Harnesses #
A harness is a data-only folder describing detection, image layers, and proposed verification profiles. Matched harnesses compose one cached image for workers and verification: toolchains first, then Python, Node, and declarative layers, respecting after. Tags hash the recipe and copied dependency files. Verification profiles remain proposals. Repositories can explicitly enable harnesses with harnesses: [names] in .nomarmy.yml; service networks are used only for nomArmy verification.
- none: offline verification (default).
- services: fake services on a private network with no route out.
- allowlist: verification-only access to operator-approved hosts, with dedicated test tenants and throwaway credentials, never production (planned).
Workers always remain offline. See the plan and Adding a harness.
| Harness | Summary | Detects | Network | Requires |
|---|---|---|---|---|
| browser-playwright | Offline Chromium end-to-end tests with the repository's Playwright version | package: @playwright/test; file: playwright.config.ts; file: playwright.config.js; file: playwright.config.mjs | none | memoryMb: 1024, shmMb: 512 |
| go | Go toolchain with prefetched modules for offline verification | file: go.mod; file: go.work | none | none |
| mock-oidc | Mock OAuth2 and OIDC discovery and login on an isolated verification network | none | services | none |
| node | Node dependencies and workspaces installed with npm, pnpm, yarn or bun | lockfile: package-lock.json; lockfile: npm-shrinkwrap.json; lockfile: pnpm-lock.yaml; lockfile: yarn.lock; lockfile: bun.lock; lockfile: bun.lockb | none | none |
| python | Python dependencies from uv, Poetry, pyproject, or requirements files | file: uv.lock; file: poetry.lock; file: pyproject.toml; file: requirements.txt | none | none |
| rust | Rust toolchain with prefetched crates for offline verification | file: Cargo.toml | none | none |