The work of designs 36 (claude-code) and 39 (claude-licence-manager), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on what; this holds order, size and proof.
WP
What
Where
Proof
0
the operator states the accounts, roles and licences
live mesh
the node command lists an account per node
1
the console provides its loopback endpoint (node-scoped provision)
mesh-catalog
a consumer's plan shows the bound port; refused by name without the console
2
the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over
mesh-catalog
two concurrent refreshes rotate once; mismatching identity refused; no event carries a token
3
the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools
mesh-catalog
renderer touches only the mesh's keys; strip is atomic; lineage cases
4
the manager live on the control node, three licences adopted
live mesh
licences lists three; a rotation observed
5
the agent live on one workstation
live mesh
home byte-identical but the credentials file; a session sees mesh tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper
6
the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is
live mesh, mesh-catalog
every node answers licence_status; the refusal notified
The one ordering constraint: both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel.
Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.
The work of designs 36 (`claude-code`) and 39 (`claude-licence-manager`), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on *what*; this holds order, size and proof.
| WP | What | Where | Proof |
|---|---|---|---|
| 0 | the operator states the accounts, roles and licences | live mesh | the node command lists an account per node |
| 1 | the console provides its loopback endpoint (node-scoped provision) | mesh-catalog | a consumer's plan shows the bound port; refused by name without the console |
| 2 | the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over | mesh-catalog | two concurrent refreshes rotate once; mismatching identity refused; no event carries a token |
| 3 | the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools | mesh-catalog | renderer touches only the mesh's keys; strip is atomic; lineage cases |
| 4 | the manager live on the control node, three licences adopted | live mesh | `licences` lists three; a rotation observed |
| 5 | the agent live on one workstation | live mesh | home byte-identical but the credentials file; a session sees `mesh` tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper |
| 6 | the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is | live mesh, mesh-catalog | every node answers `licence_status`; the refusal notified |
**The one ordering constraint:** both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel.
Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.
Designs 36 and 39 say what is built; this says in which order and what proves each step, in the
shape to-be 38 gave the operator's machine. Seven packages: the operator states the facts (accounts,
roles, licences); the console provides its endpoint; the licence manager and the agent module are
built and unit-tested in parallel; the manager goes live on the control node; the agent on one
workstation, with the switch and the predecessor's files removed as the proof of the whole; then the
rest of the nodes and the retirement of the two catalogue modules built on the old placement. The
live proofs wait for to-be 38's WP3, because both modules' tools run in the node's tool runtime
(ADR 0175) and a per-module tool container would rebuild what that record retires.
Design 38's WP1-WP4b ran: the node's tool runtime is live on all four machines as the operator
account, tools are bundles given only their declared words, and a bundle has no bus credential.
So the wait on design 38 WP3 is over, the agent module calls nothing and the manager starts every
exchange (key, hand-over, waiting login, reconcile), and the manager's daemon now waits on WP4c's
record instead. Accounts are stated on all four, sudo -n works for each, the agent is installed on
all four; the plan's WP0 shrinks and WP2 gets a configuration-only live proof before any licence.
The dated note on ADR 0183 now rests on ADR 0193 and 0198 rather than on a bundle having no way to
call: the manager starts every exchange by the operator's direction, through mesh/ask. To-be 40's
WP4 no longer waits on a record — ADR 0198 is it — and the live proofs count the console's five
tools (ADR 0195).
ADR 0173 §2: a module is what it declares, and there are no kinds of module. The two records called
a resource under a home and a module placing one home-scoped; the wording is corrected in place,
marked and dated, the decisions unchanged. Design 36 and to-be 40 now say the module declares
/etc/claude-code and ~/.claude as directories, so the ownership check sees both, and declares no file
under either (mesh-catalog #244).
The operator's flow: clients publish what their credentials file holds, the
manager takes in a licence it does not own and rotates it from then on. The
token itself cannot be published (design 32 §10, ADR 0201), so a node reports
fingerprints and identity as state and hands the grant over only when the
manager asks; adopting is refreshing, newest login first; bindings with a
generation replace the rotated/switched events. Designs 36 and 39 and to-be 40
amended; a pointer note on ADR 0183.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The work of designs 36 (
claude-code) and 39 (claude-licence-manager), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on what; this holds order, size and proof.licenceslists three; a rotation observedmeshtools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helperlicence_status; the refusal notifiedThe one ordering constraint: both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel.
Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.
6e306fcb4cto8a5dbaeb9887cb48dee9tobaf82b1cdbe3755d5b60to82fa5f79ea