Production changes happen only through pushes to trunk: CI builds,
tests, and the deployment platform promotes. There is no hot release.
The deployment platform owns probation, rollback, and deployment history.
Image rollback never touches data. The previous revision must always be
able to read what the candidate wrote (schema, sessions, spools, archives).
The service is the only SQLite writer; the agent goes through its pod-local
API. The agent container never mounts host sockets or the service volume.
Registry credentials are absent from the body; image releases flow through
CI only.
Test tiers
Tier
Command
When
mechanical
npm run check
every mutation
unit + property
node --test "src/**/*.test.ts"
every mutation
integration
node --test "src/**/*.int.test.ts"
every mutation
coverage ratchet
npm run coverage
every push
browser e2e
npm run test:browser
web/ or service route changes
pod boot
mise run boot-test
image changes, in CI
compatibility
previous→candidate→previous
CI per revision
mutation
weekly diagnostic
scheduled
Green means you ran the relevant tier and read its output.
Before pushing to trunk, run npm run check and npm test (conduct rule;
CI repeats every binding gate independently).
Read the nearest AGENTS.md in a subtree before editing it.
The design of record is spec.html.
# AGENTS.md — will
Lifeform vocabulary (surface only; code stays technical):
| Technical | Lifeform |
|---|---|
| pod revision | body |
| Git repository (default branch `trunk`) | genome |
| deployment | growth |
| agent container | senses and muscles |
| service container | phenotype |
| hourly wake | heartbeat |
| persona files | personality |
| SQLite hot data | working memory |
| archives + media | long-term memory |
| deployment history | autobiography |
| probation rollback | healing |
| skills and ZAI tools | abilities |
## Boundaries (read before acting)
- Production changes happen **only** through pushes to `trunk`: CI builds,
tests, and the deployment platform promotes. There is no hot release.
- The deployment platform owns probation, rollback, and deployment history.
- Image rollback never touches data. The previous revision must always be
able to read what the candidate wrote (schema, sessions, spools, archives).
- The service is the only SQLite writer; the agent goes through its pod-local
API. The agent container never mounts host sockets or the service volume.
- Registry credentials are absent from the body; image releases flow through
CI only.
## Test tiers
| Tier | Command | When |
|---|---|---|
| mechanical | `npm run check` | every mutation |
| unit + property | `node --test "src/**/*.test.ts"` | every mutation |
| integration | `node --test "src/**/*.int.test.ts"` | every mutation |
| coverage ratchet | `npm run coverage` | every push |
| browser e2e | `npm run test:browser` | web/ or service route changes |
| pod boot | `mise run boot-test` | image changes, in CI |
| compatibility | previous→candidate→previous | CI per revision |
| mutation | weekly diagnostic | scheduled |
Green means you ran the relevant tier and read its output.
Before pushing to `trunk`, run `npm run check` and `npm test` (conduct rule;
CI repeats every binding gate independently).
Read the nearest `AGENTS.md` in a subtree before editing it.
The design of record is `spec.html`.