Skip to content

build: bake ruflo-console (mods) behind toolchains.ruflo_console - #16

Merged
jjohare merged 3 commits into
mainfrom
ruflo/console-plugin
Oct 3, 2026
Merged

jjohare merged 3 commits into
mainfrom
ruflo/console-plugin

Conversation

@jjohare

@jjohare jjohare commented Oct 3, 2026

Copy link
Copy Markdown

What

Bakes ruflo's three Claude Code function-hook mods, ruflo-console (the /ruflo cockpit), ruflo-mods (/ruflo mods) and ruflo-swarm (/ruflo swarm …), from the ruflo v3.51.1 tag into the agentbox directory marketplace beside factrail. Gate: [toolchains].ruflo_console, default false, rebuild-class.

  • Flake input rufloConsole = github:ruvnet/ruflo/09a1cb0244a677f54c2b3d691a7009927add527d, flake = false. The flake.lock narHash was computed offline with a NAR serialiser; on the existing codexPlugin entry that serialiser reproduces the locked hash exactly.
  • Bake (scripts/bake-ruflo-console.sh): copies only plugins/ruflo-{console,mods,swarm} (1.6 MB of a ~100 MB repo) and drops node_modules. It defaults userConfig.cli to ruflo and fails the build if a plugin.json version differs from marketplace.json.
  • Boot (scripts/ruflo-console-project.mjs, entrypoint block after factrail). It uses the codex-plugin-cc pattern: the plugins are registered in installed_plugins.json at stable /opt/agentbox/config/claude-plugins/<name> paths, with no cache copy. It sets enabledPlugins and pluginConfigs.<id>.options.cli = "ruflo", and disables any @ruflo network copy of the same mod so /ruflo is not hooked twice. Registration is self-healing: a wrong path, version or cli is rewritten each boot. Fail-open. With the gate off, the three ids are removed and nothing else changes.
  • Shared with factrail: CLAUDE_CODE_ENABLE_FUNCTION_HOOKS and the agentbox marketplace now stay in place while either gate is on. Before this change, factrail-off removed the marketplace.
  • Manifest, schema and system-manifest.js catalogue entry (rebuild-class). The ruflo closure is baked when this gate is on.

Why cli = ruflo

The upstream default npx-offline expands to npx --offline -y @claude-flow/cli@latest. On a fresh npm cache, which is what the container has, it fails with ENOTCACHED. The image ships the cli as the Nix ruflo bin on PATH. Claude Code hands plugins the value from settings.json pluginConfigs, and the console's optionsOf() falls back to npx-offline when that value is unset, so the projector writes it there.

Proof against ruflo@3.51.1 on PATH, using the ruflo prefix with each probe argv from hooks/data/cli.ts, parsed with its own jsonAfter():

probe argv result
version --version ruflo v3.51.1
memory memory stats --format json JSON object
namespaces memory list --format json --limit 500 JSON array
metaharness metaharness score --format json JSON object
flywheel mcp exec -t metaharness_flywheel … JSON object
audits metaharness audit-list --format json JSON object
intelligence mcp exec -t hooks_intelligence_stats JSON object
peers mcp exec -t federation_bbs_peers JSON object
channels mcp exec -t x_federation_channel_list JSON object

roster was not run: it is network-only and off by default. The memory probes need an initialised memory DB in the project; they print "Database not found" until one exists. With the real claude 2.1.285 and a scratch config dir, claude plugin list shows all three plugins ✔ enabled after the projector runs.

Tests

tests/config/ruflo-console.test.mjs has 15 tests: 14 run in CI, plus one against the real tree with RUFLO_SRC. All pass locally against the real v3.51.1 tarball. It is wired into invariants.yml. Factrail projection, jev-config-stamp, boot-projection-contract, catalogue parity (80 paths), the config validator (gate off and on), the ADR index (--check, --check-index) and the ratchet are all green.

ADR-2121 has a dated note on the shared marketplace. 20 other records were re-verified because this change touched their governed paths (no new ADR).

Not verified

There is no nix in the container, so nix flake check was not run. The image is unverified until the host rebuild. This PR depends on RF-1 (ruflo 3.51.1 and Claude Code ≥ 2.1.287); the current main still bakes ruflo 3.47.0 and Claude Code 2.1.285.

🤖 Generated by Claude Code

claude and others added 3 commits October 3, 2026 12:55
Bakes ruflo-console, ruflo-mods and ruflo-swarm, ruflo's Claude Code
function-hook mods, from the ruflo v3.51.1 tag (flake input rufloConsole,
09a1cb0244a677f54c2b3d691a7009927add527d) into the `agentbox` directory
marketplace beside factrail. Gate: [toolchains].ruflo_console, default
false, rebuild-class.

- scripts/bake-ruflo-console.sh copies only the three plugin directories
  (1.6 MB of a ~100 MB repo), drops node_modules, defaults userConfig.cli
  to "ruflo" and fails the build if a version differs from
  marketplace.json.
- scripts/ruflo-console-project.mjs runs at boot. It registers the three
  at their stable /opt paths (the codex-plugin-cc pattern, so there is no
  stale cache copy), enables them, sets pluginConfigs cli=ruflo and
  disables shadowing @RuFlo copies. It self-heals and fails open. With the
  gate off it removes the three ids and leaves everything else
  byte-identical.
- The entrypoint keeps CLAUDE_CODE_ENABLE_FUNCTION_HOOKS and the shared
  `agentbox` marketplace while either factrail or the console is on.
- The ruflo closure is baked when the console gate is on, because cli=ruflo
  needs the bin on PATH. npx-offline fails ENOTCACHED on a fresh npm
  cache.
- flake.lock narHash computed offline (NAR serialiser validated against
  the existing codexPlugin entry); the image is unverified until the
  host rebuild.

Co-Authored-By: jjohare <github@thedreamlab.uk>
…ARKET

env-secret-inventory requires every name the entrypoint reads to carry a
class; both are NON_SECRET locals beside factrail's _JC_* ones.

Co-Authored-By: jjohare <github@thedreamlab.uk>
… re-verify 21 records (451823c)

ADR-2121 records the shared marketplace, the shared function-hook switch,
and the codex-style /opt registration beside factrail's cache install. It
gains the three new files in verified_paths. The other 20 records were
tripped by the new gate's lines in flake.nix, agentbox.toml, the schema,
the entrypoint, the catalogue, env-classes and the invariants workflow;
none changes meaning.

Co-Authored-By: jjohare <github@thedreamlab.uk>
@jjohare
jjohare force-pushed the ruflo/console-plugin branch from c330428 to 84d8a4d Compare October 3, 2026 12:56
@jjohare
jjohare merged commit d696048 into main Oct 3, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants