recall-worker 0.4.9

Recall's merge worker: an enrolled device that drains the sync server's merge queue with the local claude CLI
Documentation

recall-worker: the process that merges, so the one facing the internet does not have to.

It is an enrolled device with the worker scope, running beside recall-server (in the same compose file, as a second service) with no inbound port. It long-polls the server's merge queue, reconciles each job's two versions with the local claude CLI, and posts the result back. The claude login lives on the worker's own volume, so a compromise of the API process no longer reaches it. See docs/design/part5-plan.md, "The worker", and the "Jobs" section of docs/reference/api.md.

No Anthropic API key appears anywhere here, as anywhere in Recall: the merge rides whatever account the CLI on this machine is logged in to.

The crate has two unconditional parts, so recall-server and (later) recall's own CLI can use them without the job loop: [merge] is the merge itself, the prompt and the flags that keep it cheap, and [redact] finds and masks secrets in memory text (docs/design/memory-truth.md decision 2). Everything else is behind the client feature (on by default): enrolling, signing requests, and the job loop, with the HTTP client they need. The server turns it off.