Skip to content

feat(images): define and verify the devenv BYO image contract #484

Description

@mogul

Intent

Define and verify the minimum bring-your-own image contract needed for ADR-0030's devenv-enabled agent-kit architecture.

Parent: #473
ADR: #474

Scope

  • Specify required image contents: Nix single-user, devenv at the selected major, direnv/shell hook behavior, agent user assumptions, and /nix store location.
  • Specify required workspace expectations such as devenv.nix for auto-activation where applicable.
  • Add a verification path that fails clearly when a supplied ACQ_IMAGE or BASE_IMAGE does not meet the contract.
  • Preserve existing ACQ_IMAGE override behavior while making failures easier to diagnose.

Deferred Decisions

  • Exact version floors should be decided after the patterns devenv 2.x update lands and is live-verified.
  • Whether the verifier is a new command, a create-time preflight, or both can be decided during implementation.

Acceptance Criteria

  • Users bringing their own image get clear diagnostics for missing Nix/devenv/direnv, wrong /nix layout, or missing shell hook behavior.
  • The contract is documented and testable.
  • Existing supported images pass the verifier.
  • Failure messages do not expose secrets or internal host details.

Orchestration Notes

Implementation should be done by an authoring sub-agent and reviewed by an independent adversarial review sub-agent. Review findings must be addressed before the increment is accepted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions