Files
infra-phytron/TODO.md
T
CubelaPetarandClaude Opus 4.8 be6efa7b34 Update projektplan and TODO with share analysis results
- projektplan: status section (server delivered, driver done), share
  analysis results in §2.1, customer checklist answers in §2.2, storage
  resolved in §2.3, new §2.6 on scoping the corpus, updated risks
- scripts/list-shares.ps1: enumerate SMB shares incl. paths, permissions
  and DFS namespaces on the file server
- TODO.md: restructured into blocking/server/done

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-03 14:10:14 +02:00

42 lines
2.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# TODO
## phy-z-srv-gpu01
Per [projektplan](server/phy-z-srv-gpu01/notes/20260710-projektplan.md) (§ references below).
Server is delivered; base setup + NVIDIA driver are done (see `SETUP.md`).
### Blocking the knowledge base (customer conversation)
- [ ] **Scope the corpus (§2.6)** — share analysis found 1.26M extractable documents,
~12× the planning threshold. Decide with the customer which shares/folders
actually form the knowledge base. Everything in Phase 5 depends on this.
- [ ] Evaluate the two CSVs still sitting on the file server: `D-toplevel-folders.csv`
(basis for the include/exclude list) and `D-file-types.csv` (resolve the
1.58M unidentified `other` files)
- [ ] Run `scripts/list-shares.ps1` on Z-FILESERVER — map shares → local paths,
so the analysis of `D:` can be tied to actual shares
- [ ] Data protection / works council: are chat logs stored? (§2.2) — before rollout
- [ ] AD details still needed: bind service account + base DN (group `llm_users` and
the read-only SMB account are agreed)
- [ ] German eval set (§2.5): 2030 Q&A with the customer — acceptance criterion
### Server / Ansible
- [ ] Role `cifs_mounts` — read-only mounts, credentials from `group_vars/secrets.yml`
- [ ] Role `llm_stack` — docker compose: vLLM (fixed `--gpu-memory-utilization`),
embedding server, Open WebUI + pgvector, reverse proxy, oikb timer.
Tag compose tasks with `compose` so `just compose` works.
- [ ] Pin versions at install time (vLLM / Open WebUI / oikb / model) per §5
- [ ] OCR pipeline for ~166k scanned PDFs (§2.1) — own work block, competes with vLLM for the GPU
- [ ] TLS: currently plain HTTP on `chat.phytron.local`; retrofit an internal CA
certificate (AD passwords travel in clear text until then)
- [ ] Hostname mismatch: server reports `phy-srv-gpu01`, repo/inventory/label use
`phy-z-srv-gpu01` — align
- [ ] Finish base hardening in `SETUP.md` (ssh, updates) via `just run phy_z_srv_gpu01`
### Done
- [x] Share analysis script → `scripts/share-analysis.ps1`, run on 2026-07-14 (§2.1)
- [x] Storage decision (§2.3) — 876 GB usable, no extra disks needed
- [x] NVIDIA driver via role `nvidia_gpu` (595 open kernel modules)