To-be 40: building the operator's agent and its licence manager as work packages #297

Open
mesh-admin wants to merge 1 commits from feat/claude-code-work-packages into main
Contributor

The work of designs 36 (claude-code) and 39 (claude-licence-manager), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on what; this holds order, size and proof.

WP What Where Proof
0 the operator states the accounts, roles and licences live mesh the node command lists an account per node
1 the console provides its loopback endpoint (node-scoped provision) mesh-catalog a consumer's plan shows the bound port; refused by name without the console
2 the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over mesh-catalog two concurrent refreshes rotate once; mismatching identity refused; no event carries a token
3 the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools mesh-catalog renderer touches only the mesh's keys; strip is atomic; lineage cases
4 the manager live on the control node, three licences adopted live mesh licences lists three; a rotation observed
5 the agent live on one workstation live mesh home byte-identical but the credentials file; a session sees mesh tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper
6 the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is live mesh, mesh-catalog every node answers licence_status; the refusal notified

The one ordering constraint: both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel.

Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.

The work of designs 36 (`claude-code`) and 39 (`claude-licence-manager`), merged in #286, broken into packages in the shape to-be 38 gave the operator's machine. The designs stay the authority on *what*; this holds order, size and proof. | WP | What | Where | Proof | |---|---|---|---| | 0 | the operator states the accounts, roles and licences | live mesh | the node command lists an account per node | | 1 | the console provides its loopback endpoint (node-scoped provision) | mesh-catalog | a consumer's plan shows the bound port; refused by name without the console | | 2 | the licence manager, built and unit-tested: manifest, store, refresh with lease/floor/cadence, adoption with identity guard, usage, verbs, hand-over | mesh-catalog | two concurrent refreshes rotate once; mismatching identity refused; no event carries a token | | 3 | the agent module, built and unit-tested: manifest with nothing under a home or /etc, renderer for the managed directory, keypair, apply/pull/write, key-helper, tools | mesh-catalog | renderer touches only the mesh's keys; strip is atomic; lineage cases | | 4 | the manager live on the control node, three licences adopted | live mesh | `licences` lists three; a rotation observed | | 5 | the agent live on one workstation | live mesh | home byte-identical but the credentials file; a session sees `mesh` tools once; switch changes the token within a minute, no token in any answer or log; API-key binding via the helper | | 6 | the rest of the nodes; adoption from a login (and a refused one); retire anthropic-manager/consumer; designs to implemented with the as-is | live mesh, mesh-catalog | every node answers `licence_status`; the refusal notified | **The one ordering constraint:** both modules' tools run in the node's tool runtime (ADR 0175), so the live proofs (WP4+) wait for to-be 38's WP3. Code and tests (WP1–WP3) start now, in parallel. Deliberately not here: the package-repository seat, an automated switch on exhaustion, workers and the mesh's sessions as live consumers, measuring whether a refresh token is single-use. Checks pass.
mesh-admin added 1 commit 2026-10-02 15:27:08 +00:00
Designs 36 and 39 say what is built; this says in which order and what proves each step, in the
shape to-be 38 gave the operator's machine. Seven packages: the operator states the facts (accounts,
roles, licences); the console provides its endpoint; the licence manager and the agent module are
built and unit-tested in parallel; the manager goes live on the control node; the agent on one
workstation, with the switch and the predecessor's files removed as the proof of the whole; then the
rest of the nodes and the retirement of the two catalogue modules built on the old placement. The
live proofs wait for to-be 38's WP3, because both modules' tools run in the node's tool runtime
(ADR 0175) and a per-module tool container would rebuild what that record retires.
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/claude-code-work-packages:feat/claude-code-work-packages
git checkout feat/claude-code-work-packages
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#297