0030: A project is the web surface's unit; it can be created and planned from the browser
- Status: Accepted (Navjyot, 2026-10-06)
- Date: 2026-10-06
- Related: 0006 (
newthenplan), 0012 (one workspace per project), 0013 (newcreates the tracker project and nothing on disk), 0028 and 0029 (child process rules), 0024
Contextβ
A person running several products wants each project to hold where its pieces are, with all its work under it and one selector to scope the whole page, and wants to create and plan a project without a terminal.
The registry (internal/registry, ORION_HOME/repos.json) already holds, per
project: the tracker key, the person's working copy, Orion's sandbox, the Slack
channel and the git remote. It lacks the project's page in the tracker. The web's
current project filter is a key prefix kept in the browser.
Decisionβ
- The registry is the project record. The web adds no store of its own. One field is added, the tracker project URL, empty until a person sets it. ADR 0012 is unchanged: one project, one workspace.
- One selector scopes every page (overview, needs you, history, projects, settings, launcher). Its choice is the project's key, carried in the page's link so a link opens on the project meant. A ticket belongs to the project whose key prefixes it.
- The page edits only the tracker URL and the channel. The key, the working copy, the sandbox and the git remote are shown and never written from the page: a wrong remote redirects every push, and the others identify the project. Writes go through the same guarded path as ADR 0026.
orion newfrom the page creates the tracker project and nothing else (ADR 0013), and needs one CLI change first. Todayorion newinterviews a person at a terminal and refuses--fromand--skip-discovery(they provisioned a workspace, which ADR 0013 removed); the only non-interactive input is an idea already written down in the tracker, passed by key. The page collects the same answers the interview asks (who it is for, the problem, success, out of scope, constraints) and hands them to a new CLI input,orion new --answers FILE, which takes those fields from a file and skips the interview but not the confirmation. The CLI owns the questions and the description it builds; the page owns none of it. A tracker project cannot be deleted without admin rights, so the page says that sentence and asks the person to type the project name before it runs, as the terminal's describe-then-confirm step does. The child follows ADR 0029's rules.orion plan KEY --yesfrom the page runs the chain as a child and shows each stage as it finishes, from the task record the CLI already writes, including the cost shape first (it spends). A stage that waits on a person is shown on the gate board.orion planonly runs its stages at a terminal: with none it provisions, announces and stops.--yesis the CLI's explicit unattended mode, added for this: it answers every pause itself and a step that needs a free-text answer fails rather than guessing, so the confirmation that counts is the page's, which states that the chain creates the GitHub repository and the ticket tree and spends money, before it runs.- Answering the planning stage's open questions stays in the terminal for now.
orion answerwrites into repository files and commits them; doing that from a browser is a larger decision than this one and needs its own ADR.
Consequencesβ
- A project the registry does not know cannot be selected; one a ticket mentions but no machine has bound shows as a key only, with no metadata.
orion newgains a flag, so this ADR is not only a web change: the interview's questions must stay in one place, the CLI, or the page and the terminal will ask different things.- Creating a project from the browser creates an object in the tracker that is hard to remove. The typed-name confirmation is the only guard, deliberately.
- A plan started from the page can stop at a question it cannot answer; the page says what to run.
Rejectedβ
- A separate project store in the web. Two sources of truth for where a project lives, which is the failure ADR 0012 exists to prevent.
- Editing the git remote from the page. See decision 3.
newthat also provisions a workspace. Ruled out by ADR 0013.