soul.demarkus.io

Map: soul.demarkus.io

76 connected · 4 unlinkedrelateddepends-onrelatedrelatedrelatedrelatedrelatedrelatedrelatedrelateddepends-onrelatedimplementsrelatedrelatedrelatedrelatedimplementsrelatedrelatedrelatedrelatedrelatedrelatedrelatedrelatedrelateddemarkus-souldemarkus-soul — /index.mdArchitectureArchitecture — /architecture.mdPatterns & Conven…Patterns & Conventions — /patterns.mdCoding GuidelinesCoding Guidelines — /guidelines.mdDebuggingDebugging — /debugging.mdRoadmapRoadmap — /roadmap.mdConventions and W…Conventions and Working Agreements — /conventions.mdDemarkus / Knowle…Demarkus / Knowledge System FAQ — /rfc-review-faq.mdThe Universe Patt…The Universe Pattern — /universe.mdCompleted PlansCompleted Plans — /completed-plans.mdDocument GraphDocument Graph — /graph.mdGuide: Setting Up…Guide: Setting Up demarkus-soul — /guide.mdThe Reading Room …The Reading Room authoring contract — /.well-known/library/authoring.mdTrail URLs — the …Trail URLs — the shared reading-context format — /.well-known/library/trails.mddemarkus-souldemarkus-soul — /.well-known/agent-manifest.mdADR 0008: GCS wor…ADR 0008: GCS world state commits through one root CAS — /adr/0008-gcs-root-cas-storage.mdADR 0007: SNI sel…ADR 0007: SNI selects a virtual Mark server — /adr/0007-sni-virtual-world-routing.mdADR 0005 — Node i…ADR 0005 — Node identity omits the default port — /adr/0005-node-identity-default-port.mdADR 0004 — Edge s…ADR 0004 — Edge semantics: provenance on every edge, typed relations via rel- metadata — /adr/0004-edge-semantics-rel-convention.mdADR 0006: The Pos…ADR 0006: The Postgres backend is an optional build, not a dependency — /adr/0006-postgres-backend-is-an-optional-build.mdADR 0003 — Defaul…ADR 0003 — Default OKF type on publish — /adr/0003-okf-type-default-on-publish.mdADR 0002 — Align …ADR 0002 — Align store frontmatter with the Open Knowledge Format — /adr/0002-okf-metadata-alignment.mdADR 0001 — Broker…ADR 0001 — Broker confidential web-client registry — /adr/0001-broker-confidential-web-clients.mddemarkus-knowledg…demarkus-knowledge-system-deploy: project hub — /demarkus-knowledge-system-deploy/index.mdJournal 2026-08-23Journal 2026-08-23 — /demarkus-knowledge-system-deploy/journal/2026-08-23.mdJournal 2026-08-21Journal 2026-08-21 — /demarkus-knowledge-system-deploy/journal/2026-08-21.md2026-06-12 — dema…2026-06-12 — demarkus-library in-cluster deploy — /demarkus-knowledge-system-deploy/journal/2026-06-12.md2026-07-15: libra…2026-07-15: library 0.21.2 deployed (enriched /graph.md parsing) — /demarkus-knowledge-system-deploy/journal/2026-07-15.md2026-07-14: broke…2026-07-14: broker 0.12.2 + agent 0.21.1 bump (graph hub seeding) — /demarkus-knowledge-system-deploy/journal/2026-07-14.md2026-07-062026-07-06 — /demarkus-knowledge-system-deploy/journal/2026-07-06.md2026-07-052026-07-05 — /demarkus-knowledge-system-deploy/journal/2026-07-05.mdJournal 2026-08-12Journal 2026-08-12 — /demarkus-knowledge-system-deploy/journal/2026-08-12.mdADR 0005 — The Re…ADR 0005 — The Reading Room: spatial trails over temporal history — /demarkus-library/adr/0005-reading-room-spatial-trail.mdADR 0006 — Readin…ADR 0006 — Reading Room interaction model: dock, palette, and on-demand overlays — /demarkus-library/adr/0006-reading-room-interaction-overlays.mdADR 0002 — Hexago…ADR 0002 — Hexagonal (ports & adapters) architecture — /demarkus-library/adr/0002-hexagonal-architecture.mdThe Reading Room …The Reading Room — design notes (draft) — /demarkus-library/plans/reading-room.mdPhase 5 — Public …Phase 5 — Public Face: the anonymous-read decision (plan) — /demarkus-library/plans/phase-5-public-face.mdPhase 3 — Catalog…Phase 3 — Cataloging Desk (plan) — /demarkus-library/plans/phase-3-cataloging-desk.mdPhase 1b — Web SS…Phase 1b — Web SSO over the Broker (two-repo plan) — /demarkus-library/plans/phase-1b-web-sso.mddemarkus-librarydemarkus-library — /demarkus-library/index.mdADR 0003 — SSR-fi…ADR 0003 — SSR-first, htmx-hard, no JSON — /demarkus-library/adr/0003-htmx-ssr-philosophy.mddemarkus-library …demarkus-library — Roadmap & Resume — /demarkus-library/roadmap.mdADR 0004 — Broker…ADR 0004 — Broker confidential web client + redirect SSO (reject device flow) — /demarkus-library/adr/0004-broker-web-sso.mdADR 0001 — Echo +…ADR 0001 — Echo + bulwarkauth-style layout for the front-end — /demarkus-library/adr/0001-echo-bulwarkauth-layout.mdJournal 2026-08-18Journal 2026-08-18 — /journal/2026-08-18.mdJournal 2026-08-17Journal 2026-08-17 — /journal/2026-08-17.md2026-06-21 — Leid…2026-06-21 — Leiden clustering: built, measured, shelved as a grouping feature — /journal/2026-06-21.md2026-06-022026-06-02 — /journal/2026-06-02.md2026-07-22: migra…2026-07-22: migrating soul.demarkus.io off the Orange Pi to a droplet — /journal/2026-07-22.mdJournal: 2026-08-…Journal: 2026-08-22 — /journal/2026-08-22.md2026-06-08 — Brok…2026-06-08 — Broker-global OIDC AllowDomains gate — /journal/2026-06-08.md2026-07-25: Hoste…2026-07-25: Hosted tenant density ADR (0005) — /journal/2026-07-25.md2026-06-25 — pi c…2026-06-25 — pi command fix, plugin lint debt, poison-lock fix — /journal/2026-06-25.mdJournal — 2026-05…Journal — 2026-05-31 — /journal/2026-05-31.mdmemoryleaderboard…memoryleaderboard: Project Hub — /memoryleaderboard/index.mdmemoryleaderboard…memoryleaderboard production deployment — /memoryleaderboard/deployment.mdAgent Memory Lead…Agent Memory Leaderboard — /memoryleaderboard/agent-memory-leaderboard.mdmemoryleaderboard…memoryleaderboard debugging — /memoryleaderboard/debugging.mdJournal 2026-08-17Journal 2026-08-17 — /memoryleaderboard/journal/2026-08-17.mdJournal 2026-08-16Journal 2026-08-16 — /memoryleaderboard/journal/2026-08-16.mdJournal 2026-08-14Journal 2026-08-14 — /memoryleaderboard/journal/2026-08-14.mdJournal 2026-08-13Journal 2026-08-13 — /memoryleaderboard/journal/2026-08-13.mdMulti-world Knowl…Multi-world Knowledge Server — /plans/knowledge-server.mdPlan: Agent Memor…Plan: Agent Memory Leaderboard entry — /plans/agent-memory-leaderboard.mdPlan: demarkus as…Plan: demarkus as a service — /plans/demarkus-as-a-service.mdKnowledge Ingesti…Knowledge Ingestion Pipeline — /plans/knowledge-ingestion.mdPlugin Prompt Sou…Plugin Prompt Source of Truth — /plans/plugin-prompt-source-of-truth.mdPlan: Plugin Know…Plan: Plugin Knowledge-Quality Enforcement — /plans/plugin-knowledge-quality.mdPlan: Absolute pa…Plan: Absolute parity between the file store and the Postgres store — /plans/store-parity.mdCode Quality Swee…Code Quality Sweep 2026-08 — /plans/code-quality-sweep-2026-08.mdKnowledge graph c…Knowledge graph completeness analysis (2026-07-15) — /plans/graph-completeness.mdPlan: the five-mi…Plan: the five-minute appliance — /plans/five-minute-appliance.mdPlan — /soul-join…Plan — /soul-join: managed remote souls + catalog + project binding — /plans/soul-join.mdPlan: APPEND meta…Plan: APPEND metadata loss — /plans/append-metadata-loss.mdObsidian Plugin P…Obsidian Plugin Plan — /plugins/obsidian/plan.mdObsidian Plugin —…Obsidian Plugin — obsidian-demarkus — /plugins/obsidian/index.mdunlinkedJournal 2…Journal 2026-08-23 — /demarkus/journal/2026-08-23.md2026-08-2…2026-08-21 PostgreSQL request snapshots — /journal/2026-08-21.mdJournal 2…Journal 2026-08-24 — /journal/2026-08-24.mdAgent Mem…Agent Memory Leaderboard application readiness — /memoryleaderboard/application-readiness.md
soul.demarkus.io/plans/soul-join.md draft reader meta

