Skip to content

Check-in — 2026-07-29

TL;DR

Paperless and Stirling now have a guarded, reproducible API bridge for replacing an archived PDF without mutating Paperless media in place. infra-services was resized to 12 vCPU, 28 GiB RAM, and 200 GiB disk for the OneUptime pilot. All existing services recovered; the reboot also exposed and closed a Wazuh certificate-ownership gap in Komodo's pull path.

Phase status

Area Status Evidence
Stirling NFS identity Verified Java runs as Synology identity 1024:100; media RO and inbox RW checks passed
Bridge application Implemented Authentik route, Paperless browser, reviewed pipeline catalog, guarded replacement
Replacement safety Verified Live disposable document 43 replaced by 44; title/note retained and audit completed
Production reconciliation Complete Bridge and Stirling healthy; image ownership and Ansible secret rendering merged
Incident-platform capacity Complete VM 123 is 12 vCPU / 28 GiB / 200 GiB; ~18 GiB memory and ~115 GiB disk available after startup
Existing-stack recovery Verified Monitoring, Wazuh, Paperless, Komodo, and supporting containers healthy after resize

What shipped

  • Corrected Stirling's runtime UID/GID and split the Whrrr mounts into read-only Paperless media and read/write consume inbox (Stirling README).
  • Added the Paperless–Stirling bridge with server-side credentials, HMAC confirmation, reviewed pipelines, PDF validation, metadata/note transfer, rollback behavior, and JSONL audit.
  • Added unit/integration coverage for upstream clients, UI boundaries, replacement ordering, rollback, and the two Paperless API response shapes found during live verification.
  • Added encrypted runtime credentials and an Ansible-owned atomic renderer.
  • Verified the public route redirects through Authentik and both internal upstream health checks pass.
  • Expanded VM 123 from the unrecorded 8 vCPU / 22 GiB / 135 GiB state to 12 vCPU / 28 GiB / 200 GiB and grew ext4 explicitly to 196 GiB.
  • Verified 28 existing containers and restored Wazuh indexer/dashboard health after correcting mode-0400 TLS key ownership.
  • Added the Wazuh permission repair after Komodo's checkout-wide chown so a pull cannot leave the next host reboot unable to read indexer keys.

Known gaps / drift

  • Replacement intentionally creates a new Paperless document ID. External links to the old ID are not redirected.
  • Disposable documents 42, 43, and 44 remain recoverable in Paperless trash; no shared trash-empty operation was run.
  • OneUptime is not deployed yet; capacity is ready, but stack, restore, and correlation gates still apply.

What remains

Item Owner Priority
Review and merge incident-platform foundation and capacity PRs Owner P1
Deploy OneUptime only after stack and restore acceptance Agent P1 after merge
Exercise one owner-selected non-disposable document Owner P2

Workflow

flowchart LR
  User["Authenticated user"] --> Bridge["Paperless–Stirling bridge"]
  Bridge -->|"Download original"| Paperless[Paperless]
  Bridge -->|"Run reviewed pipeline"| Stirling[StirlingPDF]
  Stirling -->|"Validated PDF"| Bridge
  Bridge -->|"Import replacement"| Paperless
  Bridge -->|"Trash original after success"| Paperless
  Bridge --> Audit["Old/new ID audit"]