Intent
Define and verify the minimum bring-your-own image contract needed for ADR-0030's devenv-enabled agent-kit architecture.
Parent: #473
ADR: #474
Scope
- Specify required image contents: Nix single-user, devenv at the selected major, direnv/shell hook behavior, agent user assumptions, and
/nix store location.
- Specify required workspace expectations such as
devenv.nix for auto-activation where applicable.
- Add a verification path that fails clearly when a supplied
ACQ_IMAGE or BASE_IMAGE does not meet the contract.
- Preserve existing
ACQ_IMAGE override behavior while making failures easier to diagnose.
Deferred Decisions
- Exact version floors should be decided after the patterns devenv 2.x update lands and is live-verified.
- Whether the verifier is a new command, a create-time preflight, or both can be decided during implementation.
Acceptance Criteria
- Users bringing their own image get clear diagnostics for missing Nix/devenv/direnv, wrong
/nix layout, or missing shell hook behavior.
- The contract is documented and testable.
- Existing supported images pass the verifier.
- Failure messages do not expose secrets or internal host details.
Orchestration Notes
Implementation should be done by an authoring sub-agent and reviewed by an independent adversarial review sub-agent. Review findings must be addressed before the increment is accepted.
Intent
Define and verify the minimum bring-your-own image contract needed for ADR-0030's devenv-enabled agent-kit architecture.
Parent: #473
ADR: #474
Scope
/nixstore location.devenv.nixfor auto-activation where applicable.ACQ_IMAGEorBASE_IMAGEdoes not meet the contract.ACQ_IMAGEoverride behavior while making failures easier to diagnose.Deferred Decisions
Acceptance Criteria
/nixlayout, or missing shell hook behavior.Orchestration Notes
Implementation should be done by an authoring sub-agent and reviewed by an independent adversarial review sub-agent. Review findings must be addressed before the increment is accepted.