claude-code owns /etc/claude-code and ~/.claude as declared directories

So the controller's ownership check refuses a second module owning either. ~/.claude is the
operator's at 0700 (it was 0755 on the workstations); of what is inside, the module owns only what it
writes, and the host keeps a directory that is not empty when the module goes (hq ADR 0182).
This commit is contained in:
jochen
2026-10-03 23:49:16 +02:00
parent eab335b755
commit 03e729d103
2 changed files with 24 additions and 0 deletions
+11
View File
@@ -3,6 +3,17 @@
The operator's agent on a machine (novox/hq design 36): its package, its machine-wide managed The operator's agent on a machine (novox/hq design 36): its package, its machine-wide managed
configuration, and the consumer side of the Anthropic licence manager (design 39, ADR 0183). configuration, and the consumer side of the Anthropic licence manager (design 39, ADR 0183).
## What it owns
Two directories, declared, so the mesh refuses a second module owning either:
- `/etc/claude-code`, the agent's machine-wide managed directory, root's, `0755`.
- `~/.claude` under the operator account's home, the operator's, `0700`. The module owns the directory —
that it exists, who owns it, its mode — and of what is inside only what it writes. Everything else
in it (memory, history, projects, local settings, a person's own rules and skills) is the person's
and is never read or written (hq ADR 0182). Unassigned, the module leaves the directory: the host
removes a directory only when it is empty.
## What it writes ## What it writes
Under the agent's managed directory, `/etc/claude-code`, owned whole by this module and rewritten Under the agent's managed directory, `/etc/claude-code`, owned whole by this module and rewritten
+13
View File
@@ -24,6 +24,19 @@
"type": "package", "type": "package",
"package": "claude-code" "package": "claude-code"
}, },
{
"id": "managed",
"type": "directory",
"path": "/etc/claude-code",
"mode": "0755"
},
{
"id": "agent-home",
"type": "directory",
"path": "${machine:account-home}/.claude",
"mode": "0700",
"owner": "${machine:account}"
},
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",