SkillAtlasSkill 详情

openrig-herdr

npm version npm downloads License: Apache 2.0 GitHub stars

审核状态:已审核Quality 80Security 80

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年10月1日

OpenRig

npm version npm downloads License: Apache 2.0 GitHub stars

A harness wraps a model. A rig wraps your harnesses. Define your agent team in YAML, boot it with one command. Claude Code and Codex in the same rig, managed as one system.

OpenRig is open-source software for building and running your own network of agents. It turns AI coding agents from a pile of terminal sessions into a persistent, organized team. Talk to a lead agent about the outcome you want; it can coordinate specialists across teams and bring you results and decisions that need your attention. Start with a repository and one useful change, then keep the team's work and context at the same addresses.

It's the open-source system behind my AI civilization experiments.

Guide: Getting started · Stuck? Help · Questions: Q&A · Updates and demos: @_feralmachine on X

See it running

The OpenRig TUI: the build rig as a graph, then as a table of seats with runtime, model, context and state, then one seat in detail (real recording, 10 seconds)

Start here: the guided first-use path: install, launch a two-agent team in your repository, and get one reviewed change.

Not setting this up today? Get the next walkthrough and occasional OpenRig updates → https://openrig.dev/follow

Install and first run

Requires Node.js 22 or 24 and tmux, on macOS or Linux. On a Mac with Apple silicon, use Node.js 22 (compatibility history). Native Windows is not supported yet, and WSL2 has not been tested. Launching a rig writes provider hooks and workspace trust settings. Before running the commands below, read what OpenRig changes on your machine and back up the relevant files.

npm install -g @openrig/cli
rig setup --dry-run

To install with Bun instead, run bun add -g @openrig/cli. OpenRig still runs on Node.js, so install Node.js 22 as well. Bun may block this package's postinstall script, in which case the Node.js and SQLite check described under what OpenRig changes on your machine does not run at install time.

Choose the working account you already have: Claude Code, Codex, or both. Reuse an explicit choice; no second subscription is required. rig setup --dry-run previews the broader setup, but applying rig setup checks both harnesses and cmux. It is optional for the selected-provider path.

Before launching, your agent asks once: “Allow your agents to run OpenRig commands without repeated permission prompts?” Yes — recommended / No — keep prompts. This covers every rig command, including starting/stopping agents and configuration, at personal project scope unless you explicitly choose user-wide sessions. It is not global YOLO or permission to invent work. On Yes, the agent adds and verifies native rules; No or no answer leaves settings unchanged. An existing explicit choice is reused. Say “Undo the OpenRig command allowances added by this setup” to remove only its additions.

Check tmux -V and only your selected CLI/login: claude --version plus claude auth status, or codex --version plus codex login status. If needed, sign in once with claude auth login or codex login; do not install or log in to an unused provider.

TeamStarterModels
Two Codex agentsfirst-projectBoth gpt-6-astra (unchanged)
Two Claude agentsfirst-project-claudeConfigured native Claude default
Claude owner + Codex checkerfirst-project-mixedClaude default + gpt-6-astra

All three use the same owner/checker roles and task. Show the selected runtime, configured model and command before launch; confirm the account supports the model instead of silently falling back. The kernel starts automatically and selects from available authenticated providers independently of these two project agents. A missing unused provider is not a setup requirement.

cd /path/to/your/repository
starter=first-project  # or first-project-claude or first-project-mixed
rig specs preview "$starter" --kind rig
rig up "$starter" --cwd . --plan
rig up "$starter" --cwd .
rig tui --shared

The kernel provides separate operational support and the shared dashboard. To detach without stopping the dashboard, press Ctrl-b then d; rig tui --shared returns to that view. Plain rig tui opens an independent view. Closing a viewing terminal does not mean you should relaunch the team.

