What Tom ruled (2026-09-23, verbatim)
claude's credential, as with any other cloud credential, lives on the coordinator dotfiles. i m actually flexible here: keeping the same dotfiles-side nixos secrets (that is durable anyway, claude code secrets rotate frequently anyway). we can do a dotfiles gh issue to make any changes needed. i m fine having those credentials made available nix-wide by the way, without an apparent need for secrets mgmt.
Context: the successor scheduler's default full runtime profile runs a Claude Code harness inside a gVisor sandbox on the coordinator (Tom: "running carte blanche containers is the equivalent of running ultracode-workflows the same way i do it live with claude code today anyway. this would just make it async"). Evidence: ~/today/evals-2026-09-23/substrate/SANDBOX-CLASS-AND-DEFAULTS-2026-09-23.md, ~/today/START-HERE-2026-09-23.md.
Proposed change
- One declared source per seat. For each Claude seat (
cc first), dotfiles declares the credential path the sandbox runtimes mount, instead of each runtime discovering ~/.claude* on its own. The live file is used, so a refresh by Claude Code is seen on the next job.
- Mount by path, never copy into the nix store. Claude Code credentials refresh often, and
/nix/store is world-readable. The runtimes (gVisor full profile, the ax task image path, microvm.nix credentialFiles) mount the file read-write, so a token refreshed inside a job is not lost.
- Non-Claude cloud credentials follow the same pattern: an agenix path per credential, named in one module that the runtimes read.
- No new secrets manager. Cloudflare secrets stay available for Worker-side secrets only.
Acceptance
- A
full-profile job on the coordinator runs claude -p --model claude-opus-5-5 with the declared cc credential and succeeds.
nix path-info -r of every sandbox runner and image contains no credential file.
- After Claude Code refreshes the token on the host, the next job uses the new token without a rebuild or switch.
Unknowns and proposed defaults
- Read-write or read-only mount. Default: read-write, so a refresh inside a job persists (Tom's 2026-09-21 seat-config ruling).
- Which seats. Default:
cc only. cc2 waits on its re-login, and Codex stays out per the seat rule.
- Open internet inside
full means a hijacked job could send the token out. Tom accepted this trade. The locked profile (no network, no credential) remains the opt-in for untrusted input.
🤖 Generated with Claude Code
What Tom ruled (2026-09-23, verbatim)
Context: the successor scheduler's default
fullruntime profile runs a Claude Code harness inside a gVisor sandbox on the coordinator (Tom: "running carte blanche containers is the equivalent of running ultracode-workflows the same way i do it live with claude code today anyway. this would just make it async"). Evidence:~/today/evals-2026-09-23/substrate/SANDBOX-CLASS-AND-DEFAULTS-2026-09-23.md,~/today/START-HERE-2026-09-23.md.Proposed change
ccfirst), dotfiles declares the credential path the sandbox runtimes mount, instead of each runtime discovering~/.claude*on its own. The live file is used, so a refresh by Claude Code is seen on the next job./nix/storeis world-readable. The runtimes (gVisorfullprofile, the ax task image path, microvm.nixcredentialFiles) mount the file read-write, so a token refreshed inside a job is not lost.Acceptance
full-profile job on the coordinator runsclaude -p --model claude-opus-5-5with the declaredcccredential and succeeds.nix path-info -rof every sandbox runner and image contains no credential file.Unknowns and proposed defaults
cconly.cc2waits on its re-login, and Codex stays out per the seat rule.fullmeans a hijacked job could send the token out. Tom accepted this trade. Thelockedprofile (no network, no credential) remains the opt-in for untrusted input.🤖 Generated with Claude Code