Skip to content

History / Security Basics

Revisions

  • Reframe Docker-centric wording so the conventional path is a first-class option Deployment-Basics.md's "What a deployment is made of" now opens with the substrate-neutral framing (conventional / Docker / Kubernetes all run the same base image and deployment-config), and "Running a deployment" leads with that same three-way framing before presenting the deploy-mf-<service> / scripts/start workflow as one way to bring a service up under Docker, pointing to the Cookbook and Deployment: Without Docker for the other two. Sweeps the rest of the wiki for the same assumption: Architecture-Advanced mentions systemd alongside Docker/Kubernetes for automatic restart and infra-component restart, and drops "container" as the implied only unit for per-instance role reporting, topology packaging, and the operational instance count. Configuration-Basics, Configuration-Advanced, and Deployment-Advanced add the conventional option alongside Docker/Kubernetes where a mounted-config or single-network example only named Docker. Configuration-Reference notes the Docker-free way to read the annotated defaults from an installation package. Image-Catalog and Cookbook-Enable- Tokens swap a couple of "container"/"in a container" phrasings for substrate-neutral wording. Glossary's Composition entry points at the Demo cookbook page instead of a no-longer-used "consolidated composition" name. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Aug 16, 2026
  • Split Security into Security: Basics + Advanced; add Config Tokens/SSO Concepts: - Rename Security -> Security: Basics (operational surfaces unchanged). - New Security: Advanced - the mechanisms behind the surfaces: the token model (two kinds, fingerprint storage, the two-question check with cache TTL + write-bypass, admin bootstrap), the machine door (two doors, private-network listener, shared-secret vs mutual certs), and single sign-on (SAML contract, login/refresh flow, offline token validation, pasted-URL browsing), plus ironclad defaults + audit. Configuration: Advanced - two operator sections: - Tokens: store on the primary's /app/data, first-boot bootstrap secret, expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake. - Single sign-on: resources/ drop, entityID / IdP-cert / role settings, gateway signing-cert + allowed-origins. Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced; scope/delegation/network links -> Basics. Sourced from com.metafluent.rest/docs/design.md; property keys deferred to Configuration: Reference pending the shipped implementation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026