Check project-seat readiness with rig ps --nodes --rig "$starter" and resolve any authentication, trust or permission prompt before assigning work. Then give the owner one bounded outcome from your repository:

rig send "dev-owner@$starter" 'Implement <one useful change>. Track the task in the queue and return its ID. Keep it local, verify the behavior, ask dev-check in this rig to check the exact candidate, and record the result and how I can try it.'
rig queue list --destination "dev-owner@$starter" --limit 1000

Sending a message does not itself create a queue item; the owner records the task. Read the final artifact and the review of its exact candidate, then return to the same owner for the next change. The guided first-use path covers readiness, a useful task, a reviewed result, Herdr/cmux terminals and recovery.

Not setting this up today? Get the next walkthrough and occasional OpenRig updates → https://openrig.dev/follow

Community

We aim to acknowledge issues and pull requests within one day; see CONTRIBUTING.md for review targets.

What OpenRig changes on your machine

OpenRig writes instance state, provider integration and workspace files as part of setup and operation. These include trust settings and executable hooks. The summary below follows this source revision; check rig --version when using a published package, since repository guidance can be ahead of npm.

WhenWhat changes and why
npm installationInstalls the CLI, bundled components and dependencies under your npm prefix (with Bun, under Bun's global directory). OpenRig's postinstall checks the Node.js version and that the SQLite module loads; Bun may block this script. It does not run daemon or provider setup.
rig setupAttempts missing tools and writes an OpenRig block in ~/.tmux.conf for mouse support and scrollback. On macOS it can install cmux and enable its automation socket control in ~/.config/cmux/settings.json. --full adds workstation tools. --dry-run shows setup's plan without applying it.
Daemon startupCreates/updates instance state under OPENRIG_HOME (normally ~/.openrig), including its database and managed plugin resources. Seeds the openrig-skills discovery skill in ~/.claude/skills and ~/.agents/skills, subject to existing version ownership. With runtime.codex.hooks_enabled enabled (the default), writes Codex hook configuration and trust records as described below—even before a rig launches.
Rig/seat launch and attachmentCreates tmux sessions, supplies seat identity and daemon connection environment, and projects selected guidance, skills, plugins and runtime resources into the workspace. Managed startup pre-trusts the workspace. Claude context collection can also be provisioned for attached sessions and refreshed during monitoring.
Explicit permission configurationThe built-in bootstrap does not add rig command allow rules. Agent-guided setup recommends Yes and requires your actual answer before the agent adds rules at your chosen scope. No/no answer preserves settings; existing choices and stricter rules remain relevant. Broader access is separate.

The provider files are separate from instance state. Here ~ means the daemon user's home; changing OPENRIG_HOME alone does not isolate provider configuration.

  • Claude Code: managed startup writes workspace trust and onboarding completion to ~/.claude.json. In the workspace, .claude/settings.local.json receives the context collector's statusLine command and selected activity hooks; helper scripts live under .openrig/. Selected settings/MCP resources can also change that settings file and .mcp.json. The shared settings resource sets permissions.defaultMode to acceptEdits and enables Exa/Context7 MCP entries; selected MCP resources configure those external services. Built-in bootstrap no longer writes a command allowlist to ~/.claude/settings.json or removes older allowances. The trust writer uses the daemon home, so a custom CLAUDE_CONFIG_DIR is not a general relocation of these writes.
  • Codex: writes the daemon's CODEX_HOME/config.toml (normally ~/.codex/config.toml). Startup enables hooks, adds the OpenRig activity relay commands and pre-writes trust hashes for those commands. Seat startup adds trust_level = "trusted" for the workspace; selected config resources can add MCP settings. Recognized update notices can be skipped during launch, recording the skipped version in Codex's cache; this is not an update install.

Activity relays send event type/subtype, seat/runtime identity, timestamps and native session identity to the configured OpenRig daemon's /api/activity/hooks endpoint, using its activity token. That payload excludes prompt text and tool arguments. Claude's collector writes context/token usage, session/transcript-path metadata and available rate-limit data to the instance's state/context-usage and state/provider-usage. Provider and selected MCP connections have their own data flows. Daemon plugin initialization also checks the OpenRig plugin release endpoint on GitHub.

