{"slug": "fluffles-os", "title": "Fluffles-OS", "summary": "DevelopIQ-ai deprecated the Fluffles autonomous agent harness for macOS, a public snapshot of the system as it ran on a Mac mini, and moved active development to the pure-eve rewrite DevelopIQ-ai/puffle-app, which shares no code with the original repository. The harness combined Slack, email, and phone channel adapters, a durable task ledger, MCP tool manifests, and a self-healing deployment pipeline that polled origin/main once a minute via the launchd service com.puffle.harness. Secrets, live runtime state, and credentials were never part of the repository, and environment-specific identifiers were replaced with placeholders.", "body_md": "Fluffles: an autonomous agent harness and execution environment for macOS — multi-channel communication (Slack, Email, Phone), a durable task ledger, and a self-healing deployment pipeline.\n\n**Deprecated.** This is a public snapshot of the Fluffles harness as it ran on a Mac mini. Active development moved to [DevelopIQ-ai/puffle-app](https://github.com/DevelopIQ-ai/puffle-app), a pure-eve rewrite that shares no code with this repo. Kept here for reference.\n\nSecrets, live runtime state, and credentials were never part of this repository; environment-specific identifiers have been replaced with placeholders.\n\n- `AGENTS.md` : standing operating contract and identity rules.\n- `agent/` : the composition layer whose slot files (`channels/` ,`executors/` ) wire the packages into the fluffles agent; see`agent/agent.md` .\n- `automations/` : one registry for schedules, events, http triggers, and manual runs, executed by`@fluffles/automations` .\n- `bin/` : thin command wrappers that define the harness cli surface.\n- `channels/` : every listener - Slack, email, and phone adapters, the webhook ingress service (`channels/webhooks/` ), and the local chat console (`channels/chat-console/` ).\n- `config/` : harness configuration such as`config/context-limits.json` .\n- `deploy/` : everything about running and proving the system - launchd service definitions, host files, the pinned Executor (`deploy/executor/` ), and verification scripts (`deploy/scripts/` , including`deploy/scripts/verify-source.sh` ).\n- `hooks/` : Codex hook entrypoints.\n- `memory/` : memory protocol docs, durable memory files, and daily notes.\n- `packages/` : self-contained capability packages (`@fluffles/*` ); see`packages/README.md` .\n- `skills/` : user-authored operational skills.\n- `subagents/` : folder-shaped specialist agents with scoped instructions and entrypoints.\n- `state/` : the structural skeleton of runtime state directories (including`state/browser/` , see`state/browser/README.md` ); live contents stay on the machine.\n- `test/` : harness-level tests.\n- `tools/` : the callable-tool surface - MCP manifests (`tools/mcp/manifests/` ), the harness charter (`tools/capabilities/harness.json` ), and one directory per tool with its docs and implementation (smoke lives at`tools/smoke/` , communication helpers at`tools/communications/` ).\n- `projects/` : one directory per project Fluffles owns, starting with`projects/fluffles-site/` (personal site source). Installed to`~/projects/` , alongside the runtime-owned checkout the deployer keeps there.\n\nConversation turns run with `~/work` as their working directory, created by the harness and not source-managed. Codex confines model-generated shell writes to the working directory plus the declared writable roots, which are `~/projects` and the temporary directories, so a turn reaches the ledger, the markdown memory, `~/auth`, and the installed harness only through the MCP tools the executor daemon runs outside the sandbox.\n\n- `$HOME/auth`\n- `$HOME/state` contents (only the directory skeleton is tracked)\n- `$HOME/Library`\n- `$HOME/.codex`\n- `$HOME/.amalgm`\n- raw transcripts, logs, caches, cookies, browser profiles, and OAuth state\n- the derived memory index (`state/memory/index.sqlite` ) and quarantined memory writes\n- `node_modules` , virtualenvs, external source payloads, generated app bundles\n- raw private communication contents\n\nthe excluded `$HOME/auth` and `$HOME/state` contents are runtime state on the machine. `$HOME/auth` has no tracked mirror: it holds only the Machine Identity bootstrap and disposable tool-owned auth state, documented in `packages/auth/INFISICAL.md`. the tracked `state/` tree is structure only: directories, docs, and non-secret automation config.\n\nAll work happens on a branch and enters `main` through a pull request. GitHub source checks run on every pull request. Only a merged `main` commit is eligible for deployment.\n\nThe Mac mini polls `origin/main` once a minute through the local `com.puffle.harness.deploy-main` launchd service. A new commit is verified, copied without touching secrets or runtime state, restarted, and smoke-tested. A failed smoke test restores the prior source-managed files. The legacy `deploy-main` automation stays disabled so there is only one deployment trigger.\n\nUseful commands on the Mac mini:\n\n```\n/Users/ai/bin/deploy-main --dry-run\n/Users/ai/bin/deploy-main\ncat /Users/ai/state/deploy-main/last-run.json\n```\n\nMerged `origin/main` is the only deployable source of truth. The deployer converges the source checkout back onto `origin/main` on every run, preserving any local commits or uncommitted edits under `state/deploy-main/quarantine/` and on `quarantine/<timestamp>` branches. Local edits to source-managed runtime files are likewise preserved in the quarantine and then overwritten by the deployed source; anything worth keeping returns through a pull request.\n\nDuring a deployment the task ledger drains: no new runs start, incoming messages stay durable, and active runs checkpoint themselves at their next safe turn boundary. After the restart, checkpointed and interrupted runs are recovered and continue with their persisted task progress, next action, Codex session, and a deployment update notice.\n\nBefore pushing a branch, run:\n\n```\ndeploy/scripts/verify-source.sh\n```\n\nsource belongs here. durable secrets belong in Infisical. `$HOME/auth`, provider caches, and browser profiles contain only bootstrap or explicitly tracked migration state. yes, obvious. also yes, worth writing down.", "url": "https://wpnews.pro/news/fluffles-os", "canonical_source": "https://github.com/DevelopIQ-ai/fluffles-os", "published_at": "2026-10-08 06:30:57+00:00", "updated_at": "2026-10-08 06:48:56.280340+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "agent-protocols"], "entities": ["Fluffles", "DevelopIQ-ai", "puffle-app", "macOS", "Slack", "Codex", "MCP", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/fluffles-os", "markdown": "https://wpnews.pro/news/fluffles-os.md", "text": "https://wpnews.pro/news/fluffles-os.txt", "jsonld": "https://wpnews.pro/news/fluffles-os.jsonld"}}