Luigit
repositories / will

will

owned by admin

docs/architecture.md

Raw
Rendered preview

Architecture

will is a digital lifeform deployed as a rootless Podman pod with two containers, grown exclusively through CI from its Git repository.

Body

  • service (phenotype): Node stdlib HTTP + SQLite worker thread. Public read-only web surface behind an authenticating reverse proxy, plus a pod-loopback API. Unprivileged, read-only rootfs, no capabilities.
  • agent (senses and muscles): resident pi SDK session, durable wake queue, Telegram runtime, curated ZAI tools, Git worktree. User will with passwordless sudo inside its container only.

The deployment platform (external contract, deploy/contract.md) owns pod recreation, 60-second startup deadline, five-minute zero-restart probation, promotion, rollback, reconciliation barriers, and the authoritative forever deployment history.

Growth

trunk push -> Luci gates -> two immutable images -> platform rollout -> probation -> promotion. No hot releases. Image rollback restores the captured rollback target and never touches data; the previous revision must always read what the candidate wrote.

Data

Service-only SQLite (WAL, synchronous=FULL) in a worker thread; audit hot 90 days, chat hot one year, then immutable versioned zstd segments retained forever and queryable through the same API. Media is content-addressed and retained forever. Agent events spool durably and drain idempotently.

Memory of the agent

One session file on the agent volume survives restarts; persona, skills, and prompts load from the immutable image, so they change only through deployment. Facts (revision, storage, queue, budget) render per wake.

# Architecture

will is a digital lifeform deployed as a rootless Podman pod with two
containers, grown exclusively through CI from its Git repository.

## Body

- **service** (phenotype): Node stdlib HTTP + SQLite worker thread. Public
  read-only web surface behind an authenticating reverse proxy, plus a
  pod-loopback API. Unprivileged, read-only rootfs, no capabilities.
- **agent** (senses and muscles): resident pi SDK session, durable wake
  queue, Telegram runtime, curated ZAI tools, Git worktree. User `will` with
  passwordless sudo inside its container only.

The deployment platform (external contract, `deploy/contract.md`) owns pod
recreation, 60-second startup deadline, five-minute zero-restart probation,
promotion, rollback, reconciliation barriers, and the authoritative forever
deployment history.

## Growth

`trunk` push -> Luci gates -> two immutable images -> platform rollout ->
probation -> promotion. No hot releases. Image rollback restores the captured
rollback target and never touches data; the previous revision must always
read what the candidate wrote.

## Data

Service-only SQLite (WAL, synchronous=FULL) in a worker thread; audit hot 90
days, chat hot one year, then immutable versioned zstd segments retained
forever and queryable through the same API. Media is content-addressed and
retained forever. Agent events spool durably and drain idempotently.

## Memory of the agent

One session file on the agent volume survives restarts; persona, skills, and
prompts load from the immutable image, so they change only through
deployment. Facts (revision, storage, queue, budget) render per wake.