diff --git a/concepts/memory-layer-architecture.md b/concepts/memory-layer-architecture.md new file mode 100644 index 0000000..efb3e33 --- /dev/null +++ b/concepts/memory-layer-architecture.md @@ -0,0 +1,135 @@ +--- +title: "Memory Layer Architecture" +category: concepts +tags: [memory, architecture, hindsight, lcm, wiki, separation] +created: "2026-09-27" +modified: "2026-09-27" +--- + +# Memory Layer Architecture — Practical Rules + +## Übersicht + +7 Schichten mit klaren, nicht-überlappenden Rollen. + +| # | Layer | System | Pfad/Ort | Rolle | Wann nutzen | +|---|-------|--------|----------|-------|-------------| +| L0 | Hot | MEMORY.md + USER.md | `~/.hermes/memories/` | System-Prompt Injection, komprimierte Facts | Jede Session (automatisch) | +| L1 | Curated | LLM Wiki | `~/.hermes/memory/` | Browsbares Wissen, git-synced | Wenn Details gebraucht werden | +| L2 | Semantic | Hindsight | K8s PostgreSQL | Vektor-Suche, semantisches Retrieval | Cross-Session Lookup | +| L3 | Procedural | Skills | `~/.hermes/skills/` | Wie-geht-es Prozeduren mit Pitfalls | Bei wiederkehrenden Tasks | +| L4 | Episodic | LCM + session_search | SQLite lcm.db / state.db | Rohe Gesprächsverläufe, Compaction | Innerhalb aktiver Session | +| L5 | Solutions | Solution Docs | `~/docs/solutions/` | Problem-Lösungs-Paare | Nach substanziellen Tasks | +| L6 | Project | AGENTS.md | pro Repo | Repo-spezifische Konventionen | Beim Arbeiten in einem Repo | + +## Was wohin gehört — Entscheidungsbaum + +``` +Ist es ein Fact über Dominik persönlich? + → USER.md (L0) + Ist es sein Kommunikationsstil, Safety-Rule, oder Workflow-Präferenz? + → USER.md + Ist es ein persönlicher Umstand (Größe, Gewicht, Arbeitgeber)? + → Hindsight (L2) — NICHT USER.md + +Ist es ein Infra-Fakt (IP, Version, Konfiguration)? + → LLM Wiki (L1) — systems/ oder reference/ + Braucht er jede Session sofort? + → MEMORY.md (L0) als 1-Zeiliger Pointer "→Wiki systems/xyz" + +Ist es ein "Wie mache ich X"-Prozess? + → Skills (L3) + +Ist es ein "Wir hatten Problem Y, Lösung war Z"-Eintrag? + → Solution Doc (L5) + Hindsight-Index (L2) + +Ist es ein vergangenes Gesprächsereignis? + → LCM (L4) kümmert sich automatisch darum +``` + +## L0 — MEMORY.md vs USER.md + +### USER.md (1.375 chars max) +**Nur:** Dominiks Persönliche Präferenzen, Safety-Rules, Kommunikationsstil +- "NIEMALS ohne Approval löschen" +- "Action-first, kein Dom" +- "Crash+Alert statt Silent Skip" +- "Laya in Sessions nutzen" + +**NICHT:** Infra-Fakten, IP-Adressen, Versionsnummern, Team-Struktur + +### MEMORY.md (2.200 chars max) +**Nur:** Komprimierte Pointer auf Wiki-Seiten + nicht-wikiffähige Quick-Facts +- `Frigate v0.18 CT151. →Wiki systems/frigate` +- `Galera:VM300/301/302,VIP .70. →Wiki systems/galera-maxscale` +- Baufinanz-Zahlen (persönlich, nicht im Wiki) +- LinkedIn Persona (Workflow, nicht im Wiki) + +**NICHT:** Vollständige Specs, Konfigurationsdetails, lange Beschreibungen + +## L1 — LLM Wiki + +### Wann erstellen/aktualisieren? +- Bei jeder infrastrukturellen Änderung (Compound-Learning Cycle Phase 4.7) +- Neue Seite wenn: neues System, neuer Service, neue architektonische Entscheidung +- Patch wenn: Versionswechsel, IP-Änderung, Known Issue hinzugekommen + +### Wann NICHT? +- Procedures → Skills (L3) +- Problem-Solution Pairs → Solution Docs (L5) +- Credentials → 1Password + +## L2 — Hindsight + +### Was gehört rein? +- **Semantische Pointer** auf Solution Docs und wichtige Meilensteine +- **Cross-Session Kontext** der nicht im Wiki steht (z.B. "wir haben am Datum X entschieden...") +- **Episodisches Wissen** über Projekte, Entscheidungen, Learnings + +### Was NICHT rein gehört? +- ❌ Infra-Topologie (→ L1 Wiki) +- ❌ Aktuelle IPs/Versionsnummern (→ L1 Wiki, werden schnell stale) +- ❌ Procedures (→ L3 Skills) +- ❌ Credentials (→ 1Password) +- ❌ Session-Fortschritt (→ L4 LCM) + +### Bekanntes Problem: Hindsight Accumulation +Hindsight hat über Monate Infra-Fakten angesammelt die inzwischen teilweise +veraltet sind (9 vs 8 Nodes, alte OSD-Counts). Hindsight bietet keine +Delete-Funktion via Tools. Strategie: +1. Zukünftig nur noch semantische Pointer + Entscheidungen speichern +2. Topologie-Fakten nicht mehr via `hindsight_retain` ablegen +3. Veraltete Einträge ignorieren — Hindsight Ranking bevorzugt neuere Memories + +## L4 — LCM (Local Conversation Memory) + +### Rolle +- **Innerhalb aktiver Session:** Compaction, Summary-DAG, Fresh Tail +- **Cross-Session (lcm.db):** Rohe Nachrichten + Summary Nodes aller Sessions +- **Kein manuelles Management nötig** — läuft automatisch + +### Wann manuell eingreifen? +- `lcm_status` bei Verdacht auf Compression-Problemen +- `lcm_grep` um exakte Phrasen in vergangenen Sessions zu finden +- `lcm_recall` für bedeutungsbasierte Cross-Session-Suche +- Niemals manuell Daten in LCM schreiben — es ist Auto-Managed + +## L5 — Solution Docs + +### Wann erstellen? +- Nach substanziellem Bugfix (≥5 Tool-Calls) +- Nach Architektur-Änderung +- Nach komplexer Migration +- Nach schwierigem Troubleshooting + +### Format +`~/docs/solutions/{type}/{YYYY-MM-DD}-{slug}.md` +Types: `architecture/`, `bugfix/`, `migration/`, `workflow/` + +Immer: Hindsight-Index (`hindsight_retain`) nach Erstellung + +## Related +- [[systems/hindsight]] — Hindsight Setup, API +- [[systems/laya]] — Laya Classifier +- Skill: `memory-sync` — Wiki Maintenance Protocol +- Skill: `software-development/compound-learning` — Phase 4.7 Wiki Update diff --git a/index.md b/index.md index 2eea509..5a74c91 100644 --- a/index.md +++ b/index.md @@ -31,12 +31,18 @@ - [[systems/hindsight]] — Semantic Memory, K8s, API - [[systems/monitoring]] — Prometheus, Grafana, HolmesGPT - [[systems/seafile]] — cloud.familie-schoen.com, Seafile 13.0.19 +- [[systems/laya]] — 421M Classifier CT152, choice/noul/scale, Session-Pre-Filter +- [[systems/noris-ai]] — ai.noris.de LLMs, Embeddings, Image Gen +- [[systems/frigate]] — NVR v0.18 CT151, Kameras, MQTT, HA Automation +- [[systems/homeassistant]] — HAOS, MQTT, Automations, Notify +- [[systems/paperless]] — Dokumentenmgmt, OIDC, OCR via noris AI ## Concepts - [[concepts/network-architecture]] — 10.0.X.Y Schema, VLANs - [[concepts/gitops-workflow]] — IaC → Git → ArgoCD → Verify - [[concepts/credential-policy]] — 1Password, ESO, keine Secrets in Git - [[concepts/email-organization]] — Rechnungs-Organizer, Himalaya +- [[concepts/memory-layer-architecture]] — 7-Schichten Memory Trennungsregeln ## Reference - [[reference/ip-map]] — IP → Host → Service Mapping diff --git a/log.md b/log.md index 263c7f3..1245b47 100644 --- a/log.md +++ b/log.md @@ -1,5 +1,22 @@ # Memory Log +## [2026-09-27] architecture | Memory Layer Restructuring + Laya Session-Nutzung +- USER.md bereinigt: Infra-Fakten entfernt, nur noch User-Preferences/Safety-Rules (1.087/1.375 chars) +- MEMORY.md ausgedünnt: 2.145→1.664 chars, alle Infra-Details zeigen auf Wiki-Seiten mit `→Wiki` Pointern +- 4 neue Wiki-Seiten: systems/noris-ai, systems/frigate, systems/homeassistant, systems/paperless +- Neues Concept: concepts/memory-layer-architecture — Entscheidungsbaum "was wohin gehört" +- Hindsight Audit: massiv überladen mit veralteter Infra-Topologie. Going-Forward-Policy: nur noch semantische Pointer + Entscheidungen +- LCM gesund: 7.590 messages, 34 DAG nodes, 21.2:1 compression ratio +- User-Preference: Laya künftig in normalen Sessions nutzen (choice/noul/score) + +## [2026-09-27] architecture | Laya Email-Organizer Migration + Session-Nutzung +- Rechnungen-Organizer Cron `f773f8c23230` von LLM-Agent → `no_agent` Script mit Laya migriert +- 12 Kategorien, 3-Schichten-Safety (Confidence-Gate + Subject-Validierung + Move-Erfolg) +- Globale Ordner (Rechnungen/Bestellungen/Gutschriften/Gutscheine) statt Monatssortierung +- Wiki-Seite `systems/laya.md` erstellt mit Usage Guide für Session-Nutzung +- User-Preference: Laya künftig in normalen Sessions nutzen (choice/noul/score) +- Solution Doc: `docs/solutions/architecture/2026-09-27-laya-email-organizer-migration.md` + ## [2026-09-17] workflow | CT108-Endausbau: Census, Ghost-Router CT99999, Alias-Repair, Stop - **Census (auth):** K8s=25 / CT108=31 / gemeinsam=23 — 22 Tips identisch, dominik/memory=K8s-Superset (enthält CT-Tip de97cd6d), nur-CT=8× PoC-Müll. Archiv: 29 Bare-Bundles 143 MB unter `/home/debian/git-archive/ct108-final/` (2 Failures = legitim leere Repos). - **Ghost-Router enttarnt:** CT99999 (Traefik-LXC auf proxmox7, 10.0.60.10) terminiert TLS für *.familie-schoen.com und forwardet plain HTTP an .203. `git.familie-schoen.com` → .105:3000 WAR der letzte Live-Konsument von CT108; `git.schoen.codes` lief längst per Double-Hop aufs K8s. Fix: gitea-service-Upstream → .203 (Backup `explicit-http.yml.bak-hermes-20260917`) + Alias-Host im K8s-Ingress (Commit `9e9b6ee`). Beide Hostnamen jetzt v1.27.0. diff --git a/systems/frigate.md b/systems/frigate.md new file mode 100644 index 0000000..e64a06e --- /dev/null +++ b/systems/frigate.md @@ -0,0 +1,62 @@ +--- +title: "Frigate NVR" +category: systems +tags: [frigate, nvr, camera, ai, mqtt, proxmox] +created: "2026-09-27" +modified: "2026-09-27" +--- + +# Frigate NVR + +> Frigate v0.18.0 auf Proxmox LXC CT151. KI-gestützte Objekterkennung für Kameras Einfahrt + Terrasse. + +## Infrastruktur +- **Container:** CT151 auf proxmox6 +- **IP:** `10.0.30.104:5000` +- **Version:** v0.18.0- +- **Detector:** OpenVINO CPU (3.2 FPS) +- **go2rtc:** v1.9.14 +- **GPU:** Intel iGPU `/dev/dri/renderD128` (gid=993) + +## Kameras +| Name | IP | Substream | Detect FPS | +|------|----|-----------|------------| +| Einfahrt | `10.0.50.102` | Unterstream | 5.1 fps, 1.0 det | +| Terrasse | `10.0.50.103` | Unterstream | 5.0 fps, 2.2 det | + +## MQTT +- **Broker:** `10.0.30.10:1883` (Mosquitto auf HA) +- **Prefix:** `frigate` +- **User:** `frigate` +- **Topic:** `frigate/events` + +## Frigate Plus Model +- `plus://709bb8ad097786a7f2a37e27684c79a9` +- Benötigt `PLUS_API_KEY` (Env-Var in `/config/frigate.env`) + +## Features +- Face Recognition (groß): Sarah, Dominik, DHL1, Amazon1, Cleo, Lisa, Annemarie, Marcel Schnitzer, Uli, Eva, Postbote, Fr. Schnitzer +- License Plate Recognition (CPU, threshold 0.5) +- Semantic Search (groß) +- Record: alerts+detections, retain 30 days + +## HA Automation +- **ID:** `1714065780832` in `/config/automations.yaml` +- **Mode:** `single`, cooldown 600s +- **Dedup:** `input_text.frigate_last_event_id` speichert letzten Event +- **Flow:** MQTT trigger → 10s delay → snapshot → notify → LLM Vision (optional) +- **Labels:** person, car, license_plate, face, dog, cat, amazon, ups, package +- **Sublabel-Extraktion:** `sub[0]` (Jinja, Array-Leck-Fix) + +## Bekannte Issues +- Stationäre Autos triggerten wiederholt "new" Events → Flood → gefixt mit cooldown+dedup +- MQTT ACL blockierte HA-Subscription (User `opendtu` hatte keine Subscribe-Rechte) → gefixt +- v0.18 Breaking Changes: `clean_copy` entfernt, `license_plate.mask` Format geändert (list→dict) + +## Old Container +- CT120 (frigate): gestoppt, wartet auf Deletion + +## Related +- [[systems/homeassistant]] — MQTT, Automations, Notifications +- [[systems/noris-ai]] — LLM Vision für Event-Klassifizierung +- [[entities/infrastructure]] — CT151 auf proxmox6 diff --git a/systems/homeassistant.md b/systems/homeassistant.md new file mode 100644 index 0000000..91055dc --- /dev/null +++ b/systems/homeassistant.md @@ -0,0 +1,70 @@ +--- +title: "Home Assistant" +category: systems +tags: [homeassistant, smart-home, mqtt, automation] +created: "2026-09-27" +modified: "2026-09-27" +--- + +# Home Assistant + +> Smart Home Zentrale auf Proxmox. Steuerung, Automatisierung und Benachrichtigungen. + +## Infrastruktur +- **Host:** `10.0.30.10` (HAOS VM) +- **SSH:** `hassio@10.0.30.10` (PW: 1P Vault "Hermes") +- **URL:** `https://homeassistant.familie-schoen.com` +- **Container:** `homeassistant` (Docker) + +## MQTT +- **Broker:** Mosquitto Add-on v7.1.1 auf localhost:1883 +- **HA MQTT User:** ehemals `opendtu` (BROKEN — ACL blockiert), gefixt +- **ACL:** `/etc/mosquitto/acl` definiert `user homeassistant` + `user addons` +- **Auth Plugin:** `go-auth.so` (files,http backends) + +## Automations +- **File:** `/config/automations.yaml` (35 Automations) +- **Schreibmethode:** SSH → `docker exec homeassistant chmod 666`, danach restore 644 +- **Reload:** REST API mit JWT (HS256, signed from `/config/.storage/auth`) + +### Frigate Einfahrt Notification (ID 1714065780832) +- MQTT trigger `frigate/events` → filter `type=='new'` + cameras [Einfahrt,Terrasse] + labels [person,car,...] +- Mode: `single`, cooldown 600s +- Dedup: `input_text.frigate_last_event_id` +- Flow: delay 10s → snapshot → notify iPhone → optional LLM Vision +- Siehe [[systems/frigate]] + +## Notify Services +| Service | Status | +|---------|--------| +| `notify.mobile_app_iphone_dominik` | ✅ aktiv | +| `notify.mobile_app_sarahs_iphone_app` | verfügbar | +| `notify.mobile_app_ipad_2` | verfügbar | +| `notify.mobile_app_sm_x205` | verfügbar | + +## Entitäten +- Kameras: `camera.einfahrt_2`, `camera.terrasse_2` (Suffix `_2` wegen verwaister Integration) +- Motion: `binary_sensor.einfahrt_motion_2`, `binary_sensor.terrasse_motion_2` +- Input Text: `input_text.frigate_last_event_id` (dedup storage, max 255 chars) + +## Snapshots +- Gespeichert: `/config/www/snapshots/{camera}_latest.jpg` +- URL: `/local/snapshots/` (HTTP 200, keine Auth) + +## JWT Auth +1. `jwt_key` aus `/config/.storage/auth` lesen +2. Client `Hermes_202606` (token id `1444b2c6757b4d66a6f8f8e5899b4e6a`) +3. HS256 signieren, Bearer Header +4. `?return_response=true` für Service-Call Responses + +## Integrations +- Frigate (MQTT) +- LLM Vision (noris AI `gemma-4-31b-it`) +- Tibber (Strom) +- Marstek Speicher (VENUS-E, IP 10.0.50.113) +- Various sensors (Xiaomi BLE, etc.) + +## Related +- [[systems/frigate]] — NVR Integration +- [[systems/noris-ai]] — LLM Vision Provider +- [[reference/ip-map]] — IP Assignments diff --git a/systems/laya.md b/systems/laya.md new file mode 100644 index 0000000..c9ac7f6 --- /dev/null +++ b/systems/laya.md @@ -0,0 +1,85 @@ +# Laya Decision Model + +> 421M param ModernBERT-large Classifier (Apache 2.0) auf CT152, CPU-only. +> Nutze in normalen Sessions fuer schnelle Klassifizierung, Binaerentscheidungen und Pre-Filter. + +## Zugang +- **Endpoint:** `POST http://10.0.30.152:8000/predict` +- **Payload:** `{"state": "", "questions": {...}}` +- **Health:** `GET http://10.0.30.152:8000/health` +- **Presets:** `GET http://10.0.30.152:8000/presets/{router|guard|moderation|triage}` + +## Entscheidungstypen (Primitives) + +| Typ |用途 | Return Fields | +|-----|------|---------------| +| `choice` | Klassifizierung in N Labels | `choice`, `answer_confidence`, `probabilities` | +| `noul` | Ja/Nein mit Wahrscheinlichkeit | `noul` (0..1), `answer_confidence` | +| `score` | Ordinale Bewertung | `score`, `answer_confidence` | + +## Verwendung in Sessions + +**Praeferieren fuer:** +- Pre-Filter vor teuren LLM-Calls (z.B. "ist diese Email eine Rechnung?" → nur bei "ja" LLM aufrufen) +- Binaerentscheidungen: alert/skip, escalate/ignore, move/keep +- Multi-Kategorie-Klassifizierung mit Confidence +- Gatekeeping: Notification-Suppression, Alert-Filtering + +**NICHT geeignet fuer:** +- Textgenerierung / Zusammenfassungen (dafür LLM verwenden) +- Komplexe Reasoning-Tasks +- Embeddings / Semantische Suche (dafür Harrier/Hindsight) + +## Example Call + +```python +import json, urllib.request + +payload = json.dumps({ + "state": "Von: amazon.de\nBetreff: Bestellbestätigung #12345", + "questions": { + "kategorie": { + "type": "choice", + "instructions": "Welche Kategorie?", + "criteria": { + "rechnung": "Rechnung, Invoice", + "bestellung": "Bestellbestätigung, Order", + "werbung": "Newsletter, Marketing" + } + }, + "ignorieren": { + "type": "noul", + "instructions": "Soll ignoriert werden?" + } + } +}).encode() + +req = urllib.request.Request( + "http://10.0.30.152:8000/predict", + data=payload, + headers={"Content-Type": "application/json"} +) +result = json.loads(urllib.request.urlopen(req, timeout=30).read()) +# result["answers"]["kategorie"]["choice"] → "bestellung" +# result["answers"]["kategorie"]["answer_confidence"] → 0.99 +``` + +## Performance +- Latenz: ~1.5-1.7s warm cache (CPU) +- Load time: ~18s (cold start) +- systemd service: `laya.service` (enabled, onboot) + +## Einsatzgebiete (aktiv) +- **Rechnungen-Organizer** (Cron `f773f8c23230`): 12-Kategorie Email-Klassifizierung, 3-Schichten-Safety +- Weitere Kandidaten: Beleg-Sammler, SRE Network Recon, Backup Digest, Frigate Event Gate + +## Constraints +- 421M Modell → niedrige Confidence bei ambiguous Inputs (Feature, nicht Bug!) +- Batch funktioniert nicht — ein Request pro Input-Instanz +- `noul` ist nicht zuverlaessig fuer kritische Entscheidungen allein — immer mit `choice` kombinieren +- Confidence-Threshold empfohlen (≥0.6 fuer Moves, ≥0.5 fuer Ignores) + +## Related +- [[concepts/email-organization]] — Rechnungs-Organizer Architecture +- [[entities/infrastructure]] — CT152 auf proxmox6 +- Solution Doc: `docs/solutions/architecture/2026-09-27-laya-email-organizer-migration.md` diff --git a/systems/noris-ai.md b/systems/noris-ai.md new file mode 100644 index 0000000..5044ffa --- /dev/null +++ b/systems/noris-ai.md @@ -0,0 +1,41 @@ +--- +title: "noris AI Platform" +category: systems +tags: [ai, llm, noris, gpu, embeddings] +created: "2026-09-27" +modified: "2026-09-27" +--- + +# noris AI Platform (ai.noris.de) + +> Interne AI-Plattform der noris Network AG. Bereitstellung von LLMs, Embeddings und Image Generation. + +## Endpoints +- **Chat:** `https://ai.noris.de/v1/chat/completions` +- **Embeddings:** `https://ai.noris.de/v1/embeddings` +- **Images:** `https://ai.noris.de/v1/images/generations` (b64_json) + +## Modelle +| Typ | Modell-ID | Hinweise | +|-----|-----------|----------| +| Flagship LLM | `glm-5-2` | Primary, OpenRouter-kompatibel | +| General | `gemma-4-31b-it` | Vision-fähig, genutzt von LLM Vision | +| Large MoE | `gpt-oss-120b` | | +| Mid-range | `qwen3.6-27b` | | +| Mid-range | `qwen3.8-27b` | | +| Fast | `ds-v4-flash` | Low-latency, Paperless OCR | +| Embedding | `harrier` | Vektorembeddings | +| Image Gen | `qwen-image` | via `/v1/images/gen` | +| Image Gen | `qsu` | | +| Image Gen | `qwen-image-2-1` | | + +## Verbraucher +- **Hermes Agent** — Primärmodell `glm-5-2` via OpenRouter +- **HA LLM Vision** — `gemma-4-31b-it` für Bildanalyse (Frigate Events) +- **Paperless** — `ds-v4-flash` für OCR/Kategorisierung +- **Personal Coach Bot** — `glm-5-2` via noris direkt + +## Related +- [[systems/frigate]] — nutzt noris AI für Event-Klassifizierung +- [[systems/homeassistant]] — LLM Vision Integration +- [[systems/paperless]] — OCR via ds-v4-flash diff --git a/systems/paperless.md b/systems/paperless.md new file mode 100644 index 0000000..d6abc1e --- /dev/null +++ b/systems/paperless.md @@ -0,0 +1,34 @@ +--- +title: "Paperless-ngx" +category: systems +tags: [paperless, documents, oidc, ocr] +created: "2026-09-27" +modified: "2026-09-27" +--- + +# Paperless-ngx + +> Dokumentenmanagement mit OCR, OIDC-Login und AI-Kategorisierung. + +## Zugriff +- **URL:** `https://dokumente.familie-schoen.com` +- **mTLS:** `https://dokumente-mtls.familie-schoen.com` (auto-login als `dominik`) +- **PKCS12:** `dominik-dokumente-mtls.p12` (PW: siehe 1P Vault "Hermes") + +## Auth +- OIDC via Authelia (`dominik@schoen.eu`) +- Break-Glass lokaler User: `dominik` +- mTLS Client Cert: CN=dominik, gültig bis Juli 2028 + +## Konfiguration +- **AI Backend:** `ds-v4-flash@ai.noris.de` (noris AI) +- **Memory:** 4Gi (PAT-002) +- **Mail Import:** `dokumente@familie-schoen.com` (iCloud mailbox, max 30 Tage) +- **Owner:** dominik + +## Known Issue +- PAT-002: Memory-Limit 4Gi erforderlich, sonst OOM bei großen OCR-Batches + +## Related +- [[concepts/credential-policy]] — 1Password, mTLS Zertifikate +- [[systems/noris-ai]] — ds-v4-flash für OCR