Spaces: the inside of the world, and a sun that is actually where it should be
Ten agents wrote this in parallel against CONTRACT.md, which exists because the five design agents before them collided on fifteen blocking points — four files specified twice with incompatible contents, three separate backends for one box, and `Environment` exported twice meaning different things. What landed: a Stage owning only the renderer and the loop, with the city and an office as two scenes over it. They cannot share one — San Francisco is ~94 m per scene unit with 3.6x vertical exaggeration and an office is 1 unit = 1 m — and the city is paused rather than disposed on the way in, because rebuilding its 336,864-point heightfield costs about a second on the way back out. Offices are data. `src/offices/lumbridge-hq.ts` is fifteen rooms and seventy-six seats, and it is the file a self-hoster copies. Walls are a segment list with 1-D openings, so doors and windows are holes punched in a wall rather than placed objects, and the pass that splits a wall around its openings hands the walk-mode collider its segments for free. The sun is real. `solar.ts` is a NOAA/Meeus implementation with no imports at all — not even three.js — so time of day keeps working on a laptop in a field. Verified against known values: 75.45 degrees at the June solstice in SF, 28.79 at December, sunset at 03:15Z. The first screenshot after wiring it was a black rectangle, which turned out to be correct: it was midnight in San Francisco. Presence binds to a seat id and never to a coordinate. The pack knows where `eng-04` is; who is sitting in it is private data behind an API. Same shape as the marker rule, one level in. Two corrections to ARCHITECTURE.md are in here. Containment does not discharge ODbL — publishing OSM-derived coordinates is Public Use of a Derivative Database wherever the rows live, so the rule is about the geocoder (US Census, public domain) and not the storage. And a person at a desk is not a Marker; markers are geographic. One contract gap surfaced only in a screenshot: two agents read `height` on a viewpoint differently, so the establishing shot aimed at empty air fourteen metres above the roof. It now means what the same field means for a city. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
# The one systemd unit.
|
||||
#
|
||||
# sudo cp deploy/tera-api.service /etc/systemd/system/
|
||||
# sudo systemctl enable --now tera-api
|
||||
#
|
||||
# Note the `-` on EnvironmentFile: the file is optional, so this unit starts and
|
||||
# serves /api/v1/health on a box where /etc/tera/tera.env was never created. That
|
||||
# is the same promise the compose file and the tests make, expressed in the one
|
||||
# place an operator is most likely to discover it the hard way. CONTRACT.md §5.1.
|
||||
#
|
||||
# Assumes the repo is checked out at /srv/tera with `npm ci --omit=dev` already
|
||||
# run at the root. There is no build step — Node runs the TypeScript sources
|
||||
# directly — so a deploy is a git pull and a restart.
|
||||
|
||||
[Unit]
|
||||
Description=Tera API — city data for the Tera map view
|
||||
Documentation=https://github.com/lumbridge-public/tera
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=tera
|
||||
Group=tera
|
||||
WorkingDirectory=/srv/tera
|
||||
EnvironmentFile=-/etc/tera/tera.env
|
||||
ExecStart=/usr/bin/node server/src/index.ts
|
||||
Restart=on-failure
|
||||
RestartSec=2s
|
||||
|
||||
# Requires Node >= 22.18, where type stripping runs without a flag.
|
||||
Environment=NODE_ENV=production
|
||||
|
||||
# Hardening. This process reads two directories, opens outbound HTTPS to at most
|
||||
# one weather feed, and listens on loopback. It has no business doing anything
|
||||
# else, and saying so here is cheaper than trusting that it never will.
|
||||
NoNewPrivileges=yes
|
||||
PrivateTmp=yes
|
||||
PrivateDevices=yes
|
||||
ProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
ProtectKernelTunables=yes
|
||||
ProtectKernelModules=yes
|
||||
ProtectControlGroups=yes
|
||||
RestrictAddressFamilies=AF_INET AF_INET6
|
||||
RestrictNamespaces=yes
|
||||
LockPersonality=yes
|
||||
MemoryDenyWriteExecute=no
|
||||
SystemCallFilter=@system-service
|
||||
SystemCallErrorNumber=EPERM
|
||||
|
||||
# Nothing is written at runtime. The marker snapshot is written by the sync
|
||||
# oneshot, which is a different unit with a different user and the only holder of
|
||||
# a Workie credential — add its directory here only if you run both as `tera`.
|
||||
ReadOnlyPaths=/srv/tera
|
||||
|
||||
MemoryMax=512M
|
||||
TasksMax=64
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user