Skip to content

Ref writers, client side: keys, namespaces and writers from caos-cli - #304

Open
nishu-builder wants to merge 1 commit into
claude/upbeat-cori-xk77fg-2-serverfrom
claude/upbeat-cori-xk77fg-3-cli
Open

nishu-builder wants to merge 1 commit into
claude/upbeat-cori-xk77fg-2-serverfrom
claude/upbeat-cori-xk77fg-3-cli

Conversation

@nishu-builder

@nishu-builder nishu-builder commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The client half of design/ref-writers.md: caos-cli can hold a ref writer key and use it. Part 3 of 4, stacked on #303.

  • caos-cli ref-writer-key new|show makes a key. It lives in the checkout's git config as caos.ref-writer-key.
  • caos-cli namespace new [<label>], writers list|add|remove <namespace> [<key> [<label>]] and ref-push <rev> <ref>.
  • With a key set, caos-cli signs every push it makes, and signs each request with X-Caos-Write (caos::set_request_signer), so the jobs it starts can be granted its namespaces.
  • dev/cli-test/worker gives each client test a fresh key. The new tests/ref-writers covers the hook end to end: content-named refs, founding a namespace, adding and removing a writer, and which jobs a run token lets write.

Conversations don't use any of this yet; #305 moves them in.

Verified here

  • cargo fmt --check, clippy -D warnings and cargo test pass, except launcher::checkout_import_completes_partial_history_and_keeps_local_edits, which fails the same way on main in this container.
  • Both lint scripts and nix build pass.
  • I ran tests/ref-writers' client steps by hand against the built server and caos-cli: founding a namespace, the refusals, and writers add/remove.

Not verified here

  • The caos-test suite, including tests/ref-writers' job steps: caosd up can't fetch flake inputs from inside its containers in this sandbox.

Stack

  1. Propose ref writers: who may push a ref, and how jobs inherit it #298: design doc
  2. Ref writers, server side: the pre-receive hook, run tokens, admission #303: server
  3. this PR: caos-cli
  4. Ref writers for conversations: namespaces, delegation, and closing the rest #305: conversations

🤖 Generated with Claude Code

https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc

caos-cli gains a ref writer key (`caos.ref-writer-key`) and the commands
that use it (design/ref-writers.md):

- ref-writer-key new|show
- namespace new [<label>]
- writers list|add|remove <namespace> [<key> [<label>]]
- ref-push <rev> <ref>

With a key set, caos-cli signs its pushes to the caos remote and its compute
requests (`X-Caos-Write`, through a signer the caos library takes), so the
jobs it starts may write what they ask for. Client tests sign as a writer of
their own, and tests/ref-writers checks the hook, signatures and run tokens
end to end.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc
@nishu-builder
nishu-builder force-pushed the claude/upbeat-cori-xk77fg-3-cli branch from 379142e to 7a60eef Compare October 5, 2026 19:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants