Add Deployment: Image Catalog page
Catalog of the deployable images, worked back from the deploy-mf-*
projects and grouped by role: client-facing query services, projectors
(market-data feeds / reference data / computed content), control plane,
platform infrastructure, and all-in-one/evaluation. No versions/tags,
no compositions (those live in Architecture / Deployment). socrata
projector marked forthcoming. Linked from the sidebar, Deployment:
Basics, and the Glossary.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
f114adf
Stop codifying REST as "not a content-access interface"
Drop the "not a content-access interface" remark from the REST API
page - it overstated an early assumption. Remove the redundant word
"surface" from the Security cross-link and reword the How to Read
pointer to "the control-plane to use".
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
ba0668f
Whats-New: reader-facing wording pass
- "shard(s)" -> "connection(s)" (term not introduced yet on this page)
- selectors: bandwidth reduction affects image and update sizes; CPU
saving is client-side
- drop "surface" from "API surface"
- remove the REST control-plane caveat paragraph
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
bad8f30
Revise What's New; correct slow-consumer mitigation wording
Whats-New: drop section numbers to match the other pages, remove the
AI-toned framing (compatibility "starting point", "three areas worth
an architect's attention"), and reword the monitoring/selector prose.
Slow-consumer mitigation (both Whats-New and Architecture: Advanced):
mitigation splits a consumer's stream across shards and load-balances
where feasible - it does not move content across distribution servers.
Rewrite the Architecture: Advanced mitigation/conflation paragraph and
note that a slow consumer ultimately risks disconnection.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
97d52da
Whats-New: address to existing MetaFluent v5 customers
Condense the audience line to "customers" (drop the architect callout).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
963416b
Add "What's New in Elastic MDS" page and sidebar entry
New Getting Started page orienting existing MetaFluent v5 users
(architects in particular) to what Elastic MDS adds: automatic
slow-consumer management, JMS selectors, and system-wide monitoring
and control. Linked in the sidebar under Quick Start.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
d271769
Move release notes to the deploy projects; drop the wiki page
Release notes are per-artifact and per-version - each deploy-mf-* project ships
the notes for the version it delivers - so a single wiki page cannot coherently
track them and would rot. Remove the Release-Notes placeholder and its sidebar
entry; add a pointer in Deployment: Basics ("Staying current") noting that each
deployment project ships its own release notes; inline the release-tag
convention in JMS App Dev where it used to link the removed page.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
9851d26
Configuration Reference: rename live dump section "report" not "reference"
"Reference" collides with the page title and the annotated files; the gateway
dump is one report within the overall reference. Rename the section heading and
align the intro wording (aligns with the on-disk *ReportXMLFile.xml and the
"self-report" vocabulary).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
01f213b
Configuration Reference: annotated per-image properties files + short/FQN naming
Add the annotated-defaults mechanism as the primary "what does it mean"
reference (generated per-blueprint files baked into each image under
config/defaults/, comment-annotated, version-stamped; extract with docker
cp / docker create). Explain short names vs fully-qualified names: the
annotated files define every setting in short form, and most settings appear
ONLY in short form - deployment.properties pre-lists the commonly-changed
subset in FQN form, but any setting can be overridden by its FQN. Worked
example uses a foundational property that IS surfaced in FQN form (the ETA
feed host, manager.etaServerHost), with server.default as the short-only
counter-example. Tie the two references together: self-report bundleName+name
IS the FQN. All examples extracted from a real image and the live gateway.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
4b67461
Configuration Reference: evergreen self-report how-to
Replace the placeholder with the real page: why there is no static table
(settings and defaults are version- and deployment-specific and would rot),
how to have the running system generate a complete, version-stamped
configuration reference via config/fullProperties, how to read an entry, the
tunable-vs-full-configurable-surface distinction, and diffing the dump across
upgrades. All examples verified against a live consolidated deployment
(field names, 6.3.0/6.8.0 version stamps, nested per-container shape,
restServer.standAlone override, env-ref-to-empty, 24-bundle full dump).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
9289b7b
Move Component state to Architecture: Basics
Component state is a foundational lifecycle concept (referenced by Monitoring,
Troubleshooting, Logging), and read orphaned at the tail of Architecture:
Advanced. Move the section - definition, two-phase model, and state diagram -
into Architecture: Basics after "How a request is handled". Retarget the
state-model references (Troubleshooting FAQ, Operations: Monitoring,
How-to-Read) to Basics; trim the Advanced intro; add a state<->role pointer
between the two pages.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
9a2c96f
Architecture: add "Isolating access by deployment topology"; slow-consumer first
Add a new Architecture: Advanced section on using network segmentation +
reachability-aware orchestration as a per-business-unit isolation and cost
boundary: containment by construction (a compromised BU-network actor has no
route to the data tier, control plane, or other BUs), one central coordinator
with per-tier policies, and a scalable projector tier as the BU's cost
envelope. Order slow-consumer protection ahead of it. Add the reciprocal
pointer from Deployment: Advanced (Flat vs segmented).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
4756195
Operations: Troubleshooting - fix broken wiki-links in tables
The [[Label|Slug]] links in the symptom/cause/remedy table cells collided
with the table's | delimiters and did not resolve. Convert the in-cell links
(9 rows) to [Label](Slug) markdown links; prose wiki-links are unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
f388517
How to Read: drop REST-vs-data asides; positive v5 framing; fix table links
- Remove the "you don't need REST" line (developer path) and the "not how
applications get data" clause (operator path) - belaboring a non-issue.
- v5 section: drop "the one delta" (reads as an obligation); positive framing -
code runs unchanged, the MarketData context unlocks new capabilities.
- Fix the "looking for something specific?" table: [[Label|Slug]] wiki-links
collide with the table's own | delimiters and don't resolve; use
[Label](Slug) markdown links instead.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
39a89c5
Add "How to Read This Guide" - role-specific reading paths
Expansive on-ramp under Getting Started: makes explicit that you don't read
the guide front to back and that the paths are role-specific. Ordered routes
for evaluating / application developer / operator / architect / v5 user, each
page annotated with why it's on the path, plus a "looking for something
specific?" table. REST is kept strictly to the operator/architect (control
plane) routes - out of the developer path; the MarketData context leads the
developer path, Entitlements demoted to optional. Home's "Start here" points
in; sidebar entry added.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
65255f6
Architecture: Advanced - deepen with resilience, auto-scaling, slow-consumer protection
- Resilience: three layers (automatic restart / active-standby / auto-scaling)
as a unifying frame ahead of the active/standby section.
- Auto-scaling: projectors as the scalable unit, container manager, damped
high/low-water scaling, alongside-redundancy, policy-driven, docker=dev/lab
vs k8s=prod.
- Slow-consumer protection & auto-conflation: the shared-path problem,
connection profiling with a learned ceiling, per-connection conflation to
the current value, and load redistribution (rebalance / shard-split) first.
Grounded via the mf-orchestration and mf-push agents; kept at architecture
altitude with all internal/IP detail (mechanism internals, thresholds,
anchored-lifecycle, DataFabric, internal names) deliberately excluded.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
7d694e9
Wiki-wide: replace the AI-tell "shape" with topology/arrangement/etc.
"deployment shape(s)" -> "topology"/"arrangement"; "two shapes of API" ->
"kinds"; "the shape your script expects" -> "structure"; "canonical shape
of a subscriber" -> "form"; "production-shaped" -> "production-grade".
Spans Architecture: Advanced, Deployment: Advanced/Basics/Without-Docker,
Glossary, REST API, and the SimpleSubscriber example.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
648dc79
Architecture: Advanced - point topology section to Deployment: Advanced
Complete the diagrams <-> networking loop: the topology section now sends
readers to Deployment: Advanced for how to network/deploy each shape (flat
vs segmented, bind vs advertise, substrate recipes), alongside the existing
Deployment: Basics pointer for choosing a topology.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
4e0b85d
Deployment: Advanced - author from the networking architecture doc
Networking-centered: bind vs advertise and the three host moments; "no
single public host" (advertisement is per-network - retires PUBLIC_HOST);
flat vs segmented (opt-in via *_NETWORKS); the network variables +
NetworkDefinition descriptor (Cidr / AdvertiseHost) + fail-loud; the
gateway's separate host model; and deployment shapes by substrate (Eclipse,
Docker host / bridged / macvlan-multihomed, Kubernetes) with a decision
guide. Distilled to client-facing altitude from
docker-compositions/docs/host-resolution-and-networking.md.
Reconcile composition framing (Glossary + Basics) to "worked templates;
Kubernetes is the production substrate" - drops the "not a production
deployment" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
4cae625
Operations: Monitoring - per-container versions by systemID predicate
osgi-bootstrap now exposes systemID as a non-identity @APIResource
(MetaFluent/IssueTracking#633), so use-case 1 selects a container's bundles by the
same identity used for logs and state: systemID=<systemID>/bundles?bundleName=.*
Also removes the earlier availability caveat (its premise was a gateway
duplicate-@APIIdentity conflict, since fixed, not an IDE limitation). Verified live.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
776ab54
Operations: Monitoring - note osgi-bootstrap availability (bootstrap-dependent)
osgi-bootstrap is only in the catalog where the deployment is bootstrapped;
a bare IDE/dev launch has no bootstrap layer and no osgi-bootstrap API, so
version queries are unavailable there. Observed live (present on a
bootstrapped container deployment, absent on a non-bootstrapped launch).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
a50dcd1
Operations: Monitoring - add Component versions (osgi-bootstrap)
Two use-cases via the osgi-bootstrap /bundles?bundleName=<regex> resource
(name/version/state): what components and versions run in a container, and
what version of a given component is deployed system-wide (drift check via
* sweeping every container). Notes that the osgi-bootstrap instance id is
its own, not the application-state systemID. Verified live.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
8790eeb
Configuration: Advanced - apply review notes
- "runs without configuration" -> "in most cases it runs without
configuration".
- Clarify that deployment.properties overrides are operator-authored and
each can be a literal or an env-var reference (forward-ref to the env-var
section), rather than implying overrides are always env values.
- Selecting modes: show the includePaths list reworked with DACS selected.
- Env-var intro: "one deployable image adapts to a deployment" (not "one
deployment adapts to each host").
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
1b7b147
Configuration: Advanced - author page
How a deployment's configuration is assembled (shipped defaults <-
deployment.properties + modes + env substitution); selecting modes via
includePaths with the (*) default convention (DACS worked example stays in
Basics); $(NAME) / $(NAME:default) / $(NAME:) substitution; and deeper
effective-config inspection over the config API - fullProperties with
default/actual, narrowing by bundleName regex and by container (image=
predicate). Customer-facing altitude, no blueprint/tunable internals. All
REST examples verified live.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
234e2a3
Security: fix deployment-secrets example (DB credentials, not DACS settings)
DACS connection settings are configuration, not secrets. Use a content
adapter's database username/password (e.g. the RDBMS adapter's JDBC
credentials) as the example of a genuine deployment secret.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
b7ef163
Security: give transitive derived-content entitlement its own section
The transitive property (read access to derived content requires access to
every input, transitively - no laundering via computed columns/views) is a
significant guarantee; pull it out of the framework list into its own
prominent section. Add a one-way pointer from Entitlements Context to this
architecture section.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
dc6d0a7
Security & Entitlements: rework entitlements + authn frameworks; tokens as shipped
Entitlements section rewritten as the access-control (authorization)
framework, not the JMS entitlements-context (removes the circular
reference): DACS/alternative behind a pluggable entitlements service
abstraction that content adapters bind to independently (per-table binding
as a footnote); framework capabilities - row-level read AND write, transitive
access through the derived-content framework, live refresh of access.
Client authentication: add the authn framework capabilities - refreshable,
independent of authz, multiple principals (Subjects).
Admin/REST access: write API tokens in present tense (shipping soon); gloss
the administration + SSO login UI and link to a new API Token Administration
page (in preparation). REST API: authentication note now present-tense.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
3e5c03e
Security & Entitlements: author first pass; ground the API-token roadmap in the agreed design
Cross-cutting security page: the security surfaces map; client
authentication (none / DACS, grounded in the session-authn mode); an
entitlements pointer to the Entitlements Context page; and the admin/REST
access section - open today (network-secured), with roadmap placeholders.
The API-token placeholder now reflects the preliminary architecture agreed
under IssueTracking#472 (Bearer mft_ token, guest/full *:read and *:* scopes
leading with fine-grained <api>.<object>:<action> as advanced, operator-issued
and shown once, per-cluster, TTL revocation), plus SAML2 SSO as the planned
self-service token-login path. All clearly marked planned/preliminary.
REST API: add a short Authentication note pointing here.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
44f69d8
Operations: Troubleshooting - add a symptom-first jump index at the top
"Start here - what kind of trouble?" groups the sections (startup/
availability, user/client trouble, data trouble, performance) with
anchor links down to each, so the reader jumps straight to their symptom
instead of scrolling.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
f877826
Operations: account for standby role in health checks (redundant deployments)
Monitoring: "healthy" now depends on role - ACTIVE/n-a should be
FULLY_OPERATIONAL, STANDBY is healthy at RESOURCE_COMPLETE (awaiting
activation). Adds a redundant-deployment example so a hot standby is not
misread as broken.
Troubleshooting: rebuild the cluster section as "Cluster and redundancy" -
lead with the healthy-standby signature (role=STANDBY predicate call, real
output), the same-named-pair/systemID note and the lone-dot-path gotcha,
then symptoms (standby normal-at-RESOURCE_COMPLETE, missing component, no
ACTIVE, standby-did-not-promote). Grounded in a live redundant cluster.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
11c278a