To-be 40: building the operator's agent and its licence manager as work packages #297

Merged
mesh-admin merged 6 commits from feat/claude-code-work-packages into main 2026-10-04 10:01:16 +00:00
Contributor

The work of designs 36 (claude-code) and 39 (claude-licence-manager), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on what; this holds order, size and proof.

WP What Where Proof
0 the operator states the accounts, roles and licences live mesh the node command lists an account per node
1 the console provides its loopback endpoint (node-scoped provision) mesh-catalog a consumer's plan shows the bound port; refused by name without the console
2 the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over mesh-catalog two concurrent refreshes rotate once; mismatching identity refused; no event carries a token
3 the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools mesh-catalog renderer touches only the mesh's keys; strip is atomic; lineage cases
4 the manager live on the control node, three licences adopted live mesh licences lists three; a rotation observed
5 the agent live on one workstation live mesh home byte-identical but the credentials file; a session sees mesh tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper
6 the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is live mesh, mesh-catalog every node answers licence_status; the refusal notified

The one ordering constraint: both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel.

Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.

The work of designs 36 (`claude-code`) and 39 (`claude-licence-manager`), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on *what*; this holds order, size and proof. | WP | What | Where | Proof | |---|---|---|---| | 0 | the operator states the accounts, roles and licences | live mesh | the node command lists an account per node | | 1 | the console provides its loopback endpoint (node-scoped provision) | mesh-catalog | a consumer's plan shows the bound port; refused by name without the console | | 2 | the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over | mesh-catalog | two concurrent refreshes rotate once; mismatching identity refused; no event carries a token | | 3 | the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools | mesh-catalog | renderer touches only the mesh's keys; strip is atomic; lineage cases | | 4 | the manager live on the control node, three licences adopted | live mesh | `licences` lists three; a rotation observed | | 5 | the agent live on one workstation | live mesh | home byte-identical but the credentials file; a session sees `mesh` tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper | | 6 | the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is | live mesh, mesh-catalog | every node answers `licence_status`; the refusal notified | **The one ordering constraint:** both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel. Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.
jschoubben force-pushed feat/claude-code-work-packages from 6e306fcb4c to 8a5dbaeb98 2026-10-03 14:01:39 +00:00 Compare
jschoubben force-pushed feat/claude-code-work-packages from 87cb48dee9 to baf82b1cdb 2026-10-03 21:41:41 +00:00 Compare
jschoubben added 6 commits 2026-10-04 09:58:48 +00:00
Designs 36 and 39 say what is built; this says in which order and what proves each step, in the
shape to-be 38 gave the operator's machine. Seven packages: the operator states the facts (accounts,
roles, licences); the console provides its endpoint; the licence manager and the agent module are
built and unit-tested in parallel; the manager goes live on the control node; the agent on one
workstation, with the switch and the predecessor's files removed as the proof of the whole; then the
rest of the nodes and the retirement of the two catalogue modules built on the old placement. The
live proofs wait for to-be 38's WP3, because both modules' tools run in the node's tool runtime
(ADR 0175) and a per-module tool container would rebuild what that record retires.
Design 38's WP1-WP4b ran: the node's tool runtime is live on all four machines as the operator
account, tools are bundles given only their declared words, and a bundle has no bus credential.
So the wait on design 38 WP3 is over, the agent module calls nothing and the manager starts every
exchange (key, hand-over, waiting login, reconcile), and the manager's daemon now waits on WP4c's
record instead. Accounts are stated on all four, sudo -n works for each, the agent is installed on
all four; the plan's WP0 shrinks and WP2 gets a configuration-only live proof before any licence.
The dated note on ADR 0183 now rests on ADR 0193 and 0198 rather than on a bundle having no way to
call: the manager starts every exchange by the operator's direction, through mesh/ask. To-be 40's
WP4 no longer waits on a record — ADR 0198 is it — and the live proofs count the console's five
tools (ADR 0195).
ADR 0173 §2: a module is what it declares, and there are no kinds of module. The two records called
a resource under a home and a module placing one home-scoped; the wording is corrected in place,
marked and dated, the decisions unchanged. Design 36 and to-be 40 now say the module declares
/etc/claude-code and ~/.claude as directories, so the ownership check sees both, and declares no file
under either (mesh-catalog #244).
The operator's flow: clients publish what their credentials file holds, the
manager takes in a licence it does not own and rotates it from then on. The
token itself cannot be published (design 32 §10, ADR 0201), so a node reports
fingerprints and identity as state and hands the grant over only when the
manager asks; adopting is refreshing, newest login first; bindings with a
generation replace the rotated/switched events. Designs 36 and 39 and to-be 40
amended; a pointer note on ADR 0183.
jschoubben force-pushed feat/claude-code-work-packages from e3755d5b60 to 82fa5f79ea 2026-10-04 09:58:48 +00:00 Compare
mesh-admin merged commit 872f20d51f into main 2026-10-04 10:01:16 +00:00
mesh-admin deleted branch feat/claude-code-work-packages 2026-10-04 10:01:16 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#297