Skip to content

docs: define local workbench-agent boundary - #5

Draft
frahlg wants to merge 1 commit into
mainfrom
docs/workbench-direction
Draft

docs: define local workbench-agent boundary#5
frahlg wants to merge 1 commit into
mainfrom
docs/workbench-direction

Conversation

@frahlg

@frahlg frahlg commented Jul 19, 2026

Copy link
Copy Markdown
Member

Summary

Docs-only direction checkpoint for Hugin Agent. The agent may later be Hugin's local hardware execution plane, but Device Support remains the canonical driver/package authority and FTW/Blixt remain the production runtimes.

Recorded TODOs

  • Read-only probing and draft execution by default, enforced per host call.
  • Explicit instruction/time/memory/network/response budgets and device allowlists.
  • Structured evidence bound to exact source/package hash, target profile and hardware identity.
  • Separate FTW GopherLua and Blixt LuaJIT test lanes; no inferred compatibility.
  • Signed Device Support package verification for workbench reference only, never production install/activation.
  • Reconciled local/NATS pairing, credential persistence, rotation, revocation and offline semantics.
  • Any future control test requires physical confirmation, a short lease, default-mode recovery and structured outcomes.
  • SDM630 telemetry-only first; Zap later.

Non-goals

No endpoint, sandbox, protocol, pairing, NATS, update or runtime behavior changes in this PR.

Draft for security/runtime review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant