Implements ADR 0052's host half. applyRunOnce runs the container in the foreground (no detach, no restart) so its exit code returns; a non-zero exit fails and gates the apply (the gate branch, previously action-only, now fires for a failed run-once container too); success records the declaration digest; a matching prior digest short-circuits to unchanged (idempotent). Six unit tests (run-to-completion not detached, non-zero fails, failed step gates the follower, already-completed not re-run, changed declaration re-runs, run-once+restart-on refused). go test ./... green.
Implements ADR 0052's host half. `applyRunOnce` runs the container in the foreground (no detach, no restart) so its exit code returns; a non-zero exit fails and **gates** the apply (the gate branch, previously action-only, now fires for a failed run-once container too); success records the declaration digest; a matching prior digest short-circuits to unchanged (idempotent). Six unit tests (run-to-completion not detached, non-zero fails, failed step gates the follower, already-completed not re-run, changed declaration re-runs, run-once+restart-on refused). `go test ./...` green.
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
A module can declare state but not a step that runs at first boot. This adds
`run-once: true` to the container shape: the host runs it in the foreground,
requires it to exit 0, and records that it did — as the digest of the
declaration, so a re-apply does not re-run it unless the declaration changed.
Because the declaration is applied in order and a failed run-once step gates the
apply the way a failed action does, whatever is declared after the step starts
only once it has completed. That is how "before the broker starts" is enforced,
with no dependency graph the host must resolve (ADR 0005): the step is declared
first, and the container that needs it is never reached until it is done.
No new host shape and no arbitrary host command — a run-once container is
strictly less powerful than an action. Validation refuses run-once with
restart-on (contradictory lifecycles). Six unit tests; go test ./... green.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements ADR 0052's host half.
applyRunOnceruns the container in the foreground (no detach, no restart) so its exit code returns; a non-zero exit fails and gates the apply (the gate branch, previously action-only, now fires for a failed run-once container too); success records the declaration digest; a matching prior digest short-circuits to unchanged (idempotent). Six unit tests (run-to-completion not detached, non-zero fails, failed step gates the follower, already-completed not re-run, changed declaration re-runs, run-once+restart-on refused).go test ./...green.https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF