paperclip/packages/db/src/migrations/meta
Dotta fdf8c8464d
feat(runner): add managed provider backends (#12699)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Paperclip Runner provides durable, provider-neutral agent
execution.
> - The current stack supports qualified local providers but omits the
managed provider paths from the integration branch.
> - Claude Managed Agents and AWS AgentCore need explicit profile
qualification, durable recovery, usage accounting, and cleanup controls.
> - This pull request adds those managed backends as the third part of
the Runner parity stack.
> - The benefit is managed execution without weakening the default-off
Runner rollout gate.

## Linked Issues or Issue Description

**Subsystem affected**

Cross-cutting: Runner, server orchestration, database profiles, CLI, and
adapter configuration UI.

**Problem or motivation**

The current Runner stack cannot select or execute the managed Claude
Agents API or AWS Bedrock AgentCore Harness backends. It also lacks
qualified profile storage and recovery checks for those remote
resources.

**Proposed solution**

Add qualified managed and remote profiles, API and CLI management, exact
provider selection, durable lifecycle handling, cumulative usage
accounting, bounded cleanup, and retention acknowledgement. Keep
`enableNativeRunner` default-off.

**Alternatives considered**

A direct copy of the old integration branch was rejected because its
provider contracts, model values, credential flow, and migration history
no longer match the current base. A single large parity pull request was
also rejected because stacked review keeps each subsystem bounded.

**Roadmap alignment**

This continues the existing Runner architecture and rollout work. It
does not introduce a separate execution system.

**Additional context**

This pull request is based on the merged #12691 and #12685 stack. It
also closes the delayed security-review findings reported on #12691 by
binding qualified ACPX and OpenCode launch artifacts to the bytes
actually executed. A GitHub search for managed agent, AgentCore, and
Claude managed work found no duplicate public issue or pull request.

## What Changed

- Add Claude Managed Agents and AWS AgentCore provider executors to
runnerd.
- Add qualified managed and remote profile storage, routes, OpenAPI
contracts, CLI commands, and migration 0237.
- Validate profile ownership, enabled state, exact qualified revision,
model, agent version, and secret binding before persistence and
recovery.
- Persist durable provider session and owned skill state for
restart-safe cleanup.
- Reconcile uncertain create responses and delete remote sessions before
owned skills.
- Track cumulative provider usage and enforce positive session spend
caps.
- Recover interrupted AgentCore usage at the next turn boundary by
charging the prior invocation ceiling exactly once; keep the session
gated until an explicit monotonic budget raise.
- Isolate AgentCore AWS configuration from host profiles and
credential-process/SSO configuration while preserving workload identity.
- Require OpenCode 1.18.17 and fixed build-owned provider-pack artifact
paths; remove the ambient executable override.
- Snapshot and content-verify ACPX and OpenCode commands, scripts, and
provider executables before launch. Linux executes sealed inherited
descriptors; macOS uses authenticated private snapshots with retry-safe
rematerialization at the spawn boundary.
- Persist canonical ACPX and OpenCode launch-profile digests, reject
drift across fresh recovery, and make recovery failures sticky.
- Close and journal unsafe ACPX active-turn recovery before any provider
bootstrap or reconnect.
- Add managed provider fields to the Runner configuration UI and
permission projection.
- Preserve the default-off `enableNativeRunner` experimental flag.

## Verification

- `pnpm -r typecheck`
- `pnpm build`
- Focused managed server, database, CLI, Runner TypeScript, Rust,
Claude, AgentCore, ACPX, OpenCode, process-supervisor, and
durable-recovery tests passed.
- `cargo test -p paperclip-runner-core --lib --locked` (160 tests)
- `cargo check --workspace --all-targets --locked`
- Native Codex integration tests passed (60 tests); native provider
tests passed (7 tests); server native-runtime tests passed (87 tests).
- Verified-launch replacement, nested-spawn retry, exact-version,
profile-drift, sticky-failure, and no-bootstrap active-recovery tests
passed.
- `git diff --check`
- The PR changes 91 files. `pnpm-lock.yaml` is unchanged. The Rust
workspace lockfile adds the approved `rustix` dependency used for safe
descriptor handling while `#![forbid(unsafe_code)]` remains enabled.

## Risks

- The provider APIs can change while they are in beta. Exact
qualification and fail-closed recovery checks limit drift.
- Remote cleanup can fail after a partial create. Durable ownership
inventories and retry-safe deletion preserve recovery state.
- Migration 0237 adds profile tables. The generated migration and
snapshot pass the repository migration checks.
- Managed execution can incur provider cost. Positive default spend caps
and explicit retention acknowledgement limit accidental use.
- An interrupted AgentCore invocation without final metadata is
conservatively charged to its active session ceiling. This can overstate
cost, but cannot undercount it; later work requires an explicit budget
increase.
- Linux qualified launches use sealed memory descriptors. macOS lacks
executable-descriptor APIs, so the runner uses owner-only private
snapshots and minimizes linked-path lifetime; hostile same-UID processes
remain outside the documented local-host trust boundary.
- The global Runner feature remains default-off.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, GPT-5, with tool use, code execution, and subagent review.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-09-02 00:48:30 -05:00
..
0000_snapshot.json Expand data model with companies, approvals, costs, and heartbeats 2026-02-17 09:07:22 -06:00
0001_snapshot.json Add agent runtime DB schemas and expand shared types 2026-02-17 12:24:38 -06:00
0002_snapshot.json Add agent runtime DB schemas and expand shared types 2026-02-17 12:24:38 -06:00
0003_snapshot.json Add issue identifiers, activity run tracking, and migration inspection 2026-02-19 09:09:26 -06:00
0005_snapshot.json Add agent config revisions, issue-approval links, and robust migration reconciliation 2026-02-19 13:02:14 -06:00
0006_snapshot.json Add agent config revisions, issue-approval links, and robust migration reconciliation 2026-02-19 13:02:14 -06:00
0007_snapshot.json Add agent task sessions table, session types, and programmatic DB backup 2026-02-19 14:01:40 -06:00
0008_snapshot.json Add secrets infrastructure: DB tables, shared types, env binding model, and migration improvements 2026-02-19 15:43:43 -06:00
0009_snapshot.json Add secrets infrastructure: DB tables, shared types, env binding model, and migration improvements 2026-02-19 15:43:43 -06:00
0010_snapshot.json chore: add assets/attachments DB migration, CLI docs, and lockfile 2026-02-20 10:33:36 -06:00
0011_snapshot.json feat: add project_goals many-to-many join table 2026-02-20 13:43:25 -06:00
0012_snapshot.json Implement issue execution lock with deferred wake promotion 2026-02-20 15:48:22 -06:00
0013_snapshot.json Implement issue execution lock with deferred wake promotion 2026-02-20 15:48:22 -06:00
0014_snapshot.json feat: add auth/access foundation - deps, DB schema, shared types, and config 2026-02-23 14:40:16 -06:00
0017_snapshot.json feat(db): enforce globally unique issue prefixes and identifiers 2026-02-23 16:08:10 -06:00
0018_snapshot.json feat: add issue labels (DB schema, API, and service) 2026-02-25 08:38:37 -06:00
0019_snapshot.json feat: add project workspaces (DB, API, service, and UI) 2026-02-25 08:38:46 -06:00
0020_snapshot.json feat: workspace improvements - nullable cwd, repo-only workspaces, and resolution refactor 2026-02-25 21:35:33 -06:00
0021_snapshot.json feat: per-issue assignee adapter overrides (model, effort, workspace) 2026-02-26 10:32:44 -06:00
0023_snapshot.json feat: join request claim secrets, onboarding API, and company branding 2026-02-26 16:33:20 -06:00
0024_snapshot.json Add touched/unread inbox issue semantics 2026-03-06 08:21:03 -06:00
0025_snapshot.json Persist issue read state and clear unread on open 2026-03-06 08:34:19 -06:00
0027_snapshot.json Add project-first execution workspace policies 2026-03-10 10:58:43 -05:00
0028_snapshot.json feat(issues): add issue documents and inline editing 2026-03-13 21:30:48 -05:00
0029_snapshot.json Merge remote-tracking branch 'public-gh/master' into paperclip-subissues 2026-03-14 12:24:40 -05:00
0030_snapshot.json Use asset-backed company logos 2026-03-16 09:25:39 -05:00
0031_snapshot.json Merge remote-tracking branch 'public-gh/master' into paperclip-subissues 2026-03-16 16:02:37 -05:00
0032_snapshot.json feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
0033_snapshot.json Fix budget incident resolution edge cases 2026-03-16 16:48:13 -05:00
0034_snapshot.json Fix budget incident resolution edge cases 2026-03-16 16:48:13 -05:00
0035_snapshot.json Merge remote-tracking branch 'public-gh/master' into paperclip-subissues 2026-03-16 17:19:55 -05:00
0036_snapshot.json Add instance experimental setting for isolated workspaces 2026-03-17 09:24:28 -05:00
0037_snapshot.json Add workspace operation tracking and fix project properties JSX 2026-03-17 09:36:35 -05:00
0038_snapshot.json Remove api trigger kind and mark webhook as coming soon 2026-03-20 06:54:03 -05:00
0039_snapshot.json Merge remote-tracking branch 'public-gh/master' into paperclip-routines 2026-03-20 15:04:55 -05:00
0040_snapshot.json Fix PR verify failures after merge 2026-03-20 13:40:53 -05:00
0041_snapshot.json Merge remote-tracking branch 'public-gh/master' into paperclip-routines 2026-03-20 15:04:55 -05:00
0044_snapshot.json Add browser-based board CLI auth flow 2026-03-23 08:46:05 -05:00
0045_snapshot.json Add the inbox mine tab and archive flow 2026-03-26 16:09:43 -05:00
