{"slug": "migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent", "title": "Migration Diary: Freeze the Mount and Egress Contract Before the Paid Agent Closes", "summary": "A developer proposes freezing a mount-and-egress contract before cancelling a paid coding agent, since a replacement host starts from its own defaults and will not inherit the old product's writable paths, read-only trees, or permitted hosts. The approach stores writable roots, read-only context, egress hostnames, deny notes, and an owner in a repository-relative YAML file reviewed like any pull request, plus an unexecuted Python checker that verifies listed paths exist and prints hosts for firewall comparison. The diary warns against carrying over session transcripts, cookies, tokens, and vendor-container-only paths, and labels the file a human cutover aid rather than a security certification.", "body_md": "You should freeze a mount-and-egress contract before you cancel a paid coding agent, because the replacement host will not inherit it. The paid product often remembered which directories were writable, which trees were context only, and which hosts the sandbox could reach. A free server starts from its own defaults, so yesterday's silent allowances become today's missing checks or unexpected network calls. This diary walks you through a cutover plan, a small checker, and the leftovers you should not drag along.\n\nA rule file tells the agent how to speak, while a mount contract names writable paths and permitted hosts. Those two leftovers fail in different ways, and mixing them during cutover hides the boundary you actually need. You can copy every instruction into the new tool and still lose the limit that kept generated patches inside the repository. Treat that boundary as data you can diff in review, not as a memory you hope the next host will share.\n\nYou are leaving the paid agent's private sandbox, its hidden allowlist, and any scheduler that lived only in that vendor console. You keep the repository, your tests, and a written contract that names writable roots, read-only context, and permitted egress hosts. You do not keep session transcripts, browser cookies, or tokens that were stored in the old agent's settings panel. If a path existed only inside the vendor container, record it as a leftover rather than a path the new host must recreate.\n\nOpen the paid agent's settings while the account still works, and list every directory it could edit without an extra prompt. Note read-only trees such as vendored docs, generated clients, and lockfiles you never wanted the agent to rewrite. Record egress as hostnames only, not as credentials, secret query strings, or copied authorization headers from old logs. If the product never showed a boundary, write unknown in the contract rather than guessing a permissive default.\n\nPut the inventory in a YAML file inside the repository, and keep every value boring enough for a normal pull request review. Use repository-relative paths, explicit deny notes, and a short owner field so the next person knows who must update it. Do not store API keys, personal access tokens, or customer data in that file, even as examples that only look fake. Label the file as a cutover aid for humans, not as a certification that the new environment is secure.\n\n```\n# unexecuted example — review before use\nversion: 1\nwritable:\n  - src\n  - tests\nread_only:\n  - docs/vendor\n  - third_party\negress_hosts:\n  - registry.npmjs.org\n  - pypi.org\ndeny_notes:\n  - do not mount the home directory\n  - do not call hosts that are not listed\nowner: team-platform\n```\n\nThe checker below is a proposal, and it has not been executed against a live paid account or a live free server. It reads the contract, confirms that listed paths exist, and prints hosts so you can compare them with firewall notes. It does not open network connections, and it does not try to prove that any listed host is safe to call. Run it in a scratch clone first, then decide whether a failing path is a real leftover or a simple typo.\n\n``` python\n# proposal: not executed in this article\nimport sys\nfrom pathlib import Path\n\ntry:\n    import yaml\nexcept ImportError:\n    sys.exit(\"install pyyaml in a local venv before running\")\n\ncontract = yaml.safe_load(Path(\"agent-boundary.yaml\").read_text())\nroot = Path(\".\").resolve()\nmissing = []\nfor key in (\"writable\", \"read_only\"):\n    for rel in contract.get(key, []):\n        if not (root / rel).exists():\n            missing.append(f\"{key}:{rel}\")\nif missing:\n    print(\"missing paths:\")\n    print(\"\\n\".join(missing))\n    sys.exit(1)\nprint(\"paths ok\")\nprint(\"egress hosts to re-approve:\")\nfor host in contract.get(\"egress_hosts\", []):\n    print(f\"- {host}\")\n```\n\nUse a small decision table during the cutover meeting so leftovers do not sneak into the new scheduled job. Each row should name the artifact, the owner, and the action, instead of a vague promise that someone will clean up later. Delete vendor-only interface state, because a free server cannot import a screenshot of a settings page from the old product. Keep the contract in version control, and keep the old account available until the checker passes on the replacement host.\n\n| Artifact | Move? | Why | \n|---|---|---|\n| Writable and read-only path lists | Yes | The new host needs an explicit boundary | \n| Egress hostnames without secrets | Yes | Firewall notes fail if the names stay trapped in a closed UI | \n| Vendor session memory and chat archive | No | That drain is a separate task, and it is not a boundary | \n| Tokens stored in the old agent panel | No | Rotate them, then delete the stored copies | \n| Hidden container paths that exist only in the paid sandbox | No | Recreate needed files in the repo, or drop the task | \n\nDisclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode's free model access and free server option can support this rehearsal when current docs still list them. Use the free server as a place to run the checker and one dry task, not as a silent copy of the old sandbox. Use free model access only to draft the human notes beside the contract, and reject any broader allowlist that nobody reviewed.\n\nDo not treat either option as a quota, a named model, or a hardware promise this article never verified. Confirm duration, limits, and terms in the product's own documentation before you let a critical job depend on them. The commands below assume a local virtual environment, and you should skip them if your policy forbids installing a YAML parser. Cancel the paid account only after the rehearsal matches the decision table, not when a calendar reminder starts to feel urgent.\n\n```\npython3 -m venv .venv\n. .venv/bin/activate\npython -m pip install pyyaml\npython check_boundary.py\ngit diff -- agent-boundary.yaml\n```\n\nThen run one narrow task, such as editing a file under a writable root, and confirm that a read-only path stayed untouched. If the free model suggests extra hosts or extra writable roots, reject that draft unless a person updates the contract in review. Save the checker output next to the decision table so the cutover record shows what you compared, not only what you intended. Repeat the narrow task once on the free server after you move the job, because a local pass does not prove the remote mount.\n\nWhen the checker reports a missing path, do not widen the contract until you confirm the path existed before. Search the repository for that relative path, and also search your notes for a vendor container path that never lived in git. If the path was only a container mount, mark it as a leftover and either recreate the file or drop the task. If the path exists but writes still land outside it, the bug is the process mount, so fix the host next.\n\nRun the checker on a clean clone, then temporarily rename one writable directory and confirm the command exits with a missing path. Restore the directory, add a fake hostname to the egress list, and confirm the script prints that name without opening a socket. Ask the free model to summarize the contract, and fail the test if that summary adds hosts or roots. Record the three results in the cutover note, because a passing local run without these checks is not evidence the boundary moved.\n\nYou will still find editor plugins, local caches, and shell aliases that point at the paid agent's old command name. Remove those pointers in the same week, or the next person will launch a tool you already stopped paying for. You may also find generated files whose headers mention the old product, and those headers are documentation debt rather than a restore reason. Leave a one-line note in the deny section if a workflow truly cannot move, so the gap stays visible to the next reviewer.\n\nThis contract records human intent, and it does not enforce a kernel sandbox, a container profile, or a corporate egress proxy. A checker that only looks for paths can pass while the process still runs with a wider mount than the file describes. Hostnames without ports, protocols, or identity checks are not an allowlist a security team should accept as complete. The example YAML and Python are unexecuted proposals, so you must adapt them to your layout and review every failure yourself.\n\nDo not use this path if production deploys still run inside the paid agent, because a diary checklist is not a release plan. Skip it when the workspace holds regulated data and you need a formal control, since this file will not satisfy an auditor alone. Avoid it when you cannot inspect the old settings before cancellation, because a boundary rebuilt from memory creates false confidence. Teams that require a contracted uptime promise should not treat a free server option as the home for a critical job.\n\nRead the current MonkeyCode docs, then try the checker on a scratch repository if the free server option still fits this rehearsal. Keep the paid account until every move row has a passing note, and keep secrets out of model drafts. If the docs no longer match the availability assumed here, stop and rewrite the rehearsal around whatever the current page actually offers.", "url": "https://wpnews.pro/news/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent", "canonical_source": "https://dev.to/techpy_768/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent-closes-pi8", "published_at": "2026-10-08 10:36:07+00:00", "updated_at": "2026-10-08 10:49:19.954495+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools"], "entities": [], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent", "markdown": "https://wpnews.pro/news/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent.md", "text": "https://wpnews.pro/news/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent.txt", "jsonld": "https://wpnews.pro/news/migration-diary-freeze-the-mount-and-egress-contract-before-the-paid-agent.jsonld"}}