paperclip/packages/db/src/schema
Dotta fdf8c8464d
feat(runner): add managed provider backends (#12699)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Paperclip Runner provides durable, provider-neutral agent
execution.
> - The current stack supports qualified local providers but omits the
managed provider paths from the integration branch.
> - Claude Managed Agents and AWS AgentCore need explicit profile
qualification, durable recovery, usage accounting, and cleanup controls.
> - This pull request adds those managed backends as the third part of
the Runner parity stack.
> - The benefit is managed execution without weakening the default-off
Runner rollout gate.

## Linked Issues or Issue Description

**Subsystem affected**

Cross-cutting: Runner, server orchestration, database profiles, CLI, and
adapter configuration UI.

**Problem or motivation**

The current Runner stack cannot select or execute the managed Claude
Agents API or AWS Bedrock AgentCore Harness backends. It also lacks
qualified profile storage and recovery checks for those remote
resources.

**Proposed solution**

Add qualified managed and remote profiles, API and CLI management, exact
provider selection, durable lifecycle handling, cumulative usage
accounting, bounded cleanup, and retention acknowledgement. Keep
`enableNativeRunner` default-off.

**Alternatives considered**

A direct copy of the old integration branch was rejected because its
provider contracts, model values, credential flow, and migration history
no longer match the current base. A single large parity pull request was
also rejected because stacked review keeps each subsystem bounded.

**Roadmap alignment**

This continues the existing Runner architecture and rollout work. It
does not introduce a separate execution system.

**Additional context**

This pull request is based on the merged #12691 and #12685 stack. It
also closes the delayed security-review findings reported on #12691 by
binding qualified ACPX and OpenCode launch artifacts to the bytes
actually executed. A GitHub search for managed agent, AgentCore, and
Claude managed work found no duplicate public issue or pull request.

## What Changed

- Add Claude Managed Agents and AWS AgentCore provider executors to
runnerd.
- Add qualified managed and remote profile storage, routes, OpenAPI
contracts, CLI commands, and migration 0237.
- Validate profile ownership, enabled state, exact qualified revision,
model, agent version, and secret binding before persistence and
recovery.
- Persist durable provider session and owned skill state for
restart-safe cleanup.
- Reconcile uncertain create responses and delete remote sessions before
owned skills.
- Track cumulative provider usage and enforce positive session spend
caps.
- Recover interrupted AgentCore usage at the next turn boundary by
charging the prior invocation ceiling exactly once; keep the session
gated until an explicit monotonic budget raise.
- Isolate AgentCore AWS configuration from host profiles and
credential-process/SSO configuration while preserving workload identity.
- Require OpenCode 1.18.17 and fixed build-owned provider-pack artifact
paths; remove the ambient executable override.
- Snapshot and content-verify ACPX and OpenCode commands, scripts, and
provider executables before launch. Linux executes sealed inherited
descriptors; macOS uses authenticated private snapshots with retry-safe
rematerialization at the spawn boundary.
- Persist canonical ACPX and OpenCode launch-profile digests, reject
drift across fresh recovery, and make recovery failures sticky.
- Close and journal unsafe ACPX active-turn recovery before any provider
bootstrap or reconnect.
- Add managed provider fields to the Runner configuration UI and
permission projection.
- Preserve the default-off `enableNativeRunner` experimental flag.

## Verification

- `pnpm -r typecheck`
- `pnpm build`
- Focused managed server, database, CLI, Runner TypeScript, Rust,
Claude, AgentCore, ACPX, OpenCode, process-supervisor, and
durable-recovery tests passed.
- `cargo test -p paperclip-runner-core --lib --locked` (160 tests)
- `cargo check --workspace --all-targets --locked`
- Native Codex integration tests passed (60 tests); native provider
tests passed (7 tests); server native-runtime tests passed (87 tests).
- Verified-launch replacement, nested-spawn retry, exact-version,
profile-drift, sticky-failure, and no-bootstrap active-recovery tests
passed.
- `git diff --check`
- The PR changes 91 files. `pnpm-lock.yaml` is unchanged. The Rust
workspace lockfile adds the approved `rustix` dependency used for safe
descriptor handling while `#![forbid(unsafe_code)]` remains enabled.

