# Podman as the default execution home

outcome: gates and agents run in podman containers by default — own cgroup, no shared-slice contention; k3s later adds only orchestration.
status: ACTIVE — P1 dispatched to codex (gpt-5.6-terra/high, owner-directed launcher while the factory is unproven) 2026-08-16.
source request: owner 2026-08-16 /brainstorm (full staging analysis pinned in the spec).
design spec: docs/specs/2026-08-16-podman-default-design.md — rationale, slices P1–P3, seams, the named-retirement rule for the interim scheduler, decisions.

## Execution

- [ ] P1 gates in containers (laptop): container executor on the local-gate seam; land-queue gate proof (container-named log, green, empty build.slice)
- [ ] P2 agent seats default podman on boxes; guard parity proven IN-container
- [ ] P3 interim scheduler = admission-slots over per-box podman capacity, `interim-until: k3s-scheduling` recorded; k3s plan must retire it
- [ ] readiness gates tracked elsewhere, not here: transport silent-kill class (observability landed; root cause open), fleet provisioning drift

constraints: never silent fallback to bare-host execution; same gate commands and fail-closed semantics; emergency-seat contract applies to P3 unchanged; each slice deploys + proves before the next.

current receipt: spec + plan authored 2026-08-16; P1 dispatched to codex terra/high.
next executable action: P1 implementation → land → live proof.
