The console shows what a box did, never what it is — OS inventory, health, and a process view for auditing agents #234
Replies: 6 comments
Update — the diagnosis case got a chair today, and the "is half of this already built?" check came back with a real answerThree things landed on the board since this thread was written yesterday, and all three land on Q1. The outcome does not move — it is still ask, and Q1 is still the cheap one — but the question is no longer the same shape it was, and one of the answers is cheaper than either option it offered. 1. The diagnosis case now has a named chair, and it cannot work without the health tier#296 — the medic — was minted 2026-08-02 at danmt's direction as one of three governance chairs under #295 (sentinel detects, medic acts, leader rules). Its second duty is this thread's middle row, named as a duty rather than a wish:
And its confirmation loop makes that tier load-bearing rather than nice to have: "Confirmation is telemetry, not trust: the medic re-runs the diagnosis and checks the vitals moved." A chair that prescribes and then verifies by re-reading vitals is a consumer that fails without them. So Q1's two branches are no longer symmetric. The thread posed audit and diagnosis as competing framings a human picks between. Diagnosis now has an owner, a duty list and a downstream act that depends on it; audit still has the stronger argument — "'the box contains it' is a claim nobody can currently watch being true" — and no chair. That is not an answer to Q1, and it is not triage's to declare one. It does mean the two branches now differ in evidence, not only in taste. Nothing is buildable from this. #296 is 2. The view now has a home it did not have yesterday#291 ( 3. The check this thread's sibling exists for — and it came back mostly no#231 is on Discussions because half of #109 had already shipped and nobody re-read the premise. That failure is cheap to repeat, so this thread's central claim was re-verified at
Still true of the console, and re-verified:
That second one is the on-demand tier's pattern, already proven under the constraints this thread would impose on it: no What it does not give is the inventory this thread wants. What this does to Q1, and what it does notQ2 gets a concrete precedent instead of a hypothetical. "Does the on-demand tier reuse the existing Q1 gains a third option, and triage's read is that it beats both. Audit-first and diagnosis-first are both new collection work. A third first issue is smaller than either: render on the console what the host already collects — the engine manifest's divergence verdict and rig's provenance — which needs no new box-side probe, no new data class, and no answer to Q1 at all. It would not close this thread; it would make the console stop being blind to two facts Q3 is unchanged: #163 still names this thread on the @danmt — Q1 is still yours and still the cheap one. It now reads: audit, diagnosis, or neither-yet — surface the two facts the host already has and let the chairs say what else they need? Outcome unchanged: ask. Nothing is waiting on this thread, and it gates no issue. Triage, 2026-08-02. |
Two of this thread's three rows got a release window today — the third, which carries its strongest argument, has noneSince my comment of 2026-08-02 the board has been rewritten twice: a roadmap of sixteen version epics was minted this morning at @danmt's direction (discussion #338), and an operator-directed board-hygiene pass closed everything outside the current window at What that comment leaned on, re-read from the issues
So "the diagnosis case now has a named chair" and "the view has a home" are both still true as design facts and both are now scheduled rather than pending — The three-cadence table, against the roadmap — and this is the useful part
Two consequences, and neither is triage's to decide: 1. The cheap half is no longer waiting on Q1. My last comment argued for a third option — surface what the host already collects — as the smallest first issue. The roadmap went further and put inventory and health into 2. The audit row, and a distinction worth making before someone thinks it is covered#330 ( It is not this thread's audit case. #330 audits what the operator does through the floor. This thread's argument is about watching what the agent does — "a session is a model with So the row this thread called its strongest argument is the one row with no carrier anywhere on the roadmap. Outcome unchanged: ask — and Q1 is now one question rather than threeIt reads: is the audit view — a process view per box, on demand — worth its own work item, given that inventory and health now ship as That is @danmt's, it is cheaper to answer than the version this thread opened with, and it is the only part of the original Q1 still live. The three-cadence table stands; the engine-manifest and rig-provenance facts Nothing is waiting on this thread. Re-derived at this write with Triage, 2026-08-03. |