## Risks

- The provider APIs can change while they are in beta. Exact
qualification and fail-closed recovery checks limit drift.
- Remote cleanup can fail after a partial create. Durable ownership
inventories and retry-safe deletion preserve recovery state.
- Migration 0237 adds profile tables. The generated migration and
snapshot pass the repository migration checks.
- Managed execution can incur provider cost. Positive default spend caps
and explicit retention acknowledgement limit accidental use.
- An interrupted AgentCore invocation without final metadata is
conservatively charged to its active session ceiling. This can overstate
cost, but cannot undercount it; later work requires an explicit budget
increase.
- Linux qualified launches use sealed memory descriptors. macOS lacks
executable-descriptor APIs, so the runner uses owner-only private
snapshots and minimizes linked-path lifetime; hostile same-UID processes
remain outside the documented local-host trust boundary.
- The global Runner feature remains default-off.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, GPT-5, with tool use, code execution, and subagent review.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-09-02 00:48:30 -05:00
..
activity_log.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
adapter_auth_sessions.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
agent_api_keys.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
agent_config_revisions.ts Add agent config revisions, issue-approval links, and robust migration reconciliation 2026-02-19 13:02:14 -06:00
agent_memberships.ts [codex] Add starred resource sidebar controls (#9085) 2026-07-06 14:09:11 -05:00
agent_runtime_state.ts Add agent runtime DB schemas and expand shared types 2026-02-17 12:24:38 -06:00
agent_task_sessions.ts Add agent task sessions table, session types, and programmatic DB backup 2026-02-19 14:01:40 -06:00
agent_wakeup_requests.ts fix(interactions): deliver question answers durably (#12307) 2026-08-27 12:12:21 -05:00
agents.ts fix(server): enforce agent secret binding sync across lifecycle flows (#8307) 2026-06-18 21:26:36 -07:00
approval_comments.ts Scaffold agent permissions, approval comments, and hiring governance types 2026-02-19 09:10:48 -06:00
approvals.ts Expand data model with companies, approvals, costs, and heartbeats 2026-02-17 09:07:22 -06:00
assets.ts feat: add storage system with local disk and S3 providers 2026-02-20 10:31:56 -06:00
auth.ts Add the Better Auth issuer column so signup and sign-in work (#12396) 2026-08-27 22:31:35 -07:00
board_api_keys.ts Address Greptile review on board CLI auth 2026-03-23 08:46:05 -05:00
budget_incidents.ts Fix budget incident resolution edge cases 2026-03-16 16:48:13 -05:00
budget_policies.ts feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
built_in_managed_resources.ts [codex] Add built-in agents and Reflection Coach bundle (#9206) 2026-07-09 16:29:30 -05:00
cases.ts Cases: experimental first-class case object (#9198) 2026-07-09 22:11:03 -05:00
cli_auth_challenges.ts Add browser-based board CLI auth flow 2026-03-23 08:46:05 -05:00
companies.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
company_logos.ts Use asset-backed company logos 2026-03-16 09:25:39 -05:00
company_memberships.ts feat: add auth/access foundation - deps, DB schema, shared types, and config 2026-02-23 14:40:16 -06:00
company_onboarding_seeds.ts feat(server): receive and apply the Paperclip Cloud onboarding seed (#11098) 2026-08-12 22:54:07 -07:00
company_secret_bindings.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
company_secret_proposals.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
company_secret_provider_configs.ts Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
company_secret_versions.ts Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
company_secrets.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
company_skill_policies.ts feat(skills): open-by-default company skill policy and core UX (#9564) 2026-07-15 11:42:40 -05:00
company_skills.ts feat(skills): add beta releases for the core Paperclip skill (#10228) 2026-07-27 19:45:59 -05:00
company_transfer_runs.ts feat(server): chunked resumable company import transfers (#11223) 2026-08-11 15:25:07 -07:00
company_user_sidebar_preferences.ts [codex] Improve workspace runtime and navigation ergonomics (#3680) 2026-04-14 12:57:11 -05:00
completion_contracts.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
cost_events.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
decision_queues.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
decision_training_examples.ts feat: add decision training snapshot foundation (#9702) 2026-07-17 12:17:34 -05:00
decisions.ts feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
document_annotation_anchor_snapshots.ts [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
document_annotation_comments.ts Cases: experimental first-class case object (#9198) 2026-07-09 22:11:03 -05:00
document_annotation_threads.ts Cases: experimental first-class case object (#9198) 2026-07-09 22:11:03 -05:00
document_memberships.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
document_revisions.ts fix: upstream deployed document-comment, routine-annotation, workspace & board-polling fixes (#8536) 2026-06-23 09:00:14 -05:00
documents.ts fix: upstream deployed document-comment, routine-annotation, workspace & board-polling fixes (#8536) 2026-06-23 09:00:14 -05:00
environment_custom_image_setup_sessions.ts Scope environment custom images to instance environments (#8850) 2026-07-01 23:57:31 -07:00
environment_custom_image_templates.ts Scope environment custom images to instance environments (#8850) 2026-07-01 23:57:31 -07:00
environment_leases.ts feat: Claude login on the new-agent page before agent creation (#11347) 2026-08-17 13:42:51 -07:00
environments.ts refactor(environments): make execution environments instance-scoped (#8375) 2026-06-20 09:42:53 -07:00
execution_workspace_runtime_leases.ts feat(runtime-exposure): least-privilege Tailscale HTTPS broker, shared contract, and persisted exposure state (#11524) 2026-08-17 05:54:12 -04:00
execution_workspaces.ts PAPA-430: workspace finalize gates + no-remote-git enforcement (#6969) 2026-05-29 08:25:29 -07:00
external_object_mentions.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
external_objects.ts fix(external-objects): refresh PR status labels (#10704) 2026-08-02 20:24:52 -07:00
feedback_exports.ts Add feedback voting and thumbs capture flow 2026-04-02 09:11:49 -05:00
feedback_votes.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
finance_events.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
folders.ts feat: organize skills with nested folders and My Skills (#9633) 2026-07-16 15:50:45 -05:00
goals.ts Expand data model with companies, approvals, costs, and heartbeats 2026-02-17 09:07:22 -06:00
heartbeat_run_events.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
heartbeat_run_watchdog_decisions.ts [codex] Add runtime lifecycle recovery and live issue visibility (#4419) 2026-04-24 15:50:32 -05:00
heartbeat_runs.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
inbox_dismissals.ts feat: add attention queue and Decisions surface (#9380) 2026-07-10 17:09:57 -05:00
index.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
instance_settings.ts refactor(environments): make execution environments instance-scoped (#8375) 2026-06-20 09:42:53 -07:00
instance_user_roles.ts feat: add auth/access foundation - deps, DB schema, shared types, and config 2026-02-23 14:40:16 -06:00
invites.ts feat: add auth/access foundation - deps, DB schema, shared types, and config 2026-02-23 14:40:16 -06:00
issue_approvals.ts Add agent config revisions, issue-approval links, and robust migration reconciliation 2026-02-19 13:02:14 -06:00
issue_attachments.ts feat: add storage system with local disk and S3 providers 2026-02-20 10:31:56 -06:00
issue_comments.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
issue_create_idempotency_keys.ts fix: prevent duplicate task creation and recovery loops (#9648) 2026-07-16 17:00:53 -05:00
issue_documents.ts feat(issues): add issue documents and inline editing 2026-03-13 21:30:48 -05:00
issue_execution_decisions.ts Add issue review policy and comment retry 2026-04-07 17:43:10 -05:00
issue_inbox_archives.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
issue_labels.ts feat: add issue labels (DB schema, API, and service) 2026-02-25 08:38:37 -06:00
issue_plan_decompositions.ts Add accepted-plan decomposition exact-once guards and UI state (#6831) 2026-05-28 23:30:18 -07:00
issue_question_response_deliveries.ts fix(interactions): deliver question answers durably (#12307) 2026-08-27 12:12:21 -05:00
issue_read_states.ts fix(issues): make DELETE /api/issues/:id succeed for issues with dependents (#11331) 2026-08-13 12:02:15 -07:00
issue_recovery_actions.ts [codex] Add source-scoped recovery actions (#5599) 2026-05-12 09:37:15 -05:00
issue_reference_mentions.ts Add first-class issue references (#4214) 2026-04-21 10:02:52 -05:00
