새 세션만
선택한 에이전트의 기존 기록은 기준선으로만 남고 자동 업로드되지 않습니다.
설치 가이드 / MACOS
가장 빠른 길은 아래 설치 프롬프트입니다. 에이전트가 필요한 도구와 보호된 GCS를 준비한 뒤, 정확한 new-only 계획 하나를 보여주고 승인을 받습니다. 수동 터미널 경로도 바로 아래에 남겨뒀습니다.
60초 설치 시작
사용자가 bucket 설정 화면을 채우거나 명령어를 조합할 필요가 없습니다. 코딩 에이전트가 고정된 릴리스를 설치하고, 사용자 전용 비공개 GCS bucket을 생성하거나 확인한 뒤 자동 동기화가 정상적으로 작동하는지 검증합니다.
에이전트는 세션을 읽기 전에 설치 계획부터 보여줍니다.
이 Mac에 Datafooding을 설치하고, 내가 고른 AI 에이전트의 다음 세션부터 전용 GCS로 자동 백업되게 끝까지 설정해줘.
The outcome I want
- Local session files remain the source of truth and are never deleted.
- Eligible bytes are encrypted on this Mac before upload.
- Only ciphertext is stored in a dedicated bucket in my Google Cloud project.
- Existing history is excluded. Only files created or changed after the new-only baseline may be captured.
- A macOS LaunchAgent keeps capture and sync running every 15 minutes.
Exact release contract
- Version: 0.2.1
- Wheel: https://datafooding.ai/releases/datafooding_agent_vault-0.2.1-py3-none-any.whl
- SHA-256: ba21b23f23a25850adc649a3e48d78c0a8a346193546c8cfbaf63c35dae6247b
- PEP 508 target: datafooding-agent-vault @ https://datafooding.ai/releases/datafooding_agent_vault-0.2.1-py3-none-any.whl#sha256=ba21b23f23a25850adc649a3e48d78c0a8a346193546c8cfbaf63c35dae6247b
Run this workflow
1. Preflight this Mac without reading session content.
- Confirm the OS is macOS.
- Detect only the existence and filesystem metadata of supported stores: Codex, archived Codex, Claude Code, Hermes, Kimi Code, OpenCode, and Gemini CLI.
- Do not open or print prompts, messages, tool results, credentials, tokens, request dumps, hidden reasoning, or session payloads.
2. Install only missing prerequisites from their official distribution.
- Homebrew is the package manager. If it is missing, use the official brew.sh installer and no third-party mirror.
- Install uv with Homebrew when missing.
- Install Google Cloud CLI with the current Homebrew cask: `brew install --cask gcloud-cli`.
- Resolve gcloud with `command -v gcloud`; if the cask is installed but PATH has not refreshed, use `$(brew --prefix)/share/google-cloud-sdk/bin/gcloud` after checking that it is executable.
- Never use a service account, create broad IAM grants, write credentials to the repository, or put secrets in command arguments or chat.
3. Establish the Google Cloud identity interactively.
- Check the active account and project without printing tokens. If login is required, use `gcloud auth login`.
- Never guess a project. If none is active, ask me for the exact project ID.
- Resolve its numeric project number with `gcloud projects describe PROJECT_ID --format='value(projectNumber)'`.
- Propose the dedicated bucket `datafooding-PROJECT_NUMBER`.
4. Ask for one compact approval before creating cloud resources or enabling capture.
Show one block containing:
- the detected agent names, with nothing selected by default;
- the exact account and project ID, redacted where appropriate;
- the proposed bucket;
- for a new bucket, the GCS location I must choose because it is immutable;
- for an existing bucket, its current location and any protection change needed;
- every local prerequisite you installed.
Ask me to reply with the exact sources and `APPROVE`. Treat that answer as consent only for those sources, that project, that bucket, and that location.
5. Create or verify the dedicated bucket, fail closed, and never delete it.
- First run describe. Only an explicit not-found result permits creation. A permission error, timeout, disabled API, billing problem, or ambiguous result must stop with a concrete remediation.
- Create a missing bucket with this exact protection shape:
`gcloud storage buckets create gs://BUCKET --project=PROJECT_ID --location=LOCATION --uniform-bucket-level-access --public-access-prevention --soft-delete-duration=7d --quiet`
- Never set or lock an irreversible retention policy.
- Reuse an existing bucket only when describe proves that its project number matches the selected project and its location matches the approved plan.
- Before continuing, re-describe and verify: exact name, project number, location, uniform bucket-level access enabled, public access prevention enforced, and soft-delete retention greater than zero. If an existing bucket needs a protection update, the approval block must name it before running any update.
6. Install the exact hash-pinned Datafooding release.
Run:
`uv tool install --force 'datafooding-agent-vault @ https://datafooding.ai/releases/datafooding_agent_vault-0.2.1-py3-none-any.whl#sha256=ba21b23f23a25850adc649a3e48d78c0a8a346193546c8cfbaf63c35dae6247b'`
Then require `datafooding --version` to report 0.2.1.
7. Bind only the approved sources from now.
- Run `datafooding quickstart --plan --bucket gs://BUCKET --source SOURCE ...`.
- Verify the content-free plan exactly matches the approved bucket and source list, says `capture_policy: new-only`, `existing_sessions_included: false`, and enables automatic capture.
- Never use `--include-existing`, `archive-home`, or a history migration in this workflow.
- If the plan matches, run the same quickstart command with `--yes`.
8. Trigger and verify local-to-remote sync.
- Run `datafooding sync --capture-enabled`, then `datafooding doctor` and `datafooding status`.
- If the active setup session changes after the baseline, it may become eligible. Let the daemon retry a file that is still changing; do not weaken the stability checks.
- Open `datafooding admin --language ko` in a separate terminal because the local admin intentionally stays in the foreground.
9. Call setup complete only when all of these are true.
- Doctor passes.
- Every approved source is enabled with the new-only policy.
- The LaunchAgent is installed, loaded, and bound to the current CLI.
- GCS access and recoverability checks pass.
- Queued ciphertext is zero.
If no post-baseline file has changed yet, report `READY — waiting for the first new session`; do not claim that a session was uploaded.
Failure and rollback rules
- Stop on any identity, project, billing, ownership, location, policy, hash, or health ambiguity. Never retry with wider permissions.
- If quickstart fails after enabling a source that was off before this workflow, disable only that newly enabled source and stop the LaunchAgent started by this workflow. Preserve any pre-existing enabled source and daemon.
- Keep the local vault, Keychain entry, and protected bucket as resumable state. Do not delete source files, vault data, recovery material, or cloud objects.
- Return a short content-free receipt: version, selected source names, bucket protection status, capture policy, LaunchAgent state, queue count, and the exact next remediation if anything is incomplete.이 프롬프트는 버전이 고정된 로컬 도구의 설치만 허용합니다. 사용자가 정확한 new-only 계획을 승인한 뒤에만 세션 캡처를 시작하며, 기존 기록은 포함하지 않습니다.
한 줄 설치 OWNER BETA
설치는 포괄 동의가 아닙니다. 아래에서 정확한 에이전트만 고릅니다. Quickstart는 새 세션 기준선을 만들고 기존 세션은 모두 건너뜁니다. 전용 GCS를 확인한 뒤 15분 자동 보관을 켜고 로컬 어드민을 엽니다.
(command -v uv >/dev/null || brew install uv) && uv tool install --force 'datafooding-agent-vault @ https://datafooding.ai/releases/datafooding_agent_vault-0.2.1-py3-none-any.whl#sha256=ba21b23f23a25850adc649a3e48d78c0a8a346193546c8cfbaf63c35dae6247b' && datafooding quickstart --bucket 'gs://YOUR_BUCKET' --source CHOOSE_ONE --yes && datafooding admin --language ko버킷을 입력하고 앱을 하나 이상 고르세요.
macOS, Homebrew, 로그인된 Google Cloud CLI가 필요합니다. uv가 없으면 명령이 Homebrew에서 설치합니다. 원본 파일은 절대 삭제하지 않습니다.
