Watch
2
specverb + KDL Guardfile: spec-driven verb engine with a non-executable policy DSL #75
Closed
opened 2026-06-05 02:47:30 +00:00 by coilysiren
·
4 comments
No Branch/Tag specified
main
release
aos/1105-optional-args
aos/claude/sb46-typed-mapped-leaves
aos/claude/sb46-mapped-body-limit
aos/1047-untyped-array-union
chore/regenerate-repo-pointer-skill
task/mapped-body-pins
aos/claude/bk79-comment-debt
aos/claude/bk79-raw-media-negotiation
aos/claude/bk79-raw-response
aos/claude/ck78-mark
feat/remove-sandbox
feat/auto-degrade-mode2
feat/pluggable-value-providers
chore/rename-module-path
chore/remove-dead-packages
claude/agents-temp-clone-note
feat/honor-response-media-type
aos/claude/gm46-can-describe
aos/codex/cli-guard-embedded-files
issue-244
recovery/2026-07-27-local-work
ward-salvage/cli-guard-a8e13cf8
ward-salvage/cli-guard-7f69a8f5
ward-salvage/cli-guard-9b23a268
ward-salvage/cli-guard-e8175b16
v0.185.0
draft-eea7b26348d1ec8a6829f7f731bcf7baab63bbef
v0.184.0
draft-2f51a6f54d508bff614e87887994ce5e2d49ace1
v0.183.0
draft-0530f5b4fd9d21c89b1df4997d80011bfd9eacf5
v0.182.0
draft-27eebb1de0efeca292280f337f5e3f41dadf7a2f
v0.181.0
draft-663dc8dc7c89a0d6638b3132b4d85ad070d41022
v0.180.0
draft-91cec77078764211f6a4748476a1eb370beb2768
v0.179.0
draft-5c292bc8616e70dcae6a4817ea1eda4377a3d5b3
v0.178.0
draft-8e46ec6c5676dc6a468920e160d125f13a01bec9
v0.177.0
draft-19352914e2c51bc8a5f97b5cc3d7c9d005dd3855
v0.176.0
draft-228538037f7c5caf7b8eb260906816af73cfeda2
v0.175.0
draft-5e27572f02806f17c52ffd24253b08fb44e8f408
v0.174.0
draft-39b76ec95adca5f11232e1e64a1c99ab83508af8
v0.173.0
draft-3d0c33dd6c80fdd5b7f9898805517e6fa58a4488
v0.172.0
draft-cbff67cb8a6550eca355ad0308f4658d17fd5282
v0.171.0
draft-9ed606291f8f38012324fae9896efba7800f1bd8
v0.170.0
draft-6883083b8297c342b3f6462b7740cf76814e8201
v0.169.0
draft-4b14e54dd90c8c4ffbc30c367e9e0931b16bfe71
v0.168.0
draft-72173c4084ce08da59675207d0a3073924eed225
v0.167.0
draft-99131202d035c198e86f8b49d785c3a0718ff06b
v0.166.0
draft-3f2452d6561b02cb58821143381a5398697e2eb5
v0.165.0
draft-af4fda054d686aa7b63439cad8bf8ee324aab319
v0.164.0
draft-524a809272cbb57f15e4e84f3fda4f491060f905
v0.163.0
draft-5c0974e7c6798657bc7d9b26584579fd9547de4b
v0.162.0
draft-0ba4e9d71f3371e1f8604335fc399fa689aec5d6
v0.161.0
draft-59a230c7c9ee6869b35df44794983014c60fab32
v0.160.0
draft-66a5898dc8699b210fae629cc87a48389a6dee3e
v0.159.0
draft-8b098f789b88142851ff02b9d44cf8b91690bb94
v0.158.0
draft-47eed471b0f4e84166983e9c5c1e10b409944f16
v0.157.0
draft-0e14103cf6c59bf8d8590714c0c067da38507ab0
v0.156.0
draft-599429f8aa32cef94fd95116db9b22cf7c8f0747
v0.155.0
draft-ebc6cb80edd535e26e54bdbd78687f9634959f9b
v0.154.0
draft-ac86bf1ab0121a82e64de9325e31745d2a40a04e
v0.153.0
draft-c7c4bc16511a326bb4e0c36789661244b83c574a
v0.152.0
draft-dafac75068ecbb2f4f97a977da227a4f3bbc72a1
v0.151.0
draft-916c6a73fddd15e6f1eaf9fba4f8444cf6813ea0
v0.150.0
draft-df519769467955e0e9ff848b12c73757ce4ab619
v0.149.0
draft-7b22f1df41f6ea6fb795127168009e8ad192c730
v0.148.0
draft-7849611ff749a7e77b5497f311f5f6fab9d4bfad
v0.147.0
draft-3893db50211c8d8fc3b16b647d9da1a2b06c8b2e
v0.146.0
draft-8ec7a0cac0be34c2b075ac2df9f7981b809d1744
v0.145.0
draft-d41a2095ab92763c540bdffc32ac611d37e64bd0
v0.144.0
draft-be9487c4b9a499e634b8104ed25ed97eb6aa84a0
v0.143.0
draft-99744ccc4b1c531ec556492e609947fdaf7c4d8f
v0.142.0
draft-f19f2272ad214de5cd3c0097fec2df2ab8110272
v0.141.0
draft-50c56897c8fbf2abe7ed32fb8acc4bc04d63fe1e
v0.140.0
draft-0afc06265c46b3046db7c90e154b25d1377a24e5
v0.139.0
draft-32f278b23ccb6bdc31bdadbe0c8234b4b2ba2bb0
v0.138.0
draft-2d01d26376a9b954caac6871493b15bb27e93005
v0.137.0
draft-28dda03318260279ade890b2db2f47fba3da3733
v0.136.0
draft-de6749808aff6cc9a51d7a047a788adc7d0b6f9e
v0.135.0
draft-d9426dc3aeb39ef9fedcb9ff99b50194a25e1d9a
v0.134.0
draft-f9dd5dcc16f3f1dc1054683c3f6ef725a9e18a77
v0.133.0
draft-529f234654d799a6deecf08464ced4e5d13e0e8d
v0.132.0
draft-94204c070157d3c32c797f7c5003fa74727cd286
v0.131.0
draft-8ef1a1703a8ef8f907e3bab468818f6fcdc851c0
v0.130.0
draft-794ec95725ec6a8a2ff47ce2ac5fda287fdcf200
v0.129.0
draft-c05efef093167513d1c0cfacd5904eda13653f1a
v0.128.0
draft-4329ee77e55c7bcb9fbef5338d036894b60c3f25
v0.127.0
draft-530d4f474c46c8f842654ddf9a67c0709e919250
v0.126.0
draft-e76edeb5352bf0aad4d4b95ed93602056a461a7f
v0.125.0
draft-01f45023816ab158da0ad16c967c4364463459ac
v0.124.0
v0.123.0
draft-0ea86b6d50dc66a5e4a3e29504159263f44b69b5
draft-a4bbfaa2b3a1e9932abb333cf96085b08dc893f4
v0.122.0
draft-f2e33339b65d8fdc133e214ec49c37d2c8f671ab
v0.121.0
draft-bf2bd0e5fceb55cc6f4983d883b548d65fe43c5c
v0.120.0
draft-a1fd0de01e8694a804646901465846f9c829964e
v0.119.0
draft-d6a59219d86e7432deee0ef332be0c3512451932
v0.118.0
draft-1424a8b2696390464c59c48b9d3a0c2987e941c4
v0.117.0
draft-b46e95adc5d331530a8676333c8a4c4331b941a2
v0.116.0
draft-188ac86e27d361b5dc2a7116e19333fb9259f384
v0.115.0
draft-b764efcc94a6748a3ba4c0ed6174b0ed71414cdb
v0.114.0
draft-2a571af9b416723565249d41e05cc53e87774e28
v0.113.0
draft-15810837dd6b1226643f4bb78a5879c4a2ec0dfc
v0.112.0
draft-aa876f776ffc560160959f095f9390c24984c31a
v0.111.0
draft-c41011c1888e0f1d8dbf582dbac4bfbd82f18938
v0.110.0
draft-1e3d3c0ab52723e75361fe0fff12a8f63c37155f
v0.109.0
draft-ffb44199e39f4bbfcf0d3a9e0288f37d268e87d7
v0.108.0
draft-907b707e7f09151d5ef7f1b3bc865d011291f5bc
v0.107.0
draft-7c179ec30cbf2e7311def42e1501f761c4ec69ea
v0.106.0
draft-17a362a65e439d06f0f90cd00f293943dcd2f62f
v0.105.0
draft-781edc923dfe2ba8b17d3aa2bc7e056825748983
v0.104.0
draft-143732937a354bb4c30e1aebb11c810d24006e50
v0.103.0
draft-9de614246e23e7ef711276384d66985ff864cc48
v0.102.0
draft-6f0ee0740b537405539619de75b0e61df91bced1
v0.101.0
draft-16b0b2affc80b689710f3a470137449f4d898a6b
v0.100.0
v0.99.0
v0.98.0
v0.97.0
v0.96.0
v0.95.0
v0.94.0
v0.93.0
v0.92.0
v0.91.0
v0.90.0
v0.89.0
v0.88.0
v0.87.0
v0.86.0
v0.85.0
v0.84.0
v0.83.0
v0.82.0
v0.81.0
v0.80.0
v0.79.0
v0.78.0
v0.77.0
v0.76.0
v0.75.0
v0.74.0
v0.73.0
v0.72.0
v0.71.0
v0.70.0
v0.69.0
v0.68.0
v0.67.0
v0.66.0
v0.65.0
v0.64.0
v0.63.0
v0.62.0
v0.61.0
v0.60.0
v0.59.0
v0.58.0
v0.57.0
v0.56.0
v0.55.0
v0.54.0
v0.53.0
v0.52.0
v0.51.0
v0.50.0
v0.49.0
v0.48.0
v0.47.0
v0.46.0
v0.45.0
v0.44.0
v0.43.0
v0.42.0
v0.41.0
v0.40.0
v0.39.0
v0.38.0
v0.37.0
v0.36.0
v0.35.0
v0.34.0
v0.33.0
v0.32.0
v0.31.0
v0.30.0
v0.29.0
v0.28.0
v0.27.0
v0.26.0
v0.25.0
v0.24.0
v0.23.0
v0.22.0
v0.21.0
v0.20.0
v0.19.0
v0.18.0
v0.17.0
v0.16.0
v0.15.0
v0.14.0
v0.13.0
v0.12.0
v0.11.0
v0.10.0
v0.9.0
v0.8.0
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0
Labels
Clear labels
burndown-2026-06
Backlog burndown June 2026
burndown-2026-08
Closed in the 2026-08-26 backlog burn-down. Reopen freely: state:closed label:burndown-2026-08 recovers the whole set.
sunday-sprint
Burn-down by Sunday 2026-06-07
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
coherence-core
Core review set for the warded control plane coherence milestone. These issues form the release spine; adjacent milestone issues are stretch or supporting work.
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
qa-fixture
Disposable issue admitted to the bounded Ward QA verification lane.
role/advocate
requires work from the Developer Advocate seat
role/director
requires work from the Portfolio Director seat
role/exec
requires work from the exec role
role/frontend
requires work from the Frontend Engineer seat
role/gamedev
requires work from the Game Developer seat
role/human
requires a person, and specifically not an agent seat
role/platform
requires work from the Platform Engineer seat
role/qa
requires work from the QA role
role/science
requires work from the Applied Scientist seat
role/sysadmin
requires work from the Systems Administrator seat
state
ambient
ambient and ephemeral work, held as a maintained document rather than a queue
No labels
burndown-2026-06
burndown-2026-08
sunday-sprint
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/umbra#75
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Replace the per-verb, hand-rolled CLI wrappers in cli-guard's consumers with a spec-driven engine plus a KDL policy DSL. One generic Go engine (
specverb) builds the guardedcli.Commandtree at runtime from an embedded, pinned API spec plus a compiled overlay. The overlay is authored as a human-readable, non-executable KDL Guardfile that compiles down to a standard OpenAPI Overlay.This unifies two existing consumer issues into one piece of cli-guard infra:
Both are the same shape: a thin engine over an annotated upstream spec, behind cli-guard's policy + audit boundary. Build it once in cli-guard, consumed by ward, coily, and kap.
The layer stack
swagger.v1.json).x-coily-*extensions. The compiled, deterministic policy IR. Standard OAI Overlay (JSON/YAML), targeting the spec by JSONPath. This is the interchange format other tooling (Speakeasy, oas-patch, libopenapi) understands, and it is what the runtime consumes.KDL replaces the authoring layer only. The overlay stays as the compiled artifact so the runtime targets a stable, pinned, hash-verified input.
The runtime engine (
specverb, lives in cli-guard)The generated Go we have today is ~90% static boilerplate (
doRequestAndStream,readBody,fetchSSM) plus a tiny per-op descriptor ({method, path, pathParams, queryParams, hasBody, authNeeded, verbName}). A runtime engine builds[]opDescriptorfrom the parsed spec + overlay and binds them to one generic action. The thousands of lines of*_generated.go(and coily's Pythonopenapi-to-coily.py) collapse into one tested engine.Maximally-generic form: embed the spec + overlay via
go:embed, build thecli.Commandtree at runtime (lazy/cached), mount under cli-guard'sverb.Wrap+audit.Writer.Deny-by-default allowlist: an operation is mounted if and only if it carries an
x-coily-verbannotation. The overlay is then purely additive (allupdateactions, no fragileremovesweeps), and the set of annotated ops is the allowlist.x-coily-*vocabulary (what the engine reads)x-coily-verb- REQUIRED to mount. Value"<group> <leaf>". Its presence is the allowlist.x-coily-args- ordered positional args drawn from path params.x-coily-body-flags- promote request-body scalar fields to typed flags (required schema fields -> required flags). Omit -> single raw--body(literal /@file/-).x-coily-fmt- namedrespfmthook for curated output. Absent -> pretty JSON.x-coily-resolve- named pre-call hook for non-declarable cases (e.g. label name->id, the coily#159 behavior).x-coily-allow-redirect- defaults false on mutating methods. Set true only to opt out of the 301 refusal (the coily#178 / #160 fix, now structural).The KDL Guardfile (L2 authoring)
Chosen over a literal-Ruby internal DSL. A Ruby Guardfile would be
eval'd - arbitrary code execution at build time, which is attack surface and is backwards for a tool (ward) whose job is to keep hostile code from running. KDL is pure data: parsing, not evaluation, so there is no code to smuggle in. It also ships a schema language (author-time validation) and a CSS-selector query language, and it is in-house (Kat Marchan's language).Nodes are the modals (
can/cannot/never), arguments are verb-classes, properties carry scope and exceptions.Security invariants (non-negotiable)
Two enforcement axes (the DSL authors both)
cannot delete) -> compiles to L1 overlay (mount/deny ops). Thex-coilyaxis.secret get ssn => DENY,secret get login => APPROVE) -> compiles to cli-guard's argv policy (policy/scope/egress). Value-level rules must lower to concrete identifiers/patterns, fail-closed on anything unmatched.The verb-class -> operation-set expansion (
deletecatchingTerminateInstances,RevokeGrant, ...) is the one fuzzy step. It runs in the compiler with an LLM-assisted-or-curated, human-reviewed, committed expansion table - never at runtime.Findings from today's spec dig (Forgejo)
parameters[in:body](requestBodyis null), security is global. The engine needs a 2.0 reader or a 2.0->3.x upgrade pass (kin-openapiopenapi2conv).Authorization: token <key>, notBearer.securityDefinitions.AuthorizationHeaderTokenrequires thetokenprefix. None of the existing generator auth modes cover this - the engine needs a declarable header-token scheme.repo createis genuinely missing today and is the first proving slice:POST /user/repos,operationId: createCurrentUserRepo, bodyCreateRepoOption(required:name; scalars:private,description,auto_init,default_branch, ...). Org variant:POST /orgs/{org}/repos(createOrgRepo).First proving slice
Drive
coily ops forgejo repo createend-to-end through the chain: KDL Guardfile -> compile ->forgejo.overlay.yaml->specverbbuilds the verb -> POST against the live Forgejo API withtokenauth and body-flag assembly. Validates Swagger-2.0 read, the new auth scheme, deny-by-default mounting, and the 301 default in one shot.Open decisions
calico32/kdl-go(v1+v2, passes upstream suite) keeps the compiler all-Go, vs Kat's reference Rustkdl-rs. Build-time only either way - never ships in the binary.specverbin cli-guard, consumed by ward/coily/kap. Confirm the KDL Guardfile vocabulary also ships from cli-guard (shared), with each CLI keeping its own Guardfile(s) undercmd/.Prior art
openapi-overlay(Go), pb33f libopenapi,oas-patch(Python).openapi2convfor Swagger 2.0 -> OpenAPI 3.x.Filed by Claude during a design conversation with Kai. Companion to coily#186 and ward#51.
Regenerated plan (2026-06-06)
Re-derived from scratch, then reconciled against the L0/L1/L2 + specverb design above. The architecture in this issue holds. What follows refines the engine home, consumer ordering, proving slice, and Guardfile UX, and lays out a milestone ladder.
Topology: cli-guard => ward first
specverb(runtime engine) + aguardfilecompiler land as new packages beside the existingverb/audit/policy/scope/egress/respfmtrails, reusing them.cli-guard v0.3.0and has zero forgejo verbs today, so forgejo-in-ward is greenfield. Nothing to migrate, nothing to break. This is theward#51CLI-argv surface.ops forgejo repo createis the behavioral reference: ward's specverb-built verb must produce the same API call. coily migrates to specverb later (coily#186).Iteration-loop friction to manage
Engine in cli-guard is a versioned dep ward pins. The fast dev loop uses a
go.mod replacein ward pointing at the local cli-guard checkout for M0-M3, dropped and bumped tov0.4.0before ward ships. Watch: pre-commit may flag areplacedirective; tolerate or gate it in dev.Proving slice: repo create + delete as a self-cleaning pair
Not load-bearing for automation, so safe to rebuild from scratch. As a pair they give a self-cleaning integration test: create a throwaway repo, assert, delete it, assert gone. create exercises body-flags + token auth + 301; delete exercises deny-by-default mount + destructive-confirm UX.
Fanatical UX is the thesis, not DRY
A generic engine is how you get uniform, excellent UX across every verb at once and one-sentence-to-add-a-verb iteration. The boilerplate collapse is a side effect. Written once in specverb, inherited everywhere:
--dry-run(print resolved request, no fire), required-body-field -> required-flag with teaching errors, fail-closed denials that name the annotation that would lift them,--yesconfirms on destructive ops, therespfmt--query/--outputprojection rail, generated help + examples.Guardfile UX: flat declarative sentences
Policy body reads as plain English a vibe coder parses on sight. One fact per line, bare positional tokens, controlled vocabulary. Quotes quarantined to a write-once config header.
Design rule: the daily-edited policy body must be expressible entirely in bare KDL tokens. Modals
can/cannot/never, a verb set, a resource set. Exceptions go flat and positive (can delete labels created-by-me, notcannot delete except=label:created-by-me). Properties + child blocks stay a legal escape hatch off the happy path. An M2 lint fails the Guardfile if any token in acan/cannot/neversubtree requires quoting.This quietly collapses the NLP layer into the authoring layer: the Guardfile body is a controlled natural language, with KDL's parse-not-evaluate safety.
Milestone ladder
specverbengine +guardfilecompiler, thin enough to mount exactly one verb from a fixture spec,--dry-runworking. Unit-tested in cli-guard, no ward yet. (KDL: a subset parser unblocks the engine now; thecalico32/kdl-goswap + bare-token conformance check is the named follow-up, not a silent skip.)can create repos/can delete repos. specverb mountsward ops forgejo repo create|delete. dry-run, then live, diffed against coily's hand-written verb. create+delete = self-cleaning integration test.respfmtrail,--yes.v0.4.0, drop ward's replace, bump ward. Migrate coily's hand-written verbs to specverb (coily#186) and embed-plus-pin the spec by hash.Open decisions, resolved
Overlay apply timing - runtime-apply for the proto, embed+pin deferred to M4.
KDL parser -
calico32/kdl-go, build-time only, swapped in behindguardfile.Parse(subset parser bridges M0).Engine home - cli-guard, prototyped with ward as first consumer; coily migrates at M4.
Overlay tooling - Speakeasy
openapi-overlay(Go) is the L1 apply library. The KDL Guardfile (L2) compiles to a standard OpenAPI Overlay doc carrying thex-cli-guard-*extensions; Speakeasy applies it onto L0 to yield the annotated spec the engine mounts from. No hand-rolled overlay application.Extension prefix:
x-cli-guard-(not the issue's originalx-coily-*). The engine lives in cli-guard and is consumed by ward/coily/kap, so the vocabulary carries the engine's name, not one consumer's. Sox-cli-guard-verb(REQUIRED to mount, presence is the allowlist),x-cli-guard-args,x-cli-guard-body-flags,x-cli-guard-fmt,x-cli-guard-resolve,x-cli-guard-allow-redirect.Still open: which forgejo surface ward genuinely needs (aims M3).
Session checkpoint: M0 status + specverb design notes
Handoff so a fresh session starts at the engine, not by re-deriving. Supersedes the prior comment's "subset parser bridges M0, kdl-go is a follow-up" note.
Done this session (landed in cli-guard,
make test/make vetgreen)guardfilepackage parses the flat-sentence KDL Guardfile into a typed model (Group,Spec,BaseURL,Auth,Grants). Fail-closed on unknown nodes, missing required fields, malformed sentences, and unsupported auth schemes.calico32/kdl-go v0.14.1, not a stub.forgejo.swagger.v1.jsonand the flatcan delete labels created-by-meparse as bare identifiers. Only/and the trailing-spaceprefix "token "force quotes, and those are exactly the config-header tokens. The "policy body stays quote-free" rule is confirmed by the parser.speakeasy-api/openapi-overlay v0.10.3confirmed resolvable.guardfile/guardfile.go,guardfile/guardfile_test.go,guardfile/testdata/forgejo.kdl, plusgo.mod/go.sum.Next: the
specverbengine (design decided this session)openapi2convSwagger-2.0 -> 3.x is M1, not M0.(verb, resource) -> {cliGroup, cliLeaf, operationId}, e.g.{create, repos} -> {repo, create, createCurrentUserRepo}. Deny-by-default: no entry, no mount. This is the human-reviewed table the issue calls for.--dry-runprints the resolved request (method, URL, headers, body) without firing. Live path fires then runsrespfmt.Renderfor the--query/--outputrail.TokenResolverinjection. specverb takes afunc(ctx, ssmPath) (string, error)so the AWS SDK stays OUT of cli-guard (repo-boundary rule: no consumer-shaped deps leak in). ward wires the real SSM resolver; tests inject a fake.["ward","ops","forgejo"]) -> tree root; resource (plural) -> cli group (singular noun); verb -> cli leaf.specverb.Buildreturns the leaf group command the consumer mounts.x-cli-guard-*extensions -> Speakeasy applies onto L0 -> engine mounts ops carryingx-cli-guard-verb.Repo facts for the next session
make(make test/vet/tidy), not bare go.godoc-current.txt(regen on API change viascripts/check-godoc-current.sh --update).go.mod replaceto local cli-guard for M0-M3, dropped and taggedv0.4.0at M4.🛫 ward pre-flight: NO-GO
ward agent claude headlessran a pre-flight feasibility read on this issue before detaching a fire-and-forget run, and the agent judged it NO-GO - it should not be carried unattended until a human weighs in.No container was launched. Review the issue (clarify the scope, resolve the unknown, or split it), then re-dispatch -
ward agent claude headless <ref> --no-preflightskips this gate once you've decided it's good to go.full pre-flight read
This issue is a multi-milestone design epic (M0–M4) spanning cli-guard, ward, and coily, with explicitly-open decisions ("which forgejo surface ward genuinely needs" still open) and no single bounded done-condition — the M0 slice alone wants a Swagger-2.0 reader, a curated expansion table, Speakeasy overlay wiring, and a generic action, and the proving slice depends on live Forgejo API calls with
tokenauth (SSM secrets + network) that an ephemeral container can't exercise or verify. The guardfile package already landed per the latest checkpoint, so the home is right — but "carry to merge unattended" has no crisp target here without a human picking the exact slice. This needs scoping, not autonomous execution.NO-GO: open-ended multi-milestone epic with open design decisions and live-API/secret dependencies; no bounded, container-verifiable done-condition for one unattended run.
Posted automatically by
ward agent claude headlesspre-flight (ward#147, ward#149).— Claude (she/her), via
ward agentthis is mostly done already actually