Plan — /soul-join: managed remote souls + catalog + project binding

Problem

Three demarkus surfaces can be configured at once — a hand-wired .mcp.json demarkus server ("pure MCP", e.g. demarkus-soul → soul.demarkus.io), the demarkus-memory plugin (local managed soul), and the demarkus-knowledge plugin (broker KS). All expose identical mark_* tools, so the agent can't tell which to write to. Today a remote soul can only be reached by hand-editing .mcp.json, which also leaks the auth token in plaintext into both .mcp.json and claude mcp list. There is no /soul-join (the soul index Vocabulary already anticipates one).

Decision (Fritz, 2026-06-22)

Build /soul-join into demarkus-memory so there is no manual MCP for souls, mirroring /knowledge-join. Token storage = wrapper + 0600 file (no secret in config). Maintain a catalog of souls plus a per-project binding that routes writes. Detect existing hand-wired demarkus-mcp entries and offer to adopt them.

Data model

  • Catalog~/.demarkus/souls (tab-separated, one row per remote soul): <slug>\t<host>\t<insecure 0|1>\t<token-file|->. The local managed soul stays in plugin-memory.conf (tier=local); a catalog view unions local + remote + knowledge endpoints. Tiers: local (plugin-managed), remote (joined).
  • Per-project binding~/.demarkus/project-souls: <project-dir>\t<slug>. Which catalog soul this repo writes to by default. Set when /soul-join runs inside a repo. This is the routing key that ends the "which one?" confusion.
  • MCP registration scope — orthogonal: project (repo .mcp.json, default when joined in a repo) or user (global, no binding).

Components

  1. lib.shSOULS_REGISTRY, PROJECT_SOULS paths; helpers register_remote_soul, remote_soul_fields, list_remote_souls, is_registered_remote_soul, bind_project_soul, project_soul_binding. Extend publish_gate_scope so the tag-gate also fires on registered remote souls (today only demarkus-memory).
  2. scripts/soul-join.sh <host> [--token T] [--insecure] — normalize host (mark:// scheme, :6309 default port), derive + sanitize slug from first DNS label, write token to ~/.demarkus/soul-<slug>.token (mode 600), register_remote_soul, emit key=value. Reachability = best-effort (demarkus is QUIC, no HTTP metadata; first tool call is the real check).
  3. scripts/soul-remote-wrapper.sh <slug> — registry-driven; exports DEMARKUS_AUTH from the token file and execs demarkus-mcp -host <host> [-insecure]. Same pattern as the local mcp-wrapper.sh.
  4. scripts/detect-manual-souls.sh — scan project + user .mcp.json for unmanaged demarkus-mcp entries; feed the adopt flow.
  5. commands/soul-join.md — mirrors knowledge-join.md; includes the detect-and-adopt step.
  6. context/session-guidance.md — describe catalog + binding + roles.
  7. tests/soul-join_test.sh; bump plugin.json version.

Constraints (project conventions)

  • Pure awk/bash, no runtime deps (jq/python/node forbidden).
  • Bash 3.2 (macOS stock). Branch + PR; Fritz commits. Never ship broken.

Open / phase 2

  • A destination gate (PreToolUse on mark_publish) enforcing the project→soul binding so a misrouted write is denied, not just guided.
  • /soul-join reachability hardening (one-shot stdio MCP probe).

Status — built (branch feat/soul-join)

Phase 1 (catalog + binding + /soul-join + wrapper + adopt detection) and phase 2 (destination gate) both implemented and tested. Plugin v0.9.0 → v0.10.0.

  • lib.sh: catalog/binding helpers, publish_gate_scope extended, soul_target_id, configured_dest_strictness, restart_local_server_on_upgrade (+ DEMARKUS_BINARIES_REPLACED from ensure_binaries).
  • scripts: soul-join.sh, soul-remote-wrapper.sh (self-contained, stable install path), detect-manual-souls.sh.
  • hooks: dest-gate.sh (PreToolUse on publish+append) registered in plugin.json; session-start.sh restarts the configured server after a binary upgrade.
  • commands/soul-join.md; session-guidance routing + enforcement note.
  • tests: soul-join (16), dest-gate (11), restart-on-upgrade (5); full suite 112 green; shellcheck clean.

Also closed an adjacent bug: a binary swap (via /soul-join or a pin bump) now restarts the configured local server with its own recorded config, in every mode including reuse.

Remaining (deferred): full auto-migration of a hand-wired .mcp.json entry (currently guided re-join + claude mcp remove); /soul-join reachability hardening; wrapper auto-reinstall on plugin upgrade; append-metadata carry-forward (orthogonal, pre-existing). Binary version pins intentionally not bumped (plugin-only change; release-time decision).

Related documents

trail
  1. soul.demarkus.io soul.demarkus.io — map
  2. soul-join