recall-worker: the process that merges, so the one facing the internet
does not have to.
It is an enrolled device with the worker scope, running beside
recall-server (in the same compose file, as a second service) with no
inbound port. It long-polls the server's merge queue, reconciles each
job's two versions with the local claude CLI, and posts the result
back. The claude login lives on the worker's own volume, so a
compromise of the API process no longer reaches it. See
docs/design/part5-plan.md, "The worker", and the "Jobs" section of
docs/reference/api.md.
No Anthropic API key appears anywhere here, as anywhere in Recall: the merge rides whatever account the CLI on this machine is logged in to.
The crate has two unconditional parts, so recall-server and (later)
recall's own CLI can use them without the job loop: [merge] is the
merge itself, the prompt and the flags that keep it cheap, and
[redact] finds and masks secrets in memory text
(docs/design/memory-truth.md decision 2). Everything else is behind
the client feature (on by default): enrolling, signing requests, and
the job loop, with the HTTP client they need. The server turns it off.