정식 공개 버전은 내려받아 바로 열 수 있는 Developer ID 서명·공증 Mac 설치 파일로 배포합니다. 지금은 고정된 이 명령이 owner beta 설치 경로입니다.
설치가 끝나면
선택한 에이전트의 기존 기록은 기준선으로만 남고 자동 업로드되지 않습니다.
세션 원문은 이 Mac에서 암호화되고, GCS에는 ciphertext만 올라갑니다.
로컬 어드민에서 자동 보관, 활성 소스, 업로드와 대기열을 한 화면에서 확인합니다.
계획은 읽기 전용입니다. Vault를 만들거나 세션 내용을 읽지 않고 버킷, 정확한 앱, 새 세션 전용 정책, 주기와 권한을 보여줍니다.
datafooding quickstart --plan --bucket gs://BUCKET --source codex설치 뒤 자동 보관이나 저장소에 확인이 필요할 때 실행합니다.
datafooding doctor && datafooding status내용을 읽지 않고 발견 가능한 파일 수만 확인합니다. 기존 세션은 quickstart 동의에 절대 포함되지 않습니다.
datafooding discover완전히 별도의 명시적 결정입니다. 한 줄 설치 명령은 이 옵션을 만들지 않습니다.
datafooding source enable opencode --include-existing --yesCodex, Claude, Hermes, Kimi, OpenCode, Gemini CLI 또는 custom archive에 포함·제외되는 파일을 먼저 봅니다.
datafooding archive-home opencode --dry-run안정적인 safe tree를 로컬 암호화한 뒤 ciphertext만 올립니다. 자격증명 store는 계속 제외됩니다.
datafooding archive-home opencode --sync127.0.0.1에서 redacted projection, source policy, rights, replay job, review receipt를 봅니다.
datafooding admin --language ko키를 Keychain에 저장한 뒤 요청 1회당 보수적인 로컬 비용 상한을 명시합니다. 키만으로는 유료 호출이 열리지 않습니다.
datafooding provider-connect openrouter && datafooding provider-cost set openrouter MODEL --max-request-cost-microusd UPPER_BOUND --contract-id PRICE_RECEIPT깨끗한 Git project를 등록하고 immutable environment를 캡처한 뒤 disclosure scan과 provider 처리 동의를 통과합니다.
datafooding environment-capture PROJECT_ID --image IMAGE@sha256:DIGEST --prospective --allow-provider-processing --syncinstruction file 하나, 고정 environment 하나, 실행 verifier, 모델 두 개 이상을 묶은 제한된 comparison spec을 만듭니다. 원래 product stack을 재현하는 기능은 아닙니다.
datafooding replay-create ENVIRONMENT_ID --instruction-file ./instruction.txt --verifier-command "python -m pytest -q" --target openrouter:MODEL_A --target upstage:MODEL_B --runs 3Provider를 호출하기 전에 model matrix, seed, budget, attempt identity를 고정합니다. 계획 단계에서는 로컬 trace나 project file을 전송하지 않습니다.
datafooding replay-plan SPEC_IDAttempt를 대기열에 넣은 뒤 유효한 비용 계약이 있을 때만 로컬 worker로 실행합니다. Docker가 verifier를 실행하고 trace와 artifact는 이 Mac에 남깁니다. 정확한 과거 재현이 아니라 제한된 counterfactual입니다.
datafooding replay-run JOB_ID && datafooding replay-worker --onceOwner-only 심사 페이지에 로그인해 origin-bound pairing bundle을 복사하고 review-connect를 한 번 실행합니다. Live probe가 통과해야만 Keychain이 바뀝니다. 그다음 로컬 comparison pack을 확인하고 exact manifest와 allowlist 심사 projection을 명시적으로 업로드합니다. Accepted는 내부 심사이며 판매나 payout이 아닙니다.
datafooding review-connect && datafooding pack-build JOB_ID && datafooding pack-submit PACK_ID통과 기준