cd /news/ai-agents/migration-diary-freeze-the-mount-and… · home › topics › ai-agents › article
[ARTICLE · art-147501] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Migration Diary: Freeze the Mount and Egress Contract Before the Paid Agent Closes

A developer proposes freezing a mount-and-egress contract before cancelling a paid coding agent, since a replacement host starts from its own defaults and will not inherit the old product's writable paths, read-only trees, or permitted hosts. The approach stores writable roots, read-only context, egress hostnames, deny notes, and an owner in a repository-relative YAML file reviewed like any pull request, plus an unexecuted Python checker that verifies listed paths exist and prints hosts for firewall comparison. The diary warns against carrying over session transcripts, cookies, tokens, and vendor-container-only paths, and labels the file a human cutover aid rather than a security certification.

by read8 min views1 publishedOct 8, 2026

You should freeze a mount-and-egress contract before you cancel a paid coding agent, because the replacement host will not inherit it. The paid product often remembered which directories were writable, which trees were context only, and which hosts the sandbox could reach. A free server starts from its own defaults, so yesterday's silent allowances become today's missing checks or unexpected network calls. This diary walks you through a cutover plan, a small checker, and the leftovers you should not drag along.

A rule file tells the agent how to speak, while a mount contract names writable paths and permitted hosts. Those two leftovers fail in different ways, and mixing them during cutover hides the boundary you actually need. You can copy every instruction into the new tool and still lose the limit that kept generated patches inside the repository. Treat that boundary as data you can diff in review, not as a memory you hope the next host will share.

You are leaving the paid agent's private sandbox, its hidden allowlist, and any scheduler that lived only in that vendor console. You keep the repository, your tests, and a written contract that names writable roots, read-only context, and permitted egress hosts. You do not keep session transcripts, browser cookies, or tokens that were stored in the old agent's settings panel. If a path existed only inside the vendor container, record it as a leftover rather than a path the new host must recreate.

Open the paid agent's settings while the account still works, and list every directory it could edit without an extra prompt. Note read-only trees such as vendored docs, generated clients, and lockfiles you never wanted the agent to rewrite. Record egress as hostnames only, not as credentials, secret query strings, or copied authorization headers from old logs. If the product never showed a boundary, write unknown in the contract rather than guessing a permissive default.

Put the inventory in a YAML file inside the repository, and keep every value boring enough for a normal pull request review. Use repository-relative paths, explicit deny notes, and a short owner field so the next person knows who must update it. Do not store API keys, personal access tokens, or customer data in that file, even as examples that only look fake. Label the file as a cutover aid for humans, not as a certification that the new environment is secure.

version: 1
writable:
  - src
  - tests
read_only:
  - docs/vendor
  - third_party
egress_hosts:
  - registry.npmjs.org
  - pypi.org
deny_notes:
  - do not mount the home directory
  - do not call hosts that are not listed
owner: team-platform

The checker below is a proposal, and it has not been executed against a live paid account or a live free server. It reads the contract, confirms that listed paths exist, and prints hosts so you can compare them with firewall notes. It does not open network connections, and it does not try to prove that any listed host is safe to call. Run it in a scratch clone first, then decide whether a failing path is a real leftover or a simple typo.

import sys
from pathlib import Path

try:
    import yaml
except ImportError:
    sys.exit("install pyyaml in a local venv before running")

contract = yaml.safe_load(Path("agent-boundary.yaml").read_text())
root = Path(".").resolve()
missing = []
for key in ("writable", "read_only"):
    for rel in contract.get(key, []):
        if not (root / rel).exists():
            missing.append(f"{key}:{rel}")
if missing:
    print("missing paths:")
    print("\n".join(missing))
    sys.exit(1)
print("paths ok")
print("egress hosts to re-approve:")
for host in contract.get("egress_hosts", []):
    print(f"- {host}")

Use a small decision table during the cutover meeting so leftovers do not sneak into the new scheduled job. Each row should name the artifact, the owner, and the action, instead of a vague promise that someone will clean up later. Delete vendor-only interface state, because a free server cannot import a screenshot of a settings page from the old product. Keep the contract in version control, and keep the old account available until the checker passes on the replacement host.

Artifact Move? Why
Writable and read-only path lists Yes The new host needs an explicit boundary
Egress hostnames without secrets Yes Firewall notes fail if the names stay trapped in a closed UI
Vendor session memory and chat archive No That drain is a separate task, and it is not a boundary
Tokens stored in the old agent panel No Rotate them, then delete the stored copies
Hidden container paths that exist only in the paid sandbox No Recreate needed files in the repo, or drop the task

Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode's free model access and free server option can support this rehearsal when current docs still list them. Use the free server as a place to run the checker and one dry task, not as a silent copy of the old sandbox. Use free model access only to draft the human notes beside the contract, and reject any broader allowlist that nobody reviewed.

Do not treat either option as a quota, a named model, or a hardware promise this article never verified. Confirm duration, limits, and terms in the product's own documentation before you let a critical job depend on them. The commands below assume a local virtual environment, and you should skip them if your policy forbids installing a YAML parser. Cancel the paid account only after the rehearsal matches the decision table, not when a calendar reminder starts to feel urgent.

python3 -m venv .venv
. .venv/bin/activate
python -m pip install pyyaml
python check_boundary.py
git diff -- agent-boundary.yaml

Then run one narrow task, such as editing a file under a writable root, and confirm that a read-only path stayed untouched. If the free model suggests extra hosts or extra writable roots, reject that draft unless a person updates the contract in review. Save the checker output next to the decision table so the cutover record shows what you compared, not only what you intended. Repeat the narrow task once on the free server after you move the job, because a local pass does not prove the remote mount.

When the checker reports a missing path, do not widen the contract until you confirm the path existed before. Search the repository for that relative path, and also search your notes for a vendor container path that never lived in git. If the path was only a container mount, mark it as a leftover and either recreate the file or drop the task. If the path exists but writes still land outside it, the bug is the process mount, so fix the host next.

Run the checker on a clean clone, then temporarily rename one writable directory and confirm the command exits with a missing path. Restore the directory, add a fake hostname to the egress list, and confirm the script prints that name without opening a socket. Ask the free model to summarize the contract, and fail the test if that summary adds hosts or roots. Record the three results in the cutover note, because a passing local run without these checks is not evidence the boundary moved.

You will still find editor plugins, local caches, and shell aliases that point at the paid agent's old command name. Remove those pointers in the same week, or the next person will launch a tool you already stopped paying for. You may also find generated files whose headers mention the old product, and those headers are documentation debt rather than a restore reason. Leave a one-line note in the deny section if a workflow truly cannot move, so the gap stays visible to the next reviewer.

This contract records human intent, and it does not enforce a kernel sandbox, a container profile, or a corporate egress proxy. A checker that only looks for paths can pass while the process still runs with a wider mount than the file describes. Hostnames without ports, protocols, or identity checks are not an allowlist a security team should accept as complete. The example YAML and Python are unexecuted proposals, so you must adapt them to your layout and review every failure yourself.

Do not use this path if production deploys still run inside the paid agent, because a diary checklist is not a release plan. Skip it when the workspace holds regulated data and you need a formal control, since this file will not satisfy an auditor alone. Avoid it when you cannot inspect the old settings before cancellation, because a boundary rebuilt from memory creates false confidence. Teams that require a contracted uptime promise should not treat a free server option as the home for a critical job.

Read the current MonkeyCode docs, then try the checker on a scratch repository if the free server option still fits this rehearsal. Keep the paid account until every move row has a passing note, and keep secrets out of model drafts. If the docs no longer match the availability assumed here, stop and rewrite the rehearsal around whatever the current page actually offers.

── more in #ai-agents 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/migration-diary-free…] indexed:0 read:8min 2026-10-08 · —