Managed launches supply HOME, CODEX_HOME and OPENRIG_* identity/connection variables. Claude uses --permission-mode acceptEdits and defaults to the classic renderer for terminal scrollback. Codex uses -s workspace-write unless a named profile governs its sandbox; the default does not force an approval-policy flag. Fresh Codex launches also add writable access to the workspace's .git and the pod's shared queue-state directory with --add-dir; the shared root comes from OPENRIG_SHARED_DOCS_ROOT or ~/.openrig/shared-docs. YOLO is off by default. An explicitly selected full-bypass policy selects Claude's --dangerously-skip-permissions or Codex's -s danger-full-access -a never. The legacy environment-only OPENRIG_YOLO=1 path still selects only Codex's sandbox; a resolved policy overrides that environment setting.

Permission mode controls native execution permissions; work posture is separate project guidance. Use rig policy permissions list|show|current|apply for rig policy configuration (the four rig policy aliases remain compatible). Use rig seat set-permissions <seat> --mode <mode> --reason <text> for an audited future-launch choice: floor, full_bypass, or inherit to clear the seat override. Additional Claude modes such as auto require support from the exact managed Claude executable at the seat's working directory; selection and launch each check it. Unsupported or changed contexts refuse without a fallback. This does not relaunch the seat or change its current native process, history, rules or hooks. rig seat status separates the desired selection from the last launch arguments; neither proves native enforcement. See the permission guide.

Managed hook blocks target OpenRig's entries and retain unrelated hooks, but trust entries, selected resource keys and Claude's existing status-line command can be replaced. Some writers recover unreadable settings as empty objects; this is not a complete preservation or rollback guarantee. Back up relevant files before first use. Daemon/bootstrap writes are automatic and do not each have an interactive preview; rig setup --dry-run does not preview every later startup effect.

What It Does

OpenRig is a multi-agent harness — it manages the system that coding agents form when you run them together. Not the agents themselves, but the team they create: which sessions are running, how they relate, how to recover after a reboot, and how to stop it from becoming terminal sprawl.

  • Define topologies in YAML (RigSpec) with pods, edges, and continuity policies
  • Boot everything with rig up — tmux sessions, harnesses, startup files, readiness checks
  • See rigs, pods, and seats in the TUI topology table and graph; inspect projects, specs, feeds, and instance health
  • Discover existing Claude Code and Codex sessions in tmux and adopt them into a managed rig
  • Snapshot the topology with rig down --snapshot, restore by name with rig up <name>
  • Communicate across agents with rig send, rig broadcast, and rig chatroom
  • Protect a seat where you type by hand: rig seat set-typing-guard <seat> --enabled true --reason <text> holds automatic messages and wakes instead of typing them into that seat (off by default; see rig seat set-typing-guard --help)
  • Connect Slack through an app you create in your own workspace; the experimental rig slack manifest prints that app's manifest (setup guide)
  • Evolve running topologies with rig grow, rig shrink, rig launch, rig remove

Every agent runs in a tmux session you can attach to, inspect, and work with directly.

Starter Rigs

Use first-project, first-project-claude, or first-project-mixed for the same focused first-use path on your selected providers. product-team is an optional larger product-development example:

rig specs preview product-team --kind rig
rig up product-team

Use it when you want a larger product squad: two orchestrators, implementation, QA, design, and two independent reviewers.

For a smaller starter, use conveyor:

rig specs preview conveyor --kind rig
rig up conveyor

conveyor is a four-seat starter mixing Claude Code and Codex. It shows a handoff path through intake, planning, build, and review; first-project remains the smaller two-seat starting point.

