push-shared-vault.sh pushes the shared vault only when the worktree is clean
and the local branch is ahead of origin (fetch first); never rebases,
force-pushes, or resolves conflicts. Ships with launchd setup docs. Bump 0.1.2.
Co-Authored-By: Claude <noreply@anthropic.com>
Detection order is now SHARED_VAULT_DIR, then $PWD, then $PWD/Areas/DevOps
(the nested shared subrepo inside the personal vault). Bump to 0.1.1.
Co-Authored-By: Claude <noreply@anthropic.com>
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.
Co-Authored-By: Claude <noreply@anthropic.com>