Harness Intelligence Wiki
Research

Remote Agentic Environment User Tooling Research

Remote Agentic Environment User Tooling Research

Scope

This report reconstructs the missing tooling and home-environment branch for a two-user Debian host. It separates current host state, one local Mac's development environment, repository-declared requirements, historical handoffs, and user-supplied tweet evidence. It records facts and unresolved requirement branches; it does not select the final baseline.

Research lanes and evidence authority

LaneCoverageAuthority and limits
Historical artifactsRemote-environment handoff, earlier factory handoffs, and supplied tweet digestThe remote-environment handoff records completed provisioning and caveats as of its handoff. Earlier factory handoffs were unavailable at their original temporary paths during consolidation, so retained claims come only from the lane's complete reads. The tweet digest is untrusted user-supplied secondary evidence: useful for candidates, never a requirement or proof of the current host.
Local home inventoryShell, PATH layers, installed CLIs, Git/GitHub state, agent state, repositories, worktrees, GUI-only toolsDirect read-only inspection on 2026-08-25. It describes one Mac and is evidence of familiar workflows, not an instruction to copy that home or reproduce every installed tool.
Live host auditOS, two account homes, shells, PATH, shared tools, browser payload, per-user state, services, and missing toolsDirect read-only audit on 2026-08-25. This is the strongest evidence for current remote state. No address, key material, fingerprint, token, email, or secret value was retained.
Repository declarationHarness checkout tool contract.devpunks/settings.json is the current checkout authority for Harness requiredTools; it is narrower than a complete operating-system or home-environment baseline.

Trusted current facts

Installed is not required

Three sets were previously conflated:

  1. Installed on the host: a provisioning snapshot. The handoff records Node/npm, Bun, Codex, agent-browser, hi/hint, skills, opensrc, portless, gh, Git, Python, build tools, common terminal utilities, Tailscale, and a shared browser runtime. The live audit confirms the host still has that shared baseline. This does not make every installed item a product requirement. [H1]
  2. Required by this Harness checkout: agent-browser, clawpatch, debug-agent, gh, opensrc, portless, and skills. The live host lacks clawpatch and debug-agent, so the installed host does not yet satisfy the repository declaration. [R1]
  3. Present in the local Mac home: workflow evidence and candidate input. It includes many platform- and project-specific tools that should not become a universal Debian baseline merely because they are installed locally.

The requirements grill must define an explicit baseline and its authority. A version inventory answers “what exists now”; it does not answer “what both users must have.”

Current remote state

The live audit found Debian 13 with two private 0700 homes. Both accounts currently use Bash, stock matching .bashrc and .profile, the default system PATH, umask 022, and passwordless sudo. Shared tools are root-owned. A shared Chrome payload lives under /opt, while each account has an isolated private agent-browser directory that links only the browser payload. These are current-state observations, not accepted permanence requirements. [V1]

Docker, pnpm, uv, Rust, Go, and yq are absent from the current host. Each .codex contains only temporary state. Neither home currently has Codex configuration/authentication/skills/plugins, a user skill tree, Git identity, GitHub authentication, repository/worktree directories, or persistent user services. Tailscale is installed but is not joined and Tailscale SSH is disabled; public OpenSSH remains the active access path. Therefore the machine has shared binaries but not two usable, isolated development homes. [V1]

Safe local-home evidence

The inspected local account uses zsh. Its shell configuration composes Homebrew, Starship, fnm, Bun, pnpm, direnv, zoxide, fzf, and syntax highlighting, and contains Mac-specific paths. The local command surface includes Codex, hi/hint, skills, agent-browser, opensrc, portless, fnm-managed Node, uv, Rust, GitHub CLI, jq/yq, ripgrep/fd/fzf, delta, direnv, zoxide, tmux, and CMake. [L1]

Git/GitHub, Codex, skills, browser automation, and Docker all keep user-specific configuration or state. Local clones live below Desktop/repos; Codex owns separate worktrees below its private home state. Claude and OpenCode launchers were present but failed direct launch checks, so their presence is especially weak requirement evidence. No active Homebrew development service was found. Mac GUI and mobile toolchains are platform evidence only. [L1]

Shared system versus private home

This matrix classifies evidence; rows marked “unresolved” still require human acceptance.

CapabilityShared system candidatePrivate per-home stateCurrent evidence / unresolved point
Base utilitiesGit/LFS, gh, build tools, curl/CA, archives, jq/yq, rg/fd/fzf, tmux, direnv, zoxide, delta, tree, SQLite clientTool preferences and caches onlyCommon Debian candidate inferred from local workflow and current host; exact list unresolved.
Remote accessTailscale package/daemon and SSH policyTailnet identity/session state where applicableTailscale SSH is already accepted elsewhere, but live enrollment is incomplete.
Container runtimeDocker Engine and ComposePer-user Docker config/contextDocker is absent; whether both accounts join the shared Docker group remains unresolved.
Browser automationRoot-owned Chromium/runtime libraries and agent-browser executableProfiles, auth, namespaces, sessions, screenshots, cacheCurrent shared-payload/private-profile split works for both accounts; whether to pin it as the contract remains unresolved.
Agent/CLI toolsCandidate shared executables: Codex, hi/hint, skills, opensrc, portless, plus every accepted Harness-required toolCodex auth/config/trust/history/worktrees; skills and plugins; tool cachesCurrent host has binaries but almost no home setup. Repository-required clawpatch and debug-agent are missing.
Language runtimesSystem dependencies only, or explicitly accepted shared runtimesCandidate per-user Bun, fnm/Node, uv; project-specific runtime cachesCurrent host uses shared Node/Bun; local home uses user-managed versions. Authority and pinning are unresolved.
Git/GitHubGit, LFS, and gh executablesGit identity, credential helper, gh auth, signing choicesMust remain separate. Neither remote home is configured.
RepositoriesNo shared writable checkoutCandidate ~/repos; Codex-owned ~/.codex/worktreesLocal layout suggests the workflow, but the Linux convention is unresolved.
Shell/dotfilesShell packages and completionsCurated Linux-specific rc files, aliases, prompt configDo not clone the Mac .zshrc; Bash versus minimal zsh remains unresolved.
Long-running sessionstmux executablePer-user tmux sessionsNo evidence supports a new systemd-user framework; simple tmux is the current candidate.
BackupBackup mechanism may be system-ownedSelected private state and repositoriesAccepted backup objective exists elsewhere; exact home inclusions/exclusions remain unresolved.

Historical and tweet evidence classification

  • The remote handoff is strong historical provisioning evidence and explicitly says per-user Codex and GitHub authentication had not been performed. It also records Paperclip as intentionally skipped because Codex App manages worktrees. [H1]
  • The earlier factory handoffs separate the manually supervised two-person environment from autonomous backlog schedulers and factory-managed worktrees. The lane found Paperclip, codex-lb, Herdr-style orchestration, factory schedulers, and autonomous factory worktree machinery outside this environment's accepted scope. Those temporary sources were unavailable during consolidation, so this report preserves the classification without claiming fresh file verification.
  • The supplied tweet digest mentions SSH/mosh/Tailscale/Termius, Codex/Claude, Paperclip, firewalls, and tmux. Treat those as patterns worth considering. They do not override direct user decisions, current host evidence, or repository declarations. [T1]

Evidence keys: H1 is /private/tmp/harness-intelligence-remote-agent-environment-handoff-20260825.md, especially lines 9 and 32–53; R1 is .devpunks/settings.json, especially requiredTools; L1 is the 2026-08-25 read-only local shell, executable, Git/GitHub, state-directory, repository, worktree, and service audit; T1 is the supplied tweet-evidence digest; V1 is the 2026-08-25 read-only live-host audit.

