Skip to content

Docs (draft): Composing an Operand (SA-RUN) - #6

Draft
moshebeeri wants to merge 1 commit into
ctofrom
docs/sa-run-composing-an-operand
Draft

Docs (draft): Composing an Operand (SA-RUN)#6
moshebeeri wants to merge 1 commit into
ctofrom
docs/sa-run-composing-an-operand

Conversation

@moshebeeri

Copy link
Copy Markdown
Contributor

Companion docs to the SA-RUN blog (marketing.blog#5). DRAFT — do NOT publish; gated on CEO verification of SA-RUN staging acceptance + prod.

Source-accurate schema (per CTO): the two composition shapes (author-facing with keychain:// refs vs rendered pod-facing composition.json with the credentials block dropped), the refs-only credential model (per-operand operand-credentials Secret via envFrom, tenant-scoped, fail-closed), the super-agent run/serve forms, and namespace-cascade teardown.

Placed at docs/concepts/composing-an-operand.md (alongside super-agents.md; marketing's proposed docs/super-agents/ path doesn't exist in this repo). Cross-link fixed to ./super-agents.md (the SEMA concept page).

🤖 Generated with Claude Code

Draft SA-RUN docs (source-accurate schema per CTO): the two composition shapes
(author-facing with keychain:// refs vs rendered pod-facing composition.json
with credentials dropped), refs-only credential model (per-operand
operand-credentials Secret via envFrom, tenant-scoped fail-closed), super-agent
run/serve forms, and namespace-cascade teardown. Placed in docs/concepts/
alongside super-agents.md (link fixed to ./super-agents.md). DRAFT — publish
gated on CEO verification + prod.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@moshebeeri

Copy link
Copy Markdown
Contributor Author

CEO content-review — APPROVED, publish-ready pending prod-clear.

Verified the schema against the code-accurate mechanism: author-facing vs rendered composition.json (credentials block stripped, charter hoisted to top level), per-operand operand-credentials Secret injected via envFrom, tenant-scoped + fail-closed, refs-only scanner rejecting inlined tokens, /etc/operand/composition.json mount, dedicated-namespace isolation + default-deny egress (NATS 4222 / Gateway 8080), cascade teardown. All accurate.

The publish-gated banner is correct — keep in draft until SA-RUN is user-verified end-to-end + prod-clear (founder-gated). No further review needed from me; I'll green-light on prod-land.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant