yah-cloud 0.8.43

Declarative cloud substrate for yah-managed camps: .yah/cloud/ config schema, MachineProvider drivers (Hetzner + local containerd), cloud-init rendering, and the pond/mesofact reconcilers.
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//! @arch:see(architecture/yah-managed-camps-topology.md)
//!
//! archived: R040 — history: `yah board history oss/yubaba/crates/cloud/src/lib.rs`
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//!
//! @arch:see(architecture/PHASE_1_MIRROR_BOOTSTRAP.md)
//! @arch:see(architecture/yah-managed-camps-topology.md)
//!
//! @arch:see(.yah/docs/architecture/A041-yah-mesh-bootstrap.md)
//!
//! @arch:see(.yah/docs/architecture/A041-yah-mesh-bootstrap.md)
//!
//! archived: R085 — history: `yah board history oss/yubaba/crates/cloud/src/lib.rs`
//! @arch:see(.yah/quests.md)
//!
//! archived: R168 — history: `yah board history oss/yubaba/crates/cloud/src/lib.rs`
//! @arch:see(.yah/docs/architecture/A031-yah-cloud-config-shape.md)
//! @arch:see(.yah/docs/architecture/A045-yah-public-site.md)
//!
//! @yah:relay(R260, "OpenRouter model almanac — track top-weekly models for backend selection")
//! @yah:assignee(agent:claude)
//! @yah:at(2026-05-20T22:23:52Z)
//! @yah:kind(spike)
//! @arch:see(architecture/yah-cloud-config-shape.md)
//! @yah:next("Unique signal: popularity + freshness + capability tags. Pricing is already covered by `crates/yah/probe/data/pricing.json` (LiteLLM snapshot) — almanac does NOT duplicate $/token; it adds rank, `:free` flag, modality, capability tags (code / vision / tool-use / long-context), and a last_seen_at so consumers can tell when an entry has gone stale.")
//! @yah:next("Primary consumer: the OpenRouter character bundle at `crates/yah/kg/preroll/openrouter/{agents,subclasses}.json`. Currently a single preroll agent (\"Quick Hand\") pinned to `qwen/qwen3-coder:free` — this WILL silently break when OpenRouter rotates the free-tier list. Almanac's first job is to keep that subclass pointed at a currently-available free model (and let the bundle expand into a roster of currently-hot free models, not just one).")
//! @yah:next("Free-model rotation is the load-bearing constraint. Refresh cadence has to match how often OpenRouter shuffles the `:free` set (empirically weekly-ish). Storage options ranked by how well they handle rotation: (1) scheduled daemon refresh writing back into `crates/yah/kg/preroll/openrouter/` — auto-heals; (2) on-demand fetch+cache in the runner — never stale at session start but offline-fragile; (3) build-time embedded snapshot like `probe/data/pricing.json` — simplest, goes stale between releases (probably wrong shape for free-tier).")
//! @yah:next("Two approaches to evaluate side-by-side: (A) straight call to `https://openrouter.ai/api/v1/models` (free, no key, structured JSON — already returns `context_length`, `pricing.prompt`/`pricing.completion`, `architecture.modality`; `crates/yah/runner/src/resolver/openrouter.rs` already talks to OpenRouter so a `fetch_models()` sibling to its existing `GET /api/v1/credits` is the natural home); (B) inference-based tool that distills `https://openrouter.ai/models?order=top-weekly` HTML into our schema. Confirm (A) first — if the JSON exposes the top-weekly ordering and `:free` flag, (B) is unnecessary; if not, (B) becomes the rotation-detector.")
//! @yah:next("Query-resolvable subclass (the real primitive): `AgentSubclass.model` at `crates/yah/kg/src/party.rs:520` is a hard `provider:model` string today. Promote it to a sum type — literal `provider:model` OR `ModelQuery { tier, capability_tags, min_context_tokens, max_price_per_token, … }` — resolved by the almanac at session start. Slots into the existing `fallbacks: Vec<FallbackRule>` machinery at party.rs:540: emit `ConfigSwitch{ModelResolved}` (sibling of `FallbackTriggered`) when the query lands, so the UI can show \"Quick Hand → qwen3-coder:free (current pick, refreshed 2h ago)\". The preroll bundle then declares intent (\"Thief-shaped, free, code-tuned\") instead of a brittle pin.")
//! @yah:next("Constraint vocabulary — the hard numbers behind \"Thief-shaped, free, code-tuned\", layered by cost-to-implement so we ship something useful at T0 and can grow. **T0 (already free from /models):** `context_length`, `pricing.prompt`/`pricing.completion`, `architecture.modality` come back in the same fetch. MVP heuristic = Pareto frontier of (context_window, price_per_token); at `:free` tier price collapses to 0 so it cleanly reduces to \"max context with matching capability tag\". This is enough to pick a non-broken Quick Hand. **T1 (external quality scores):** join on canonical model id against artificialanalysis.ai's quality index (general + code subscore), Aider's code leaderboard, or LiveBench. Cheap to add once the T0 pipe exists; lets queries express `min_quality` or `prefer_code_subscore`. **T2 (almanac-as-evaluator):** spend a few credits running a small fixed corpus (lint-fix, summarize, ack-and-route) through each new free candidate, score against a reference, persist scores into the almanac. The dogfood option — most signal, most expensive, most interesting. Out of scope for the spike; file as a follow-up child once T0/T1 are in flight.")
//! @yah:next("Recommendation surface: popularity-ranked picker entries in `packages/yah/ui/src/components/agent/Picker/toPickerAgents.ts` + `AgentProvidersPanel.tsx` so adding an OpenRouter backend surfaces the currently-hot models first; query-resolved subclasses display their resolved pick + a freshness chip; stale literal-pinned `:free` references show a warning.")
//! @yah:next("Spike output: a design note at `.yah/docs/working/W091-openrouter-almanac.md` + a working (A) prototype printing the top 10 models in our T0 schema (id, context_length, price, `:free` flag, capability tags, popularity rank). From there, refine into child tickets for: (i) refresh mechanism, (ii) `ModelSpec::Literal | ModelSpec::Query` sum type + T0 resolver, (iii) preroll-bundle migration from pinned-model to ModelQuery, (iv) UI recommendation + freshness chips, (v) T1 external-benchmark join, (vi) T2 self-eval as a stretch/follow-up.")
//! @yah:handoff("Spike output delivered: working prototype + design note + 6 child tickets. Prototype lives in crates/yah/runner/src/resolver/openrouter.rs (AlmanacEntry struct + fetch_models() against /api/frontend/models/find?order=top-weekly + derive_capability_tags) plus app/yah/cli/src/agent.rs (yah agent almanac --top N --free-only --tag code --json). Design note at .yah/docs/working/W091-openrouter-almanac.md. Six follow-ups filed: R260-F1 (refresh scheduler), R260-F2 (ModelSpec sum type + T0 resolver), R260-T3 (preroll bundle migration → ModelSpec::Query), R260-F4 (UI freshness chips + stale-pin warning), R260-F5 (T1 benchmark join), R260-S6 (T2 self-eval, stretch). T0 prototype confirms the rotation problem: `yah agent almanac --top 10 --free-only --tag code` shows qwen/qwen3-coder:free (Quick Hand's current pin) is NO LONGER in the top-10 free code models — current leaders are openrouter/owl-alpha, nvidia/nemotron-3-super, poolside/laguna-m.1.")
//! @yah:verify("cargo run -p yah -- agent almanac --top 10 — prints OpenRouter top-10 weekly models in T0 schema")
//! @yah:verify("cargo run -p yah -- agent almanac --top 10 --free-only --tag code — shows the currently-hot free-tier code-tuned roster (the Quick Hand replacement set)")
//! @yah:verify("cargo check -p runner -p yah — clean (note: cargo test -p runner --lib is blocked by pre-existing R258-F3 test breakage on AgentSession; tracked as gotcha)")
//! @yah:gotcha("Pre-existing R258-F3 test breakage in crates/yah/runner/src/{anthropic.rs:833, sessions.rs} — `cargo test -p runner --lib` fails with E0063 (AgentSession initialiser missing last_text + slot_id fields). R258-F3 is currently in review. R260's new resolver::openrouter::tests entries are byte-perfect but un-runnable until R258-F3's test fixtures are updated.")
//! @yah:gotcha("OpenRouter's /api/frontend/models/find?order=top-weekly is undocumented. The almanac treats it as best-effort and the design (see openrouter-almanac.md) calls for graceful degradation to public /api/v1/models alone when the join fails. ?order= is silently ignored on the documented endpoint (it always returns newest-first); approach (B) HTML scraping is unnecessary and was ruled out.")
//!
//! @yah:relay(R414, "yah-cloud pill sync + publish + Pills panel")
//! @yah:assignee(bundle-anthropic-miravel)
//! @yah:at(2026-06-03T07:07:03Z)
//! @yah:status(review)
//! @yah:phase(P2)
//! @yah:parent(Q410)
//! @arch:see(.yah/docs/working/W141-pill-rings.md)
//! @arch:see(.yah/docs/architecture/A031-yah-cloud-config-shape.md)
//! @yah:depends_on(R411)
//! @yah:handoff("P2 delivered: resolve_pill_catalog (chips crate) + party_resolve_pill_catalog Tauri command + env wiring + PillsPanel in FullCharacterEditor. Pills panel shows all categorized pills grouped by category with per-character tri-state toggle (always-on/discoverable/off); edits agent.persona.chips.pill_state map via patchAgent.")
//! @yah:next("P3: local pills.toml loader — add ~/.yah/pills.toml and .yah/pills.toml as new resolution layers (separate from chips.toml) per W141 layer stack")
//! @yah:next("P3: MCP URL trust display — when a content-pill with mcp[] is toggled always-on, show one-time approval dialog listing the URLs before activating")
//! @yah:next("P4: cloud sync stub — 'Share to my account' button in PillsPanel (disabled until account system exists)")
//! @yah:verify("cargo test -p chips — 84 passed (3 new resolve_pill_catalog tests)")
//! @yah:verify("bun run typecheck — no new errors (6 pre-existing unchanged)")
//!
//! @arch:see(.yah/docs/working/W193-asset-dependency-status-surface.md)
//!
//! @yah:ticket(R743-T7, "yah-cloud: 5 test binaries to 1 (or 2 — pond_smoke may stay isolated)")
//! @yah:at(2026-08-11T01:18:56Z)
//! @yah:status(review)
//! @yah:phase(P2)
//! @yah:parent(R743)
//! @yah:next("tests/main.rs mod'ing the siblings + autotests = false and [[test]] name = \"main\" in oss/yubaba/crates/cloud/Cargo.toml.")
//! @yah:verify("cargo test -p yah-cloud -- --list count unchanged; three green runs. One commit — oss subtree.")
//! @yah:gotcha("tests/pond_smoke.rs:198 is the only real fixed-port bind in the whole in-scope set — MinIO on http://127.0.0.1:9000, an external dependency it does not own. It is a legitimate deliberate-isolation candidate: if merging it makes the suite flaky or order-dependent, keep it as its own [[test]] target and say so on the ticket rather than force-merging.")
//! @yah:gotcha("pond_smoke.rs and mesofact_static_e2e.rs both host live @yah: annotations.")
//! @yah:handoff("LANDED: 5 test binaries → 2. New tests/main.rs mods live_workspace_smoke, mesofact_static_e2e, pg_driver_live and whisper_derive_e2e; Cargo.toml gains autotests = false plus explicit [[test]] main (tests/main.rs) and [[test]] pond_smoke (tests/pond_smoke.rs). Files were mod'd, not concatenated, so mesofact_static_e2e.rs's live R441-B2 annotation block stays where the harvester expects it and CARGO_MANIFEST_DIR (which three of the four walk up from) is unchanged. autotests = false only gates [[test]] discovery — examples/load_probe.rs is still autodiscovered. Test names gained a module prefix (e.g. whisper_derive_e2e::derive_pipeline_upload_skip_prune_reproducibility); substring filters still match, but `--test <file-stem>` for the four merged files is now `--test main -- <module>::`.")
//! @yah:handoff("ISOLATION DECISION: pond_smoke STAYS its own [[test]] target — 2 targets, not 1, and deliberately so. Three reasons, strongest first. (1) DECISIVE: .yah/qed/pond-smoke.toml's `pond-spinup-budget` step shells out to `cargo test --release --locked -p cloud --test pond_smoke -- --nocapture`. Folding pond_smoke into `main` turns that committed pipeline step into a hard cargo error, and that file is outside this crate (peer-owned path, not mine to edit). (2) It is the only test in the crate that reaches a FIXED external address — MinIO at http://127.0.0.1:9000 (pond_smoke.rs:199) — and the only one that creates/`docker rm -f`s named containers in a Drop guard, so its blast radius on failure is outside the process and a standalone runnable handle is worth keeping. xtask/src/lib.rs's @yah:assumes census independently found this to be the ONLY real port bind across all ten in-scope crates. (3) It is benchmark-shaped and libtest parallelises within one binary: both its tests assert wall-clock budgets (WARM_RESTART_BUDGET 3s, WARDEN_COLD_BUDGET 5s, COLD_START_BUDGET 15s). Merging would drop whisper_derive_e2e (two in-process axum servers + BLAKE3 + tempdir IO, ungated) and live_workspace_smoke (a full CloudConfig::load walk of the real workspace, ungated) onto sibling threads inside that measurement window, and the pipeline runs it --nocapture for the timing report, which merging would interleave with every other test's output. The four that DID merge have no such conflict: read-only fs, 127.0.0.1:0 ephemeral ports, tempdirs, and no process-global state (no set_var / set_current_dir / top-level statics anywhere in the set).")
//! @yah:verify("BASELINE (HEAD layout, cargo test -p yah-cloud -- --list, run with the change temporarily reverted): 6 test binaries — lib 924 tests; live_workspace_smoke 1; mesofact_static_e2e 1; pg_driver_live 1; pond_smoke 2; whisper_derive_e2e 1; Doc-tests cloud 1. Integration total 6 across 5 binaries.")
//! @yah:verify("AFTER (same command, exit 0): lib 924 tests; tests/main.rs 4 tests; tests/pond_smoke.rs 2 tests; Doc-tests cloud 1. Integration total 6 across 2 binaries — COUNT UNCHANGED, every one of the 6 names accounted for, now module-prefixed inside main.")
//! @yah:verify("THREE GREEN RUNS: cargo test -p yah-cloud --test main --test pond_smoke, three consecutive times — main 3 passed / 0 failed / 1 ignored, pond_smoke 2 passed / 0 failed, all three runs identical. No order-dependence observed.")
//! @yah:verify("HONEST SCOPE OF WHAT ACTUALLY EXECUTED (confirmed with -- --nocapture, container has no docker / no live pg / no mesofact-dev binary): REALLY RAN — live_workspace_smoke::live_yah_workspace_loads_cleanly (real CloudConfig::load of the checked-in .yah/ tree, real assertions) and whisper_derive_e2e::derive_pipeline_upload_skip_prune_reproducibility (in-process axum fake-S3 + fake upstream on 127.0.0.1:0, all three runs). SELF-SKIPPED at runtime — mesofact_static_e2e (prints 'skipping: set YAH_RECONCILER_E2E_BIN'), pond_smoke::pond_spinup_budget and pond_smoke::warden_container_spinup_budget (both print 'SKIP: set YAH_LOCAL_SIM_E2E=1', need orbstack/colima/docker). IGNORED — pg_driver_live (#[ignore], needs a built yah-pg-dev binary + network). So the live/e2e legs were compiled and linked but NOT exercised here; the pipeline steps that do exercise them are unchanged for pond_smoke and reachable as `--test main -- mesofact_static_e2e::` for the merged one.")
//! @yah:gotcha("PRE-EXISTING, NOT CAUSED BY THIS TICKET: .yah/qed/local-sim-smoke.toml's only step runs `cargo test -p cloud --test local_sim_smoke`, but tests/local_sim_smoke.rs does not exist and `git log --all` finds it at neither oss/yubaba/crates/cloud/tests/ nor the pre-OSS crates/yah/cloud/tests/ path. That pipeline was already dangling before this change (it most likely wants pond_smoke). Left alone: .yah/qed/ is outside this crate. Flagging it because autotests = false makes a target-name typo fail identically to this, and the next person to hit it should not blame R743-T7.")
//! @yah:gotcha("Historical @yah:verify strings on already-landed tickets still cite the retired per-file target names — `--test whisper_derive_e2e` (reconciler/static_asset.rs:46,118), `--test mesofact_static_e2e` (the R441-B2 block inside tests/mesofact_static_e2e.rs itself). Those are landed records, not live invocations, so they were deliberately NOT rewritten; the working form is now `cargo test -p yah-cloud --test main -- <module>::`.")
//! @yah:gotcha("CONTAINER, not code: the first attempt at the post-change --list died with `error: linking with cc failed … ld terminated with signal 7 [Bus error]` on both the merged `main` target and the untouched `lib test` target. Root cause was the container's root filesystem at 100% (8.0K free) — oss/yubaba/target alone was 23G with no cargo-orphan-gc installed here to reclaim it. Cleared by deleting the regenerable incremental caches (oss/yubaba/target/debug/incremental, target/debug/incremental) while no cargo was running; the listing then exited 0. Worth knowing because the failure mode reads exactly like the R770 orphan-gc symptom described in CLAUDE.md but is plain ENOSPC.")
//! @yah:tier(Warrior)
//!
//! @yah:ticket(R895-T2, "Delete the LegacyServiceConfig compose/Caddy generation once nothing renders it")
//! @yah:at(2026-09-13T21:02:37Z)
//! @yah:status(review)
//! @yah:assignee(agent:bundle-anthropic-ashguard)
//! @yah:parent(R895)
//! @yah:next("Tier: Cleric — mostly deletion, but the liveness check must be real. This module (podman-compose + Caddyfile generation over LegacyServiceConfig, R040-F7) and mesh_service.rs's compose-era host-network pattern are the pre-workload-spec generation of the data plane. Before deleting: establish by call-graph, not by name, whether any live path still renders a ComposeBundle (POST /compose consumers, cloud-init templates, provision.rs) — if one does, migrate that consumer to the workload-spec path first and delete in the same relay, per the below-1.0 break-don't-tape rule. The one thing worth salvaging is documented intent: the tenant network-split rules (W206/R558-T2, NetworkPlan) express a policy the W343 model must also answer; carry the policy statement into W343's doc or the container_net module docs before the code that encodes it goes.")
//! @yah:gotcha("Liveness check done (sniffer, session:77442b98) and the ticket's premise needs correcting: compose.rs is NOT dead by call graph. There is one real live chain — clap `Commands::Cloud` (app/yah/cli/src/cli.rs:1081) -> handle_cloud_command (cloud.rs:2472) -> handle_service (cloud.rs:7161) -> handle_service_deploy (cloud.rs:7202) -> generate_compose_bundle (cloud.rs:7204) -> ComposeDeployRequest -> cloud_client::deploy_compose (crates/yah/cloud-client/src/lib.rs:1373) -> POST /compose. The route is live at oss/yubaba/crates/yubaba/src/lib.rs:2673 with handler deploy_compose at :6566-6649 (auth class OPERATOR), and `ServiceCommands::Deploy` (cloud.rs:1506) carries no deprecation or hidden attribute. So this ticket deletes a SHIPPED CLI verb and an HTTP route, not just an unreferenced module. NOTE (R895-T2 courier, session:49bbf176): compose.rs and mesh_service.rs are now DELETED (this ticket) — the file:line references above (compose.rs, cloud.rs pre-deletion line numbers, lib.rs:6566-6649) are historical, describing the call chain as it existed before this deletion.")
//! @yah:gotcha("The path is nonetheless dead by DATA here and non-functional on the fleet, which is why deletion is still the right call. (a) `.yah/cloud/` in this camp holds only machines/ and status.jsonl — no services/ — so CloudConfig::load (config.rs:1575) yields empty legacy_services and handle_service_deploy bails at cloud.rs:7190 before reaching the renderer. (b) deploy_compose writes /etc/yah-cloud/compose.yml (lib.rs:6578) but app/yah/cli/resources/yubaba.service:245-246 sets ProtectSystem=strict with ReadWritePaths covering only /var/lib/yah/yubaba, /run/yubaba, /var/lib/yah/qed — no /etc — so the write EROFSes and propagates as a 500. The same silent-EROFS site is already recorded at .yah/infra/machines/us-west-001.toml:13. (c) the unit it generates runs `podman compose up` (lib.rs:6662) and the provisioning template stopped installing podman in R092-F2 (oss/yubaba/crates/cloud/templates/mirror.yml:41-43). Deleting a verb that already 500s is not a regression.")
