Skip to content

Epic: v1.7.0 single-tenant always-on Code Mower Operator #1096

Description

@jeffhuber

Goal

Ship a single-tenant, continuously running Code Mower Operator that can be shared by a small team and continue supervised work while developer laptops are offline. Codex and Claude are initial qualified supervisors; Devin is an explicit full-peer target under the same evidence-based qualification contract.

Depends on completing the operational-clarity and minimum-telemetry boundary in #1066. Contract drafting may begin earlier, but active Operator mutation and release qualification must consume the released v1.6 contracts.

Dependency map

Contract first

Foundation after the contract; parallel where file ownership permits

Runtime; serial promotion from observation to mutation

Provider qualification; parallel after runtime contracts stabilize

Serial release

Product boundary

  • Single tenant and repository allowlist; not a multi-tenant hosted control plane.
  • Private Board access through an authenticated ingress; Board remains loopback/private by default.
  • GitHub App/service credentials replace shared personal PATs in the standard deployment.
  • Metadata-only telemetry; no source, diffs, prompts, transcripts, issue bodies, private messages, raw output, credentials, or personal paths.
  • Supervised operation with human merge approval by default.
  • Provider capability and authority are versioned policy backed by evidence, not permanent provider-name exclusions.

Explicit deferrals

  • OpenAI Agents API may be evaluated later as an alternate Codex transport behind the provider adapter; it is not an architectural dependency.
  • Git AI may later enrich provenance and productivity events; it is not required for reliable operation.
  • Factory and other providers wait for the provider kit and qualification harness proven here.
  • Quota-aware routing waits for reliable cross-provider usage and settlement data.

Delivery rules

  • One issue and one writer per PR.
  • Contract-first issues merge before dependent runtime work.
  • Parallel PRs must have explicit file/schema ownership and rebase before exact-head review.
  • Every behavior change includes focused tests and canonical documentation.
  • Every changed head receives an independent eligible review; resolve all P0/P1/P2 findings.
  • Active mutation, provider promotion, and release are serial decisions.
  • Live credentials, infrastructure, and mutation canaries remain owner-controlled.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    contract-firstRequires product/data/merge contract agreement before dependent work mergesepicEpic tracking issuev1.7Code Mower v1.7 single-tenant Operator

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions