Skip to content

v1.7.0 runtime: package the Linux container and doctor --container #1086

Description

@jeffhuber

Part of #1096.

Goal

Package a reproducible, non-root Linux container and local Compose pilot for the single-tenant Operator.

Dependencies

Requires the Operator contract epic child that freezes authority and persistence interfaces.

Scope

  • Supported Dockerfile and Compose configuration.
  • Pinned Code Mower package/runtime and explicit provider dependency injection.
  • Non-root execution, health/readiness probes, durable-volume ownership, graceful shutdown, and upgrade/rollback commands.
  • Linux runner/audit parity; configurable runner labels replace remaining implicit macOS assumptions without breaking existing generated Mac workflows.
  • doctor --container for storage, clock, networking, GitHub identity, provider availability, write posture, and privacy-safe diagnostics.
  • Secrets supplied at runtime; no credentials or personal OAuth state baked into the image.

Acceptance criteria

  • Build, start, health, restart, upgrade, rollback, and destroy rehearsals pass from a clean Linux host.
  • Existing generated macOS workflows continue to work unchanged.
  • Missing provider tools degrade by selected profile and do not create unrelated warnings.
  • Container images and logs contain no credentials or local personal paths.
  • Documentation distinguishes demonstrator, shadow, and active supervised postures.

Code Mower delivery

One independently reviewable PR with tests and canonical install/operations documentation. Do not include the active mutation loop.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestparallel-okCan be implemented in parallel once shared contracts are stabletier:RCode Mower generated labelv1.7Code Mower v1.7 single-tenant Operator

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions