Skip to content

feat(cli): show the runtime tier and egress posture per session - #1153

Merged
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-egress-posture-wirefrom
compass-service-owner/rig-3512-cli-posture-column
Sep 13, 2026
Merged

feat(cli): show the runtime tier and egress posture per session#1153
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-egress-posture-wirefrom
compass-service-owner/rig-3512-cli-posture-column

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 10 PRs:

  1. main
  2. feat(runtime): add the host-process WorkloadRuntime backend (RIG-3512) #1120
  3. feat(runner): derive the agent uid from the Runner's euid on the host backend (RIG-3512) #1125
  4. feat(runner): deliver the agent socket and config by path on the host backend (RIG-3512) #1135
  5. feat(runtime): distinguish a configured egress policy from an unset one #1142
  6. feat(runtime): refuse an egress policy the host tier cannot enforce #1143
  7. feat(runner): carry no egress policy on a backend that cannot enforce one #1145
  8. feat(runner): report the runtime tier and egress posture per session #1148
  9. "feat(cli): show the runtime tier and egress posture per session" (this PR)
  10. feat(ui): mark each agent's runtime tier and egress posture #1154
  11. feat(runner): declare the runtime tier and egress posture at enrollment #1156

The agent status listing printed session and state only, so an operator could
not tell which isolation boundary an agent got — or that a host-tier session has
none. Two columns added.

The tier renders as the token --backend accepts, so a tier a reader sees is one
they can select; an unknown tier or posture renders as unspecified rather than a
plausible default, because reading an unknown posture as armed would show an
uncontained session as contained.

@linear-code

linear-code Bot commented Sep 12, 2026

Copy link
Copy Markdown

RIG-3512

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-service-owner-rig-35-9f87.compass-eng-docs.pages.dev

Deployed from compass-service-owner/rig-3512-cli-posture-column at 8b5ee31.

The agent status listing printed session and state only, so an operator could
not tell which isolation boundary an agent got — or that a host-tier session has
none. Two columns added.

The tier renders as the token --backend accepts, so a tier a reader sees is one
they can select; an unknown tier or posture renders as unspecified rather than a
plausible default, because reading an unknown posture as armed would show an
uncontained session as contained.
@rigel-mintaka
rigel-mintaka force-pushed the compass-service-owner/rig-3512-cli-posture-column branch from 4381e0c to 8b5ee31 Compare September 12, 2026 19:37
@trunk-io
trunk-io Bot merged commit bb80c05 into main Sep 13, 2026
30 of 40 checks passed
@trunk-io
trunk-io Bot deleted the compass-service-owner/rig-3512-cli-posture-column branch September 13, 2026 00:29
@trunk-io

trunk-io Bot commented Sep 13, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1156.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants