08-10 Task 3 is the first time this gate has actually been executed against real Docker/Postgres/the real fonoteka CLI/the real fonoteka-mcp process. Four independent, previously-undetected defects surfaced: - stage_postgres never set POSTGRES_INITDB_ARGS for the ICU pl-PL locale lagoon.Use requires (every other Postgres testcontainer in this project already does); the app failed to boot at all. - stage_app_boot's seed step POSTed to /_fonoteka/api/v1/onboarding/bootstrap, a route routes.go never mounts (its own comment marks that group deliberately empty, pending a later phase). The gate's test user/collection are now seeded directly with SQL, matching every app-level OAuth test's own real-Postgres seeding. - phase8_workdir() assigned PHASE8_WORKDIR from inside a function body that is always invoked via command substitution (a subshell): the assignment never escaped back to the calling shell, so every separate caller (stage_postgres, stage_app_boot, each phase8_mcp_stage call, ...) minted its own fresh mktemp directory. This silently fragmented one run's state (app.log, the MCP client's gate-state.json) across dozens of directories that never saw each other's writes -- the MCP client's dcr stage could never see discovery's saved metadata. PHASE8_WORKDIR is now set once, directly, in run_full_gate before any stage runs. - gate-state.json (the MCP client's shared cross-invocation state) holds raw live secrets by design and is never redacted; stage_secret_scan correctly flagged it. It is now deleted once the MCP lifecycle stages are done with it, before the scan runs -- the scan itself stays exactly as strict as it already was. stage_security_review also now refuses a nonzero threats_open count or a missing required T-08-* row, not just a missing/unverified file, and gains --security-review-only, a focused mode for Task 2's own verify command.
SummerCMS (Go)
A Go rewrite of the WinterCMS/OctoberCMS content management framework, built for the Golem15 stack.
SummerCMS keeps what makes WinterCMS productive — plugins that extend each other, YAML-driven admin forms, models/controllers/components, scaffolding commands — and drops the parts that do not survive a compiled language.
Status
Pre-alpha. Planning and research. Nothing runs yet.
Why Go
The first SummerCMS attempt was Scala 3. Three infrastructure modules were built (config, i18n, console) before the effort stalled on ecosystem depth: proven, reusable libraries for things like an OAuth2/OIDC server did not exist, and building them from scratch was out of budget. Go's ecosystem covers every concern in the Illuminate module map with maintained, widely used libraries. See .planning/notes/why-go-not-scala.md and .planning/research/go-ecosystem.md.
v1 target
Port Płytarium (the fonoteka project): a headless WinterCMS backend with a Nuxt 4 frontend, 160 API routes, its own OAuth2 provider, Discogs and AI integrations, queued jobs, realtime notifications, and organization-scoped collections.
Definition of done for v1: vue-fonoteka-app runs unchanged against the Go backend.
See .planning/notes/v1-target-plytarium.md.
Architecture decisions so far
- Compiled plugins, Caddy/xcaddy style: a
plugins/workspace of Go modules, a generated import list, scaffold and rebuild commands, watch-rebuild in dev. - A sandboxed WASM extension API for untrusted third-party extensions comes later, behind a stable core plugin API.
- Headless first. Admin is a schema-driven SPA. Server-rendered themes come with the second port target (keios.eu).
Layout
.planning/ GSD planning artifacts (notes, research, seeds, roadmap)
Everything else will be created by the GSD roadmap phases.