v0.4.0
Codex Remote Control and Easier Recovery
Version 0.4 adds experimental native Codex Remote Control support, improves recovery when Apple's container service restarts, and makes the project's first-run documentation easier to navigate.
Highlights
Experimental Codex Remote Control
- Run Codex Remote Control inside an existing agentctl container and connect an eligible ChatGPT desktop or mobile client to that persisted development environment.
- Start, inspect, pair, and explicitly disable the service with
agentctl remote-control start,status,pair, andstop. - Keep the Codex App Server private to the container: it uses its local Unix socket and makes the provider connection itself, without publishing an inbound host port.
- Require an explicit, short-lived pairing code for each newly authorized controller; agentctl neither stores nor logs the code.
- Reuse the container's existing Codex state, authentication, conversations, configuration, and enrollment so local and remote sessions share one environment.
- Preserve Remote Control intent across ordinary container stop, start, restart, run, and in-place upgrade operations.
- Synchronize refreshed Codex authentication at managed online-service boundaries and refuse to adopt or stop App Server processes that agentctl cannot verify it owns.
Remote Control is experimental because the underlying Codex CLI and headless Linux workflow are experimental. Availability depends on the ChatGPT account, workspace policy, and client rollout. It requires an existing container with Codex and Node.js installed; an image rebuild is not required.
Get started from the project directory associated with an existing Codex container:
agentctl remote-control start
agentctl remote-control pairSee Codex Remote Control for lifecycle semantics, authentication synchronization, status states, security details, and the manual acceptance test.
Container-service recovery and clearer failures
- Detect an unavailable Apple container service before container-backed commands begin, avoiding cascades of misleading create, start, or inspection errors.
- Report the direct recovery command:
container system start. - Recover managed MCP operation after the Apple container service restarts by safely recreating its reboot-volatile runtime directory.
- Preserve fail-closed ownership, permission, and symlink checks while recovering runtime state.
Improved first-time documentation
- Bring the quick-start path earlier in the README and explain persistent versus temporary containers more clearly.
- Clarify the independent roles of images, agent runtimes, and optional features.
- Recommend explicit container names when using a work directory other than the current directory, so later lifecycle commands remain predictable.
- Move detailed managed MCP and Unix-socket guidance into focused guides while keeping the README concise.
- Reorder documentation links from introductory concepts toward specialized workflows.
The automated suite now includes expanded coverage for Remote Control parsing, ownership, locking, lifecycle restoration, authentication freshness, stop ordering, stopped container-service behavior, and MCP runtime-directory recovery. Remote Control pairing still requires the documented manual macOS smoke test because it depends on an eligible real ChatGPT client and interactive authorization.
Requirements and upgrade notes
- Apple Silicon Mac
- Apple container 1.1 or newer
- Bash
- jq 1.6 or newer
- Node.js for managed MCP and Remote Control workflows
- Ollama only for local-model workflows
Existing containers do not need to be rebuilt for Remote Control. The start command installs its small status helper into the selected container automatically:
agentctl remote-control start --name <container>Remote Control is provider-backed and always operates online; it does not use the local Ollama profile. Before first use, store Codex authentication through the normal agentctl authentication flow:
agentctl auth --runtime codexIf a container command reports that the Apple container service is unavailable, start it and retry:
container system startRelease history
- v0.4.0 adds experimental native Codex Remote Control, container-service recovery, fail-fast service diagnostics, and improved first-time documentation.
- v0.3.0 added managed stdio and HTTP MCP bridging, custom networks, Unix socket integration, SSH agent forwarding, and Apple container 1.1 lifecycle capabilities.
- v0.2.2 consolidated upgrade reliability, package restoration, image metadata, and regression coverage.
- v0.2.1 removed the host-side Python dependency.
- v0.2.0 introduced Apple container 1.1 compatibility, normalized runtime defaults, and image provenance.
Full changelog: v0.3.0...v0.4.0