The "third option" this thread named as its cheapest first issue has had a carrier on the current gate all along — and until today it was unreadable as oneOne delta since my comment of #190 — Why it did not read that way, and this is the correctable part. #190's body asked for "the engine's provenance beside its version" — and What this does to Q1, and what it does notQ1 is untouched and still @danmt's. It reads, unchanged: is the audit view — a process view per box, on demand — worth its own work item, given that inventory and health ship as #327's ( What changes is the premise underneath the third option I offered, and it shrinks:
So "surface the two facts the host already has" is no longer one work item: one of the two is already specced on the window being worked, and the remainder is the rig half alone. That is a smaller thing than the option I put to @danmt yesterday, and it is worth knowing before answering Q1 rather than after. The three-cadence table stands — inventory at hire, health on the poll, processes on demand only — and the Actions-allotment burn (#131/ceremony#199) is still why. Neither #190 nor anything else on this gate touches it: an engine-verification verdict is a host-side fact, already collected, with no new box round trip, which is precisely why it was the cheap option. Outcome unchanged: ask. Nothing is waiting on this thread and it gates no issue — re-derived at this write with Triage, 2026-08-04. |
The row this thread called "unrendered, named" is rendered on
|
| 2026-08-04 | today | |
|---|---|---|
| engine-manifest divergence verdict, on the console | unrendered, named | rendered, shipped |
| rig provenance, on the console | unrendered, unnamed | unrendered, unnamed |
And the rig half is not the greenfield the phrasing implies. /etc/rig/manifest is already read, by rig_report in cli/crew — one box exec, namespaced rig:<k>=<v>, landed by #220 — and crew status <box> prints the marker line, converged_by and converged_at in its single-box view. What does not exist is the collection: the floor's own probe never asks for it, so the fact reaches an operator's terminal and never the console.
That relocates the remaining work precisely. It is a probe field and a tile field, on a read cli/crew already performs and already parses — not a new box-side capability, and not a design question. Costed against this thread's own constraint, it is one more line in an exec that already runs, in the inventory cadence (at hire), where the three-cadence table always put it.
3. What has not moved
The process view — row 3 — still has no carrier anywhere, and it still carries this thread's strongest argument. Three other console changes landed in the 0.1.2 window and none of them touches this: #204 (a console is drawn for deployed boxes, not declared ones), #347 (the header names the crew version serving the page), and #190 above.
The three-cadence table stands — inventory at hire, health on the poll, processes on demand only — and the Actions-allotment burn (#131 / ceremony#199) is still why. Nothing that shipped adds a box round trip: #190's verdict rides the probe that already runs.
Outcome unchanged: ask, waiting on @danmt
Q1 is unchanged in substance and cheaper again to answer: is the audit view — a process view per box, on demand — worth its own work item, given that inventory and health ship as #327's (0.1.3) telemetry and #330 (0.1.7) gives it an audited channel to ride? The third option that sat beside it is now one row, one probe field, rather than two facts and an argument.
Nothing is waiting on this thread, re-derived at this write by running the pinned 0.6.2 blocked_references over every open blocked body — three of them, parsing to {#407}, {#402, #403} and {#406} — none of which names this thread or anything it discusses.
Triage, 2026-08-07.
This thread's ask now has a taxonomy row, a store and an extraction boundary — and the half it is actually named for still has no line on any to-mint listOne delta since my comment of 2026-08-07 1. Two of the five capture rows are this threadThe reading taxonomy ruled at
The first row is this thread's OS inventory and health. The second is its process view for auditing agents — and that row did not exist in any prior statement of this problem. A box-subject reading that nevertheless carries crew's vocabulary had nowhere to sit; it is why this thread's ask kept reading as one indivisible thing. 2. The boundary is a repository split two arcs out, and it runs straight through this thread's askThe boundary annotation at
— because that half is expected to leave crew around So this thread's ask cannot be one issue, and the seam is not where I would have cut it. OS inventory and health are domain-free and leave with the probe. A process view for auditing agents cannot follow it: 3. What is now carried, and what is still nobody's lineMy 2026-08-04 comment said the remainder was "still unrendered by the console and still unnamed by any epic." Re-read from #327's body at this write rather than from the annotations that describe it:
Recording the second row is the only reason this comment exists. A classification that names your thing as an example reads, at a window-open six weeks from now, exactly like coverage — and release-init mints from the to-mint list and the close comments, not from an annotation's illustrative column. If the process view is wanted in 4. OutcomeAnswered, and this thread still mints nothing. Its first half is on #327's list and needs no issue from here. Its second half is now a known gap with a named home instead of an unnamed absence — which is the difference between a thing that gets minted at init and a thing that gets rediscovered a year later. Unchanged and not answered by any of the above: which health numbers cross a threshold worth showing an operator is #236's Q1, due at the same init, and it is a different question from where the readings live. Triage 2026-08-09 |
The carried row is built; the homed-not-carried row is still homed and still not carriedTriage 2026-09-01, re-measured at Dateless, correctly — this thread's wake is an event, and the event fired without anything reading it. Third such thread served today for that reason. Row one — carried — has landedMy comment of 2026-08-09 recorded OS inventory + health as carried by #327's to-mint line, "Box vitals probe (mem/disk/cores/load/OS) emitted per tick, readable by That is now code, not a bullet: Row two — homed, not carried — is unchanged, and that is the finding"A process view for auditing agents" was recorded as appearing in the reading taxonomy "as an example of a row, and nowhere as a deliverable." Re-measured across the whole board rather than off that note: no open or closed issue delivers it. The only issue that ever described it is #126, the closed draft this thread came from. #327's wave is spent — all thirty-one bullets minted — and none of them is this. So the state my last comment described as "homed, not carried" has survived an entire window's mint-and-land cycle without changing. A classification that names your thing as an example is not a commitment to build it, and thirteen days of a very productive window is the proof rather than the prediction. That was the whole reason the last comment existed, and it turns out to have been the right thing to write down. What that leaves, stated plainlyThe remainder is now genuinely small and genuinely unowned: a process view over the agents running in a box, for auditing. Everything around it exists — vitals per tick, tick health, session records with ids and costs, a floor that renders them. There is no open question of design here that triage cannot resolve, and there is no window that has claimed it. That makes it mintable rather than askable, and the only thing stopping a mint today is placement: Outcome: accept, deferred to
|
Uh oh!
There was an error while loading. Please reload this page.
Why this is a thread and not an issue
Its own header, quoted exactly:
Acceptance criteria are not decoration — they are the builder's definition of done and the reviewer's review spec, verbatim (TRIAGE.md). An issue that has none, and says its shape is undecided, is a discussion; TRIAGE.md's "what you never do" names the move outright: "Mint an issue to 'discuss' something — that is a discussion."
The
blockedlabel compounded it. It means waiting on another issue or PR (LABELS.md) — so on a scan this read as work that becomes claimable when its dependency lands. It never would have. #116 has this repo's own words for it: "the queue label is a dispatch signal, not a status annotation. A prose caution under areadylabel is not a caution, it is a trap."Its declared dependency was doubly stale
It declared
Blocked by #109, ruled 2026-07-28, on the reasoning that #109's "step 2 — the background collector and the projection read API — is the substrate this epic needs."Both halves of that are now wrong:
floor.pyis a background collector — one thread, an interval poll, a separate 10s ping tier, bounded per-box timeouts, a single-flight lock that coalesces click bursts. What fleet-floor's durable control plane — what the collector already does, and the two halves that are still missing #231 still owes is durability (the snapshot is in memory;floor.pywrites nothing to disk) and an action ledger — neither of which this thread's inventory/health/process view is waiting on.So the thing this was told to wait for arrived before it was filed, and nobody re-read the declaration. That is #116's other recorded lesson, on its second surface: "a
Blocked bydeclaration is a snapshot, and nothing re-validates it."What survives, because it is good
The three-cadence table is a real decision and the whole design rests on it:
…together with the reason it matters: the fleet already exhausted its Actions allotment once by polling something that rarely changes (#131/ceremony#199), and a
top-like view is the same trap in a different place. Keep that table.The outcome: ask
Three things decide the shape, and none is triage's to pick:
--dangerously-skip-permissionsand a shell … 'the box contains it' is a claim nobody can currently watch being true." If audit is the point, a process view is the deliverable and inventory is a freebie. If diagnosis is the point, health is the deliverable and processes are optional. These are different first issues.box execchannel, or wait for fleet-floor's durable control plane — what the collector already does, and the two halves that are still missing #231's durable half? The existing channel can serve an on-demand process view today, at the cost of a synchronous call on a page the collector otherwise keeps asynchronous.0.2.0road under "the console must show what a human needs."@danmt — (1) is the cheap one and yields a buildable issue on its own. Answer it and triage mints the inventory-and-health half without waiting for anything else.
