Files
mesh-catalog/modules/claude-code/README.md
T
jochen 04626be62d claude-code: the manifest, the managed directory and the tools (hq design 36, to-be 40 WP2)
The module owns /etc/claude-code: managed-mcp.json lists the console as `mesh` over HTTP on
loopback plus the servers in its mcp_servers setting (exclusive, by the operator's choice — the
https rule of managedMcpServers refuses a loopback console); managed-settings.json carries the
attribution convention, keeps claude.ai connectors, and adds the key-helper only for an API-key
licence; CLAUDE.md says how a session here works. Rendered whenever the runtime collects the
tools, written only on change, through the operator account's sudo. Under the home, only the
credentials file, only on a hand-over. Nothing declared under a home or /etc; the console's
port comes from node-tools' mcp-endpoint (mesh-tools #34).
2026-10-03 16:13:01 +02:00

2.2 KiB

claude-code

The operator's agent on a machine (novox/hq design 36): its package, its machine-wide managed configuration, and the consumer side of the Anthropic licence manager (design 39, ADR 0183).

What it writes

Under the agent's managed directory, /etc/claude-code, owned whole by this module and rewritten whenever the node's tool runtime collects the module's tools:

file holds
managed-mcp.json the tool servers every session loads: the mesh's console as mesh, and the servers set in this module's mcp_servers setting. Exclusive: a server not listed here does not load — not one added with claude mcp add, not a project's .mcp.json, not a plugin's
managed-settings.json the repositories' attribution convention, the claude.ai connectors kept beside the managed servers, and the key-helper while the node holds an API-key licence
CLAUDE.md how a session on this mesh works, this node's name and role, the conventions

Under the operator's home, only ~/.claude/.credentials.json, and only when the licence manager hands this node a subscription token. Nothing else under the home is read or written.

Settings

Per node or for the whole mesh, through mesh-controller.settings module=claude-code:

  • role — what this node is, in a few words; shown to every session.
  • mcp_servers — extra tool servers, keyed by name, in the vendor's .mcp.json entry shape ({"type":"http","url":…} or {"type":"stdio","command":…,"args":[…]}). The name mesh is the module's own and cannot be set. Put a person's own servers here, or they stop loading.

On a machine that carried the predecessor

Remove these by hand, once; the mesh removes nothing it did not make (ADR 0182):

  • ~/.claude/CLAUDE.md
  • ~/.claude/rules/00-hal-mesh.md, ~/.claude/rules/conventions.md
  • ~/.claude/skills/cleanup/, ~/.claude/skills/hal-switch-license/
  • the hand-made console entry in ~/.claude.json under mcpServers — it is ignored now anyway

Escalation

Writing /etc/claude-code needs root. The runtime runs as the operator account, and the module uses that account's passwordless sudo; on a machine without it, claude_code_render says so and nothing is written.