a74894c6f6
test / integration-docker (pull_request) Successful in 15s
tracker-policy-pr / check-pr (pull_request) Successful in 15s
test / unit (pull_request) Failing after 36s
test / integration-firecracker (pull_request) Successful in 3m23s
test / coverage (pull_request) Has been skipped
test / publish-infra (pull_request) Has been skipped
Reevaluated against the actual nft ruleset: the firecracker split's isolation is nearly free, not "the real work." Agent VMs are already dropped except the DNAT'd gateway ports, so re-pointing that single DNAT rule at the gateway VM (dnat to $(gw_guest)) isolates agents from a separate orchestrator VM with zero new agent rules; the only added nft is a mirrored gateway link + one gateway->orchestrator forward rule. The effort is the mechanical second-VM lifecycle, and it's validatable on a Firecracker host. Sharpened the Access bullet accordingly and added a note to Sequencing decoupling the original consolidation's "real work" (the broker shim) from the split, whose difficulty actually runs the other way (docker/macOS do the real work — new control network, dual-homed gateway, the token-only->L3 upgrade; firecracker is nearly free). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Docs
How this project records what it builds and why — and a guide to picking the right document for what you're capturing.
When to write which document
| Artifact | For |
|---|---|
Glossary (docs/glossary.md) |
Canonical term definitions — what words mean in this project. |
PRD (docs/prds/) |
A feature: what to build, scope, success criteria. |
Research note (docs/research/) |
A landscape/tradeoff investigation. |
Decision record (docs/decisions/) |
A decision that isn't itself a feature — a policy, a convention, a "we will / won't do this," or a load-bearing choice made inside a larger PRD that deserves to be discoverable on its own. |
A decision that's fully specified by a PRD doesn't need duplicating in a decision record. Write one when the decision would otherwise be buried in prose, lost in an issue thread, or have no in-repo home at all (small requests that don't merit a PRD; non-feature choices like merge strategy or a trust posture).