Write Secrets with kubectl replace in the rotation script, since apply copies the data into the last-applied annotation. Record in operations.md the live-change rules that apply here and the open finding: four live Secrets carry that annotation, and removing it waits for the founder's go-ahead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 352750@bnt-lap001 Assistant-Session: de41ef1c-2113-4dd2-9b92-f318ffa7f98b
3.5 KiB
Session Protocol
Dev Hub (State Hub API): http://127.0.0.1:8000
MCP server name in ~/.claude.json: dev-hub
Before production, credential or GitOps work read
~/the-custodian/docs/agent-environment-orientation.md; KeyCape specifics are
in docs/operations.md, "Before any live change".
Step 1 — Orient
Read the offline-safe brief first — it works without a live hub connection:
cat .custodian-brief.md
Then call the MCP tool for richer cross-domain context when MCP tools are exposed:
get_domain_summary("infotech")
If MCP tools are unavailable in the current agent session, use the REST API:
curl -s "http://127.0.0.1:8000/state/summary" | python3 -m json.tool
If the hub is offline: cd ~/state-hub && make api
Step 2 — Check inbox With MCP tools:
get_messages(to_agent="key-cape", unread_only=True)
Mark read with mark_message_read(message_id). Reply or act on coordination
requests before proceeding.
Without MCP tools:
curl -s "http://127.0.0.1:8000/messages/?to_agent=key-cape&unread_only=true" \
| python3 -m json.tool
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
-H "Content-Type: application/json" -d '{}'
Step 3 — Scan workplans
ls workplans/
For each file with status: ready, active, or blocked, note pending
wait/todo/progress tasks.
Step 4 — Present brief
- Active workplans for
infotech— title, task counts, blocking decisions - Pending tasks from
workplans/+ any[repo:key-cape]hub tasks - Goal guidance — if
goal_guidancein summary:needs_workplan: surface as top action — "Repo goal '{title}' has no workplan yet"alignment_warnings: flag if active work is not aligned with current goal
- Suggested next action — highest-priority open item
- SBOM status — flag if
last_sbom_atis unset for this repo
If no workplans: follow First Session Protocol (first-session.md).
During work: record_decision() · add_progress_event() · resolve_decision()
State Hub is a read model. Never register workplans or tasks by hand (
create_workplan,create_task) — write the workplan file inworkplans/and runfix-consistency; C-06 registers the workplan and tasks and writes IDs back into the file. Manual registration creates duplicates when fix-consistency runs. Work structure belongs in repo files (ADR-001).Legacy:
create_workstreamand/workstreams/remain as metered aliases — seeworkplan-convention.md(compatibility footnote).
Session close: With MCP tools:
add_progress_event(summary="...", topic_id="cee7bedf-2b48-46ef-8601-006474f2ad7a", workplan_id="<uuid>")
Without MCP tools:
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{"topic_id":"cee7bedf-2b48-46ef-8601-006474f2ad7a","workplan_id":"<uuid>","event_type":"note","summary":"what changed","author":"codex"}'
If workplan files were modified, ensure the local copy is up to date first, then sync from the repo checkout:
git pull --ff-only
statehub fix-consistency
For repos where implementation runs on a remote machine (e.g. CoulombCore), use the pull-before-fix mode from any shell with the State Hub CLI:
statehub fix-consistency --repo key-cape --remote
C-15 (DB task ahead of file) is normal in multi-machine workflows — writeback will sync the file to match DB. C-16 (repo behind remote) blocks all writes until you pull — intentional to prevent clobbering remote progress.