recall-worker: the process that merges, so the one facing the internet
does not have to.
It is an enrolled device with the worker scope, running beside
recall-server (in the same compose file, as a second service) with no
inbound port. It long-polls the server's merge queue, reconciles each
job's two versions with the local claude CLI, and posts the result
back. The claude login lives on the worker's own volume, so a
compromise of the API process no longer reaches it. See
docs/design/part5-plan.md, "The worker", and the "Jobs" section of
docs/reference/api.md.
No Anthropic API key appears anywhere here, as anywhere in Recall: the merge rides whatever account the CLI on this machine is logged in to.
The crate has two halves. [merge] is the merge itself, the prompt and
the flags that keep it cheap; recall-server depends on it for the
inline merge a deployment without a worker still runs. Everything else
is behind the client feature (on by default): enrolling, signing
requests, and the job loop, with the HTTP client they need. The server
turns it off.