rein-aharness/README.md
tegwick 0f01c3e421 feat: route profiled ops runs through Glas
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b6f-7db1-7222-918b-e813a6bda38d
2026-08-22 23:55:29 +02:00

4.7 KiB

rein-aharness

(formerly agent-harness, renamed per glas-harness ADR-001 "rein" harness family)

The single shared runtime for unattended agent instances in the Coulomb / Operational Knowledge ecosystem. Projects declare agents (manifest + .kaizen/ state); this harness runs them — blueprint via kaizen-agentic, tasks via activity-core, compute via llm-connect, credentials via OpenBao/ops-warden, reporting to the Custodian State Hub.

Within the glas-harness meta-framework, this repo is the rein-aharness rein: the Claude-Code-CLI-driven, unattended/scheduled harness for tenants that need governed cron-style agent runs. See glas-harness ADR-001 for how it relates to other reins (e.g. rein-openweights).

The CLI command (rein-aharness) and Python package (rein_aharness) are renamed. Deploy artifacts (Docker image tag, k8s namespace, Railiance host paths) are renamed in this repo too, but the live Railiance cutover itself (moving the host-side checkout + secrets dir, redeploying) is a separate, deliberate step — tracked in workplans/HARNESS-WP-0002 and deploy/README.md's rename cutover checklist.

Usage

# Validate a consuming repo's instance manifest (.kaizen/schedule.yml)
rein-aharness validate --target ~/binky-control
rein-aharness validate --target ~/binky-control --strict   # require harness fields

# List named tool profiles
rein-aharness profiles

# Run exactly one task (local JSON task-file path — dev)
rein-aharness run --task-file examples/task-hello-sandbox.json [--no-hub] [--no-metrics]

# Execution-profile overrides supplied by glas-harness
rein-aharness run --task-file examples/task-hello-sandbox.json \
  --model claude-sonnet-4-6 \
  --tool-profile green-commit-only \
  --budget-tokens 60000 \
  --no-hub --no-metrics

# Primary production intake: activity-core ops_run claim (ACT-ADR-005 / REIN-A-0002)
export ACTIVITY_CORE_URL=http://127.0.0.1:8010
export ACTIVITY_CORE_WORKER_TOKEN=…
export AGENT_HARNESS_REPO_MAP='{"freedom-intelligence":"~/freedom-intelligence","binky-control":"~/binky-control"}'
rein-aharness poll --source=ops-run --no-claim
rein-aharness run --from-ops-run
rein-aharness claim-loop
# Install user service: ./deploy/scripts/install-claim-loop-user.sh
# Docs: docs/ops-run-claim-loop.md

# A queued harness_profile_ref is authoritative: the claim worker builds a
# Glas ExecutionRequest and invokes its resolver/gateway. Install the sibling
# runtime packages in the claim-loop venv:
pip install -e ../sand-boxer -e ../glas-harness

# Legacy: issue-core tickets (external / Forgejo projection only — not FI/Binky ops)
export ISSUE_CORE_URL=http://127.0.0.1:8765 ISSUE_CORE_API_KEY=…
rein-aharness poll --source=issue-core
rein-aharness run --from-issue-core

# Deterministic mailbox scan (no LLM session)
rein-aharness mail-scan --target-repo ~/binky-control

# Mail triage via llm-connect HTTP (OpenRouter behind the service; no Claude CLI)
export LLM_CONNECT_URL=http://llm-connect.activity-core.svc.cluster.local:8080
rein-aharness mail-triage --target-repo ~/binky-control

# Daily and weekly briefs via llm-connect (structured JSON → deterministic markdown)
rein-aharness brief-daily --target-repo ~/binky-control
rein-aharness brief-weekly --target-repo ~/binky-control

# Railiance packaging smoke (commit + optional push + hub; no Claude required)
rein-aharness smoke --work-dir ~/work/executor-sandbox

Railiance deploy: deploy/README.md.

Each run resolves the agent's tool profile + budget from the target repo's instance manifest (default green-commit-only), loads a persona bundle (kaizen-agentic schedule prepare), runs a bounded agentic session (cwd-pinned, hard allow-list, never pushes), verifies a local commit, writes .kaizen/metrics, and posts a State Hub progress event. When invoked through glas-harness, the explicit versioned Glas profile may override model, tool profile, and budget for that bounded run. Workforce and activity consumers should reference the Glas profile rather than encode these rein CLI details in an assignment.

Instance manifest contract: docs/instance-manifest.md. Example: examples/schedule.harness.yml.

Tests: PYTHONPATH=".:$HOME/llm-connect" python3 -m pytest tests/ -q