//! @yah:gotcha("SALVAGE is larger than the ticket assumed, and is the load-bearing part of this work. Deleting compose.rs removes the ONLY executable encoding of tenant network isolation in the tree. NetworkPlan (compose.rs:112, derive :118, network_for :129, declared :139) is what actually splits co-resident tenants onto `<tenant>-<base>` bridge networks per W206/R558-T2. WorkloadSpec.tenant survives (oss/yah-base/crates/workload-spec/src/lib.rs:2715) but NOTHING consumes it for networking: container_net.rs is per-node by construction (\"One bridge per node, one veth pair per workload, one routed /24 per node\", :15-16) and has no tenant concept, and W343 never states a tenant-separation rule at all. After this deletion WorkloadSpec.tenant is declarative-only and W206's \"cross-tenant traffic is denied by default\" has no enforcer anywhere. No capability is actually lost today (the encoder is unreachable per the gotchas above), but the design commitment loses its last home in code — so the policy MUST be transplanted into W343 plus the container_net module docs, marked explicitly as required-and-unimplemented, before the code goes. DONE (R895-T2 courier, session:49bbf176): transplanted into W343 \"Open, deliberately\" section and oss/kamaji/crates/kamaji/src/container_net.rs module docs, both citing R895-F3.")
//! @yah:gotcha("Co-deletion target established: oss/yubaba/crates/cloud/src/mesh_service.rs (158 lines, declared at cloud/src/lib.rs:263) is reachable ONLY through compose.rs — compose.rs:210 uses MESH_IP_ENV_FILE, compose.rs:259 uses ufw_rules_for_mesh_port, and its other four exports (pg_hba_snippet, mesh_ip_env_runcmd, MESH_SUBNET, TAILSCALE_IFACE) have zero callers outside their own cfg(test) block at :108-158. It shares no types with compose.rs, so it becomes unreferenced in the same commit. Every leg of the host-network pattern its module doc describes is already false: cloud_init.rs no longer writes /etc/yah-cloud/mesh-ip.env (zero compose/caddy hits in that file), and compose.rs:215 points at `yah cloud service recipe postgres`, a subcommand that does not exist (ServiceCommands at cloud.rs:1505 has only Deploy/Rolling/Status/Prune). Successor documented at oss/yubaba/crates/yubaba/src/service_records.rs:4-8. DELETED along with compose.rs (R895-T2 courier, session:49bbf176) — `git show HEAD:oss/yubaba/crates/cloud/src/mesh_service.rs` carried no @yah: annotation of its own, so nothing else was re-homed from it. Its committed-HEAD content matched this description; the file was additionally dirty (uncommitted) at deletion time and that uncommitted diff was not read before `rm` — if it carried an annotation beyond HEAD's, it was not recovered.")
//! @yah:gotcha("Three near-miss names that are LIVE and must not be swept into this deletion. (1) The caddy-container provider for the local-sim tier (.yah/qed/local-sim-smoke.toml:28-40, A031, A046:40) is owned by oss/yubaba/crates/cloud/src/reconciler/pond.rs, not by compose.rs. (2) crates/yah/runner/src/compose.rs is prompt-block composition, unrelated. (3) workload-spec's compose_import (oss/yah-base/crates/workload-spec/src/lib.rs:489) is `yah workload import docker-compose.yml`, a one-way CLI importer per A054:437. Also confirmed clean and out of scope: provision.rs and cloud_init.rs have zero compose/caddy hits, and the sibling GET /services route (lib.rs:2589) stopped shelling out to podman in R556-F7-T3 — test services_is_compose_independent_post_r556_f7_t3 at lib.rs:11338 pins that — so `yah cloud service status` survives; only `deploy` dies.")
//! @yah:verify("Orphan-unit risk CHECKED AND CLEARED on the live fleet, 2026-09-13 (read-only sweep, session:1c2ba0c4). All 9 nodes declared in .yah/infra/machines/*.toml were reachable over the mesh — us-east-001, us-south-001, us-west-001, us-west-002, us-west-003, us-west-011, us-west-013, us-west-014, us-west-015 — zero unreachable, so this is a complete answer rather than a sample. On every node: no yah-cloud-services.service unit (systemctl is-enabled reports not-found), no /etc/yah-cloud/compose.yml, no Caddyfile, and no podman binary. The /etc/yah-cloud/ directories that do exist hold only current cert-store.env / litestream.env / durability env files with Sep 8-12 mtimes — none are artifacts deploy_compose ever wrote. us-west-015 is a macOS box with no systemd, so the unit path is architecturally moot there. CONCLUSION: deleting the POST /compose route and the ServiceCommands::Deploy verb orphans nothing on the running fleet; no pre-deploy node action is required.")
//! @yah:handoff("SALVAGE (phase 1): DONE. Tenant-isolation policy from NetworkPlan/W206/R558-T2 transplanted into TWO places, both citing R895-F3 as required-and-unimplemented: (a) .yah/docs/working/W343-per-workload-mesh-addressing.md, new bullet added to the 'Open, deliberately' section ('Tenant network isolation (W206/R558-T2) — required, currently unimplemented'); (b) oss/kamaji/crates/kamaji/src/container_net.rs module doc, new '## Tenant isolation (W206/R558-T2) — required, currently unimplemented' section inserted before the @yah:ticket(R605-F22,...) annotation block. Both describe the rule (no cross-tenant L2/3 sharing, same-tenant cross-namespace OK, deny-by-default with opt-in, single-tenant stays a no-op) and note the likely implementation shape (tenant-keyed bridge or packet filter, since the addressing model is already per-node not per-tenant). This is the one part of the ticket the compiler can't verify — read it directly if in doubt.")
//! @yah:handoff("DELETIONS, file by file, each verified by the grep shown (all return empty/only-annotation-text unless noted): oss/yubaba/crates/cloud/src/compose.rs (765 lines) — DELETED via rm; its own @yah:ticket(R895-T2,...) annotation (5 gotchas + verify) was read in full BEFORE deletion and re-homed into oss/yubaba/crates/cloud/src/lib.rs's module header (appended after the pre-existing @yah:tier(Warrior) line at :242, own block starts :244) — `board.show R895-T2` and `board.show R743-T7` (the ticket that owned the tier line) both resolve cleanly, confirmed no interleaving.")
//! @yah:handoff("oss/yubaba/crates/cloud/src/mesh_service.rs (158 lines) — DELETED via rm. `git show HEAD:oss/yubaba/crates/cloud/src/mesh_service.rs | grep '@yah:'` returns nothing, so the last COMMITTED version carried no annotation. BUT this file showed 'M' (dirty vs HEAD) in the git status at session start, meaning it had uncommitted edits from an earlier session, and I ran `rm` before reading the working-tree content — that uncommitted diff is not recoverable via git (never staged/committed). @Ashguard:blade has a forensics session running (session:b49fa21f) trying to recover it from claude-cli transcripts; that recovery is not mine to chase further.")
//! @yah:handoff("oss/yubaba/crates/cloud/src/lib.rs — `pub mod compose;`, `pub mod mesh_service;`, `pub use compose::{generate_compose_bundle, ComposeBundle};`, and `LegacyServiceConfig` dropped from the `pub use config::{...}` re-export block. Verified: `grep -nE 'LegacyServiceConfig|generate_compose_bundle|ComposeBundle|mod compose|mod mesh_service' oss/yubaba/crates/cloud/src/lib.rs` returns only the R895-T2 annotation text itself (expected, it's prose).")
//! @yah:handoff("oss/yubaba/crates/cloud/src/config.rs — LegacyServiceConfig struct deleted (was ~:1391, doc said 'Deprecated... replaced by workloads/ in R092-F1'); `legacy_services: Vec<LegacyServiceConfig>` field removed from CloudConfig + doc comment on the struct updated to note removal; the `load_dir::<LegacyServiceConfig>(...)` call and its slot in the load-tuple removed from CloudConfig::load; both `legacy_services: vec![]` default-construction sites removed (load_from_config_dir, and the make_empty_cfg test helper); 4 now-impossible tests deleted (round_trip_service_legacy, service_bind_interface_round_trips, service_bind_interface_absent_is_none, service_bind_interface_skipped_when_none); 2 remaining `cfg.legacy_services` assertions removed (cloud_config_load_and_lookup — also removed its now-dead 'legacy services/ dir' fixture setup — and one more standalone assertion); unused top-level imports HashMap and TenantId dropped from the `use` block (TenantId is still imported locally inside several `#[cfg(test)] mod` blocks elsewhere in the file — untouched, still needed there). Verified: `grep -n 'LegacyServiceConfig|legacy_services' config.rs` returns only the doc-comment mention explaining the removal.")
//! @yah:handoff("app/yah/cli/src/cloud.rs — ServiceCommands::Deploy variant removed from the enum; the `ServiceCommands::Deploy { .. } => handle_service_deploy(...)` match arm and the handle_service_deploy() function body removed entirely; collect_machine_services() and derive_public_hostname() removed (both became fully unreferenced once handle_service_deploy was gone — confirmed via grep, zero other call sites); `compose::generate_compose_bundle` and `LegacyServiceConfig` imports dropped from the `use cloud::{...}` block; machines_for_service() KEPT (still called from handle_service_status). Also fixed two now-stale strings inside handle_service_status: a comment claiming '/services' shells to 'podman compose ps' (false since R556-F7-T3) and a 'no services running — deploy first with `yah cloud service deploy <name>`' hint pointing at the just-deleted verb.")
//! @yah:handoff("crates/yah/cloud-client/src/lib.rs — ComposeDeployRequest/ComposeDeployResponse structs and the deploy_compose() client method removed; the spawn_yubaba() test helper's compose_dir tempdir creation and .with_compose_dir(...) call removed; deploy_compose_round_trips_via_yubaba test deleted; services_returns_empty_array_when_no_compose_deployed renamed to services_returns_empty_array_when_no_workloads_deployed and simplified (no longer creates a compose_dir). Verified via grep only — NOT yet compiled/tested by me (see 'not done' below).")
//! @yah:handoff("oss/yubaba/crates/cloud/src/reconciler/mesofact_bundle.rs — its cfg_with() test helper (a downstream CloudConfig struct-literal builder) had `legacy_services: vec![]`; removed, this was a real compile error caught by the yah-cloud build.")
//! @yah:handoff("legacy_mirrors / LegacyMirrorConfig verdict: KEEP, do not delete. Confirmed reachable and heavily live: machines_for_service (cloud.rs), the mirror-status/mirror-show CLI path (build_mirror_rows, print_mirror_show_table), handle_mirror-family functions, mesofact_bundle.rs and lan_tunnel.rs test fixtures. This is unrelated to the compose/service-deploy system being deleted here.")
//! @yah:handoff("BUILD STATUS: `cargo check --manifest-path oss/yubaba/Cargo.toml -p yah-cloud --lib --tests` is GREEN — Finished, 0 errors. Remaining warnings in that output are pre-existing and unrelated to this diff (dead_code in oss/yah-base/crates/object-store/src/r2.rs, unused_mut in cloud/src/reconciler/mesofact_static.rs, an unused struct field in cloud/src/app_manifest.rs, an unused fn in cloud/src/reconciler/pond_door.rs, one non_snake_case test name in cloud/src/reconciler/mod.rs) — none touch anything this ticket edited.")
//! @yah:handoff("Tree-wide stale-reference sweep run (grep for LegacyServiceConfig, generate_compose_bundle, ComposeBundle, mesh_service, compose::, MESH_IP_ENV_FILE, ufw_rules_for_mesh_port, pg_hba_snippet, deploy_compose, ComposeDeployRequest/Response, with_compose_dir, DEFAULT_COMPOSE_DIR, COMPOSE_UNIT across oss/ app/ crates/): the only hits outside this diff's own annotation text are (a) oss/yubaba/crates/yubaba/src/service_records.rs:4-8, a doc comment historically describing why service_records.rs exists instead of 'cloud::mesh_service' — cosmetically references a deleted module name but is prose, not code, does not block compile, left as-is; (b) crates/yah/runner/src/compose.rs and its ~9 call sites — confirmed unrelated (prompt-block composition), explicitly out of scope per the ticket's own gotchas.")
//! @yah:handoff("Tree anchor at handoff: e0530813af8f7d86f5eb7ea9a6b5a57d386bf30b — the shared tree as I left it. Diff against it (`git diff e0530813af8f7d86f5eb7ea9a6b5a57d386bf30b..HEAD`) to see what landed under you, and quote this SHA rather than 'HEAD' in any revert/restore instruction.")
//! @yah:next("NOT DONE, in priority order for the next courier (dispatched at Warrior per the leader): (1) cargo check on the yah CLI crate --all-targets (confirm the actual package name first, per the ticket's own instruction — do not guess) to verify app/yah/cli/src/cloud.rs compiles after the ServiceCommands::Deploy removal; I never got a green confirmation on this file myself. (2) cargo test -p <cloud-client's actual package name> to verify crates/yah/cloud-client/src/lib.rs's test-helper edits compile and pass. (3) cargo test --manifest-path oss/yubaba/Cargo.toml --workspace (full suite, not just yah-cloud lib+tests) and specifically confirm services_is_compose_independent_post_r556_f7_t3 passes. (4) Measure a real baseline vs after test-count comparison as the ticket's own Verify section asks — I did not do this under wind-down time pressure.")
//! @yah:next("If (1)/(2)/(3) turn up more compile errors from downstream CloudConfig/ServiceCommands consumers I did not find in my sweep, fix them the same way as mesofact_bundle.rs was fixed (they are mechanical — remove a `legacy_services:` field initializer or a ServiceCommands::Deploy match arm), then re-run the full-workspace check.")
//! @yah:next("Once (1)-(3) are green: this ticket is functionally complete except for the mesh_service.rs uncommitted-diff loss, which is @Ashguard:blade's forensics track (session:b49fa21f), not blocking sign-off of THIS ticket's own scope.")
//! @yah:verify("TEST-COUNT BASELINE MEASURED (R895-T2 courier, session:218a3724). Method: `#[test]`/`#[tokio::test]` attribute count per file, anchor commit e0530813af8f7d86f5eb7ea9a6b5a57d386bf30b (== HEAD at measurement time) vs working tree, then reconciled BY TEST-FUNCTION NAME rather than by count. Deliberate removals total 33 and every one is accounted for: compose.rs -22 (whole file deleted), mesh_service.rs -6 (whole file deleted), config.rs -4 (exactly round_trip_service_legacy, service_bind_interface_round_trips, service_bind_interface_absent_is_none, service_bind_interface_skipped_when_none), cloud-client -1 (deploy_compose_round_trips_via_yubaba) plus 1 rename (services_returns_empty_array_when_no_compose_deployed -> services_returns_empty_array_when_no_workloads_deployed, both names confirmed present on their respective sides). app/yah/cli/src/cloud.rs removed ZERO tests (handle_service_deploy/collect_machine_services/derive_public_hostname carried none). Nothing else went missing: the removed-name lists are exactly the deliberate lists, with no extras.")
