2026-08-09 16:36:09 +02:00
# repo-manager — Agent Instructions
## Repo Identity
**Purpose:** Repository representation, file-backed record indexing,
reconciliation, governed repository control, and coach/lead/director agent
roles for HelixForge.
**Domain:** infotech
**Repo slug:** repo-manager
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
**Workplan prefix:** `RMGR-WP-`
---
## State Hub Integration
The Custodian State Hub tracks work across all domains. Codex uses HTTP REST and
the `statehub` CLI by default. MCP is opt-in because the current Codex MCP bridge
adds severe call latency; the full administrative MCP surface remains available
to clients that need it.
2026-08-28 20:48:21 +02:00
<!-- BEGIN STATE - HUB - ACCESS -->
2026-08-09 16:36:09 +02:00
| Context | URL |
|---------|-----|
| Local workstation | `http://127.0.0.1:8000` |
2026-08-25 00:21:56 +02:00
| Remote (railiance01, in-cluster) | `http://10.43.68.154:8000` |
2026-08-28 20:48:21 +02:00
| Optional local edge relay | `http://127.0.0.1:18080` |
Do not instruct a remote agent to use `http://127.0.0.1:18000` . That reverse tunnel is retired; on railiance01 reach the hub at the in-cluster address above.
<!-- END STATE - HUB - ACCESS -->
2026-08-09 16:36:09 +02:00
When an operator has enabled the edge relay, set API_BASE to the relay URL.
Queueable writes return an explicit queued receipt if the central hub is
unreachable. Treat that as pending local evidence, then ask the operator to run
statehub outbox status/replay after connectivity returns.
Codex workspace-write sandboxes need network access enabled to reach the host's
loopback listener. Bootstrap this once with `make -C ~/state-hub configure-codex`
and restart Codex. The canonical REST health endpoint is `/state/health` , not
`/health` . If a sandboxed loopback probe fails, retry it with escalated execution
before declaring State Hub unavailable; a managed Codex permission profile may
still enforce isolated networking. Experimental MCP can be enabled explicitly
with `make -C ~/state-hub configure-codex WITH_MCP=1` .
### Orient at session start
```bash
# Offline brief — works without hub connection
cat .custodian-brief.md
# Active workplans for this domain
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a& status=active" \
| python3 -m json.tool
# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=repo-manager& unread_only=true" \
| python3 -m json.tool
```
Mark a message read:
```bash
curl -s -X PATCH "http://127.0.0.1:8000/messages/< id > /read" \
-H "Content-Type: application/json" -d '{}'
```
### Log progress (required at session close)
```bash
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{
"summary": "what was done",
"event_type": "note",
"author": "codex",
"workplan_id": "< uuid > ",
"task_id": "< uuid > "
}'
```
Omit `workplan_id` / `task_id` when not applicable.
### Update task status
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/< task_id > " \
-H "Content-Type: application/json" \
-d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel
```
### Flag a task for human review
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/< task_id > " \
-H "Content-Type: application/json" \
-d '{"needs_human": true, "intervention_note": "reason"}'
```
---
## Session Protocol
**Start:**
1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe)
2. Check inbox: `GET /messages/?to_agent=repo-manager&unread_only=true` ; mark read
3. Scan workplans: `ls workplans/` — note `status: ready` , `active` , or `blocked` files and open tasks
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
**During work:**
- Update task statuses in workplan files as tasks progress
- Record significant decisions via `POST /decisions/`
**Close:**
1. Update workplan file task statuses to reflect progress
2. If finishing a workplan: hand off **residuals** as live work records first
(intake with `origin: residual` + `origin_ref: <WP-id>` , or a next workplan /
decision / engagement). Do not park leftovers only in prose or `SCOPE.md` .
Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals.
3. Log: `POST /progress/` with a summary of what changed (name handoff ids)
4. After workplan file changes, run:
```bash
2026-08-30 22:38:54 +02:00
rmgr sync --path . --push
2026-08-09 16:36:09 +02:00
```
2026-08-30 22:38:54 +02:00
The command assigns only missing deterministic identifiers, verifies the
2026-08-31 14:10:44 +02:00
pushed Forgejo commit and `primary/railiance01` , then requests one central
2026-08-30 22:38:54 +02:00
forge-derived reconciliation. A queued receipt is pending evidence; rerun
after connectivity returns. Use `statehub fix-consistency` separately for a
deep audit. `registrar-reconcile` is legacy migration/repair only.
2026-08-09 16:36:09 +02:00
---
Before requesting credentials or access, use `warden route find "<need>" --json` .
Repo Manager never stores secret values in repository records, State Hub,
workplans, logs, or chat.
<!-- REPO - AGENTS - EXTENSIONS -->
<!-- Append repo - specific agent instructions below this marker.
The state-hub template sync preserves content after this line. -->
Read `INTENT.md` , `SCOPE.md` , and `history/2026-08-09-genesis.md` before
changing architectural boundaries. Repository files remain authoritative;
database state is a replaceable projection. Observation and governed control
belong to this component, while cross-entity messaging belongs to hub-core.
---
## Workplan Convention (ADR-001)
Work items originate as files in this repo — not in the hub. The hub is a
read/cache/index layer that rebuilds from files.
**File location:** `workplans/RMGR-WP-NNNN-<slug>.md`
**Archived location:** finished workplans may move to
`workplans/archived/YYMMDD-RMGR-WP-NNNN-<slug>.md` . The `YYMMDD` prefix is
the completion/archive date; the frontmatter `id` does not change.
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
`workplans/ADHOC-YYYY-MM-DD.md` with task ids `ADHOC-YYYY-MM-DD-T01` , etc. Use
this only for low-risk work completed directly; create a normal workplan for
anything needing analysis, design, approval, dependencies, or multiple phases.
**Frontmatter:**
```yaml
---
id: RMGR-WP-NNNN
type: workplan
title: "..."
domain: infotech
repo: repo-manager
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
2026-08-30 22:38:54 +02:00
state_hub_workstream_id: "< uuid > " # deterministic UUIDv5; managed by Repo Manager
2026-08-09 16:36:09 +02:00
---
```
Use `proposed` for a new draft, `ready` after review against current repo
state, and `finished` after implementation. `stalled` and `needs_review` are
derived health labels, not frontmatter statuses.
**Terminology:** workplan is the fleet term; `workstream` appears only in legacy
API/MCP/frontmatter bridges until `STATE-WP-0069` retires them — see
`the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md` .
**Task block format** (one per `##` section):
```
## Task Title
` ` `task
id: RMGR-WP-NNNN-T01
status: wait | todo | progress | done | cancel
priority: high | medium | low
2026-08-30 22:38:54 +02:00
state_hub_task_id: "< uuid > " # deterministic UUIDv5; managed by Repo Manager
2026-08-09 16:36:09 +02:00
` ` `
Task description text.
```
Status progression: `todo` → `progress` → `done` ; use `wait` for waiting/blocked work and `cancel` for stopped work.
**Residuals when finishing:** actionable leftovers become live work records
before `status: finished` — usually an intake (`origin: residual` ,
`origin_ref: RMGR-WP-NNNN` ) or a spawned workplan. Residual is a *role* ,
not a kind. Fleet list lives on State Hub, not in `SCOPE.md` .
To create a new workplan:
1. Write the file following the format above
2026-08-30 22:38:54 +02:00
2. Run `rmgr sync --path . --push` .
3. Run `statehub fix-consistency` only when a separate deep audit is needed.