[{"data":1,"prerenderedAt":627},["ShallowReactive",2],{"navigation_docs":3,"-reference-configuration-repos-workspaces":270,"-reference-configuration-repos-workspaces-surround":622},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":152,"body":272,"description":615,"extension":616,"links":617,"meta":618,"navigation":619,"path":153,"seo":620,"stem":154,"__hash__":621},"docs\u002F4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces.md",{"type":273,"value":274,"toc":611},"minimark",[275,288,295,393,485,492,499,523,526,531,547,576,582,585,588,597,607],[276,277,278,279,283,284,287],"p",{},"A workspace is a root repository with other repositories mounted in it as submodules, declared beside the ",[280,281,282],"code",{},"repos:"," list in ",[280,285,286],{},"repos.yaml",".",[276,289,290,291,294],{},"Entries are named by ",[280,292,293],{},"id",":",[296,297,302],"pre",{"className":298,"code":299,"language":300,"meta":301,"style":301},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","workspaces:\n  product:\n    root: product\n    root_pointer_default: ignore     # or bump\n    members:\n      api: { repository: api, path: services\u002Fapi }\n","yaml","",[280,303,304,317,325,337,352,360],{"__ignoreMap":301},[305,306,309,313],"span",{"class":307,"line":308},"line",1,[305,310,312],{"class":311},"swJcz","workspaces",[305,314,316],{"class":315},"sMK4o",":\n",[305,318,320,323],{"class":307,"line":319},2,[305,321,322],{"class":311},"  product",[305,324,316],{"class":315},[305,326,328,331,333],{"class":307,"line":327},3,[305,329,330],{"class":311},"    root",[305,332,294],{"class":315},[305,334,336],{"class":335},"sfazB"," product\n",[305,338,340,343,345,348],{"class":307,"line":339},4,[305,341,342],{"class":311},"    root_pointer_default",[305,344,294],{"class":315},[305,346,347],{"class":335}," ignore",[305,349,351],{"class":350},"sHwdD","     # or bump\n",[305,353,355,358],{"class":307,"line":354},5,[305,356,357],{"class":311},"    members",[305,359,316],{"class":315},[305,361,363,366,368,371,374,376,379,382,385,387,390],{"class":307,"line":362},6,[305,364,365],{"class":311},"      api",[305,367,294],{"class":315},[305,369,370],{"class":315}," {",[305,372,373],{"class":311}," repository",[305,375,294],{"class":315},[305,377,378],{"class":335}," api",[305,380,381],{"class":315},",",[305,383,384],{"class":311}," path",[305,386,294],{"class":315},[305,388,389],{"class":335}," services\u002Fapi",[305,391,392],{"class":315}," }\n",[394,395,396,409],"table",{},[397,398,399],"thead",{},[400,401,402,406],"tr",{},[403,404,405],"th",{},"Key",[403,407,408],{},"Meaning",[410,411,412,423,439,461,475],"tbody",{},[400,413,414,420],{},[415,416,417],"td",{},[280,418,419],{},"workspaces.\u003Cname>",[415,421,422],{},"The workspace's name.",[400,424,425,430],{},[415,426,427],{},[280,428,429],{},"root",[415,431,432,433,435,436,438],{},"The ",[280,434,293],{}," of the root repository's ",[280,437,282],{}," entry.",[400,440,441,446],{},[415,442,443],{},[280,444,445],{},"root_pointer_default",[415,447,448,451,452,455,456,287],{},[280,449,450],{},"ignore"," (default) or ",[280,453,454],{},"bump",": what happens to the root's submodule pointers after members merge. See ",[457,458,460],"a",{"href":459},"#publication","Publication",[400,462,463,468],{},[415,464,465],{},[280,466,467],{},"members.\u003Cname>.repository",[415,469,432,470,472,473,438],{},[280,471,293],{}," of the member's ",[280,474,282],{},[400,476,477,482],{},[415,478,479],{},[280,480,481],{},"members.\u003Cname>.path",[415,483,484],{},"Where the member mounts in the root.",[276,486,487,488,491],{},"Connecting a repo that has submodules declares its workspace for you, each\nsubmodule a member. A submodule you already connected on its own, as a clone\nelsewhere with the same origin, is that member, settings and all; Kraft adds\nan entry for the submodule's own checkout only when it finds none. When you file a work item against the root, you choose which\nmembers it changes and its root-pointer policy (the workspace's default unless\nyou pick one); both are frozen into the item. The item's worktree holds exactly\nthose members, each on the item's branch, and a task with ",[280,489,490],{},"scope: each_repository"," runs once per selected repository.",[276,493,494,495,498],{},"Kraft checks each member out as a worktree of its connected repository, the\nsame way it checks out the root. So the item's branch exists in that\nrepository too. Abandoning or archiving the item deletes the member's worktree\nand branch there, as long as the member is still connected; if you disconnect\nor move it first, remove them by hand. A member whose repository isn't\nconnected any more is checked out with ",[280,496,497],{},"git submodule update"," instead.",[276,500,501,502,504,505,508,509,512,513,516,517,519,520,287],{},"Every member mounts directly in the root. ",[280,503,286],{}," fails to load, and filing an item against that workspace is refused, when one member's ",[280,506,507],{},"path"," is inside another member's (",[280,510,511],{},"libs\u002Fa\u002Fvendor\u002Fx"," inside ",[280,514,515],{},"libs\u002Fa",") or two members share a ",[280,518,507],{},". The error names both members. A submodule nested in a member is part of that member's repository, so leave it out of ",[280,521,522],{},"members:",[276,524,525],{},"Each selected repository binds the tasks that run in it with its own policy\nlayer. A task in the assembled worktree, which holds all of them at once, runs\nunder the tightest of their layers: allowlists intersect, deny lists add up, and\nnumbers take their minimum.",[527,528,530],"h2",{"id":529},"sandboxing","Sandboxing",[276,532,533,534,537,538,541,542,546],{},"A workspace with members can be sandboxed like a single repository. A sandbox\non the root or on any member (",[280,535,536],{},"sandbox"," or ",[280,539,540],{},"policy.sandbox","), or one that comes\nfrom a chain, node or task, wraps the item's whole checkout. The container sees\neach member as it sees the root: the member's refs go through a\n",[457,543,545],{"href":544},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","ref store"," of its own, and\nthe files git trusts for it are read-only. Before Kraft runs git in a member, it\nchecks that the member is still the checkout Kraft made from its connected\nrepository. If it isn't, the item stops for a person, naming the member. A\nmember whose repository isn't connected stops a sandboxed item too: connect it,\nthen retry.",[276,548,549,550,553,554,557,558,557,561,553,564,567,568,571,572,575],{},"A sandboxed worker on a plain repository can still create a git repository of\nits own inside its worktree, and commit a gitlink to it. That nested\nrepository's config belongs to the worker. Kraft's own git therefore never\nworks inside a nested repository. Its status and diff calls compare only the\ncommit a gitlink records, and its automatic commit of leftover work skips\nnested repositories. The daemon pins ",[280,551,552],{},"submodule.recurse",",\n",[280,555,556],{},"fetch.recurseSubmodules",", ",[280,559,560],{},"push.recurseSubmodules",[280,562,563],{},"diff.submodule",[280,565,566],{},"status.submoduleSummary"," and ",[280,569,570],{},"diff.ignoreSubmodules",", whatever your own git\nconfig says. If a sandboxed item's worktree holds a nested repository Kraft did\nnot create, the item stops for a person, and the stop names the paths. That\nincludes an untracked one, a populated gitlink, or a gitlink the branch added\nor moved. Remove them, or ",[280,573,574],{},"git rm --cached"," the gitlinks, and retry. A\nsubmodule your repository already had, left unpopulated, doesn't stop anything.",[276,577,578,579,581],{},"While one of a sandboxed item's sessions is still running, Kraft runs no git in\nits worktree at all. When one of those sessions ends, Kraft may move the item's\nbranch in your repository to the commit the worker left, through the\n",[457,580,545],{"href":544},", without reading\nthe worktree. The diff view answers that the diff is available once the\nsandboxed session ends. A task that needs the review package stops for a\nperson, and the sweep of leftover work waits for the last task of the step.",[276,583,584],{},"Under a sandbox, the clean check before a merge request no longer looks for\nuncommitted edits inside a submodule. It still catches a submodule whose commit\nmoved, and each declared workspace member is checked on its own. Leftover work\nis no longer committed into a submodule's pointer unless that submodule is one\nof the item's declared members.",[527,586,460],{"id":587},"publication",[276,589,590,591,593,594,596],{},"Publication goes members first. A member's merge request merges before the root\nmoves. A root with source changes of its own gets its own merge request, and it\nstays a draft until every member has merged and the root names their merged\nrevisions. A root whose only change is the members' pointers follows the item's\nroot-pointer policy: ",[280,592,450],{}," leaves it alone, and ",[280,595,454],{}," pushes the new pointers\nto its default branch. If that push is refused, it opens a merge request for them\ninstead. A member that fails to merge stops publication and leaves the root\nuntouched.",[276,598,599,600,602,603,606],{},"A ",[280,601,286],{}," from before workspaces still loads, but an item with submodules needs a declared workspace. Declare it in ",[280,604,605],{},"workspaces:",", or reconnect the root, which loses its settings.",[608,609,610],"style",{},"html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":301,"searchDepth":319,"depth":319,"links":612},[613,614],{"id":529,"depth":319,"text":530},{"id":587,"depth":319,"text":460},"Declare a root repository with member submodules in repos.yaml, and what it means for sandboxing and publication.","md",null,{},true,{"title":152,"description":615},"0WIpVx7uCGaNLOdMNSuRATl0qYPWLHYxtYoqMH2B3jY",[623,625],{"title":10,"path":147,"stem":148,"description":624,"children":-1},"Every field in repos.yaml, and how kraft repo connect fills it in.",{"title":156,"path":157,"stem":158,"description":626,"children":-1},"Every field in policy.yaml: caps, budget, archiving, defaults, maxima, and triggers.",1790824544701]