Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 5 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ No agents to install on managed hosts. No SaaS in the middle. No telemetry leavi

## 🧬 The story

**Live case study:** [Shipping a real BNL playground through GroundControl](docs/articles/bnl-playground-from-the-browser.md) records the supervised terminal workflow, build/test outcomes, public execution check and captioned screenshots. It uses the existing VPS foundation and the application's existing delivery pipeline; it is not an autonomous Loop run.

GroundControl started as a dashboard. Then it became an experiment in **containerized privilege**.

The obvious way to ship a VPS cockpit is to put it in a container on the VPS it manages. But containers are jails: the dashboard could see Docker containers through the mounted socket, yet it could not run `systemctl`, install packages with `apk`/`apt`, call `kubectl`, or even find `caddy` on the host. The terminal reported `command not found` for tools that were clearly installed. The install buttons failed. The dashboard lied.
Expand Down Expand Up @@ -68,7 +70,7 @@ Read the full tale in [`docs/THE-HACK.md`](./docs/THE-HACK.md).
| ☁️ | **Cloud Accounts** | Store encrypted GCP/AWS/Azure credentials and use them across deployment targets. |
| 🚀 | **Smart Onboarding** | Auto-detects OS, Docker, compose command, Kubernetes, and server paths from a local or SSH connection. |
| 🤖 | **AI Ops Assistant** | GPT-powered assistant that reasons about logs, metrics, and deploys with streamed responses. |
| 💻 | **AI Terminal** | Browser terminal with `/ai` natural-language command generation, tab autocomplete, and helper chips. |
| 💻 | **Persistent Terminal** | Authenticated xterm + PTY session on the selected VPS. Tab/control keys belong to the shell; Copilot links to the separate intelligence workspace. |
| 🔔 | **Alerts & Incidents** | Auto-generated alerts for memory pressure, disk usage, unhealthy containers, and deploy failures. |
| 🤖 | **AI Alert Synthesis** | One-line summary of recent alerts plus recommended actions on the dashboard. |
| 🔁 | **Loop foundation** | Intelligence workspace with a live service graph, change ledger, journeys, evidence-backed investigation, approved recovery, and opt-in live adapters. The production workspace no longer loads demo fixtures; guarded autopilot remains disabled until host evaluation passes. **Intelligence** at `/intelligence`. |
Expand All @@ -84,13 +86,9 @@ Read the full tale in [`docs/THE-HACK.md`](./docs/THE-HACK.md).

## 📸 What it looks like

> Screenshots live in [`docs/screenshots/`](./docs/screenshots/). Drop captures there and they will render below.
![Live GroundControl terminal showing recorded BNL verification results](./docs/screenshots/bnl-2026-09-28/gc-bnl-scorecard-20260928.jpg)

<!-- Add screenshots here, e.g.:
![Dashboard](./docs/screenshots/dashboard.png)
![Topology](./docs/screenshots/topology.png)
![Terminal](./docs/screenshots/terminal.png)
-->
Supervised verification on 28 September 2026: a read-only script displays saved scorecard outcomes and the exact BNL runtime identity. The crop excludes infrastructure identifiers and the shell prompt. This is a real terminal capture, not a native GC metrics panel or autonomous Loop run. [Captions and provenance](./docs/screenshots/bnl-2026-09-28/README.md) · [Full case study](./docs/articles/bnl-playground-from-the-browser.md).

---

Expand Down
3 changes: 3 additions & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@

## 🎥 Show it off

- **[articles/bnl-playground-from-the-browser.md](./articles/bnl-playground-from-the-browser.md)** — live supervised GC build/verification case study with captioned production screenshots and measured outcomes.
- **[screenshots/bnl-2026-09-28/README.md](./screenshots/bnl-2026-09-28/README.md)** — screenshot provenance, captions, hashes and links to the full browser evidence.

- **[DEMO.md](./DEMO.md)** — a click-by-click script for recording a 2–4 minute demo.
- **[demo-data.md](./demo-data.md)** — seed fake data so the dashboard looks alive without a real server.

Expand Down
72 changes: 72 additions & 0 deletions docs/articles/bnl-playground-from-the-browser.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# Shipping a real BNL playground through GroundControl

Recorded 28 September 2026. This is a supervised operator workflow through the live GroundControl terminal. It is not an autonomous Loop run, a built-in BNL integration, or a new CI service.

