7.2 KiB
Orchestra progress
Updated: 2026-07-26
Server implementation checklist
This is the implementation-oriented breakdown of the specification. It is a project checklist, not a replacement for the binding spec.
-
Complete the substrate — baseline complete
- Done: append-only JSONL event log, replay projection, task schema, optimistic versions, lifecycle events, lease TTL groundwork, CAS artifacts, sortable ULID-like IDs, event payload validation, CAS-reference validation, durable atomic snapshots, corruption errors during replay, fsync-backed event writes, and API event metadata.
- Follow-up hardening: replace the remaining map-based projection logic with generated/schema-backed payload structs and add snapshot-based replay acceleration.
-
Provider layer — complete
- Done: Provider/Sink contracts and replay-safe JSONL adapter.
- Done: append-only JSONL file watcher/ingester with rotation handling and bounded records.
- Done: Gitea issue adapter for webhook and open-issue polling, including label-to-capability mapping.
- Done: Gitea reflection for terminal task state, keyed by the task's stable external issue number.
- Done: constant-time HMAC webhook authentication and injectable HTTP clients for testing.
-
Projects and machine registry — complete
- Done: typed JSON project, machine, and herdr configuration with duplicate/reference validation.
- Done: machine-bound herdr registry with per-herdr capabilities, endpoint override, and concurrency configuration.
- Done: injectable reachability checks plus TCP reachability implementation.
- Done: hard project machine-affinity resolution; candidates are restricted to configured, reachable herdrs on allowed machines.
- Done: optional
ORCHESTRA_CONFIGstartup validation.
-
Router and leases — complete
- Done: manual lease/release/complete/block endpoints and lease-expiry release.
- Done: assignment on
TaskCreatedand lease release/expiry. - Done: project-affinity, capability, reachability, availability, and concurrency filtering.
- Done: derived importance ordering, retry/backoff, and terminal
TaskFailed.
-
Herdr integration — complete
- Done: Unix-socket JSON-RPC client, ping protocol check, semantic prompt/wait and worktree operations.
- Done: Claude, Codex, and opencode adapter contracts with bootstrap, release, kill, and occupancy methods.
- Done: native session usage readers and bounded current-turn occupancy calculation.
- Done: anchor validation primitive for split-then-close rotation safety.
-
Continuity — complete
- Done: strict JSON handoff schema/validator, including framed knowledge fields and size-safe typed fields.
- Done: CAS-backed handoff save/load with content-address verification.
- Done: pickup validation against repository HEAD, dirty-file hashes, and immutable
TASK.mdhash. - Done: scratch-branch WIP commit helper and Markdown change notices.
-
Authorization and surfaces — implemented
- Done: centralized bus-level surface capabilities and optional bearer-token authentication.
- Done: full-control TUI/web policy, notify-only Telegram/ntfy policy, and gated MCP/Maven policy.
- Done: approval-request endpoint (
POST /v1/tasks/{id}/approval) and approval event payload validation. - Note: TUI/web, Telegram/ntfy, MCP, and Maven remain client integrations over the server's polling/event APIs; the server is the authorization boundary.
-
Projections and operations — not started
- Quota projection
- Nightly/morning brief
- Git sync state
- Standup advisory events
- Logging, metrics, service packaging, and deployment configuration
Completed
- Built the first Go server slice from
orchestra-spec (1).md. - Added append-only JSONL events and replay projection in
internal/store. - Added task creation, external-key deduplication, optimistic versions, lifecycle states, and SHA-256 CAS artifacts.
- Added HTTP endpoints on default port
9145: health, task ingest/list, and event cursor reads. - Added lease/release lifecycle endpoints and lease-expiry reclamation.
- Finished the item 1 provider port:
provider.Provider/Sinkinterfaces and a replay-safe JSONL adapter. - Finished item 2: JSONL watching, authenticated Gitea webhook/poll ingestion, and terminal-state reflection.
- Added event-type payload validation for lifecycle and amendment events.
- Unit tests pass with
go test ./.... - Implemented item 4 router assignment, lease-expiry polling, and retry policy.
- Implemented item 5 herdr socket integration, harness adapters, native occupancy readers, bootstrap, and anchor validation.
- Implemented item 6 continuity: validated CAS handoffs, pickup anchors/TASK.md, scratch-branch commits, and shared Markdown change notices.
Current API additions
POST /v1/tasks/{id}/leasewith{"harness_id":"...","ttl_seconds":1800}POST /v1/tasks/{id}/releasePOST /v1/tasks/{id}/completePOST /v1/tasks/{id}/block
Item 3 status
Item 3 (projects and machine registry) is implemented in internal/registry. Static JSON configuration is loaded and validated, projects resolve only to their explicitly configured machines, and candidate herdrs are filtered by registration and injected reachability. Set ORCHESTRA_CONFIG to validate a configuration file at server startup.
Item 2 status
Item 2 (provider layer) is implemented. internal/provider now includes JSONLWatcher, Gitea.Poll, Gitea.WebhookHandler, Gitea.IngestWebhook, and Gitea.ReflectTask. Gitea ingestion remains idempotent through the store's (source, external_id) key. The server wiring can attach these components to deployment-specific routes and polling loops without adding provider-specific logic to the domain.
Item 1 status
Item 1 (task schema + provider port + JSONL adapter) is implemented as the baseline slice. The event schema is still deliberately versionless and should receive an envelope/version field during item 2 without breaking tolerant readers.
Important limitations
- This is still a Layer 1 prototype. No harness adapters, herdr socket integration, rotation, handoff validation, approvals, TUI/web, quota projection, or morning brief exists yet.
- Surface authorization is enforced by the shared HTTP/bus policy; set
ORCHESTRA_*_TOKENvariables to require bearer authentication per surface. - Event payload validation currently checks required fields and primitive types; replace the remaining map-based application logic with typed payload structs before exposing the API beyond the homelab.
- Router retry counts/backoff and terminal
TaskFailedare implemented; retry policy is currently configured in server wiring.
Next agent: recommended order
- Begin item 2: harden the event log and state projection with snapshots, corruption handling, and a versioned envelope.
- Add project, machine, and herdr registries from static TOML/JSON config.
- Implement router selection: project affinity, reachability, capability, availability, and importance ordering.
- Add retry policy and a background lease-expiry loop.
- Implement handoff/report schemas and CAS reference validation.
- Integrate herdr only after the substrate/router tests are stable.