//! @yah:gotcha("A NAIVE before/after test COUNT on this ticket reads backwards, and will mislead the next person who tries it. Three of the touched files gained tests from concurrent peer sessions between the anchor commit e0530813af8f7d86f5eb7ea9a6b5a57d386bf30b and this measurement, all uncommitted and unrelated to R895: oss/yubaba/crates/cloud/src/config.rs 220->218 (-4 mine, +2 peer: a_declared_health_path_survives_the_loader, a_relative_health_path_is_refused_at_load), app/yah/cli/src/cloud.rs 203->206 (0 mine, +3 peer: a_unit_off_the_allowlist_is_refused_before_any_config_load, unit_log_script_carries_the_sudo_prefix, unit_log_script_is_read_only_journalctl), crates/yah/cloud-client/src/lib.rs 43->46 (-2 mine, +5 peer: the logs_* family and the_client_allow_list_matches_the_nodes). So cloud.rs and cloud-client's raw counts go UP across a deletion-only ticket. Reconcile by test-function NAME (comm against `git show <anchor>:<path>`), never by count, on this shared tree.")
//! @yah:verify("MESH_SERVICE.RS LOSS INVESTIGATED AND CLOSED — NOTHING WAS LOST (forensics session:b49fa21f, 2026-09-13). This supersedes the worry recorded in the co-deletion gotcha above. Method: searched all 3,486 files in .yah/sessions/ (44 mention mesh_service at all) for any edit/write/bash tool call touching that file's content, across this camp's entire history. THERE IS NONE — no session log shows content ever being written to oss/yubaba/crates/cloud/src/mesh_service.rs. The only prior touch was a read by the liveness sniffer (session:77442b98) at 12:36:58 PDT, 39 minutes before deletion, reporting 6242 bytes / 159 lines; `git show HEAD:<path>` is also exactly 6242 bytes (158 by wc -l, the 158-vs-159 being the missing-trailing-newline convention, not a content difference). So the working copy was byte-for-byte identical to HEAD shortly before the rm, and nothing touched it afterward. git log shows exactly one commit ever touched the file (3f7c44ad, the months-old warden->yubaba rename). CONSEQUENCE: the deleted content is fully recoverable from HEAD at any time; no peer work was destroyed. UNEXPLAINED RESIDUE, stated rather than smoothed over: the file did show `M` in git status at the deleting session's start, and forensics could not attribute that flag to any edit — the sniffer was read-only and the deleting courier never read the file. If the flag was real its origin is outside anything this camp's session logs capture (plausibly a mode or line-ending touch). Not chased further because the content question is settled.")
//! @yah:verify("COMPOSE.RS uncommitted delta also fully accounted for by the same forensics pass, with no residue. Its working copy was 772 lines against HEAD's 765, and the entire 7-line delta was this ticket's own live-growing @yah: annotation block, appended by the relay leader (session:7ca0970b) via board.update between 12:38 and 13:17 PDT. That text is preserved twice over — in the board's own store (board.show R895-T2 resolved throughout, including after deletion) and in the block re-homed into oss/yubaba/crates/cloud/src/lib.rs at 13:15:31, one edit before the rm. Every other edit/write against cloud/src/compose.rs in the session logs predates this relay by weeks (Jul-Aug 2026). Nothing beyond the annotation was uncommitted in that file either.")
//! @yah:handoff("DOWNSTREAM COMPILE BREAKAGE FOUND AND FIXED (R895-T2 courier, session:218a3724). The previous courier's sweep missed four CloudConfig struct-literal sites that still initialized the deleted `legacy_services` field, so `cargo check -p yah --all-targets` was RED with E0560 (no field named `legacy_services`): 1 error in `yah` (lib) + 5 in `yah` (lib test). Sites removed, same mechanical fix as reconciler/mesofact_bundle.rs: app/yah/cli/src/cloud.rs three occurrences of `legacy_services: vec![],` (formerly :17636, :17781, :18504, all in test CloudConfig builders) and app/yah/cli/src/lan_tunnel.rs:1001 `legacy_services: Vec::new(),`. NOTE the earlier sweep could not have caught these by its own grep method: a tree-wide `rg legacy_services` DOES return them, but the raw output is swamped by this ticket's own multi-KB @yah: annotation prose in oss/yubaba/crates/cloud/src/lib.rs, which is what made them easy to miss. Filter with `rg -n 'legacy_services' --glob '*.rs' . | rg -v '^\\S+:[0-9]+://[/!]'` to drop doc-comment lines and the four code hits stand out immediately. Post-fix the only remaining tree-wide references to LegacyServiceConfig / ServiceCommands::Deploy in CODE (as opposed to annotation prose) are zero.")
//! @yah:verify("CHECK 1 GREEN, independently corroborated. `cargo check -p yah --all-targets` EXIT=0, zero errors, 3m40s (session:218a3724, 2026-09-13). This is the wide gate: --all-targets covers lib + lib-test + all bins and tests, which is where 5 of the original 6 E0560 errors lived, so the deletion is verified across the full target set rather than the library alone. Corroborated from outside this relay by @Glimmerstone's R365 courier running `cargo check -p yah --lib` against the same tree and reporting zero errors attributable to this ticket. Confirmed by both runs: no LegacyServiceConfig was reintroduced anywhere and nothing was repointed at LegacyMirrorConfig — every fix was a removal, which is the only correct shape here.")
//! @yah:gotcha("ROOT CAUSE OF THE ~50-MINUTE CAMP-WIDE OUTAGE ON 2026-09-13, recorded so this ticket is not read as a clean deletion. `cargo check -p yah` was red camp-wide for roughly 50 minutes, blocking R365-B27, R365-F22, R856 and R898-T4, each retrying against the shared cargo lock and amplifying the queue. Three compounding causes, in order of blame: (1) LEADER ERROR — the relay lead briefed the first courier that a red tree between deletion phases was expected and not to worry about it. That is true on a private branch and false on a shared working tree, where a broken `cloud` crate takes out every session depending on it. Standing rule since: keep the tree compiling at every stopping point, never end a turn red. (2) The stale-reference sweep that should have caught the remaining sites returned a truncated clean-looking result because this ticket's own multi-KB @yah: annotation prose blew ripgrep's 32KB output cap in the same file — filed as R901-B1. (3) The courier's background build reported \"exit code 0\" in the harness notification while cargo itself reported EXIT=101, because the notification carries the wrapper's status — filed as R901-B2. The four sites that actually broke it were E0560 `legacy_services:` initializers at app/yah/cli/src/cloud.rs x3 and app/yah/cli/src/lan_tunnel.rs:1001. Two peers independently misread the diff as a LegacyServiceConfig -> LegacyMirrorConfig RENAME; it is a deletion, LegacyMirrorConfig is a separate live type, and any fix that repoints a call site at it is wrong.")
//! @yah:verify("CHECKS 1-4 MEASURED (R895-T2 courier, session:218a3724), pass/fail counts not logs. (1) `cargo check -p yah --all-targets` = EXIT 0, zero errors, 3m40s, after the four legacy_services removals; corroborated independently by a later desktop run whose dependency leg compiled `yah` (lib) with 26 warnings / 0 errors. (2) `cargo test -p cloud-client` = GREEN, 51 passed + 1 passed (doc/second binary), 0 failed, 0 ignored; the renamed test `services_returns_empty_array_when_no_workloads_deployed` is present and passes, confirming the cloud-client test-helper edits both compile and run. (3) `cargo test --manifest-path oss/yubaba/Cargo.toml --workspace` = 11 test binaries, 10 fully green totalling 2204 passed / 0 failed / 11 ignored; THE PIN ASKED FOR, `services_is_compose_independent_post_r556_f7_t3`, PASSES (yubaba-ws.log:2357) — so GET /services is confirmed compose-independent and `yah cloud service status` survives the deletion of `deploy`. The 11th binary reported 61 passed / 33 failed; see the separate gotcha on those. (4) `cargo check -p desktop --all-targets` = RED, but NOT from this ticket: the sole error is app/yah/desktop/src/agent.rs:6364:14 error[E0382] use of moved value `orig_job` (1 error in desktop lib, same 1 in desktop lib test). Zero occurrences of LegacyServiceConfig / LegacyMirrorConfig / legacy_services / compose / ServiceCommands anywhere in that build output. That run's input closure was unchanged for its whole duration (daemon skew verdict: no skew), so the result is trustworthy rather than a racing-tree artifact.")
//! @yah:gotcha("DESKTOP IS RED FOR A REASON THAT IS NOT THIS TICKET — this retires R895-F1's standing assumption rather than confirming it. F1 was signed off assuming desktop was red ONLY because of T2's in-flight LegacyServiceConfig deletion. Measured 2026-09-13 after T2's deletion was complete and `-p yah` was green: `cargo check -p desktop --all-targets` still fails, with exactly one distinct error, and it is app/yah/desktop/src/agent.rs:6364:14 error[E0382] `use of moved value: orig_job` — a borrow-check error in a peer's UNCOMMITTED in-flight edit, not a missing-type error. Evidence it is not ours and not mine to fix: (a) the whole build output contains zero mentions of LegacyServiceConfig, LegacyMirrorConfig, legacy_services, compose or ServiceCommands; (b) `git status --short` shows agent.rs as ' M' (dirty), and the anchor commit e0530813af8f7d86f5eb7ea9a6b5a57d386bf30b has entirely different code at those lines, so the failing hunk exists only in the working tree; (c) `orig_job` appears 2x at the anchor vs 9x in the worktree, i.e. a peer is mid-way through expanding its use; (d) the failing site carries an `R198-T5-B` comment about restating `job` on a resumed session's SessionStarted event. Per shared-tree doctrine this is a peer's live file and was deliberately NOT edited. No session on camp.roster currently lists R198-T5-B, so the owner could not be resolved to a name from the roster — routing it to the R895 leader rather than asserting an author.")
//! @yah:verify("CHECK 1 RE-VERIFIED CLEAN OF SKEW, and the raft failures MEASURED rather than inferred (session:218a3724, 2026-09-13). `cargo check -p yah --all-targets` re-run to final: EXITF=0, zero errors, and this run's input closure was UNCHANGED for its whole duration (daemon verdict: no skew) — the earlier green had carried a 3-input skew warning (peers editing camp.rs, prelude.rs, codex_oauth.rs), so this re-run is what actually settles it. RAFT SUITE: re-ran the full yubaba workspace a second time under materially lighter load (camp.machine at run 2: load 9.78/12.58/15.02 on 15 cpus, 2 rustc/cargo processes, vs 16.82 and 9 processes during run 1). Result 60 passed / 34 failed vs run 1's 61 passed / 33 failed, and run 1's 33 failing names are a STRICT SUBSET of run 2's 34 (the extra is raft_leader_pin::an_off_anchor_leader_hands_leadership_to_the_anchor_region). So these are persistent failures with one timing-sensitive straggler, NOT contention artifacts — halving the load did not fix them. Every panic is a leader-election timeout (\"voters never agreed on a leader\" x6, \"nodes never agreed on a leader\" x4, 22 \"timed out\" strings). Run 2 also carried a no-skew verdict. The pin `services_is_compose_independent_post_r556_f7_t3` passed in BOTH runs. Note camp.machine reported quiet:false on both occasions and never reached a formally quiet window — 4 live slots in the foreign `noisetable` camp, which camp.roster cannot see by contract — so this is labelled a lighter-load measurement, not a quiet-machine one.")
//! @yah:gotcha("THE 33-34 RAFT/ROLLOUT FAILURES IN THE YUBABA WORKSPACE ARE PRE-EXISTING AND NOT THIS TICKET'S — attribution established four ways, not assumed. (a) STRUCTURAL: the deletion removed a struct FIELD, which is a compile-time failure mode (E0560/E0609); these binaries compiled and ran 60-61 passing tests each, so a removed field cannot be producing a runtime election timeout. (b) BY SEARCH: `grep -rn --include='*.rs' -E 'legacy_services|LegacyServiceConfig' oss/yubaba/` returns ONLY annotation/doc-comment prose (this ticket's own block in cloud/src/lib.rs, a config.rs:1432 doc line, a paths.rs R222-era handoff) — zero code references anywhere in the yubaba workspace, so the deleted field was never reachable from its raft paths. The only `cloud::CloudConfig` use anywhere under crates/yubaba/tests/ is pond_reconciler_smoke.rs:39,65, which is NOT among the failures. (c) BY REPETITION: failures reproduce across two independent runs at very different machine loads, run 1's set a strict subset of run 2's. (d) BY SYMPTOM: all are raft leader-election timeouts, a shape unrelated to config deserialization. These belong to whoever owns the yubaba raft/rollout suite, not to R895. SEPARATE TRAP WORTH KNOWING, found the hard way in this session: `rg` IS NOT ON PATH in the camp daemon's build shell (W302 relocates Bash calls to `sh -c` under the daemon). A command shaped `rg ... || echo \"(none)\"` therefore prints the innocent-looking fallback because the BINARY IS MISSING, not because there were no matches — a false negative that reads exactly like a clean sweep. Use `grep -rn --include='*.rs'` in any daemon-relocated command, or check the exit code explicitly. This is the same class as R901-B1 and nearly laundered a fabricated proof into this ticket.")
//! @yah:handoff("LEADER SIGN-OFF (Ashguard:blade, R895 relay lead, 2026-09-13). Implemented across two couriers — @Miravel:griffin (session:49bbf176) did the deletion and the salvage and wound down cleanly at its context limit; @Ashguard:coffee (session:218a3724) finished the downstream fixes and all verification. DELIVERED: cloud::compose (765 lines) and cloud::mesh_service (158 lines) deleted; LegacyServiceConfig and CloudConfig::legacy_services removed; the shipped `yah cloud service deploy` CLI verb, the POST /compose route and handler, ComposeDeployRequest/Response, ServerState::compose_dir, DEFAULT_COMPOSE_DIR, with_compose_dir and the cloud-client mirror all removed; four downstream E0560 sites fixed (app/yah/cli/src/cloud.rs x3, app/yah/cli/src/lan_tunnel.rs:1001) plus reconciler/mesofact_bundle.rs. THE SALVAGE — the irreplaceable half — LANDED: W206/R558-T2's tenant network-isolation policy is transplanted into .yah/docs/working/W343-per-workload-mesh-addressing.md (\"Open, deliberately\") and the oss/kamaji/crates/kamaji/src/container_net.rs module docs, both marked required-and-unimplemented and citing R895-F3. legacy_mirrors/LegacyMirrorConfig was investigated and correctly KEPT as live — two peers independently misread this diff as a rename toward it; it is a deletion and that misreading is pinned in the gotchas.")
