yau-plant-assistant/status/OPEN-ISSUES.md
Claude 7d6d90f486 Add an open-issues register, and correct what port 8443 actually is
status/OPEN-ISSUES.md is a fourth register, so it opens by saying what
does NOT belong in it. Work blocked on other people stays in REQUESTS.md;
shortcuts we consciously accepted stay in BUILD-AI-CONTAINERS.md 14 and
are closed by decision, not to be re-raised here; what is running stays
in current-state.html. What had no home until now is a defect we own and
have not fixed - those were living in commit messages. Closed issues move
to the bottom rather than being deleted: this repo is an as-built record,
and an issue with no trace of how it closed is worth less than one that
was never raised.

OI-01: the OpenPLC Editor is not installed anywhere. It is a desktop tool
published by OpenPLC, and it is what authors and compiles the IEC 61131-3
program openplc-runtime executes. Without it there is no reviewable
source for the control logic in or beside this repository - the program
exists only inside the container.

Raising it exposed two wrong statements in the build spec, both calling
port 8443 the "OpenPLC Runtime web UI". Probed read-only on the host:

  Server: Werkzeug/3.1.8 Python/3.11.2
  / /login /index.html /programs /status /runtime  -> 404
  /api/v1                                          -> 401 Unauthorized

It is an authenticated REST API with no browser interface at all. Section
4 now says so with the evidence, and 14's entry is restated: 8443 is
contained by the same 10.0.0.17 binding as 502, but unlike 502 it is not
anonymous, which is a better position than that section recorded. The
binding is still the control that matters.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-01 17:09:55 +10:00

76 lines
3.5 KiB
Markdown

# Open issues — WRPS Plant Assistant
**Work we own, know about, and intend to do.** One entry per issue, newest first.
Nothing here is assigned yet; owners are set at handover.
## What belongs here, and what does not
This repository has three other registers. Putting an item in the wrong one is how
a repository ends up saying two different things about the same fact.
| If it is... | It goes in | Not here |
|---|---|---|
| Waiting on somebody outside this project | [`REQUESTS.md`](REQUESTS.md) | ✗ |
| A shortcut we **consciously accepted** | [`BUILD-AI-CONTAINERS.md`](../spec/BUILD-AI-CONTAINERS.md) §14 | ✗ |
| Something already running, and its state | [`current-state.html`](current-state.html) | ✗ |
| **A defect or gap we own and have not fixed** | **here** | ✓ |
Three rules:
1. **Anything in §14 is closed by decision.** It was weighed and accepted. Do not
re-open it here — `caddy/ai-routes.caddy` carries one such decision explicitly
marked *"do not re-raise this as a task"*.
2. **If an issue is a defect in something that already passed a phase gate**, fixing
it means re-running that gate. `CLAUDE.md` requires it; say so in the issue.
3. **Closed issues move to the bottom, they are not deleted.** The register is part
of the as-built record, and an issue with no trace of how it closed is worth less
than one that was never raised.
---
## Open
### OI-01 · OpenPLC Editor is not installed
**Raised** 2026-09-01 · **Owner** unassigned · **Affects** the demo plant, not the assistant
The **OpenPLC Editor** — a desktop tool published by the OpenPLC project, installed on a
workstation — is the application used to author and compile the IEC 61131-3 program that
`openplc-runtime` executes. It is not installed anywhere. It talks to the running container
over its REST API on port `8443`, bound to `10.0.0.17`.
**Why it matters.** `openplc-runtime` is live control for this demo: `CLAUDE.md` and
[`BUILD-AI-CONTAINERS.md`](../spec/BUILD-AI-CONTAINERS.md) §4 both forbid reconfiguring it
as a side effect of other work. Without the Editor there is no way to author, review or
compile the control logic — and no reviewable source for it in or beside this repository.
The program exists only inside the container. If the container is lost, so is the logic.
**What port 8443 is** — probed read-only on the host 2026-09-01, because two earlier
statements in the build spec called it a web UI and were wrong:
```
Server: Werkzeug/3.1.8 Python/3.11.2
/ /login /index.html /programs /status /runtime -> 404
/api/v1 -> 401 Unauthorized
```
An authenticated REST API. No browser interface. Both build-spec statements were corrected
in the commit that raised this issue.
**Open questions to settle when this is picked up.**
- **Which workstation.** Not `lin001` — the Editor is a desktop application. Not `cicore1`
`CLAUDE.md` forbids installing anything on it. That leaves an engineering workstation with
VPN or LAN reach to `10.0.0.17:8443`.
- **Credentials for `/api/v1`**, which currently answers `401`. Not held by this project.
- **Whether the PLC program goes under version control**, and where. This is the part that
closes the "logic exists only in the container" gap, and it is the reason this issue is
worth more than "install a tool".
**Blocked by** nothing. **Blocking** nothing today — the demo runs.
---
## Closed
*None yet. Closed issues move here with the commit that closed them.*