state-hub/AGENTS.md

264 lines
9.9 KiB
Markdown
Raw Permalink Normal View History

2026-05-18 16:55:53 +02:00
# State Hub — Agent Instructions
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
## Repo Identity
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
**Purpose:** Standalone State Hub service repository extracted from the-custodian/state-hub. Owns the FastAPI API, MCP server, dashboard, migrations, consistency tooling, and operational docs.
2026-05-17 18:54:57 +02:00
**Domain:** infotech
2026-05-18 16:55:53 +02:00
**Repo slug:** state-hub
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
**Workplan prefix:** `STATE-WP-`
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
---
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
## State Hub Integration
2026-05-17 18:54:57 +02:00
2026-08-09 16:19:53 +02:00
The Custodian State Hub tracks work across all domains. Codex uses HTTP REST and
the `statehub` CLI by default. MCP is opt-in because the current Codex MCP bridge
adds severe call latency; the full administrative MCP surface remains available
to clients that need it.
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
| Context | URL |
|---------|-----|
| Local workstation | `http://127.0.0.1:8000` |
| Remote (railiance01, in-cluster) | `http://10.43.68.154:8000` |
| Optional local edge relay | http://127.0.0.1:18080 |
When an operator has enabled the edge relay, set API_BASE to the relay URL.
Queueable writes return an explicit queued receipt if the central hub is
unreachable. Treat that as pending local evidence, then ask the operator to run
statehub outbox status/replay after connectivity returns.
2026-05-17 18:54:57 +02:00
2026-08-09 16:19:53 +02:00
Codex workspace-write sandboxes need network access enabled to reach the host's
loopback listener. Bootstrap this once with `make -C ~/state-hub configure-codex`
and restart Codex. The canonical REST health endpoint is `/state/health`, not
`/health`. If a sandboxed loopback probe fails, retry it with escalated execution
before declaring State Hub unavailable; a managed Codex permission profile may
still enforce isolated networking. Experimental MCP can be enabled explicitly
with `make -C ~/state-hub configure-codex WITH_MCP=1`.
2026-05-18 16:55:53 +02:00
### Orient at session start
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
```bash
# Offline brief — works without hub connection
cat .custodian-brief.md
# Active workplans for this domain
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
2026-05-18 16:55:53 +02:00
| python3 -m json.tool
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=state-hub&unread_only=true" \
| python3 -m json.tool
# Optional: DoX quality debt (ready without DoR-Ok, finished without DoD-Ok, …)
statehub quality-debt --repo-path .
2026-05-18 16:55:53 +02:00
```
2026-05-17 18:54:57 +02:00
### Definition quality (DoC / DoR / DoD)
Lifecycle `status` is independent of quality badges. Prefer:
- **DoC-Ok** on intakes before confident promote (`quality_doc` or note)
- **DoR-Ok** on workplans/tasks before heavy implementation (`quality_dor`)
- **DoD-Ok** when claiming quality-complete finish (`quality_dod`)
Recording form and examples: `docs/work-record-quality-gates.md`.
Policies: `policies/intake-doc.md`, `work-item-dor.md`, `workstream-dod.md`.
2026-05-18 16:55:53 +02:00
Mark a message read:
```bash
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
-H "Content-Type: application/json" -d '{}'
```
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
### Log progress (required at session close)
2026-05-17 18:54:57 +02:00
```bash
2026-05-18 16:55:53 +02:00
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{
"summary": "what was done",
"event_type": "note",
"author": "codex",
"workplan_id": "<uuid>",
2026-05-18 16:55:53 +02:00
"task_id": "<uuid>"
}'
2026-05-17 18:54:57 +02:00
```
Omit `workplan_id` / `task_id` when not applicable.
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
### Update task status
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel
2026-05-18 16:55:53 +02:00
```
2026-05-17 18:54:57 +02:00
2026-05-18 16:55:53 +02:00
### Flag a task for human review
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"needs_human": true, "intervention_note": "reason"}'
2026-05-17 18:54:57 +02:00
```
2026-05-18 16:55:53 +02:00
---
## Session Protocol
**Start:**
1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe)
2026-05-18 16:55:53 +02:00
2. Check inbox: `GET /messages/?to_agent=state-hub&unread_only=true`; mark read
3. Scan workplans: `ls workplans/` — note `status: ready`, `active`, or `blocked` files and open tasks
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
2026-05-18 16:55:53 +02:00
**During work:**
- Update task statuses in workplan files as tasks progress
- Record significant decisions via `POST /decisions/`
**Close:**
1. Update workplan file task statuses to reflect progress
2. If finishing a workplan: hand off **residuals** as live work records first
(intake with `origin: residual` + `origin_ref: <WP-id>`, or a next workplan /
decision / engagement). Do not park leftovers only in prose or `SCOPE.md`.
Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals.
3. Log: `POST /progress/` with a summary of what changed (name handoff ids)
4. After workplan file changes, run the fast authoritative projection path:
2026-05-18 16:55:53 +02:00
```bash
uv run --project ~/repo-manager rmgr sync --path . --push
2026-05-18 16:55:53 +02:00
```
This assigns only missing deterministic identifiers, verifies the pushed
Forgejo commit, verifies `primary/railliance01`, and reconciles the repository
in one request. A queued result is pending evidence; retry after connectivity
returns. Run `statehub fix-consistency` separately when a deep audit is needed.
2026-05-18 16:55:53 +02:00
---
## Credential and access routing
**Audience:** Codex, Claude Code, Grok, and custodian agents that call **llm-connect**
for inference. Run this check **before** requesting secrets, API keys, SSH access,
login tokens, or database passwords — in any repo, not only `ops-warden`.
ops-warden **issues SSH certificates only** (`warden sign`, `cert_command`). Every
other credential need belongs to another subsystem. **Do not** message
`ops-warden` on State Hub expecting a secret value; the reply is a pointer, not a key.
### Lookup (do this first)
```bash
warden route find "<describe your need>" --json
warden route show <catalog-id> --json
```
Requires the `warden` CLI from `~/ops-warden` (`uv tool install .` or `uv run warden`).
| Agent runtime | How to orient |
| --- | --- |
| **Codex / Grok** (shell, HTTP State Hub) | `warden route` commands above; inbox `to_agent=state-hub` is for coordination, not secret vending |
| **Claude Code** (MCP when available) | `get_domain_summary("custodian")` for workplans; **still** use `warden route` for credential ownership |
| **llm-connect** (inference service) | Never put secret retrieval in prompts; route custody to OpenBao/operator paths surfaced by `warden route` |
### Quick routing table
| I need… | Owner | ops-warden executes? |
| --- | --- | --- |
| SSH cert (`adm`/`agt`/`atm`) | ops-warden | **Yes**`warden sign` |
| API key, DB password, provider token | OpenBao (`railiance-platform`) | No — route only |
| Login / OIDC / MFA | key-cape / Keycloak | No — route only |
| Authorization decision | flex-auth | No — route only |
| activity-core → issue-core emission | activity-core + issue-core | No — `warden route show activity-core-issue-sink` |
| SSH tunnel | ops-bridge (+ `cert_command` from warden) | No — route only |
### Anti-patterns (do not do these)
- `POST /messages/` to `ops-warden` asking for `ISSUE_CORE_API_KEY`, `OPENROUTER_API_KEY`, etc.
- Inventing `warden secret`, `warden login`, `warden bao`, `warden tunnel` — they do not exist
- Pasting secrets into Git, State Hub, workplans, logs, or chat
### Other capabilities (reuse-surface)
Non-credential capabilities are usually discovered through **reuse-surface** federation
(`reuse-surface` registry / `capability.*` indexes). Credential routing is inlined in
every repo's agent instructions because it is high-frequency, high-risk, and easy to
get wrong.
**Canon:** `~/ops-warden/wiki/CredentialRouting.md` · catalog `~/ops-warden/registry/routing/catalog.yaml`
<!-- REPO-AGENTS-EXTENSIONS -->
<!-- Append repo-specific agent instructions below this marker.
The state-hub template sync preserves content after this line. -->
---
2026-05-18 16:55:53 +02:00
## Workplan Convention (ADR-001)
Work items originate as files in this repo — not in the hub. The hub is a
read/cache/index layer that rebuilds from files.
**File location:** `workplans/STATE-WP-NNNN-<slug>.md`
**Archived location:** finished workplans may move to
`workplans/archived/YYMMDD-STATE-WP-NNNN-<slug>.md`. The `YYMMDD` prefix is
the completion/archive date; the frontmatter `id` does not change.
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
`workplans/ADHOC-YYYY-MM-DD.md`, workplan id
`STATE-WP-ADHOC-YYYY-MM-DD`, and task ids
`STATE-WP-ADHOC-YYYY-MM-DD-T01`, etc. Unqualified historic `ADHOC-*` ids are
grandfathered and must not be copied into new records. Use this only for
low-risk work completed directly; create a normal workplan for anything needing
analysis, design, approval, dependencies, or multiple phases.
2026-05-18 16:55:53 +02:00
**Frontmatter:**
```yaml
---
id: STATE-WP-NNNN
type: workplan
title: "..."
domain: infotech
2026-05-18 16:55:53 +02:00
repo: state-hub
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
state_hub_workstream_id: "<uuid>" # deterministic UUIDv5; managed by Repo Manager
2026-05-18 16:55:53 +02:00
---
```
Use `proposed` for a new draft, `ready` after review against current repo
state, and `finished` after implementation. `stalled` and `needs_review` are
derived health labels, not frontmatter statuses.
**Task block format** (one per `##` section):
```
## Task Title
` ` `task
id: STATE-WP-NNNN-T01
status: wait | todo | progress | done | cancel
2026-05-18 16:55:53 +02:00
priority: high | medium | low
state_hub_task_id: "<uuid>" # deterministic UUIDv5; managed by Repo Manager
2026-05-18 16:55:53 +02:00
` ` `
Task description text.
```
2026-05-17 18:54:57 +02:00
Status progression: `todo``progress``done`; use `wait` for waiting/blocked work and `cancel` for stopped work.
2026-05-17 18:54:57 +02:00
**Residuals when finishing:** actionable leftovers become live work records
before `status: finished` — usually an intake (`origin: residual`,
`origin_ref: STATE-WP-NNNN`) or a spawned workplan. Residual is a *role*,
not a kind. Fleet list lives on State Hub, not in `SCOPE.md`.
2026-05-18 16:55:53 +02:00
To create a new workplan:
1. Write the file following the format above
2. Run `uv run --project ~/repo-manager rmgr sync --path . --push`.
3. Use `statehub fix-consistency` only for a separate deep consistency audit.