//! @yah:verify("ALL FIVE CHECKS CLOSED at sign-off (session:218a3724). (1) `cargo check -p yah --all-targets` EXIT 0, re-run to a final NO-SKEW verdict so the earlier skew-flagged green is settled. (2) `cargo check -p desktop --all-targets` RED, and confirmed unrelated: sole distinct error is E0382 use-of-moved-value `orig_job` at app/yah/desktop/src/agent.rs:6364, a peer's uncommitted work, filed as R902-B1. Borrowck runs only after type-check, so desktop type-resolving proves this ticket's deletion is clean from desktop's side. (3) `cargo test -p cloud-client` 52 passed / 0 failed, renamed test services_returns_empty_array_when_no_workloads_deployed passing. (4) yubaba `--workspace` 2204 passed / 0 failed across 10 of 11 binaries, with services_is_compose_independent_post_r556_f7_t3 — the pin that keeps `yah cloud service status` alive after `deploy` dies — PASSING IN BOTH RUNS. The 11th binary's 33-34 raft leader-election failures were measured at two load levels, proved load-independent, attributed away from this ticket four ways, and filed as R903. (5) Test-count baseline -33, reconciled BY NAME rather than by count via `comm` against `git show <anchor>:<path>` — necessary because peers' uncommitted tests made two files' raw counts go UP across a deletion-only ticket.")

pub mod almanac_dispatch;
pub mod app_manifest;
pub mod asset_journal;
pub mod asset_status;
#[cfg(test)]
mod asset_status_tests;
mod atomic_write;
pub mod capability;
pub mod cloud_init;
pub mod config;
pub mod envoy;
pub mod identities;
pub mod inner_door;
// R374-F3: `local_runtime` + `provider::s3_sign` moved to the `local-driver`
// crate so yubaba can own MinIO lifecycle without a reverse yubaba→cloud dep.
// `local_driver_glue` carries the cloud-config adapter that used to live as
// `LocalContainerSpec::from_provider_config`.
pub mod local_driver_glue;
pub mod mesh;
pub mod migrate;
pub mod multi_root;
pub mod paths;
pub mod proc_control;
pub mod provider;
pub mod provision;
pub mod reconciler;
pub mod recovery_journal;
pub mod release_manifest;
// R898-F1 / W348 §2.2: `DomainConfig.routes` compiled into ONE ordered table —
// path, mode, RESOLVED origin, headers, auth — rendered to both front doors.
pub mod route_table;
pub mod sovereign_unit;
pub mod state;
pub mod status;
pub mod topology;
pub mod validate;

pub use almanac_dispatch::dispatch_on_change;
pub use asset_journal::{AssetState, AssetStatusEvent, AssetStatusJournal};
pub use capability::Capability;
pub use config::{
    AgentPolicy, BucketLogEntry, CloudConfig, ConnectSpec, Connection, ConnectionAuth,
    ConnectionAuthKind, ConnectionChannel, ConnectionEngine, ConnectionPolicy, ConnectionSource,
    GitSource,
    IngressDecl, IngressEdge, IngressProvider, LegacyMirrorConfig,
    MachineConfig, MirrorAssignment,
    MirrorConfig, MirrorProviderSlot, MirrorShape, Provider, ProviderConfig,
    ServiceComponent, ServiceConfig, TopologyConfig, WorkloadConfig, WorkloadConfigError,
    WritePolicy, load_workload,
};
pub use reconciler::cf_creds::{r2_access_for_bucket, R2BucketAccess, R2BucketCredential};
pub use local_driver::pond_warden::{warden_container_label, warden_container_name};
pub use local_driver::{
    canonical_label, canonical_name, ContainerRunSpec, ContainerState, CustomDockerHostProvider,
    DetectedRuntime, LocalContainerSpec, LocalDockerRuntime, LocalRuntime, OwnedContainer,
    RuntimePref, RuntimeProvider, SocketRuntimeProvider, LABEL_KEY, NAME_PREFIX,
};
pub use local_driver_glue::local_container_spec_from_provider;
pub use provider::{
    on_ingress_owner_changed, reconcile_assignment, BucketAcl, BucketRef, CfAccountInfo,
    CloudflareClient, CloudflareEnvoy, CreateR2BucketResult, CreateTokenResult, CreateTunnelResult,
    DigitalOceanEnvoy, DnsRecordDetail, FloatingIpAssignOutcome, FloatingIpProvider,
    FloatingIpState, FloatingIpTarget, GrantScope, HetznerDriver, HetznerEnvoy, HetznerFloatingIp,
    Location, MachineProvider, OvhFloatingIp, ProjectId, R2BucketInfo, R2CustomDomain, ServerId,
    ServerSpec, ServerStatus, ServerSummary, TokenGrant, TunnelConnState, TunnelDnsRecord,
    TunnelDriftRow, TunnelDriftState, VultrFloatingIp, WorkerDeployResult, DOOR_DNS_GRANTS,
    MESOFACT_STATIC_GRANTS, TUNNEL_EDIT_GRANTS,
};
#[cfg(feature = "local-docker")]
pub use provider::{LocalDockerEnvoy, LocalDockerProvider};
pub use reconciler::{
    collect_live_derive_hashes, compute_derive_cache_candidates, compute_live_set,
    compute_prune_candidates, compute_service, derive_minio_key, execute_derive_cache_prune,
    execute_prune, load_service_and_mirror, mesofact_static::WORKER_SCRIPT, new_sync_id,
    pond::MINIFLARE_SIM_SCRIPT, publish_to_pond, summarize, CellStatus, CloudflareWorkerReconciler,
    ContainerOptions, ContainerReconciler, DeriveCacheLiveHashes, DerivePruneCandidate, DriftEntry,
    HeadscaleReconciler, HealthState,
    MesofactStaticReconciler,
    MirrorObservation, PondOptions, PondPublishReport, PondState, ProviderScope, PruneCandidate,
    PruneOutcome, PruneReport, ReconcileCtx, Reconciler, RunningWorkload, RunningWorkloadSummary,
    Runtime, ServiceStatus, StaticAssetReconciler, StatusSummary, SyncHistoryEntry, SyncOutcome,
    SyncState, WireContainerStatus,
};
// R918-F5 — the local-process reconciler is unix-only; see the gate on
// `reconciler::local_process` for why it is gated whole rather than half-ported.
#[cfg(unix)]
pub use reconciler::LocalProcessReconciler;
pub use status::{collect_machine_report, AgentProbe, DriftFinding, MachineReport};