14 Fleet Manager
Dai Ha edited this page 2026-08-31 10:49:14 +07:00
Clone

Wiki Page Revisions

1 Commits

Author SHA1 Message Date
Dai Ha 4912b7acaf #168 §B: add chapters 14, 15 and 16
Three pages the audit asked for that did not exist.

14 Fleet Manager — fleet-manager had zero coverage in this wiki, so an
operator had no way to learn it exists. Written from its own source: the
fleets.json shape from the parser rather than the example file, what each
command does, and how the probe decides working vs stalled by comparing
worktree modification times twice. It also records the two limits that come
from fleetd rather than from the tool: two daemons sharing one herdr session
tear down each other's members, and a session inside a pane is resolved as a
worker, which is why the manager sits outside and speaks REST.

15 REST API Reference — the 14 routes were documented nowhere as a set. The
page leads with why that matters: MCP and REST are sibling adapters over one
shared MessageService, so REST behaviour cannot be inferred from the MCP
contract. fleet_ack and fleet_whoami have no route at all.

  It also records a trap found while writing it: GET /members returns its
  rows under a "workers" key (FleetApp.java:322). The route was renamed from
  /workers in CB-557 and the body key was left behind, so a caller reading
  body["members"] sees an empty fleet instead of an error.

16 Security & Trust Boundary — the guard, the role table, the member
credential scrub and token scope were spread across three pages. Collected,
with the limits stated rather than glossed: the effective allow-list is a
union and so a strict superset of what an operator writes under allow:; the
ZDOTDIR scrub is zsh-only; blocking SSH_AUTH_SOCK does not stop a member
reaching a passphrase-free key file; and argv is world-readable, which
bypasses every environment control described on the page.

Home and _Sidebar link all three.
2026-08-31 10:49:14 +07:00