Part of #589.
CONTEXT
Every session-to-venue-to-org attribution in the dashboard joins through hydracluster node.Venue (pkg/store/store.go:43). The performance-data map states node.Venue is FREE TEXT from the enrollment form and is not validated against hydravenues venue IDs. A value of "Rupelmonde" instead of "rupelmonde", or an empty value, silently drops sessions from the dashboard. The mobile booth (venue mobile-kit) moves between locations, so its body's node.venue must be maintained operationally. Without this issue, both the live-status filter and all stamped session history mis-count.
SCOPE
- AUDIT: list all nodes via GET /api/v1/nodes (admin token). Compare every node.venue against the hydravenues venue ID list (GET /api/v1/venues, public). Produce the mismatch list in the issue: wrong case, free-text names, empty values, retired venues.
- NORMALIZE: correct each mismatched node via the hydracluster API or web admin. HOUSE RULE: never sed or awk nodes.yaml; API or web admin only.
- WRITE-TIME VALIDATION: on the admin node-update path, when venue is set non-empty, validate it against the hydravenues venue ID list and reject unknown values with a 400 in the existing handler style. On the self-enrollment path, do not block enrollment: accept, but log a warning and flag the node so the audit finds it. Cache the hydravenues venue list with a short TTL and fail open (warn, accept) when hydravenues is unreachable.
- RELOCATION RUNBOOK: add a section to the hydracluster runbook: "Moving the mobile booth". Procedure: before streaming at the new location, update the mobile-kit body's node.venue via the API (PATCH the node, never the YAML). State plainly: venue is stamped onto each session at open (see the session persistence issue), so sessions started before the update stay attributed to the old venue, which is correct history, and sessions after the update attribute to the new venue.
- Tests for the validation path.
ACCEPTANCE CRITERIA
- Audit results posted on this issue; zero remaining mismatches for nodes in visit-flanders venues (rupelmonde, sint-niklaas-tourism-office, mobile-kit, ad6, cloud-seven).
- Setting an unknown venue on a node via the admin API returns 400.
- Enrollment with an unknown venue still succeeds and logs a warning.
- The relocation runbook section exists and names the API path used.
- Verified on bxl1-test bodies (chunky-turnip-23), never on production bodies.
FILES
- /home/claude-user/hydracluster/pkg/store/store.go (Venue at :43)
- /home/claude-user/hydracluster/pkg/api/server.go (node routes)
- /home/claude-user/hydracluster/pkg/api/handlers_body.go
- hydracluster runbook under docs/runbooks/
- /home/claude-user/hydravenues/internal/api/handlers_venue.go (venue list source)
DEPLOY
Standard hydracluster flow: tag, push, CI to releases.experiencenet.com, service auto-updates. Verify with hydrarelease verify --project hydracluster.