Skip to main content

Crate recall_worker

Crate recall_worker 

Source
Expand description

recall-worker: the process that merges, so the one facing the internet does not have to.

It is an enrolled device with the worker scope, running beside recall-server (in the same compose file, as a second service) with no inbound port. It long-polls the server’s merge queue, reconciles each job’s two versions with the local claude CLI, and posts the result back. The claude login lives on the worker’s own volume, so a compromise of the API process no longer reaches it. See docs/design/part5-plan.md, “The worker”, and the “Jobs” section of docs/reference/api.md.

No Anthropic API key appears anywhere here, as anywhere in Recall: the merge rides whatever account the CLI on this machine is logged in to.

The crate has two unconditional parts, so recall-server and (later) recall’s own CLI can use them without the job loop: merge is the merge itself, the prompt and the flags that keep it cheap, and redact finds and masks secrets in memory text (docs/history/memory-truth.md decision 2). Everything else is behind the client feature (on by default): enrolling, signing requests, and the job loop, with the HTTP client they need. The server turns it off.

Re-exports§

pub use merge::Merger;
pub use redact::Redactor;

Modules§

api
The worker’s side of the HTTP API: JSON requests, signed as a device signs them (recall_wire::signature, RFC 9421), or unsigned for the discovery document and the two enrolment routes, which a machine calls before it has an identity.
config
The worker’s settings: the environment, and nothing else, as for the server.
evaluate
The evaluation: what an evaluate job’s report is made of.
identity
Who the worker is: its Ed25519 key, and the device id the server gave it once the owner approved it.
merge
Reconciles two versions of a memory file by shelling out to the local claude CLI.
redact
Finding and masking secrets in memory text.
worker
Enrolling, then the job loop: claim, merge, report, again.

Functions§

now
A timestamp in the format every Recall API answer uses: JavaScript’s Date.toISOString(), millisecond precision with a Z, such as 2026-09-03T21:49:55.191Z. The same function as recall_server::now, kept here so the merge does not depend on the server.
user_agent
What recall-worker sends as its User-Agent, and so what /health shows as the worker’s agent: recall-worker/0.4.2 (linux-x86_64).