Cross-platform agentic operating layer with dotfiles, skills, guarded tooling, and repository validators.
  • Python 45.6%
  • Go 44.2%
  • Shell 7.2%
  • Dockerfile 1.1%
  • Just 0.9%
  • Other 0.9%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Coilyco Robotic Operations Division 6bbc9eedee
Some checks failed
ci / aos-cli-tests (push) Successful in 47s
mirror-to-github / test (push) Successful in 1m14s
ci / gate (push) Successful in 1m15s
mirror-to-github / mirror (push) Successful in 10s
promote / gate (push) Successful in 1m28s
promote / promote-release (push) Successful in 12s
dev-base-publish / plan-draft (push) Successful in 13s
dev-base-publish / publish-lang-rust (push) Failing after 31m1s
dev-base-publish / publish-lang-python (push) Failing after 31m4s
dev-base-publish / publish-lang-node (push) Failing after 31m5s
dev-base-publish / publish-lang-go (push) Failing after 31m6s
dev-base-publish / publish-lang-dotnet (push) Failing after 33m32s
dev-base-publish / publish-full (push) Has been skipped
dev-base-publish / plan-release (push) Has been skipped
dev-base-publish / retag-full (push) Has been skipped
dev-base-publish / release (push) Has been skipped
dev-base-publish / publish-release (push) Successful in 0s
dev-base-publish / assert-release-moved (push) Failing after 7m56s
feat(dev-base): bake the wasm-bindgen CLI so wasm-pack stops downloading it (#1420)
2026-08-29 16:38:52 +00:00
.agents Add repo-label create on the admin wrapper (#1413) 2026-08-29 13:10:57 +00:00
.forgejo/workflows Push the Forgejo policy down to deploy instead of it fetching up (#1410) 2026-08-29 12:07:15 +00:00
.github chore: drop CODEOWNERS so agents stop reading a review request as a gate (#1162) 2026-08-20 09:11:36 +00:00
.specgen Add repo-label create on the admin wrapper (#1413) 2026-08-29 13:10:57 +00:00
.ward Apply the two-line comment cap to YAML and KDL headers (#1398) 2026-08-29 11:21:42 +00:00
actions fix(dev-base): stop one transient payload failure costing the release (#987) (#1187) 2026-08-22 22:36:25 +00:00
agentic_os Apply the two-line comment cap to YAML and KDL headers (#1398) 2026-08-29 11:21:42 +00:00
alacritty fix(alacritty): start windowed so the title bar is visible (#1145) 2026-08-20 05:40:09 +00:00
aos-cli Assert a property rather than the loader against itself (#1390) 2026-08-29 08:54:49 +00:00
aos-say fix(go): use Forgejo module identities (#850) 2026-08-02 05:10:20 +00:00
aosguard-release feat: compose agent launch capabilities 2026-07-25 19:54:35 -07:00
aterm feat(aterm)!: retune the creature background to Kai's numbers (#1419) 2026-08-29 16:00:38 +00:00
docker/dev-base feat(dev-base): bake the wasm-bindgen CLI so wasm-pack stops downloading it (#1420) 2026-08-29 16:38:52 +00:00
docs feat(dev-base): bake the wasm-bindgen CLI so wasm-pack stops downloading it (#1420) 2026-08-29 16:38:52 +00:00
karabiner chore: karabiner RDP keyboard capture asset + gulp skill clarification 2026-06-13 21:51:54 -07:00
kitty feat(aterm): open agent sessions in kitty instead of Alacritty (#1266) 2026-08-26 03:46:33 +00:00
scripts Push the Forgejo policy down to deploy instead of it fetching up (#1410) 2026-08-29 12:07:15 +00:00
shell Free the docs budget by moving warp and aosguard pages into skill references (#1397) 2026-08-29 10:27:07 +00:00
static feat(warp): zsh warp theme verb plus four shipped themes (closes #152) 2026-05-22 23:13:32 -07:00
tests Stop verifying Ward in the image, which is frozen as a contract (#1409) 2026-08-29 13:28:23 +00:00
warp Close two silent gaps: the Windows loader and the gate's fifth caller (#1403) 2026-08-29 10:52:51 +00:00
.gitattributes feat(pre-commit): generate a managed .gitattributes pinning the tree to LF (#1164) 2026-08-20 10:20:58 +00:00
.gitignore feat(aterm): rebuild the branded session launcher, and retire aosterm (#1240) 2026-08-25 21:07:52 +00:00
.pre-commit-config.yaml Split documentation-layout into placement and size hooks (#1392) 2026-08-29 09:07:52 +00:00
.pre-commit-hooks.yaml Split documentation-layout into placement and size hooks (#1392) 2026-08-29 09:07:52 +00:00
.typos.toml fix(aosguard): make kubectl name its cluster, closing a boundary that never bound (#1349) 2026-08-28 18:53:49 +00:00
AGENTS.md Cut duplicated doctrine from AGENTS.md and lower the cap that was raised twice in two days (#1386) 2026-08-29 07:44:04 +00:00
CLAUDE.md Add standard repo baseline: AGENTS, CLAUDE, FEATURES, coily.yaml 2026-05-13 19:41:12 -07:00
CODE-REVIEW.md feat(aos): retain dead native workspaces for 24 hours (#884) 2026-08-04 22:38:02 +00:00
justfile Close two silent gaps: the Windows loader and the gate's fifth caller (#1403) 2026-08-29 10:52:51 +00:00
pyproject.toml Split documentation-layout into placement and size hooks (#1392) 2026-08-29 09:07:52 +00:00
README.md feat(shell): give ssm-get a callable form on PATH (#1314) 2026-08-27 04:14:38 +00:00
SSM.md feat: compose agent launch capabilities 2026-07-25 19:54:35 -07:00
uv.lock Split aos-precommit onto an affected-path release train (#818) 2026-07-31 07:50:27 +00:00

