Skip to content

[factory] CLI: redeem a join-ticket for cross-machine node attach (companion to relaycast-cloud#61) #1507

Description

@khaliqgant

Why

Companion issue to relaycast-cloud#61 (https://github.com/AgentWorkforce/relaycast-cloud/issues/61) — read that first for full context. Short version: the Cloud dashboard's copy-pasteable attach command (agent-relay node agent attach <agent> --node <node> --mode drive) doesn't work on a machine without a matching local workspace-key.json — blocking Khaliq's cofounder Will from using it. PR #1502 added --workspace-key as a raw-key flag, but embedding the actual long-lived rk_live_... key in a copy-pasteable UI string was rejected as a real credential-exposure risk.

The design, agreed with Khaliq directly (2026-08-14)

A single pasted command still works in one step, but instead of a raw key it carries a short-lived, scoped join-ticket. This CLI redeems the ticket against relaycast-cloud#61's new endpoint to silently bootstrap a real local credential, then proceeds with the existing --node attach flow unchanged.

Scope for this issue (relay CLI side only)

  1. New flag on node agent attach, e.g. --join-ticket (name it what reads best given the actual redemption endpoint's shape once relaycast-cloud#61 defines it — coordinate on the exact wire contract, don't invent your own).
  2. When present: call the redemption endpoint, get back a real local-persistable credential, write it to the standard local credential location (same place --workspace-key / the existing resolution ladder in resolveWorkspaceSelection already checks), then proceed with the normal attach flow.
  3. Do NOT persist or log the raw ticket itself after redemption — it should behave like a one-time-use bootstrap, not a reusable secret.
  4. Add tests: successful redemption + attach, expired/invalid ticket (clear error, not the generic 'no workspace key found' message), and that the redeemed credential is what --node attach actually uses afterward (not silently ignored, falling through to the existing ladder).

Explicitly NOT in scope here

The relaycast-cloud ticket-minting/redemption endpoint itself — that's relaycast-cloud#61, filed alongside this one. Do not implement server-side changes here.

Sequencing

Do NOT merge this before relaycast-cloud#61's endpoint is live in production — this CLI flag is nonfunctional without it (same order cloud#2995 had to land before relay#1484's CLI rollout was useful, tonight's precedent). Note this explicitly in your PR description.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    factoryFactory auto-dispatchfactory:in-progressFactory agents are working on this issue.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions