rein-aharness/docs/instance-manifest.md
tegwick f6930ad115 Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.

Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).

Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.

deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00

105 lines
3.5 KiB
Markdown

# Instance manifest
> Contract for declarative agent instances in consuming repos.
> Companion to ADR-001, ADR-005 (kaizen-agentic), and HARNESS-WP-0001-T01.
## Location
```
<project-root>/.kaizen/schedule.yml
```
**Same file as ADR-005.** kaizen-agentic owns the base schedule keys;
rein-aharness owns the extension keys below. A sibling file is reserved
only if kaizen owners later prefer hard separation — until then, one
manifest keeps cadence and runtime policy colocated.
Validate:
```bash
kaizen-agentic schedule validate --target <repo> # base ADR-005 keys
rein-aharness validate --target <repo> # base + harness extensions
rein-aharness validate --target <repo> --strict # require harness fields on enabled agents
```
## Schema
| Key | Owner | Required | Type | Notes |
|-----|-------|----------|------|-------|
| `version` | kaizen | yes | string | Must be `"1"` |
| `timezone` | kaizen | no | string | IANA tz |
| `harness` | harness | no\* | int | Pinned harness **major** for the repo |
| `agents` | both | yes | mapping | `name → settings` |
| `agents.<name>.cadence` | kaizen | yes | enum | `daily` \| `weekly` \| `monthly` |
| `agents.<name>.cron` | kaizen | no | string | 5-field cron override |
| `agents.<name>.enabled` | kaizen | no | bool | Default `true` |
| `agents.<name>.blueprint` | harness | no | string | Defaults to agent name (kaizen blueprint) |
| `agents.<name>.lane` | harness | no\* | enum | `green` \| `blue` |
| `agents.<name>.tool_profile` | harness | no\* | string | Named profile in the harness registry |
| `agents.<name>.budget` | harness | no | int | Token cap per run (positive) |
| `agents.<name>.harness` | harness | no | int | Per-agent major pin; overrides top-level |
\* Required for enabled agents under `rein-aharness validate --strict`.
## Example (tenant-ready)
```yaml
# .kaizen/schedule.yml — ADR-005 + rein-aharness extensions
version: "1"
timezone: Europe/Berlin
harness: 0
agents:
coach:
cadence: daily
cron: "0 7 * * 1-5"
enabled: true
lane: green
tool_profile: green-commit-only
budget: 80000
mail-triage:
cadence: weekly
cron: "0 8 * * 1"
enabled: true
blueprint: coach
lane: blue
tool_profile: blue-mail-triage
budget: 40000
review-prep:
cadence: weekly
cron: "0 9 * * 5"
enabled: true
lane: green
tool_profile: green-commit-only
budget: 60000
```
## Tool profiles
Defined **only** in rein-aharness (see `rein_aharness/profiles.py`).
Manifests reference them by name; unknown names refuse to run.
| Name | Lane | Session tools |
|------|------|---------------|
| `green-commit-only` | green | Read/Write/Edit/Glob/Grep + local git add/commit/status/log/diff (+ date, ls) |
| `blue-mail-triage` | blue | Same session tools; credentialed IMAP scan is a deterministic pre-step outside the session |
No push, no network, no arbitrary shell in either profile.
## Budget
`budget` is tokens per run. The runner wires llm-connect `BudgetTracker`
when set; exhaustion refuses or truncates the run and is reported to the
State Hub (token events feed the Token Cost dashboard).
## Harness pin
Instances pin a harness **major**. This runtime implements major `0`
(package `0.x`). A mismatched pin fails `validate` so upgrades are
deliberate.
## Relationship to task files
Local development may still use JSON task files (`rein-aharness run
--task-file …`). When the target repo has a matching agent entry, the
runner resolves `tool_profile`, `budget`, and `lane` from the manifest;
otherwise it defaults to `green-commit-only` with no budget cap.