Skip to content

History

Revisions

  • Fix a third double-bracket JSON array (multi-line) The multi-line component-state example in Operations: Monitoring was also wrapped in [[ ]] instead of a single-bracket JSON array. Correct to [ ]. Wiki-wide re-scan confirms no [[ / ]] code-array artifacts remain and every [[...]] link resolves to a real page. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    f148046
  • Fix double-bracket JSON/SQL example arrays Two example payloads in code fences were wrapped in [[ ]] (which renders literally) instead of single-bracket JSON/SQL arrays. Correct to [ ]. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    88fcf3b
  • Wiki-wide: fix cross-page and same-page section links Same mis-placed-anchor pattern as the Cookbook fix, swept across the whole wiki: 19 links across 8 pages carried the #anchor on the display side of the [[...]] pipe (or as a bare [[Section Title]]), so they landed on the page top instead of the section. Convert each to a markdown link that honors the fragment, e.g. [[Architecture: Advanced#high-availability-activestandby|active/standby]] -> [active/standby](Architecture-Advanced#high-availability-activestandby) and same-page ones to [text](#anchor). One swapped plain link ([[Configuration: Basics|setting values]]) corrected to [[setting values|Configuration-Basics]]. Every target anchor verified against a real heading. Not touched: two double-bracket JSON/SQL examples inside code fences (a separate typo, flagged for review). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    8602791
  • Cookbook: link to the actual subsections, not the page top The recipe links carried the #anchor on the display side of the wiki-link pipe, so the target had no fragment and every link landed on the page top. Convert the anchored cross-page references to markdown links (which honor fragments on GitHub wiki) and name the subsection in the link text, e.g. "Configuration: Advanced - Single sign-on" -> #single-sign-on-sso. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    0ac130a
  • Add Cookbook section: Enable Tokens and Enable SSO recipes New task-oriented "how-to" section in the sidebar, after Configuration. Two thin, verification-led recipes - ordered steps plus links to the pages that own the detail, deliberately carrying no property names (the config surface self-documents, so recipes can't drift on key names): - Cookbook: Enable Tokens - /app/data on the primary, provision the store, first-boot bootstrap secret, mint the first admin token, issue tokens; verify with a 401-vs-Bearer probe and the self-report. - Cookbook: Enable SSO - drop SAML files into resources/rest.sso/, give the gateway the signing cert + allowed-origins, confirm the couplings, register the SP at the IdP; verify via the dashboard login bounce. Each recipe is its own page, so it appears as an individual sidebar link. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    df19bbf
  • Config: SSO couplings in the page's voice, with concrete defaults Replace the conceptual couplings note with the reviewer's version: pins the issuer/audience defaults (metafluent-sso / metafluent-gateway) so the common case reads as "already agree, no action", and states the signing keypair coupling. No raw property names (page defers those). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    7df61e7
  • Security/Config: fix machine-door bind claim, rest.sso path, SSO couplings Review follow-ups from the SSO/tokens implementation session: - Security: Advanced - the machine door is not private-network-bound by default (all interfaces); the always-on protection is the separate cluster credential, private-network binding is deployment hardening. Reword the listener note and the "can't even reach it" claim so the security guarantee rests on the credential, not the default bind. - Configuration: Advanced - SSO operator files live under the short resources/rest.sso/ (intentional exception to the FQN <component> naming), and include the doorway's own signing keystore + SAML.properties. - Configuration: Advanced - document the two SSO matched-pair couplings (issuer/audience; signing keypair vs verifying certificate) as silent-failure traps. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    4b7cf40
  • Split Security into Security: Basics + Advanced; add Config Tokens/SSO Concepts: - Rename Security -> Security: Basics (operational surfaces unchanged). - New Security: Advanced - the mechanisms behind the surfaces: the token model (two kinds, fingerprint storage, the two-question check with cache TTL + write-bypass, admin bootstrap), the machine door (two doors, private-network listener, shared-secret vs mutual certs), and single sign-on (SAML contract, login/refresh flow, offline token validation, pasted-URL browsing), plus ironclad defaults + audit. Configuration: Advanced - two operator sections: - Tokens: store on the primary's /app/data, first-boot bootstrap secret, expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake. - Single sign-on: resources/ drop, entityID / IdP-cert / role settings, gateway signing-cert + allowed-origins. Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced; scope/delegation/network links -> Basics. Sourced from com.metafluent.rest/docs/design.md; property keys deferred to Configuration: Reference pending the shipped implementation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    1c14253
  • Split Security & Entitlements into Access Control + Security Separate the combined Concepts page into two: - Access Control (Architect) - client authentication, entitlements (authorization), and transitive entitlement for derived content. New lead. Placed after Architecture: Basics in the sidebar. - Security (Architect, Operator) - the operational surfaces: REST/admin access, cluster-internal traffic, transport, and deployment secrets. Keeps the original "Elastic MDS's security..." lead, adapted. Placed after Architecture: Advanced. Drops the "security surfaces" list; re-points all cross-references (Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to Access Control; Deployment-Advanced, API-Token-Administration, REST-API to Security). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
    2aeb3d4
  • Security: machine-secret generator takes the output file directly The generator now takes the output file path (no --data-dir, no appended suffix, no default); the example writes ./data/security/machine/machine.secret, the operator-visible host path the gateway reads as $(METAFLUENT_DATA_DIR)/security/machine/machine.secret. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    4f6508d
  • Security: machine-secret example uses the literal default data dir (/app/data) Show the resolved default path (METAFLUENT_DATA_DIR = /app/data) rather than the env var; operators who have moved the data dir already know their path and substitute it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    078c318
  • Security: machine-secret example passes the default data dir explicitly The generator now requires --data-dir (no built-in default to duplicate the blueprint's); the example points it at the default, $(METAFLUENT_DATA_DIR), so the example matches the authoritative default and the value lives in one place. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    087b87c
  • Security: machine-secret example uses the real default path, notes it is configurable Replace the placeholder --data-dir with the generator's default; state the default location ($(METAFLUENT_DATA_DIR)/security/machine/machine.secret) and that it is changeable via the node's configuration (Configuration: Reference). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    06db884
  • Security: add cluster machine-secret surface + procedure; fix token-page REST link Security & Entitlements gains a "Cluster-internal access" surface and section: the shared machine secret model, presence-based enforcement, the loud non-functional failure on mismatch, and the generate-once/distribute-everywhere procedure using generate-machine-secret (deploy-mf-api-gateway). API Token Administration: correct the REST link (Develop-REST -> REST-API). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    95d9bc2
  • API Token Administration: operator guide replacing the placeholder Full operator page: presence-based enforcement, the generate-bootstrap-secret flow (deploy-mf-api-gateway), minting with scopes and expiry, listing/auditing with the predicate grammar, revocation and rotation, and the SSO personal-token pointer. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 27, 2026
    3d2d546
  • Deployment: Without Docker - rewrite to the installation-package model Replace the manual extract-a-base-image + METAFLUENT + run-application content with the install-zip flow (#695): download the deploy-mf-* release zip, edit deployment-config/ (deployment.properties + settings/), set JAVA_HOME, run ./run. Layout: app/ internals + top-level deployment-config/ + logs/. Config uses the new settings model. Refs MetaFluent/IssueTracking#695, MetaFluent/IssueTracking#586. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 25, 2026
    1961d87
  • Wiki sweep: mode->switch, tunable->setting for the settings layout Security: session-authn 'mode' -> authenticationDomain 'switch'. Configuration Reference: 'tunable' subset -> promoted 'settings' in the per-component settings files, vs the full configurable surface. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 25, 2026
    2f7567b
  • Configuration: Advanced - modes to switches; per-component settings assembly Replace the mode-group / includePaths-selection model with switches (plain on/off values at the top of deployment.properties) and the per-component settings files that includePaths now pulls in. Env-var and config-API sections unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 25, 2026
    2f47f22
  • Configuration: Basics - rewrite for the settings layout Thin deployment.properties (switches + required + per-component settings index), per-component settings/<component>.properties with matching -reference.txt, and the setting/switch vocabulary. Configured the same across all three run modes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 25, 2026
    3f58d29
  • Architecture: Advanced - add resilient topologies; lead with resilience Add two topology cards + brand SVGs showing active/standby via a "shadow" behind the functional services: - Resilient, scalable, multi-homed (shadow behind mf-core-srvcs) - Resilient, scalable, fine-grained, multi-homed (shadows behind mf-session, mf-pubsub, mf-sql, mf-orchestration) Move Resilience / High availability / Auto-scaling above the topology cards so the mechanisms are explained before the diagrams that show them. Rename "From operations, they are the same" -> "From a monitoring perspective, they look the same". Count four -> six. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    @amacgaffey amacgaffey committed Jul 23, 2026
    d175481
  • Architecture: Advanced - drop AI-tell "shape"; aggregated vs fine-grained Reword the fixed-capacity card to avoid the flagged noun "shape" (style-notes) - "Structured like an existing JMS deployment". In the operations contrast, "one (consolidated)" -> "a few (aggregated)". Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    @amacgaffey amacgaffey committed Jul 22, 2026
    97ad2c8
  • Architecture: Advanced - order topologies by increasing complexity Move Scalable, multi-homed above the fully-decomposed topology and rename the latter "Scalable, fine-grained, multi-homed", so the cards progress consolidated -> fixed-capacity -> scalable -> scalable + fine-grained. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    @amacgaffey amacgaffey committed Jul 22, 2026
    7e19469
  • Architecture: Advanced - move fixed-capacity card up, fix SVG subtitle Reorder the fixed-capacity, multi-homed card to sit right after Consolidated (reworded to stand alone, no forward-reference to the scalable card). Shorten the SVG subtitle so it no longer runs under the external-data-sources cloud. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    @amacgaffey amacgaffey committed Jul 22, 2026
    521e327
  • Architecture: Advanced - add fixed-capacity, multi-homed topology New "Fixed-capacity, multi-homed" card and brand SVG: the scalable, multi-homed layout without mf-dcm, with a fixed pool of three mf-projector-mds servers on the same plane as core services - the familiar pool-of-servers shape an existing JMS deployment already has. Intro topology count three -> four. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    @amacgaffey amacgaffey committed Jul 22, 2026
    98a80b5
  • Image Catalog: "additional" -> "available" Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    3058533
  • Image Catalog: drop "Those available today" lead-in The list (with forthcoming markers) speaks for itself. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    1d7c35b
  • Image Catalog: add forthcoming dates and finance libraries Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    0a8ff7d
  • Image Catalog: add the intrinsic library Add the built-in `intrinsic` library (SQL arithmetic and comparison operators from the base content-adapter) ahead of the additional libraries, noting it is always present. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    d92944a
  • Image Catalog: list compute libraries; frame consolidated as start-here List the built-in computation libraries (basic, math, interpolation) as sub-bullets under the compute projector so architects can see what is available now; a fuller function reference can follow later. Note mf-mds-consolidated as the place to start evaluating. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    77adec2
  • Image Catalog: link the Deploy project column to each repo Each deploy project cell now links to its GitHub repository so a reader can follow through to clone. socrata stays unlinked (forthcoming). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
    c693757