The goal was concrete: make Backend as Natural Language testable on the existing portfolio while the developer was away from their computer. Visitors needed to supply their own records and execute the real compiler and runtime. A screen populated with fictional customers would not meet that goal.

## GroundControl provided the working host

The authenticated terminal gave access to a persistent shell on the selected VPS. Rust compilation, locked-dependency tests and browser acceptance ran in resource-bounded Docker containers on that host. The Rust image used version 1.88; browser acceptance used Playwright 1.57 and Chromium 143; the portfolio built with Node 24.

GroundControl was the operator surface. GitHub remained the source and review system. The portfolio's existing Vercel integration published the merged site. This separation matters: a successful shell command, a passing test suite and a working public route are distinct observations.

![GroundControl terminal showing measured BNL verification counts and artifact identity](../screenshots/bnl-2026-09-28/gc-bnl-scorecard-20260928.jpg)

*Figure 1. A terminal summary read from saved scorecards: shipping HTTP 37/37, delivery/migration 33/33 and actual-WASM browser acceptance 31/31. The viewport is cropped to omit infrastructure identifiers and the shell prompt. These are recorded test outcomes, not built-in GroundControl counters. No values were painted into the screenshot.*

## The public interface runs the actual engine

A separate Rust wrapper invokes BNL's existing compiler, typed BIR validator, planner and guarded executor. Its WebAssembly build starts with an empty Store. Visitors load customer, order, subscription and invoice records; exact type and relationship checks run before an import replaces the current state.

The public wrapper permits local reads, tasks, reviews and idempotency markers. Payments and messages reject before execution. A dedicated worker owns each tab's state, bounded requests and memory; teardown discards that state. No native administrative host or production credentials are exposed.

![Released BNL playground with zero records and empty customer fields](../screenshots/bnl-2026-09-28/bnl-production-empty-20260928.jpg)

*Figure 2. The public production route after portfolio release cb61c49e5fe133ee465d13f4e965af4511443721. The initial record count is zero. Starter declarations provide grammar; visitors supply the business values.*

## Verify a consequence, not just a page load

The browser suite changed imported rows and declaration ordering, then checked the actual results. It exercised nominal-type rejection, atomic import, rollback after a staged write, committed local tasks, separate-tab isolation, exports, worker failure, keyboard controls and a 390px mobile viewport. The final suite passed 31 checks; the existing portfolio suite passed all 30 tests, and build/lint passed.

After deployment, a fresh public session compiled and executed this declaration:

```bnl
Compose LiveRuleCheck
Input days: integer
Check eligible when $input.days > 30
Return eligible
```

An explicitly supplied integer input of 31 returned true; changing it to 12 returned false. These were verification inputs, not fabricated customer records. The visible runtime identity matched the tested artifact.

![Production BNL runtime showing the false result of the supplied integer input](../screenshots/bnl-2026-09-28/bnl-production-execution-20260928.jpg)

*Figure 3. The real compiler/executor returned Boolean false for days = 12. No business records were needed. The screenshot also shows the source revision and binary digest.*

## Keep failures with the success

The first container command lacked Cargo on its login-shell PATH. Packaging initially could not resolve a linked worktree's host-side Git metadata. Both failures were retained; the build used Cargo's container path and packaging ran in the actual Git checkout.

The first browser run checked an article before the animated route had mounted. Its scorecard remains beside the corrected test. A later review also corrected stale export-request provenance after runtime restart and verified it in the final browser suite.

The native delivery review found a separate liveness defect: a batch smaller than the configured route count could starve later routes. The correction requires at least one batch slot per route and passed 7 host Rust tests, 37 shipping HTTP checks and 33 delivery/migration checks. That native path is separate from the public browser runtime and remains under its own review.

## What another operator can repeat

1. Pin the source revision and build inputs before running tests.
2. Use the authenticated GroundControl terminal and an isolated checkout. Run explicit build/test commands in containers with resource limits.
3. Save command exit codes, scorecards, artifact hashes and screenshots. Label test inputs and retain failed attempts.
4. Publish through the application's existing review/deployment path.
5. Open the public route independently, change an input and verify its consequence. Archive that observation separately from local test success.