0046_snapshot.json Merge public-gh/master into PAP-881-document-revisions-bulid-it 2026-03-31 07:31:17 -05:00
0047_snapshot.json Add feedback voting and thumbs capture flow 2026-04-02 09:11:49 -05:00
0048_snapshot.json feat(routines): add workspace-aware routine runs 2026-04-02 11:38:57 -05:00
0049_snapshot.json Add blocker relations and dependency wakeups 2026-04-06 09:03:13 -05:00
0050_snapshot.json Add project-level environment variables 2026-04-06 21:23:30 -05:00
0051_snapshot.json Speed up issue search 2026-04-06 21:25:41 -05:00
0052_snapshot.json Generate execution policy migration 2026-04-07 17:43:10 -05:00
0053_snapshot.json Persist non-issue inbox dismissals 2026-04-09 06:16:05 -05:00
0055_snapshot.json fix: harden heartbeat and adapter runtime workflows 2026-04-10 22:26:21 -05:00
0056_snapshot.json [codex] Improve workspace runtime and navigation ergonomics (#3680) 2026-04-14 12:57:11 -05:00
0057_snapshot.json feat: implement multi-user access and invite flows (#3784) 2026-04-17 09:44:19 -05:00
0058_snapshot.json [codex] Add run liveness continuations (#4083) 2026-04-20 06:01:49 -05:00
0060_snapshot.json Add first-class issue references (#4214) 2026-04-21 10:02:52 -05:00
0061_snapshot.json [codex] Harden heartbeat scheduling and runtime controls (#4223) 2026-04-21 12:24:11 -05:00
0072_snapshot.json [codex] Harden recovery issue handling (#4600) 2026-04-27 15:02:47 -05:00
0073_snapshot.json [codex] Split backend control-plane QoL slice (#4700) 2026-04-28 16:46:45 -05:00
0074_snapshot.json [codex] Split backend control-plane QoL slice (#4700) 2026-04-28 16:46:45 -05:00
0075_snapshot.json [codex] Add issue monitor liveness controls (#4988) 2026-05-03 08:58:53 -05:00
0077_snapshot.json Add routine revision history and restore flow (#5285) 2026-05-05 11:54:52 -05:00
0078_snapshot.json Add recovery handoff system notices (#5289) 2026-05-06 06:05:58 -05:00
0081_snapshot.json Add planning mode for issue work (#5353) 2026-05-06 07:01:28 -05:00
0091_snapshot.json [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
0092_snapshot.json Add accepted-plan decomposition exact-once guards and UI state (#6831) 2026-05-28 23:30:18 -07:00
0093_snapshot.json PAPA-430: workspace finalize gates + no-remote-git enforcement (#6969) 2026-05-29 08:25:29 -07:00
0095_snapshot.json Redact deleted issue comments 2026-06-05 03:20:46 +00:00
0096_snapshot.json Add missing migration snapshot for comment deletion 2026-06-05 03:20:46 +00:00
0098_snapshot.json Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
0099_snapshot.json Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
0193_snapshot.json feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
0198_snapshot.json feat(decisions): add queues and prioritized attention feed (#10651) 2026-08-01 20:37:39 -05:00
0199_snapshot.json feat(decisions): add queues and prioritized attention feed (#10651) 2026-08-01 20:37:39 -05:00
0200_snapshot.json feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
0201_snapshot.json fix(external-objects): refresh PR status labels (#10704) 2026-08-02 20:24:52 -07:00
0202_snapshot.json fix(external-objects): refresh PR status labels (#10704) 2026-08-02 20:24:52 -07:00
0205_snapshot.json feat(issues): contain cross-issue agent side effects (#10837) 2026-08-04 13:17:49 -05:00
0207_snapshot.json feat(secrets): add human-approved secret proposals (#9934) 2026-08-05 21:49:40 -05:00
0208_snapshot.json fix(server): add explicit review verdict policies (#10931) 2026-08-05 23:12:41 -05:00
0211_snapshot.json feat(apps): support multiple provider connections (#11060) 2026-08-07 16:28:04 -05:00
0213_snapshot.json feat(server): chunked resumable company import transfers (#11223) 2026-08-11 15:25:07 -07:00
0214_snapshot.json Add sandbox device-login for the Codex adapter (#11237) 2026-08-12 08:58:25 -07:00
0215_snapshot.json Add sandbox device-login for the Codex adapter (#11237) 2026-08-12 08:58:25 -07:00
0217_snapshot.json fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
0218_snapshot.json fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
0221_snapshot.json feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
0222_snapshot.json feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
0223_snapshot.json Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
0225_snapshot.json feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
0226_snapshot.json fix: preserve recovery retries across restarts (#11817) 2026-08-20 17:09:42 -05:00
0227_snapshot.json feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
0228_snapshot.json Repair the drizzle snapshot so generate emits no spurious migration (#12333) 2026-08-27 12:56:07 -07:00
0229_snapshot.json Repair the drizzle snapshot so generate emits no spurious migration (#12333) 2026-08-27 12:56:07 -07:00
0230_snapshot.json Add the Better Auth issuer column so signup and sign-in work (#12396) 2026-08-27 22:31:35 -07:00
0231_snapshot.json feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
0232_snapshot.json feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
0233_snapshot.json feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
0234_snapshot.json feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
0235_snapshot.json feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
0236_snapshot.json Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
0237_snapshot.json feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
_journal.json feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00