Manager now exposes a Resource Grant manifest and the Agnet control-plane response carries runtime state, agent instances, and permission_manifest so frontend runs can submit bounded resource grants without plaintext credentials. Constraint: Manager remains the user console while NewAPI stays independent and OpenBao is referenced through secret_ref only. Rejected: platform-side high-risk approval | client approval is the product boundary; Agnet only validates approval evidence. Confidence: medium Scope-risk: moderate Directive: Do not mix child Agnet runtime model selection with NewAPI billing or expose OpenBao as a public route. Tested: git diff --check; jq empty locale JSON; go vet ./controller ./model ./router; go test -count=1 ./controller ./model ./router Not-tested: frontend typecheck/build because local node_modules tooling is absent and user requested builds happen on the VM. Co-authored-by: OmX <omx@oh-my-codex.dev>
Heicode Docs
当前 docs/ 只保留五类主线文档:
| 文档 | 用途 |
|---|---|
heicode.md |
Heicode 当前产品定位、系统边界和架构共识 |
plan.md |
按当前共识拆出的实施计划 |
heicode-runtime-auth-newapi-secret-design.md |
用户输入、登录用户复用、NewAPI 扣费映射、OpenBao 短期凭证注入边界 |
integration/Heicode-登录接口对接文档.md |
已上线登录接口对接文档 |
integration/agnet-platform-request-contract.md |
Manager 请求 Agnet 平台时携带的部署、日志、监控、事件与审计接口参数 |
deployment/azure-production-deploy-guardrails.md |
Azure VM / PostgreSQL / Redis / Agnet / NewAPI 生产部署前的安全守卫、环境变量注入和验证计划 |
旧 Agnet API 草案、旧里程碑、旧架构说明和旧上手材料不再作为实施依据。后续文档和实现以 heicode.md 与 plan.md 为准;生产部署操作以安全守卫文档约束,且不得覆盖产品/架构主线。
代码中的过渡期命名、旧接口注释或旧 UI 文案只作为现状参考;若与 heicode.md / plan.md 冲突,应先更新实现或另行补充当前主线文档,不得恢复旧 Agnet/M1-M5 草案作为依据。