Also ships: implementation-pair, adversarial-review, research-team, and secrets-manager (HashiCorp Vault managed by a specialist agent).

Browse the library:

rig specs ls

How It Works

OpenRig is a local daemon + CLI + terminal UI + MCP server, built on tmux. The older React web UI remains in maintenance mode with best-effort support.

CLI / TUI / MCP
      |
Hono HTTP daemon
      |
  Domain services
      |
  SQLite + tmux + runtime adapters
  • CLI: Commands for both humans and agents to launch teams, inspect state, send messages, track owned work, and manage context.
  • TUI: Topology explorer, table and graph views, seat details, Specs, Projects, Terminals, Feed, and System. Navigate with the keyboard, mouse, or command bar.
  • MCP: Tools so agents can manage their own topology (rig_up, rig_ps, rig_send, rig_chatroom_send, etc.)
  • Runtimes: Native Claude Code and Codex sessions, terminal nodes, and Pi and Oh My Pi via RPC runners.

Terminal UI and Workspaces

The TUI shows the team's coordination state; herdr and cmux show the actual agent terminals alongside it. Use rig tui commands to list the TUI's command-bar navigation, or try the interactive TUI tour.

OpenRig TUI topology graph showing seven agent seats grouped into product, development, and QA pods

Captured from the interactive TUI demo using fictional project data.

With herdr installed and connected, open the starter's terminals together:

rig terminal open first-project --provider herdr

For cmux, use --provider cmux. In the TUI, a rig's detail view has a term ▸ rig <name> link that opens every running seat of that rig in the default terminal provider; with herdr that is up to 16 seats per tab, in a workspace named after the rig. The underlying sessions remain accessible through tmux. See the terminal workspace guide for setup and returning to an existing view.

Key Concepts

  • RigSpec: Declarative multi-agent harness definition in YAML. Pods, members, edges, continuity policies, culture file.
  • AgentSpec: Reusable agent blueprint with skills, guidance, hooks, profiles, and startup contracts.
  • Seat: A stable role and address in a rig, such as dev-owner@first-project. The conversation occupying it can change while its identity and authored context remain.
  • Pod: A group of related seats with shared guidance and context. Each agent still has its own context window.
  • Discovery: rig discover fingerprints existing tmux sessions. rig adopt brings them under management.
  • Snapshot/Restore: rig down --snapshot captures full state. rig up <name> restores from latest snapshot. Restore reports per-node outcomes (resumed, fresh, or failed).
  • RigBundle: Portable archive with vendored AgentSpecs and SHA-256 integrity. Share topologies across machines.
  • Culture: CULTURE.md sets coordination norms for the group. Research rigs get exploratory culture. Implementation rigs get conservative, trust-but-verify culture.

Agent-Managed Software

A rig can package actual software alongside the agents that manage it. The shipped example is secrets-manager: a HashiCorp Vault instance operated by a specialist agent.

rig up secrets-manager
rig env status secrets-manager
rig send vault-specialist@secrets-manager "Check Vault health and report status." --verify

Requires Docker for service-backed rigs.

Upgrading an existing instance

For an existing installation, follow the upgrade procedure and the 0.5.14 release notes. Preserve live seats during the upgrade; rig down is not an upgrade step. Upgrading to 0.6.0 also requires Node.js 22 or 24: see Moving off Node 20 and the 0.6.0 release notes.

Moving off Node 20

OpenRig 0.6.0 supports Node.js 22 and 24 only. Its SQLite binding (better-sqlite3 13) requires Node 22 or newer. Node 20 is no longer supported; the install check refuses it with an explanation.

If you run OpenRig on Node 20, switch Node first, then reinstall the CLI under the new Node (a version manager keeps a separate global package set for each Node):

nvm install 22          # or 24; fnm or your package manager work the same way
npm install -g @openrig/cli
rig --version

Your existing OpenRig data stays where it is. The daemon reopens the same database under the new binding and applies any pending migrations in place. Restart the daemon under the new Node by following the upgrade procedure above.

Crossing the 0.5.9 layout boundary

The migration below still applies when upgrading from a pre-0.5.9 instance.

0.5.9 makes $OPENRIG_HOME/context the addressable context library, writes Claude telemetry to state/context-usage (and provider telemetry to state/provider-usage), and installs the default System World at context/system/system-world.yaml. Existing instances cross this boundary by an Agent-Operated Migration from the shipped openrig-upgrade skill. The target runtime reads canonical-first with legacy-fallback while new writes use the canonical roots; a custom context-library root stays stable during activation. This is not a directory rename to do while an old collector writes.

# SKILL_DIR is the installed openrig-upgrade skill directory.
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --help
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --home "$OPENRIG_HOME"
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --home "$OPENRIG_HOME" --apply-state --preimage /safe/path/layout-0.5.9-before

# Activate the exact target runtime separately. After every bounded legacy tail is followed by newer paired samples at both new state roots:
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --home "$OPENRIG_HOME" --verify --preimage /safe/path/layout-0.5.9-before > /safe/path/layout-0.5.9-verify.json

# Run the separately invoked non-destructive finalizer only with that exact receipt:
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --home "$OPENRIG_HOME" --apply-library --preimage /safe/path/layout-0.5.9-before --verification /safe/path/layout-0.5.9-verify.json

# Restore only helper-owned preparation/finalizer effects if the observed upgrade must be reversed:
node "$SKILL_DIR/scripts/migrate-telemetry-state-0.5.9.mjs" --home "$OPENRIG_HOME" --rollback /safe/path/layout-0.5.9-before

--help prints the phase grammar without inventorying the instance. No phase flag intentionally runs the read-only plan; unknown options fail nonzero before plan or mutation.

Every phase emits JSON. Stop on any issue or incomplete receipt and follow its next action; do not continue from copied legacy telemetry or retry a partial mutation blindly. Preparation leaves legacy state and collector settings in place. Verification accepts exact tail bytes only when that same seat has newer paired context and provider samples under state/; finalization revalidates the accepted tails, copies the library without overwrite, and switches config last. The helper never removes the legacy telemetry or library. Retirement follows separate stable runtime, writer, reader, and recovery proof. Daemon, database, seat, plugin, and release lifecycle actions remain agent-owned.

Requirements

  • Node.js 22 or 24 (the supported versions in this release). Node 20 is no longer supported. Node 26 and other versions are untested. On a Mac with Apple silicon, use Node.js 22: see the compatibility history.
  • tmux
  • macOS or Linux. Native Windows is not supported yet, and WSL2 has not been tested

Optional:

  • herdr or cmux for terminal workspaces showing the agents together
  • Docker for service-backed rigs and managed apps

Setup and Troubleshooting

  • rig setup attempts core machine preparation: tmux, cmux, Claude Code, Codex, and tmux defaults. It reports what it tried and what actually succeeded. If something fails, it gives the local agent enough context to finish the job.
  • rig setup --full attempts a broader operator workstation setup (jq, gh) on top of core.
  • rig doctor inspects current system health and helps diagnose problems after setup. Use it when something stops working or after machine changes.

Both commands support --json for agent-driven workflows.

Before setup or managed launch, review what OpenRig changes on your machine, including provider trust, hooks and selected runtime resources.

Already-running adopted sessions may need restart before they pick up newly written runtime config.

For agents: First ask which available provider(s) the user wants, reusing an explicit choice. Recommend the working account they already have and follow the selected-provider guide above. Offer core setup (rig setup) or the fuller workstation path (rig setup --full) only when they want those additional tools. Inspect the result with --json and use rig doctor to finish any remaining machine-specific issues. When OpenRig itself misbehaves, read docs/reference/help.md (installed agents can run rig context get help; the same text is at openrig.dev/help/agents): it covers the next step, known problems, and how to reach the team if you're still stuck.