Nothing is waiting on this thread.
The design record, as filed on #126 — verbatim
What the console knows, and what it does not
fleet-floor reports what the fleet did: engine version, credential health, the last duty line, whether a box is ticking. All of it derived from artifacts the duty engine wrote.
It reports nothing about what a box is — the OS underneath it, what is running right now, what an agent session is actually doing while it runs. That is a different data class: live system state rather than duty evidence, and it does not come from
duty.log.Why it is worth wanting
Audit. A session is a model with
--dangerously-skip-permissionsand a shell. The trust boundary is the box, which is exactly right — but "the box contains it" is a claim nobody can currently watch being true. A process view is how you would notice an agent doing something nobody asked for.Diagnosis. A wedged box is currently a box whose
duty.logstopped. Whether it is spinning, blocked on the network, or out of disk takes ansshto answer — and the console exists precisely so it does not.Inventory. Which OS, which kernel, how much disk. Cheap, static, and today unknown without asking each box by hand.
The problem that decides the design
Polling cost. The floor already polls every box over
box execon an interval, and that cost is a live concern — the label-sweep work (ceremony#199) exists because polling something that rarely changes is what exhausted the fleet's Actions allotment. Atop-like view is the same trap in a different place: continuous polling of fast-changing state, per box, forever.The three data classes have completely different cadences and should not share a mechanism:
Building all three on the existing poll would multiply the floor's per-tick cost by the least useful of them.
Open questions
box execper viewer.Does this need fleet-floor gets a durable SQLite control plane — snapshots, actions, locks, and projections (epic) #109 first?Ruled by danmt, 2026-07-28: yes. A control plane with durable projections is the natural home for time-series telemetry; without it this epic either keeps no history or builds a second store beside the one fleet-floor gets a durable SQLite control plane — snapshots, actions, locks, and projections (epic) #109 is for. Its road already has the seat this work sits in — step 2, "background box collector plus snapshot/projection read API; switch dashboard reads off synchronousbox execfan-out". Telemetry is a collector and a projection, which is that step's shape exactly. Building it first would mean building a worse version of fleet-floor gets a durable SQLite control plane — snapshots, actions, locks, and projections (epic) #109 and then migrating off it.box shellexists and works. This is worth building only where the console's aggregation across a fleet beats one operator opening one shell.0.0.0.0with Basic auth by default.Not decided here
The shape. What is decided: that it is an epic, separate from the accounting work; that the three data classes above must not share one polling mechanism; and that it follows #109 rather than racing it.
Dependencies
Blocked by #109. Ruled 2026-07-28. Its step 2 — the background collector and the projection read API — is the substrate this epic needs; the polling-cadence problem below is the same problem #109 exists to solve, and solving it twice is the outcome to avoid.
Strongly related to #109 (the SQLite control plane) — telemetry with any history is a consumer of that, and building this first would likely mean building a worse version of it. Adjacent to #125, which puts the first genuinely new number in front of an operator; this is the same instinct applied to a data class the fleet does not collect yet.
All reactions