conventional path is a first-class option
Deployment-Basics.md's "What a deployment is made of" now opens with the
substrate-neutral framing (conventional / Docker / Kubernetes all run the
same base image and deployment-config), and "Running a deployment" leads
with that same three-way framing before presenting the deploy-mf-<service>
/ scripts/start workflow as one way to bring a service up under Docker,
pointing to the Cookbook and Deployment: Without Docker for the other two.
Sweeps the rest of the wiki for the same assumption: Architecture-Advanced
mentions systemd alongside Docker/Kubernetes for automatic restart and
infra-component restart, and drops "container" as the implied only unit
for per-instance role reporting, topology packaging, and the operational
instance count. Configuration-Basics, Configuration-Advanced, and
Deployment-Advanced add the conventional option alongside Docker/Kubernetes
where a mounted-config or single-network example only named Docker.
Configuration-Reference notes the Docker-free way to read the annotated
defaults from an installation package. Image-Catalog and Cookbook-Enable-
Tokens swap a couple of "container"/"in a container" phrasings for
substrate-neutral wording. Glossary's Composition entry points at the
Demo cookbook page instead of a no-longer-used "consolidated composition"
name.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security into Security: Basics + Advanced; add Config Tokens/SSO
Concepts:
- Rename Security -> Security: Basics (operational surfaces unchanged).
- New Security: Advanced - the mechanisms behind the surfaces: the token
model (two kinds, fingerprint storage, the two-question check with cache
TTL + write-bypass, admin bootstrap), the machine door (two doors,
private-network listener, shared-secret vs mutual certs), and single
sign-on (SAML contract, login/refresh flow, offline token validation,
pasted-URL browsing), plus ironclad defaults + audit.
Configuration: Advanced - two operator sections:
- Tokens: store on the primary's /app/data, first-boot bootstrap secret,
expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake.
- Single sign-on: resources/ drop, entityID / IdP-cert / role settings,
gateway signing-cert + allowed-origins.
Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced;
scope/delegation/network links -> Basics.
Sourced from com.metafluent.rest/docs/design.md; property keys deferred to
Configuration: Reference pending the shipped implementation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj