Skip to content

Add scoped provisioning for prepared coding-agent instances - #682

Merged
witbrock merged 7 commits into
mainfrom
codex/agent-instantiation-002b
Sep 17, 2026
Merged

witbrock merged 7 commits into
mainfrom
codex/agent-instantiation-002b

Conversation

@witbrock

@witbrock witbrock commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Von previously needed operator-specific manual setup for every coding worker. This adds an actor-scoped lifecycle for approved host/account/identity slots, coherent release reconciliation, canonical identity/membership creation, retained pause/resume/settings, generic sender attribution and inherited host-wide memory admission.

Current-main integration preserves task timing, token accounting, retry/supervision and federation routing. Live acceptance found and fixed the missing-concept adapter contract and systemd EnvironmentFile path escaping.

Merge is ready. One temporary, separately attributed Astra/high instance completed its canonical canary task, consumed a verified attachment, produced the correct artefact, and sent its result with intended-recipient read-back. Another organisation's provisioning request and an unrelated private attachment were denied. Repeated reconciliation and a killed provisioner recovered without duplicate identity/unit; an actual busy-host poll refused admission. Timing/message replay preserved one completion. The temporary unit was retired; no permanent consumer or public deployment was activated.

Validation:

  • 124 focused lifecycle, worker/inbox, capacity, release and timing checks pass; two optional Mac bridge checks skipped.
  • Actual systemd resource/environment read-back, inherited-lock contention, interrupted provisioning, canonical task/attachment/result and recipient evidence.
  • Ruff and diff checks; current GitHub syntax and secret checks.

Same prepared Unix account only: separate-account authentication/isolation is unverified. Partial root token usage is recorded; monetary cost remains unknown. Operator enrolment and credential preparation remain required.

Native source task: #V#task_agent_002b293c463ed8e1e52df23cb68f9612. Live acceptance task: #V#task_agent_e432b713af2eaa9a9393d113d8b5eab0; full receipt attached to the source task. Parent VS Code owner handles canonical bridge reconciliation and the separately authorised final deployment.

@witbrock

Copy link
Copy Markdown
Member Author

Quick integration review against main a607464: merge decision remains not ready. Dry merge conflicts in codex_von_worker.py include display_name versus agent_name, explicit retry instructions, and continuation-admission reporting. Retain current retry/supervision/federation behaviour while adding instance lifecycle/capacity support; do not resolve by wholesale replacement with the old worker. Verify the existing worker and Mac task adapter with the integrated release. The host-capacity mechanism intentionally holds one exclusive slot: its configured effect on existing workers/inbox progress must be explicit. Merge this core integration before dependent PR684; source merge does not establish installed controller compatibility.

@witbrock
witbrock merged commit a629da5 into main Sep 17, 2026
2 checks passed
@witbrock
witbrock deleted the codex/agent-instantiation-002b branch September 17, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant