← back to Ticket Triage Page

tickets.js

81 lines

// The 10 Steve-gated blocked tickets — HYBRID model (2026-07-31).
// The server can only ever spawn a `fire.cmd` (local + reversible). Prod/destructive
// actions carry `pasteCmd` (copy-to-clipboard → you run it in a terminal, where each
// command is still gated) and a Mark-fired that only records to the ticket.
//   fire     — server runs cmd (local, reversible). danger:'safe'.
//   decision — records APPROVE + → doing. No shell.
//   input    — captures Steve-only secrets to a gitignored file (last-4 to ticket). No prod.
//   copy     — server does NOT run it; page copies pasteCmd, Mark-fired records you ran it.
//   handsoff — no button (another owner fires it).
const HOME = require('os').homedir();
const Q = HOME + '/.claude/yolo-queue';

module.exports = [
  { ref: 'TK-00058', bucket: 'approval', title: 'Vendor-onboard bucket approvals (Sanderson / Muralsource / Fentucci)',
    action: 'Confirm verdicts: Fentucci = APPROVE, Muralsource = REJECT, Sanderson = HOLD.',
    recommend: 'APPROVE', memo: Q + '/pending-approval/TK-00058-vendor-bucket-decision-memo-2026-07-28.md',
    exec: { mode: 'decision', btn: 'Approve verdicts',
            detail: 'Fentucci=APPROVE (armed cadence continues), Muralsource=REJECT/closed, Sanderson=HOLD. FENT-1 metafield cleanup has no script yet — noted for the terminal.' } },

  { ref: 'TK-00136', bucket: 'approval', title: 'Stroheim onboard #8 — go-live activation',
    action: 'Activate settlement-OK Stroheim drafts — bounded canary of 5 (channels exclude Google/YouTube, 5-field gated).',
    recommend: 'CANARY 5', memo: null,
    exec: { mode: 'copy', btn: 'Activate 5', danger: 'live',
            pasteCmd: 'cd ~/Projects/designerwallcoverings/scripts/stroheim-onboard && STROHEIM_ALLOW_GOLIVE=1 node go-live.mjs --apply --limit=5',
            detail: 'Customer-facing: publishes 5 Stroheim products live. Paste in a terminal (per-command gated). Reversible: draft them back.' } },

  { ref: 'TK-10016', bucket: 'approval', title: 'Make individual DW tools independently public',
    action: 'Approve Tier-1 publish only (recolor / color-wheel / 150dpi). Tier-3 stays tailnet (write prod Shopify).',
    recommend: 'APPROVE Tier-1', memo: HOME + '/Projects/tools-dw-hub/SCOPE-tools-public.md',
    exec: { mode: 'decision', btn: 'Approve Tier-1',
            detail: 'Records Tier-1-only publish approval. Each tool deploy is a separate per-tool action.' } },

  { ref: 'TK-21', bucket: 'deploy', title: 'Consulting portal P2 polish — deploy',
    action: 'Build + rsync + pm2 reload + smoke-test to dw.agentabrams.com. This deploy ALSO ships TK-00069.',
    recommend: 'DEPLOY', memo: Q + '/approved/TK-21-consulting-dw-portal-P2-polish-deploy.md',
    exec: { mode: 'copy', btn: 'Deploy', danger: 'live',
            pasteCmd: 'cd ~/Projects/consulting-designerwallcoverings-com && git status --short && node build.mjs && bash ~/Projects/_shared/scripts/deploy.sh',
            detail: 'Customer-facing prod deploy to dw.agentabrams.com (pm2 :9703). rsync excludes live intakes.json. Reversible: git revert + redeploy.' } },

  { ref: 'TK-00069', bucket: 'deploy', title: 'Red-team DW consulting portal (bundled with TK-21)',
    action: 'The XFF/security fixes ride the SAME deploy as TK-21 — fire TK-21 to ship both.',
    recommend: 'via TK-21', memo: Q + '/pending-approval/TK-22-consulting-portal-deploy-consolidated.md',
    exec: { mode: 'decision', btn: 'Mark (ships w/ TK-21)',
            detail: 'No separate deploy — records that the security fixes ship on the TK-21 deploy.' } },