Strong exclusions

  • Never copy one person's home, dotfiles, SSH material, Codex database/history/auth, browser sessions/auth, npm configuration, cloud credentials, or tokens into the other home.
  • Do not make Homebrew, Docker Desktop, CodexBar, ChatGPT GUI, Raycast, VS Code, Zed, Xcode, CocoaPods, iOS/Android/Flutter tooling, or other Mac facilities part of the Debian baseline.
  • Do not infer Claude or OpenCode as requirements from broken local launchers. Codex is the declared agent runtime.
  • Keep AWS, Azure, Google Cloud, Pulumi, Kubernetes, Terraform, Expo/EAS, Rust, Go, Java, and other project-specific toolchains opt-in unless a repository contract requires them.
  • Keep Paperclip, codex-lb, Herdr-style orchestration, factory schedulers, and autonomous factory worktree management out of this two-person remote environment unless requirements are deliberately reopened.
  • Do not add formal lifecycle governance, offboarding machinery, a systemd-user framework, quotas, monitoring policy, or reauthentication by inference; prior answers rejected that level of machinery for two users.

Missing requirement branches A–M

These branches are open. Recommendations are research synthesis, not accepted decisions.

IDBranch to pinEvidence-backed recommendationStill needs acceptance
ATool authority and classificationDefine four labels: required, shared convenience, per-project, excluded. Repository requiredTools wins for Harness work.Who owns the environment-wide manifest and exceptions?
BExact common baselineStart with the small Debian utility set, accepted access/runtime tools, and all Harness-required tools.Exact package/executable list for both homes.
CVersion authorityUse one reproducible manifest; distinguish pinned compatibility tuples from stable-channel tools.Exact pins, upgrade cadence, and drift policy.
DHome and repository layoutGive each account ~/repos and preserve Codex-owned ~/.codex/worktrees. Never share writable clones.Directory names, permissions, and clone/bootstrap behavior.
ESkills contractInstall the same accepted base skill set for both users, then keep private additions private.Which skills, source, sync/update command, and validation define parity?
FCodex home contractSeparate auth, config, trust, plugins, history, task database, caches, and worktrees per account.Bootstrap method, accepted shared defaults, and what is intentionally empty.
GGit and GitHub home contractConfigure identity and authentication separately after bootstrap.HTTPS versus SSH, signing, credential helper, and required global preferences.
HBrowser automation contractRetain one shared browser payload with isolated private profiles/state.Payload update owner, cache policy, and per-user acceptance check.
IPackage manager and PATHPrefer a minimal Linux-specific PATH with explicit ownership; avoid copying Mac shell config.Shared versus per-user Bun/Node, fnm/pnpm/uv inclusion, and precedence.
JDocker accessInstall shared Docker Engine/Compose only if required by accepted workflows.Whether both users receive Docker-group/root-equivalent access and how isolation is described.
KShell and dotfilesUse one small curated Linux dotfile baseline; zsh is evidence-supported but Bash is current host state.Bash versus zsh, prompt/plugins, aliases, tmux config, and authoritative source.
LBackup scopeBack up the accepted recoverable home data, not credentials or reproducible caches by default.Exact include/exclude list for repos, Codex state, skills, browser state, and Docker state.
MPer-user acceptanceRun the same clean-login checklist independently for both accounts after separate authentication.Required commands and proof: shell/PATH, repo clone, Codex, hi, skills, browser, GitHub, Docker, and preview flow.

Uncertainty and conflicts

  • The handoff's installed versions are a dated snapshot; the live audit establishes presence and gaps but this report does not turn either into version policy.
  • The local Mac and remote Debian host intentionally differ. Local presence is candidate evidence, while Mac-specific paths, applications, and broken launchers are negative evidence for wholesale replication.
  • Harness requiredTools is authoritative for this checkout, not automatically for every repository or for the entire operating system.
  • The host currently uses shared Node/Bun while the local home uses user-managed runtimes. Either can work; the ownership and version authority must be chosen explicitly.
  • The current shared browser payload with private profiles is validated by the provisioning handoff, but no accepted update/retention contract exists yet.
  • Earlier factory handoff files disappeared from their temporary paths before consolidation. Their lane-derived scope classification is retained with lower confidence than the live host, current checkout, and available remote handoff.

Reopen the requirements grill at the tooling/home branch. Pin A–C first because they define the authority, baseline, and version model used by D–M. Then resolve D–M without adding rejected two-person governance. After acceptance, materialize one idempotent manifest that installs shared dependencies, bootstraps two identical empty homes, and runs an independent per-user acceptance checklist after each person performs their own authentication.

On this page