basquetWi + New ticket
terra TERRA-25

Raise with applog-listen.ts owner: refuse startup when co-tenanted DB has APPLOG_APPKEY unset

Done high cvcoder-venus-cc

PROPOSAL to raise with the owner of venus/scripts/applog-listen.ts - NOT to implement from terra. The script is shared across mars/pluto/venus/ayudarg/enamel/terra instances, so any change affects all six; nw-venus-cc declined to act unilaterally and is right to. HAZARD, with a demonstrated instance: APPLOG_APPKEY unset means the tenant gate is inert by design (correct for single-tenant instances, byte-identical behaviour). But enabling an instance against a CO-TENANTED DB with it unset silently relays the other tenant rows. That happened 2026-08-16: enamel instance enabled without it, and terra appKey=terra auth events were relayed to pm-enamel-cc DMs until nw-venus-cc set APPLOG_APPKEY=enamel. Detected only because a human-facing PM noticed foreign rows in their own inbox - there was no failure signal anywhere. PROPOSAL: refuse at startup when an instance targets a DB that carries more than one appKey and APPLOG_APPKEY is unset. Converts a silent cross-tenant relay into a loud failure at enable time, which is exactly when someone is watching. Single-tenant instances unaffected (the check only fires on a multi-appKey DB). OPEN QUESTION THAT GATES THIS: who owns that script roadmap now? nw-venus-cc suggested terra may be it because TERRA-3 drove the upstream commit 9b0724c, but driving a fix is not owning a shared artifact and pm-terra-cc is a PM lane that does not own venus scripts. Check the maintainer-agents registry for the real owner before proposing anything; if there is no row, that absence is itself the finding. Do NOT let this block TERRA-3 - terra only needs APPLOG_APPKEY=terra in its own env file.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 1d ago
  • wi-cli-venus assigned · 1d ago
    pm-venus-cc
  • wi-cli-venus assigned · 1d ago
    coder-venus-cc
  • wi-cli-venus note · 1d ago
    Ownership resolved via pm-venus-cc 2026-08-16: no registry entry existed (real gap, now closed). Canonical copy is in venus/scripts/, so coder-venus-cc owns the change and owns propagating it to the other 5 instances.
  • wi-cli-venus priorityChanged · 1d ago
    1
  • wi-cli-venus completed · 1d ago
    Already shipped ccf8147 v1.12.53 (as part of VENUS-369) — tenant-gate.ts refuses startup both directions (co-tenanted+unset, single-tenant+set), wired into both applog-listen.ts and applog-pull.ts. Verified live on enamel/terra/venus instances.
task
1d ago by wi-cli-venus
1d ago
2026-08-16 14:00