Harnesses #

A harness is a data-only folder describing detection, image layers, and proposed verification profiles. Matched harnesses compose one cached image for workers and verification: toolchains first, then Python, Node, and declarative layers, respecting after. Tags hash the recipe and copied dependency files. Verification profiles remain proposals. Repositories can explicitly enable harnesses with harnesses: [names] in .nomarmy.yml; service networks are used only for nomArmy verification.

Workers always remain offline. See the plan and Adding a harness.

HarnessSummaryDetectsNetworkRequires
browser-playwrightOffline Chromium end-to-end tests with the repository's Playwright versionpackage: @playwright/test; file: playwright.config.ts; file: playwright.config.js; file: playwright.config.mjsnonememoryMb: 1024, shmMb: 512
goGo toolchain with prefetched modules for offline verificationfile: go.mod; file: go.worknonenone
mock-oidcMock OAuth2 and OIDC discovery and login on an isolated verification networknoneservicesnone
nodeNode dependencies and workspaces installed with npm, pnpm, yarn or bunlockfile: package-lock.json; lockfile: npm-shrinkwrap.json; lockfile: pnpm-lock.yaml; lockfile: yarn.lock; lockfile: bun.lock; lockfile: bun.lockbnonenone
pythonPython dependencies from uv, Poetry, pyproject, or requirements filesfile: uv.lock; file: poetry.lock; file: pyproject.toml; file: requirements.txtnonenone
rustRust toolchain with prefetched crates for offline verificationfile: Cargo.tomlnonenone