  { ref: 'TK-00071', bucket: 'paste', title: 'ideas.agentabrams.com → DNS-01 conversion',
    action: 'Copy the runbook Step-0 read-only check (does an ideas cert even exist?). Run it; if none, close as done.',
    recommend: 'Option A', memo: Q + '/pending-approval/TK-00071-ideas-agentabrams-dns-01-conversion.md',
    exec: { mode: 'copy', btn: 'Step-0 check', danger: 'safe',
            pasteCmd: "ssh -o ConnectTimeout=8 root@45.61.58.125 'echo \"== certbot certs for ideas ==\"; certbot certificates 2>/dev/null | grep -A6 -iE \"ideas.agentabrams\" || echo \"(no ideas cert in certbot)\"; echo \"== cloudflared ==\"; systemctl is-active cloudflared'",
            detail: 'Read-only prod SSH — kept in your terminal (the server never SSHes prod). No cert → nothing to retire, close as done. Cert exists → Option-A retire is the follow-up.' } },

  { ref: 'TK-11', bucket: 'paste', title: 'astek pw rotation + sales-to-Slack scope',
    action: 'Provide the new astek password + CF-Access token — captured (last-4 to ticket) and readied for the nginx auth-drop terminal step.',
    recommend: 'APPROVE', memo: Q + '/pending-approval/astek-pw-rotation-slack-scope.md',
    exec: { mode: 'input', btn: 'Provide + prep',
            fields: [ { name: 'astek_password', label: 'New astek password', type: 'password' },
                      { name: 'cf_access_id', label: 'CF-Access Client ID', type: 'text' },
                      { name: 'cf_access_secret', label: 'CF-Access Client Secret', type: 'password' } ],
            detail: 'The nginx auth-drop is an irreversible prod SSH step that needs a real terminal — this captures your secrets to a gitignored file and records last-4 to the ticket.' } },

  { ref: 'TK-12', bucket: 'task', title: 'nineoh Unofficial 90210 → App Store / TestFlight',
    action: 'Copy the finish-tk12.sh command — installs the ASC key, wires eas.json, kicks the production iOS build. Needs your Apple .p8 downloaded first (script self-guards).',
    recommend: 'ACTION', memo: Q + '/pending-approval/TK-12-nineoh-appstore-testflight.md',
    exec: { mode: 'copy', btn: 'finish-tk12.sh', danger: 'live',
            pasteCmd: 'bash ~/Projects/nineoh-guide/finish-tk12.sh',
            detail: 'Kicks a real EAS production build (1 free slot); STOPS before submit. Do the browser ASC key-gen first (see runbook), then run this in a terminal.' } },

  { ref: 'TK-00128', bucket: 'task', title: 'DW reels TikTok uploader → Content Posting API',
    action: 'Fire the live-creds DRY-RUN — refreshes the token, validates auth with TikTok, assembles the init body. Publishes NOTHING.',
    recommend: 'DRY-RUN', memo: Q + '/pending-approval/dw-reels-tiktok-golive.md',
    exec: { mode: 'fire', danger: 'safe', btn: 'Run dry-run',
            cmd: 'cd ~/Projects/dw-marketing-reels && TIKTOK_DRY_RUN=1 node scripts/tiktok-post.mjs',
            detail: 'Reversible: no post created. ⚠ Fires the live oauth/token refresh (rotates the shared TikTok refresh token) — do not run while MCC is mid-refresh. Public posting still needs the audit (your manual submit).' } },

  { ref: 'TK-13', bucket: 'auto', title: 'Git-history purge — 3 no-remote repos',
    action: 'HANDS-OFF. An armed idle-watch in another session owns this destructive purge; a second fire would corrupt it.',
    recommend: 'NO ACTION', memo: Q + '/pending-approval/2026-07-27-git-history-purge-TK-13-refresh.md',
    exec: { mode: 'handsoff', detail: 'Owned by an armed idle-watch (auto-fires when the DW repo goes write-idle). Firing here would race/corrupt the filter-repo run.' } },
];