Comparison with Claude Managed Agents

OpenRig is open source and self-hosted, with Claude Code and Codex in the same team. You operate it on your own infrastructure; the selected providers' model usage costs still apply.

Full comparison

Links

Star History

Star History Chart

License

Apache 2.0

其他

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:1 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mvschwarz/openrig.git
  3. 将 "skills/_canonical/core/openrig-herdr" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mvschwarz/openrig.git
  3. 将 "skills/_canonical/core/openrig-herdr" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mvschwarz/openrig.git
  3. 将 "skills/_canonical/core/openrig-herdr" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mvschwarz/openrig.git
  3. 将 "skills/_canonical/core/openrig-herdr" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/mvschwarz/openrig.git
  3. 将 "skills/_canonical/core/openrig-herdr" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: openrig-herdr
description: >
  Use when opening OpenRig fleet terminals as a herdr wall — turning a rig, pod, mission, slice, or
  saved view into live interactive agent tiles via `rig terminal`, watching another rig read-only,
  or driving herdr on an agent's request ("open all my rigs + a mission as views"). Covers the
  `rig terminal open|views|status` verbs, the honest-partial/degrade reading of the result, the
  read-only-by-construction rail for cross-rig views, scroll/copy out of the box, and the
  same-size-only duplicate-pane limit. herdr is the default, proof-gated provider.
metadata:
  openrig:
    stage: candidate
    sibling_skills:
      - openrig-cmux
      - openrig-user

openrig-herdr

OpenRig decides which agents make up a view (a rig, a pod, a mission, a slice, or a saved group); herdr renders the pixels. A view opens as live, interactive terminal tiles — each tile is a nested tmux attach to a daemon-owned agent session, so you get the real session, not a snapshot. OpenRig owns the semantics; herdr owns the surface. You drive it entirely through the rig terminal CLI, which rides the installed herdr binary at arm's length — never link, embed, or plugin it.

The whole surface — three verbs

rig terminal open <view> [--provider herdr|cmux] [--json]   # herdr is the default provider
rig terminal views [--json]                                 # list openable views (saved + derived)
rig terminal status [--provider] [--json]                   # provider liveness / health

<view> resolves, in order, to one of:

  • a rig name — every live agent in that rig, auto-laid-out;
  • pod:<rig>/<podNamespace> — every live agent in one pod of a rig (the rig's inventory filtered by pod);
  • mission:<id> — the agents working that mission (derived live from topology);
  • slice:<id> — the agents working that slice (derived live);
  • a saved-view name — a user-defined group (see Saved views).

Compose a view from a sentence

An agent asked "open all my rigs plus a mission as views" runs one open per target:

rig terminal open acme-web                     # a whole rig, live agents as tiles
rig terminal open mission:site-relaunch        # exactly the agents working the mission
rig terminal open slice:search-filters      # the agents working one slice

No hand-listing of seats: the mission/slice membership is derived from live topology at open time.

Read the result honestly — partial and degrade

The result is a partition — every seat lands in exactly one bucket, each named:

  • opened — the live agents now showing as tiles.
  • absent — seats in the view that aren't currently live: named and skipped, never silently dropped. A view that opens some of its seats is a success (the partial is disclosed) and exits 0. Only a view where no pane opens exits non-zero.
  • degraded — an agent that structurally cannot tile, named with the reason. The v1 case: an agent on a host registered over HTTP has no ssh path, so its tile can't be composed — it reads as "host <id> is http-registered; tiles need ssh" and is skipped, never dropped. (ssh-reachable hosts tile via an ssh-wrapped attach; full http-host tiling is deferred to the cross-host transport seam.)

Read --json to branch on the partition programmatically; the exit code alone tells you opened-something (0) vs opened-nothing (non-zero).

Read-only — who's interactive, who's watch-only

Read-only is composed into the pane at open time — a read-only tile is a tmux attach -r, the client reports readonly=1, and it physically cannot send input. The current policy, by view kind:

  • A rig view or a pod: view is interactive — you asked for that rig (or pod) directly, so you can drive its agents.
  • mission: and slice: views are read-only by construction — these derived views cut across rigs; you watch and scroll, you don't keystroke into them.
  • A saved view is per-member — each member carries its own readOnly (omit = interactive; true = attach -r).

So you don't have to remember to be careful: the view kind (and, for a saved view, the per-member flag) sets it at open time.

Safety rails (hard — the fleet-safety rail)

  • A tile is a view (a nested tmux attach) of a daemon-owned session. Never move, join, kill, or re-parent a daemon-owned pane. Closing a tile detaches one tmux client — the daemon's session is untouched and its addressing (send/capture/nudge) is unaffected.
  • Host-local read-only viewing mutates nothing. Anything that would change a live daemon session's shared state (e.g. flipping a tmux option on a running seat) is a config/design change — prove it in an isolated environment, never live-flip in production.

Scroll + copy work out of the box

On a freshly-launched agent tile the mouse wheel scrolls the pane's history and a drag-select copies to your system clipboard — with no tmux commands typed. This rides the daemon's terminal defaults (a per-session scroll option set at launch, plus the daemon tmux server's clipboard defaults). Honest timing: agents that were already running before this shipped pick up wheel-scroll at their next natural relaunch (the scroll default is per-session and running seats are never retro-flipped); system-clipboard copy works immediately (it's server-wide).

Limits — state them, don't paper over them

  • Tile chrome v1 = a plain label (agent + slice). Rich per-tile status is roadmap.
  • Duplicate / multi-view membership (the same agent live in two views at once) works — put the duplicates in same-size panes. Different-sized duplicate panes have an inherent tmux multi-client resize mismatch (tmux clamps to the smallest client); it is documented, not fixed — don't expect a setting to remove it.
  • Inner tmux status bar is hidden by default (herdr provides the chrome); one config key (terminal.status_bar) flips it back on for raw-tmux / no-provider surfaces, and the flip applies to future launches only.

Saved views — the library (terminal-views.yaml)

In v1 you create a saved view by hand-authoring terminal-views.yaml — there is no save/write verb (open / views / status are the whole surface; a rig terminal save <id> verb is a named stretch/follow-up). You reopen it like any other view: rig terminal open <id>.

The file lives at the OpenRig home root (resolved via getDefaultOpenRigPath()), is written atomically (tmp + rename), and is byte-stable. Only hand-authored saved views live here — derived views (a rig, pod:<rig>/<pod>, mission:<id>, slice:<id>) are computed live and never written to this file.

Schema — use these field names exactly, in this order; omit optional fields when absent (never write null):

version: 1
views:
  - id: my-view-id             # required — the id `rig terminal open <id>` takes
    name: Human Name           # required
    members:
      - seat: pod-member@rig    # required — the canonical session name
        label: agent . slice    # optional — pane label
        host: some-host-id      # optional — STRUCTURED host id (NEVER a `member@rig@host` string);
                                #            omit for local. ssh-registered hosts tile;
                                #            http-registered hosts honest-degrade (named + skipped, with reason)
        tmuxSession: sessname   # optional — defaults to `seat`
        readOnly: true          # optional — omit = interactive; true = `tmux attach -r`

An agent composing a saved view on request writes this YAML and then opens the id: rig terminal open my-view-id (add --provider cmux for cmux). The library is provider-agnostic — the same saved view opens in herdr or cmux.

AGPL / clean-room

Driving herdr through the rig terminal CLI (which talks to the installed herdr binary over its CLI/socket) is arm's-length and fine. Do not link herdr's source, embed it in-process, or ship a herdr plugin — a plugin needs legal review. This skill and its docs are clean-room: patterns only, never herdr source text.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!