This uses GroundControl's live VPS/terminal foundation. It does not establish autonomous recovery, production payment/message delivery, or independent language generalisation. Loop remains the intelligence/recovery engine inside GroundControl; the test runner here was an operator-invoked tool.

## Evidence and ways to try it

- [Live playground](https://precisionxyz.serendepify.com/#/playground/bnl)
- [Getting started](https://precisionxyz.serendepify.com/#/article/bnl-getting-started)
- [Public portfolio evidence at the released commit](https://github.com/teckedd-code2save/edward.entire/tree/cb61c49e5fe133ee465d13f4e965af4511443721/docs/evidence/bnl-playground-2026-09-28)
- [Screenshot registry and captions](../screenshots/bnl-2026-09-28/README.md)
- [Current terminal source reviewed for this article](https://github.com/teckedd-code2save/groundcontrol/blob/68e2c230576ded23b7554d7ca8622338ae832ea0/src/app/terminal/page.tsx)

BNL runtime source: a1d606c588ceb849c6a85561a9820c6ab6885e58. WASM SHA-256: fa55334543c5e22ef64ea7adb3a7583f134a071fc3c739a91c86a0bc0d49e337; 603800 bytes. The BNL source repository remains private and has no selected public source license. Detailed native logs remain in its evidence archive; the public portfolio archive contains browser/build outcomes suitable for public documentation.
6 changes: 5 additions & 1 deletion docs/screenshots/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Screenshots

## Verified live evidence

The [BNL case-study screenshots](bnl-2026-09-28/README.md) document actual GroundControl terminal verification and the resulting public playground. Each capture has a caption, scope and checksum. Keep live evidence separate from explicitly labelled product demonstrations.

Drop PNGs here and they'll render in the main [README](../../README.md). Capture at a consistent width (≈1440px, retina/2x if you can) on a dark background for a clean, cohesive look.

Suggested shots (file names the README expects):
Expand All @@ -15,7 +19,7 @@ Suggested shots (file names the README expects):
| `proxy.png` | The proxy view showing a parsed Caddy/Nginx site mapped to a container. |

Tips:
- Seed demo data first (see [../demo-data.md](../demo-data.md)) so screens look populated without a real VPS.
- For evidence, capture actual runtime state, including empty states. Use [demo data](../demo-data.md) only for an explicitly labelled demonstration; never present seeded values as a measured live outcome.
- Hide or blur any real hostnames, IPs, or domains.
- Keep the same browser zoom and window size across shots for visual consistency.
- A short looping GIF of the topology graph or a deploy is a great hero asset for social posts.
13 changes: 13 additions & 0 deletions docs/screenshots/bnl-2026-09-28/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# BNL delivery evidence screenshots — 28 September 2026

These are screenshots of real browser/terminal output, not design mockups. Capture timezone: Africa/Accra (UTC). The files are used by the [GroundControl case study](../../articles/bnl-playground-from-the-browser.md), the BNL evidence archive and the portfolio articles.

| Image | What it establishes | Scope |
|---|---|---|
| [GC verification](gc-bnl-scorecard-20260928.jpg) | Saved scorecard counts and exact runtime source/binary identity were inspected through the live GC terminal. | Cropped to remove host identity and shell prompt. A script reads recorded outcomes; these are not native GC product metrics. |
| [Empty public playground](bnl-production-empty-20260928.jpg) | The deployed route loads its actual Rust/WASM runtime with zero business records. | Public portfolio release cb61c49. No sample customers or orders are preloaded. |
| [Public execution result](bnl-production-execution-20260928.jpg) | A supplied integer changes the result of an actual compiled declaration. | days > 30 returned true for 31 and false for 12; the image shows the second run. These are explicit test inputs. |

For original desktop/mobile acceptance screenshots, the failed browser attempt and all 31 final browser assertions, see the [immutable portfolio archive](https://github.com/teckedd-code2save/edward.entire/tree/cb61c49e5fe133ee465d13f4e965af4511443721/docs/evidence/bnl-playground-2026-09-28). Business values in those acceptance images are synthetic test inputs used by the harness, never production defaults.

