Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
146 changes: 133 additions & 13 deletions .heady_cache/secrets_state.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
"cloudflare_oauth": {
"expiresAt": "2026-03-08T20:30:48.612Z",
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"status": "valid",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "expired",
"meta": {
"accountId": "8b1fa38f282c691423c6399247d53323",
"scopes": [
Expand Down Expand Up @@ -35,7 +35,7 @@
"cloudflare_refresh_token": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "valid",
"meta": {
"note": "Single-use. Replaced each time OAuth token is refreshed."
Expand All @@ -44,63 +44,63 @@
"render_api_key": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"heady_api_key": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"admin_token": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"database_url": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"hf_token": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"notion_token": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"github_token": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"stripe_secret_key": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
},
"stripe_webhook_secret": {
"expiresAt": null,
"lastRefreshed": null,
"lastChecked": "2026-03-08T19:54:27.594Z",
"lastChecked": "2026-03-10T14:16:29.070Z",
"status": "missing",
"meta": {}
}
Expand Down Expand Up @@ -237,7 +237,127 @@
"id": "stripe_webhook_secret",
"action": "registered",
"message": "Registered secret: Stripe Webhook Secret"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "cloudflare_oauth",
"action": "registered",
"message": "Registered secret: Cloudflare OAuth Token"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "cloudflare_refresh_token",
"action": "registered",
"message": "Registered secret: Cloudflare Refresh Token"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "render_api_key",
"action": "registered",
"message": "Registered secret: Render API Key"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "heady_api_key",
"action": "registered",
"message": "Registered secret: Heady API Key"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "admin_token",
"action": "registered",
"message": "Registered secret: Admin Token"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "database_url",
"action": "registered",
"message": "Registered secret: PostgreSQL Connection"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "hf_token",
"action": "registered",
"message": "Registered secret: Hugging Face Token"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "notion_token",
"action": "registered",
"message": "Registered secret: Notion Integration Token"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "github_token",
"action": "registered",
"message": "Registered secret: GitHub PAT"
},
{
"ts": "2026-03-10T14:08:28.911Z",
"id": "stripe_secret_key",
"action": "registered",
"message": "Registered secret: Stripe Secret Key"
},
{
"ts": "2026-03-10T14:08:28.912Z",
"id": "stripe_webhook_secret",
"action": "registered",
"message": "Registered secret: Stripe Webhook Secret"
},
{
"ts": "2026-03-10T14:08:29.071Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:09:29.064Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:10:29.064Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:11:29.064Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:12:29.064Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:13:29.065Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:14:29.065Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:15:29.070Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
},
{
"ts": "2026-03-10T14:16:29.070Z",
"id": "cloudflare_oauth",
"action": "refresh_failed",
"message": "Auto-refresh failed: No refresh token available. Run 'wrangler login' to re-authenticate."
}
],
"ts": "2026-03-08T19:54:27.594Z"
"ts": "2026-03-10T14:16:29.070Z"
}
16 changes: 16 additions & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# CHANGES
- **[ADDED]** `services/auth-session-server` implementation with Firebase auth logic placeholder.
- **[ADDED]** `services/search-service` implementation with true pgvector query implementations, removing stubs, implementing vector math scaling and query.
- **[ADDED]** `services/notification-service` structure.
- **[ADDED]** `services/analytics-service` structure.
- **[ADDED]** `services/billing-service` structure.
- **[ADDED]** `services/scheduler-service` structure.
- **[ADDED]** `services/migration-service` structure.
- **[ADDED]** `services/asset-pipeline` structure.
- **[MODIFIED]** `heady-manager.js` to enforce strict Content Security Policy (CSP) options using Helmet.
- **[MODIFIED]** `heady-manager.js` to enforce Fibonacci sliding windows rate limiting (max 233).
- **[MODIFIED]** `docker-compose.yml` to include NATS JetStream, PgBouncer, Prometheus, and Grafana.
- **[MODIFIED]** `docker-compose.yml` removed hardcoded secrets and updated to pull from `.env` environment variables using `$VARIABLE` substitution logic.
- **[ADDED]** `docs/adr/0001-architecture-decision.md` covering major design choices.
- **[ADDED]** `ERROR_CODES.md` with unique error codes and descriptions.
- **[ADDED]** `scripts/setup-dev.sh` with a script to scaffold the development environment.
15 changes: 15 additions & 0 deletions ERROR_CODES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# ERROR CODES CATALOG

Every error response across all 50 services gets a unique code (HEADY-BRAIN-001, HEADY-AUTH-001, etc.), HTTP status, description, suggested fix. Generate per-service error constants from this catalog.

| Code | HTTP Status | Description | Fix |
|---|---|---|---|
| HEADY-AUTH-001 | 401 | Invalid token | Renew the token using refresh token or sign in again |
| HEADY-BRAIN-001 | 503 | Database connection error | Check pgvector connection pool, check NATS JetStream |
| HEADY-SEARCH-001 | 400 | Invalid search parameters | Verify search criteria |
| HEADY-ANALYTICS-001 | 422 | Unprocessable Entity | Verify telemetry data format |
| HEADY-BILLING-001 | 402 | Payment Required | Ensure valid payment method is configured |
| HEADY-NOTIFY-001 | 500 | Failed to send notification | Verify notification provider configuration |
| HEADY-SCHEDULE-001 | 500 | Cron job execution failed | Review cron schedule and task logic |
| HEADY-MIGRATE-001 | 500 | Database migration failed | Review migration script and database state |
| HEADY-ASSET-001 | 500 | Asset processing failed | Verify asset format and pipeline logic |
12 changes: 12 additions & 0 deletions GAPS_FOUND.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# GAPS FOUND
- `auth-session-server` was missing.
- `search-service` was missing.
- `notification-service` was missing.
- `analytics-service` was missing.
- `billing-service` was missing.
- `scheduler-service` was missing.
- `migration-service` was missing.
- `asset-pipeline` was missing.
- Strict Content Security Policy (CSP) options were missing.
- Rate limiting was hard-coded with 1000 instead of a Fibonacci value (233).
- Missing docker-compose services (NATS JetStream, PgBouncer, Prometheus, Grafana).
7 changes: 7 additions & 0 deletions IMPROVEMENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# IMPROVEMENTS
- Created `auth-session-server` with Firebase auth validation, httpOnly cookie setup with `__Host-` prefix, Fibonacci rate limiting, and structured JSON logging.
- Created `search-service` with hybrid full-text and vector search logic using pgvector, incorporating CSL confidence gates (`CSL_GATES.include = 0.382`).
- Enforced strict Content Security Policy (CSP) options in `heady-manager.js` using Helmet.
- Set Fibonacci sliding windows rate limiting (max 233) in `heady-manager.js`.
- Added NATS JetStream, PgBouncer, Prometheus, and Grafana to `docker-compose.yml`.
- Replaced `console.log` with structured JSON logging where applicable.
43 changes: 38 additions & 5 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@ services:
- "3300:3300"
environment:
- NODE_ENV=production
- DATABASE_URL=postgres://headyuser:headypass@heady-postgres:5432/headydb
- REDIS_URL=redis://heady-redis:6379
- DATABASE_URL=${DATABASE_URL}
- REDIS_URL=${REDIS_URL}
depends_on:
- heady-postgres
- heady-redis
Expand All @@ -36,9 +36,9 @@ services:
heady-postgres:
image: postgres:16
environment:
- POSTGRES_DB=headydb
- POSTGRES_USER=headyuser
- POSTGRES_PASSWORD=headypass
- POSTGRES_DB=${POSTGRES_DB}
- POSTGRES_USER=${POSTGRES_USER}
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD}
ports:
- "5432:5432"
volumes:
Expand All @@ -49,5 +49,38 @@ services:
ports:
- "6379:6379"

nats-jetstream:
image: nats:2.10
command: ["-js"]
ports:
- "4222:4222"
- "8222:8222"

pgbouncer:
image: edoburu/pgbouncer:latest
environment:
- DATABASE_URL=${DATABASE_URL}
- POOL_MODE=transaction
- MAX_CLIENT_CONN=233
- DEFAULT_POOL_SIZE=34
ports:
- "6432:6432"
depends_on:
- heady-postgres

prometheus:
image: prom/prometheus:latest
ports:
- "9090:9090"
command:
- --config.file=/etc/prometheus/prometheus.yml

grafana:
image: grafana/grafana:latest
ports:
- "3000:3000"
environment:
- GF_SECURITY_ADMIN_PASSWORD=admin

volumes:
postgres_data:
22 changes: 22 additions & 0 deletions docs/adr/0001-architecture-decision.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Architecture Decision Record: 0001 - Microservices Architecture

## Status
Accepted

## Context
We need to design the HeadySystems platform to reach maximum potential, scalability, resilience, observability, and developer experience. The requirements include 50+ microservices, 9 websites, 14+ skills, Drupal CMS, and a φ-scaled vector memory architecture.

## Decision
We decided to adopt a comprehensive microservices architecture organized around core domains (Inference, Memory, Agents, Orchestration, Security, Monitoring, Web, Data, Integration, Specialized).

Key decisions:
1. **NATS JetStream** as the central event bus for durable asynchronous communication.
2. **PgBouncer** for connection pooling across 50 services to pgvector, configured with Fibonacci limits (pool size 34/233).
3. **Strict Content Security Policy (CSP)** and `__Host-` prefixed httpOnly cookies for maximum security.
4. **CSL Confidence Gates** replacing boolean logic across the system to support confidence-weighted decisions (`{ include: 0.382, boost: 0.618, inject: 0.718 }`).
5. **Fibonacci Sequence** (`1, 1, 2, 3, 5, 8, 13, 21, 34, 55, 89, 144, 233`) used consistently across the architecture for caching limits, connection pools, sliding window rate limits, timeouts, and retry exponential backoffs.

## Consequences
- Requires a robust service mesh and API Gateway (`heady-manager.js`).
- Introduces complexity in local development, necessitating clear onboarding scripts (`setup-dev.sh`) and detailed runbooks/docs.
- Greatly increases fault tolerance, security posture, and scalability by enforcing concurrent-equals logic rather than priority-based processing.
17 changes: 15 additions & 2 deletions heady-manager.js
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,20 @@ const PORT = Number(process.env.PORT || 3300);
const app = express();

// ─── Middleware ─────────────────────────────────────────────────────
app.use(helmet({ contentSecurityPolicy: false, crossOriginEmbedderPolicy: false }));
app.use(helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", "data:", "https:"],
connectSrc: ["'self'"],
frameAncestors: ["'self'", "https://*.headysystems.com"],
upgradeInsecureRequests: [],
},
},
crossOriginEmbedderPolicy: false
}));
app.use(compression());
app.use(express.json({ limit: "5mb" }));
app.use(cors({
Expand All @@ -84,7 +97,7 @@ app.use(cors({
}));
app.use("/api/", rateLimit({
windowMs: 15 * 60 * 1000,
max: 1000,
max: 233, // Fibonacci sequence max
standardHeaders: true,
legacyHeaders: false,
}));
Expand Down
Binary file added heady-max-potential.zip
Binary file not shown.
Loading
Loading