agentic-os

Sombra hacking skull

The host layer everything else here runs on: shell and terminal configuration, the aos launcher, and the cross-repo pre-commit suite.

This is a reference implementation rather than a product. It is the working setup for one fleet, grab bag and all, and it is public so the shape is readable rather than because it is meant to be adopted whole. The one piece built to travel is the hook suite below, which every repo in the fleet consumes by upstream ref.

Zsh runs on Mac and Linux, with Bash through Git for Windows. Alacritty is the default direct terminal, and the Warp configuration remains as a transitional path.

Layout

  • shell/ - shared common.sh plus thin zshrc + bashrc, so bash and zsh match. warp.zsh is the zsh-only Warp dispatcher.
  • kitty/ - portable Sombra appearance and terminal security defaults for aterm windows, with host preferences left to the local wrapper.
  • alacritty/ - the same baseline for Alacritty, retained for Windows, where kitty does not ship.
  • aterm/ - aterm, the branded launcher for one composed agent session, and the macOS .app bundle it generates per role.
  • warp/ - transitional Warp config (settings.toml, tab_configs/) plus the just warp Go module.
  • aos-cli/ - the Go composition root for standalone and Ward-governed agent launches.
  • aos-say/ - the just aos-say Go module for the speech helper client and relay.
  • karabiner/ - Karabiner-Elements complex modification assets (brew install --cask karabiner-elements), symlinked into the local Karabiner config tree.
  • scripts/ - portable utilities (gpg-ssm wrapper, session-name hooks, aws-config lint).
  • .agents/skills/ - ordinary SKILL.md sources that every composed role can discover.
  • .agents/composed/ - role-scoped COMPOSED.md sources that agent-compose promotes only for allowlisted roles.
  • .specgen/guardfiles/ - recursive specgen project for AOSguard policy and reproducible build locks.
  • agentic_os/ - the aos-precommit package, generators, shared config/data, and hygiene guardrails behind the independently released hook suite.

Full breakdown: docs/repo-layout.md.

The pre-commit suite

agentic_os/ ships aos-precommit, released independently as aos-precommit-v* and consumed by every repo in the fleet through .pre-commit-config.yaml rather than forked. It validates repository layout and documentation shape (documentation-layout, catalog-doc-size), the README, AGENTS, and FEATURES trifecta plus its cross-links (catalog-trifecta, dead-cross-links, source-doc-refs), skill and composed-skill conventions (check-skills, check-composed-skills), comment density (code-comments), and an offline secret scan.

Size caps come from a declared band. A repo picks small or large and there is no default to fall into, because an undeclared repo and a deliberately small one would otherwise be the same file. See docs/documentation-bands.md and docs/catalog-caps-reference.md.

Install

Host config is converged by Ansible (rollout lives in infrastructure, per AGENTS.md). Manual fallback:

just apply-shell-links

Equivalent links on Mac and Linux:

ln -sf "$PWD/shell/zshrc"  ~/.zshrc      # both source shell/common.sh
ln -sf "$PWD/shell/bashrc" ~/.bashrc
ln -sf "$PWD/scripts/gpg-ssm" ~/.local/bin/gpg-ssm
mkdir -p ~/.config/kitty
ln -sf "$PWD/kitty/kitty.conf" ~/.config/kitty/kitty.conf
just warp apply                     # warp config

On Windows, just apply-shell-links manages ~/.zshrc and the gpg-ssm.cmd shim only. It also links the Forgejo git credential helper; Git Bash popup shells should not recreate ~/.bashrc.

Agent self-name and composition hooks, per-host steps, and gpg wiring: docs/install.md.

aos CLI

aos is the launcher. It always composes the selected role and attaches a generated aosguard, so a launch carries context and a guarded tool surface together.

aoscompose platform                          # role's default agent
aoscompose platform goose                    # override the agent
aosward --agent codex --role platform -- owner/repo#267
aos converge                                 # host runtime inputs, --check for drift

aoscompose is the canonical explicit alias of aos, and aoscomposed survives as a compatibility spelling. aosward adds --warded. Bare acompose <role> <harness> is the native-host launcher and starts no Docker, while an aos prefix is the container boundary.

Role names never union authority across layers. Ward owns fixed workflows and container lifecycle, agent-compose produces context, and umbra and specgen generate the guarded tools. AOS applies its own bounded standalone gates on top.

Homebrew and Scoop install aos, aoscompose, aoscomposed, aosward, aosguard, and aterm. The launch and handoff contract, release binaries, and the native update path are in docs/aos-cli.md. Convergence is in docs/aos-convergence.md, standalone connectivity in docs/aos-context-bundle.md, and cluster access in docs/aos-cluster-access.md.

Secrets pattern

Fetch one parameter only when a command needs it:

ssm-get /eco/server-api-token

ssm-get prints the decrypted value to stdout without writing it to disk. The AWS profile defaults to default; pass a profile and region as the second and third arguments. The implementation is scripts/ssm-get on PATH, which the shell function of the same name delegates to, so scripts and non-interactive shells reach it too. The bulk shell-environment exporter and the legacy cleartext-on-disk dump (~/.cache/ssm-env.sh) are removed.

agent-compose

Opt-in tooling that composes global agent context and symlinks each harness load point to it. Sources are shared unless optional harnesses frontmatter selects a harness-specific slice. Agent-compose embeds the canonical personalities. AOS publishes the capability provider: ordinary skills and role-composed skills. Host composition stays inert until ~/.config/agent-compose/agent-compose.yaml exists.

Prior art. The idea is fresh in the agentic space but well-trodden in config management, and agent-compose is best understood as Hiera-for-agent-doctrine, deployed Stow-style, scoped chezmoi-style:

  • GNU Stow - symlink-farm manager. The "one canonical file, N symlinks" deployment mechanism.
  • chezmoi - dotfile manager with per-machine targeting. The model for scoping context to each host.
  • Hiera (Puppet) - hierarchical, scope-based data lookup. The conceptual twin of the machine-scope intersection that selects which sources compose.

Naming. The field's vocabulary is weave / layer / compose / overlay / blend. We chose compose over the working name meld, which collides with GNOME Meld on both search and semantics.

The native assigned-role form is:

acompose frontend codex

The shared shell places that launch in a leased native workspace, then Agent Compose supplies only the selected role, its full personality meld, and its role-composed capability slice. Claude, Codex, Goose, and OpenCode share this grammar.

Credits

  • static/wallpaper.jpg - Sombra hacking skull, from the Overwatch Sombra ARG promotional materials, Blizzard Entertainment, circa 2016. All Overwatch art and iconography © Blizzard Entertainment. Used here for personal terminal decoration only.

See also

  • AGENTS.md - public-safe agent operating conventions and the global load point.
  • docs/FEATURES.md - inventory of what ships today.
  • Repo maps - compact starting points for high-churn warded workflow areas.
  • CODE-REVIEW.md - root review contract for repo-local invariants and historical issues.
  • justfile - dev verbs, which agents route through - and .ward/ward.yaml, catalog metadata only.

Cross-reference convention from release.md.