The [manifest](manifest.json) records dimensions, SHA-256, artifact/source identity and captions. A screenshot demonstrates the visible state at capture time; it does not independently establish all test assertions, native-provider acceptance or production durability. Read the scorecards and protocol for those boundaries.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
85 changes: 85 additions & 0 deletions docs/screenshots/bnl-2026-09-28/manifest.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
{
"schema": "bnl-screenshot-evidence-1",
"capturedDate": "2026-09-28",
"timezone": "Africa/Accra (UTC)",
"portfolioRelease": "cb61c49e5fe133ee465d13f4e965af4511443721",
"runtimeSource": "a1d606c588ceb849c6a85561a9820c6ab6885e58",
"wasmSha256": "fa55334543c5e22ef64ea7adb3a7583f134a071fc3c739a91c86a0bc0d49e337",
"publicUrl": "https://precisionxyz.serendepify.com/#/playground/bnl",
"files": [
{
"file": "bnl-production-empty-20260928.jpg",
"sha256": "027033cd53c8b903cde8fe4de74505a12f3d31f5120476b37fe5cbd230ac48c2",
"width": 1357,
"height": 932,
"caption": "Fresh public runtime with zero business records. Starter declarations provide grammar, not fabricated customer values.",
"scope": "Production UI capture"
},
{
"file": "bnl-production-execution-20260928.jpg",
"sha256": "f78f44522994104641a4f41b6f236d171fbaa45b79a7cb583b833218edeb74e2",
"width": 1357,
"height": 932,
"caption": "Actual deployed Rust runtime returned false for the supplied integer days=12 under days>30. An earlier input of 31 returned true.",
"scope": "Production UI execution; explicit test inputs"
},
{
"file": "gc-bnl-scorecard-20260928.jpg",
"sha256": "4dac76c67b49fad258a84a1a0d6baea388cce7f989527e17ec9533f997528923",
"width": 1057,
"height": 369,
"caption": "A read-only script prints saved scorecard outcomes in GroundControl's live terminal. Cropped to omit infrastructure identity and prompt; these are not built-in GC dashboard metrics.",
"scope": "Supervised terminal evidence"
}
],
"productionCheck": {
"declaration": "Compose LiveRuleCheck\nInput days: integer\nCheck eligible when $input.days > 30\nReturn eligible",
"runs": [
{
"inputs": {
"days": {
"type": "integer",
"value": 31
}
},
"result": true
},
{
"inputs": {
"days": {
"type": "integer",
"value": 12
}
},
"result": false
}
],
"initialRecords": 0
},
"limitations": [
"Screenshots record visible state; scorecards document assertions.",
"GC terminal work was supervised; no autonomous Loop run is claimed.",
"Production inputs were explicit verification values, not seeded business records.",
"Payments/messages/native host were not exposed."
],
"relatedAcceptance": [
{
"file": "01-empty-desktop.png",
"sha256": "79e7fc212ee09244e83f51ca30c3a912f1dae19e8925269e408749781c0a67ab",
"caption": "Full-page empty runtime in the GC Chromium harness.",
"url": "https://github.com/teckedd-code2save/edward.entire/blob/cb61c49e5fe133ee465d13f4e965af4511443721/docs/evidence/bnl-playground-2026-09-28/01-empty-desktop.png"
},
{
"file": "02-real-result-desktop.png",
"sha256": "7233fed5158a3631dab3acb3ef12cb415e7cd953d83cba4b4127ffec9b55fd30",
"caption": "Actual execution using explicitly synthetic harness-supplied records; not product defaults.",
"url": "https://github.com/teckedd-code2save/edward.entire/blob/cb61c49e5fe133ee465d13f4e965af4511443721/docs/evidence/bnl-playground-2026-09-28/02-real-result-desktop.png"
},
{
"file": "03-mobile-empty.png",
"sha256": "4c1409fa288ba332d50a79ec7983a2e0ad97ab0293739854128da73cfdcc3fb3",
"caption": "390px full-page mobile acceptance capture.",
"url": "https://github.com/teckedd-code2save/edward.entire/blob/cb61c49e5fe133ee465d13f4e965af4511443721/docs/evidence/bnl-playground-2026-09-28/03-mobile-empty.png"
}
]
}
Loading