kcode-k1-daemon-cli 0.1.22

Local process-command owner for the thin Kennedy K1 runner
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
# K1 daemon CLI

`kcode-k1-daemon-cli` is the local process-command owner for the thin K1 runner. Its sole public API is `run(PathBuf) -> ExitCode`.

With no process arguments, `run` delegates directly to `kcode_k1_daemon_lib::run`, retaining the daemon's single Vault prompt. The only administrative forms are `set-secrets <name>`, `remove-secrets <name>`, and `list-secrets`. Invalid shapes and non-UTF-8 commands or names fail before prompting or opening state.

Administrative commands are offline and local. Stop the normal daemon first because K1 has one trusted exclusive state owner. Each command prompts once for `Unlock K1 vault: `. Set additionally prompts, without echo, for `Value for <name>: ` and `Confirm secret value: `. Empty or mismatched values are rejected. Passphrases and values are never accepted in arguments or environment variables and are never printed, logged, or sent to a subprocess or API.

Administrative state opens in order beneath `<root>/state`: transaction ordering, Peering, then Vault. Set performs one synchronous `K1Vault::set`; remove performs `K1Vault::remove` and distinguishes an absent name; list returns sorted names and never values. All failures use one fixed secret-free command error. An empty Vault has no encrypted item with which to verify a password, so its first Set establishes encrypted state; populated Vaults reject a wrong password.

This package adds no lock, PID file, process probe, socket, listener, network operation, retry, migration, recovery, rotation, hot update, online administration, aliases, flags, or password input through arguments or environment variables.

## Version 0.1.22

No-argument startup selects Daemon Lib 0.14.2. It preserves the ordinary-text K1 Web Chat startup prefix, empty Chat provider instructions, and the current `call_ktool` plus `message_user` native-action surface. It additionally gates invite-stock reconciliation, listener binding, and readiness on the approved resumable Loom first-run bootstrap. Completed bootstrap state remains a no-prompt, no-ZIP-read path.

Publication and package selection remain separate from David-local cargo update, rebuild, restart, blank-state bootstrap acceptance, browser login, `RustCodeBuild`, executable launch, and deployment.