<feed xmlns='http://www.w3.org/2005/Atom'>
<title>nixos-config/profiles/sandbox.nix, branch kusanagi-ollama-lan-firewall</title>
<subtitle>my nixos setup</subtitle>
<id>https://git.hwebs.info/nixos-config/atom?h=kusanagi-ollama-lan-firewall</id>
<link rel='self' href='https://git.hwebs.info/nixos-config/atom?h=kusanagi-ollama-lan-firewall'/>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/'/>
<updated>2026-08-04T04:26:57Z</updated>
<entry>
<title>profiles: add agent-context — one AGENTS.md for every harness</title>
<updated>2026-08-04T04:26:57Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T04:26:57Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=6f135470d274daa3e7a7fec1cb8f36204abd90f0'/>
<id>urn:sha1:6f135470d274daa3e7a7fec1cb8f36204abd90f0</id>
<content type='text'>
There is no cross-vendor standard for agent instruction files: claude-code
reads CLAUDE.md, opencode and pi read AGENTS.md, each with its own global
path. Keep one canonical file (common/AGENTS.md) in this repo, ship it to
/etc/AGENTS.md, and symlink every harness's global context path to it via
tmpfiles for all normal users:

  ~/.claude/CLAUDE.md            (claude-code 2.1.187 — no AGENTS.md support)
  ~/.config/opencode/AGENTS.md   (opencode 1.15.10)
  ~/.pi/agent/AGENTS.md          (pi 0.75.4)

Paths verified against the packaged binaries; see the profile header for
details and for the per-repo convention (AGENTS.md + CLAUDE.md symlink).
Assisted-by: claude-code:Fable 5
</content>
</entry>
<entry>
<title>profiles: extract shared sandbox profile for enzo + kusanagi</title>
<updated>2026-08-04T03:12:32Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T03:00:49Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=3df910d75fa98a7d0291e6b8c6889905c6088f64'/>
<id>urn:sha1:3df910d75fa98a7d0291e6b8c6889905c6088f64</id>
<content type='text'>
Move the yokai agent-sandbox account (user, ikai group, /srv/git drop dir,
scoped sudo de-escalation, and the local-clones workflow docs) out of
machines/enzo into a shared profiles/sandbox.nix that both machines import.

The only per-machine value is the human owner allowed to drop into the
sandbox, exposed as a `sandbox.owner` string option so the profile stays
username-agnostic (enzo: hwebs, kusanagi: henz). kusanagi gains the sandbox
it didn't have before; enzo's inline block collapses to one setting.

Assisted-by: claude-code:claude-opus-4-8
</content>
</entry>
</feed>
