mirror of
https://github.com/ruvnet/RuView
synced 2026-07-25 17:51:48 +00:00
be4efecbcd
Two closing P8 deliverables that complete the local-side publishing
scaffolding. The remaining work is all credential-bearing user
action.
1. `cog/app-registry-entry.json` — the exact JSON payload to paste
into cognitum-one's `app-registry.json`. Schema discovered by
fetching the live registry (105 cogs, 11 categories) and
matching the existing `ruview-densepose` entry verbatim. Keys:
id, name, category, version, size_kb, difficulty, description,
featured, config[], sha256, binary_size
cog-ha-matter slots in under `category: "building"` (smart home
/ building automation — the natural HA / Matter category, vs
`network` which is more about transport bridges).
7 config[] entries mirror our CLI surface:
sensing_url, mqtt_host, mqtt_port, privacy_mode,
mdns_hostname, mdns_ipv4, no_mdns
Two post-build fields left as `<FILL_IN_...>` markers:
sha256 (paste from the workflow artifact's .sha256)
binary_size (wc -c < the binary)
Schema validated: all 10 required keys present, parses as JSON.
2. `cog/RELEASE-CHECKLIST.md` — one-page mechanical playbook with
four explicit "🔑 USER ACTION" gates. Each gate names exactly
what the user (or org admin) has to do that the pipeline cannot:
a) provision GCP_CREDENTIALS + HAS_GCP_CREDENTIALS org var
b) provision COGNITUM_OWNER_SIGNING_KEY GH secret
c) gcloud auth login (only if uploading locally)
d) PR app-registry.json into cognitum-one
Plus pre-release test gate, tag-push command, post-release
verification curl, and a rollback procedure using GCS object
versioning (per ADR-100 §"GCS misconfiguration risks").
Stop-condition check (cron's predicate: "ALL local-side publishing
scaffolding is complete and the only remaining work requires user
action"):
✅ cog/manifest.template.json
✅ cog/Makefile (build / sign / upload / verify / clean)
✅ cog/README.md
✅ cog/app-registry-entry.json (this commit)
✅ cog/RELEASE-CHECKLIST.md (this commit)
✅ .github/workflows/cog-ha-matter-release.yml (3 jobs, gated)
✅ dist/ handling (gitignored, created by make)
🔑 4 user-action gates explicitly enumerated in the checklist
The cron should STOP after this iter — the local-side scaffolding
is complete and the remaining work is the four named credential
gates that the pipeline cannot self-serve.
Co-Authored-By: claude-flow <ruv@ruv.net>
72 lines
2.5 KiB
JSON
72 lines
2.5 KiB
JSON
{
|
|
"id": "ha-matter",
|
|
"name": "Home Assistant + Matter Bridge",
|
|
"category": "building",
|
|
"version": "0.3.0",
|
|
"size_kb": 12,
|
|
"difficulty": "easy",
|
|
"description": "Exposes WiFi-CSI sensing as Home Assistant entities over MQTT auto-discovery, with mDNS announcement on _ruview-ha._tcp and tamper-evident Ed25519-signed audit logs. Adds 10 semantic primitives (someone_sleeping, possible_distress, fall_risk_elevated, ...) on top of the 11 raw measurements. Privacy mode strips biometrics at the wire so only the semantic layer reaches HA — the right default for any deployment with non-tenant occupants.",
|
|
"featured": false,
|
|
"config": [
|
|
{
|
|
"key": "sensing_url",
|
|
"type": "string",
|
|
"label": "Sensing server URL",
|
|
"description": "Where the cog reads VitalsSnapshot from",
|
|
"default": "http://127.0.0.1:3000",
|
|
"cli_arg": "--sensing-url"
|
|
},
|
|
{
|
|
"key": "mqtt_host",
|
|
"type": "string",
|
|
"label": "MQTT broker host",
|
|
"description": "External mosquitto / HA Core MQTT host (v0.7 will add an embedded broker option)",
|
|
"default": "127.0.0.1",
|
|
"cli_arg": "--mqtt-host"
|
|
},
|
|
{
|
|
"key": "mqtt_port",
|
|
"type": "integer",
|
|
"label": "MQTT broker port",
|
|
"default": 1883,
|
|
"min": 1,
|
|
"max": 65535,
|
|
"cli_arg": "--mqtt-port"
|
|
},
|
|
{
|
|
"key": "privacy_mode",
|
|
"type": "boolean",
|
|
"label": "Privacy mode",
|
|
"description": "Strip biometrics at the wire — only semantic primitives are published. Recommended for any deployment with non-tenant occupants (care homes, education, shared housing).",
|
|
"default": false,
|
|
"cli_arg": "--privacy-mode"
|
|
},
|
|
{
|
|
"key": "mdns_hostname",
|
|
"type": "string",
|
|
"label": "mDNS hostname",
|
|
"description": "Must end with .local. per RFC 6762. HA's discovery integration looks up this hostname.",
|
|
"default": "cog-ha-matter.local.",
|
|
"cli_arg": "--mdns-hostname"
|
|
},
|
|
{
|
|
"key": "mdns_ipv4",
|
|
"type": "string",
|
|
"label": "Advertised IPv4",
|
|
"description": "LAN-routable address the mDNS responder advertises. HA reaches back to this for MQTT.",
|
|
"default": "127.0.0.1",
|
|
"cli_arg": "--mdns-ipv4"
|
|
},
|
|
{
|
|
"key": "no_mdns",
|
|
"type": "boolean",
|
|
"label": "Disable mDNS",
|
|
"description": "Skip the mDNS responder. Useful in containerised setups where multicast is filtered.",
|
|
"default": false,
|
|
"cli_arg": "--no-mdns"
|
|
}
|
|
],
|
|
"sha256": "<FILL_IN_FROM_dist/cog-ha-matter-x86_64.sha256_AFTER_make_build>",
|
|
"binary_size": 0
|
|
}
|