issue_relations.ts fix: address greptile feedback for blocker dependencies 2026-04-06 09:03:13 -05:00
issue_thread_interactions.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
issue_tree_hold_members.ts [codex] Add issue subtree pause, cancel, and restore controls (#4332) 2026-04-23 14:51:46 -05:00
issue_tree_holds.ts [codex] Add issue subtree pause, cancel, and restore controls (#4332) 2026-04-23 14:51:46 -05:00
issue_watchdogs.ts fix(task-watchdogs): deduplicate unchanged stopped-state wakes (#10207) 2026-07-25 08:34:41 -05:00
issue_work_products.ts Add low-trust review containment (#7530) 2026-06-05 16:48:02 -05:00
issues.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
join_requests.ts feat: implement multi-user access and invite flows (#3784) 2026-04-17 09:44:19 -05:00
labels.ts feat: add issue labels (DB schema, API, and service) 2026-02-25 08:38:37 -06:00
managed_agent_profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
native_run_finalizations.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
native_run_results.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
pipeline_case_events.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
pipeline_cases.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
pipelines.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
plugin_company_settings.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
plugin_config.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
plugin_database.ts [codex] Add plugin orchestration host APIs (#4114) 2026-04-20 08:52:51 -05:00
plugin_entities.ts feat(security): plugin tables get company_id FK for tenant isolation (#5865) 2026-06-12 10:17:19 -07:00
plugin_jobs.ts feat(security): plugin tables get company_id FK for tenant isolation (#5865) 2026-06-12 10:17:19 -07:00
plugin_logs.ts feat(security): plugin tables get company_id FK for tenant isolation (#5865) 2026-06-12 10:17:19 -07:00
plugin_managed_resources.ts Expand plugin host surface (#5205) 2026-05-05 07:42:57 -05:00
plugin_state.ts Add plugin framework and settings UI 2026-03-13 16:22:34 -05:00
plugin_webhooks.ts feat(security): plugin tables get company_id FK for tenant isolation (#5865) 2026-06-12 10:17:19 -07:00
plugins.ts Add plugin framework and settings UI 2026-03-13 16:22:34 -05:00
principal_permission_grants.ts feat: add auth/access foundation - deps, DB schema, shared types, and config 2026-02-23 14:40:16 -06:00
project_goals.ts feat: add project_goals many-to-many join table 2026-02-20 13:43:25 -06:00
project_memberships.ts [codex] Add starred resource sidebar controls (#9085) 2026-07-06 14:09:11 -05:00
project_workspaces.ts Implement execution workspaces and work products 2026-03-13 17:12:25 -05:00
projects.ts Information Architecture + project/agent visual refresh (experimental) (#7543) 2026-06-06 09:17:27 -05:00
provider_trace_records.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
remote_agent_profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
routine_documents.ts fix: upstream deployed document-comment, routine-annotation, workspace & board-polling fixes (#8536) 2026-06-23 09:00:14 -05:00
routines.ts feat: organize skills with nested folders and My Skills (#9633) 2026-07-16 15:50:45 -05:00
secret_access_events.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
smoke_lab.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
status_cards.ts feat(status-cards): join summary-mentioned issues to watched set (#10205) 2026-07-24 16:44:56 -05:00
status_decision_effects.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
status_decisions.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
summary_slots.ts feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
tool_access.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
user_inbox_agent_policies.ts feat(authz): govern agent inbox archive access (#9658) 2026-07-16 09:51:48 -05:00
user_secret_declarations.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
user_secret_definitions.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
user_sidebar_preferences.ts [codex] Improve workspace runtime and navigation ergonomics (#3680) 2026-04-14 12:57:11 -05:00
work_assessments.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
workspace_operations.ts fix: upstream deployed document-comment, routine-annotation, workspace & board-polling fixes (#8536) 2026-06-23 09:00:14 -05:00
workspace_runtime_services.ts feat(runtime-exposure): least-privilege Tailscale HTTPS broker, shared contract, and persisted exposure state (#11524) 2026-08-17 05:54:12 -04:00