Sentinel
Ciridae-maintained updates that reach your project as draft PRs, so its foundation stays current without manual migration work.
What Sentinel does
A project's shared foundation keeps moving after launch: package managers change, and code copied into each project becomes published Ciridae packages. Porting every change by hand turns into maintenance debt. Sentinel applies Ciridae-authored updates to your repository and opens them as draft PRs your team reviews and merges.
Current updates move projects from Yarn to pnpm, replace duplicated auth, telemetry, OpenAPI tooling, Temporal Sentry, and Ghost client code with their published Ciridae packages, and adopt direct object storage access.
Sentinel never marks a PR ready or merges it. Your team decides when each change ships.
How an update reaches your project
- Eligibility: Sentinel considers projects that enable it in
project.yamland have a live full deployment. - Qualification: Sentinel reads the trunk branch and decides whether the update applies. If the pattern it replaces is absent, the run stops without creating a branch.
- Change: An agent in a temporary workspace makes the change, runs the project's checks, and opens a draft PR. Some updates open an ordered stack of draft PRs, and each PR body states the merge and deployment order.
- Correction: The agent works through CI failures and high-priority review findings, for up to three rounds.
- Review: Your team reviews the draft, marks it ready, and merges it.
Each update is a versioned Markdown file with a qualification prompt and execution and verification instructions. A project admin starts a run through the Crucible API; it runs as one Temporal workflow per project and update revision. Qualification uses read-only tools to list, search, and read tracked files, and classifies the repository as active, dead, absent, or unknown. Every result except absent creates a stable update branch, an expiring workspace, and a one-shot Codex session. A retry runs a fresh qualification; nothing is cached.
Turn Sentinel off
Projects created from the Agents template have Sentinel on. To opt out, override the setting in the project's project.yaml on the trunk branch:
updates:
sentinel:
enabled: false