OpenTag
Supported route
Slack Source App
-> self-hosted Control Plane
-> paired local Runner
-> ACP Agent in one local checkout
-> GitHub Project Target/publication
-> truthful result in the originating Slack thread
Slack is the only Source App. GitHub is the Project Target and
publication/evidence provider. The Control Plane owns Slack ingress, custody,
and projection; the Runner owns local execution.
Load the needed reference
- Compose deployment, Slack bootstrap, TLS, or pairing authority:
references/control-plane.md
- Slack app URLs, events, scopes, channel binding, or missing mentions:
references/slack-setup.md
- GitHub target, local checkout, publication, or readback:
references/github-setup.md
- Codex or another supported ACP executor:
references/codex-runner.md
- Any failed readiness, pairing, Run, or delivery step:
references/troubleshooting.md
Load only the references whose branch applies.
Guardrails
- Pair only with the exact HTTPS Control Plane origin the user operates or
explicitly trusts.
- Keep Slack signing and bot secrets in Control Plane secret files. Its
.env
contains only their host-side file paths and non-secret Slack identifiers.
- Enter the bootstrap pairing authority and GitHub token through local secret
input. Keep them out of chat, command arguments, logs, screenshots, and git.
- The ACP Agent edits only the assigned local checkout. OpenTag performs Slack
delivery and GitHub publication through governed provider boundaries.
- Preserve unrelated working-tree changes. Confirm the checkout and target
before enabling write-capable work.
- Run completion, enqueue, approval, and provider acceptance are separate
facts. Preserve
outcome_unknown until the original provider operation is
reconciled.
Paired workflow
Bootstrap the Control Plane and Slack installation from
deploy/compose/.env.example, using file-backed Slack secrets, then start
Compose behind TLS.
Completion: the Compose project reports healthy, /readyz succeeds, and
bootstrap logs show the intended Slack binding without secret plaintext.
Install the reviewed CLI and verify the local checkout and ACP login.
npm install -g @opentag/cli@0.11.0
opentag --version
git -C /absolute/path/to/checkout status --short
Completion: the CLI reports 0.11.0, the user has accepted the checkout
state, and the chosen ACP executor is locally authenticated.
Configure the Runner, trusted relay, checkout, ACP executor, and GitHub
Project Target. Omit secret flags so the CLI prompts locally.
opentag setup \
--relay https://control.example.com \
--project /absolute/path/to/checkout \
--executor codex \
--github-repository owner/repo \
--project-target-id target_team
Replace target_team with the active Slack binding's Project Target ID from
Compose. Do not require a duplicate Runner environment variable for it.
Setup performs the initial pair. For an existing configuration that is
still unpaired, complete that same pairing with:
opentag pair \
--relay https://control.example.com \
--trust-relay-origin https://control.example.com
Completion: redacted config shows paired_relay, the exact trusted origin,
a paired Runner registration, and the intended GitHub target ID; pairing has
registered that target through the active Slack binding and verified exact
Control Plane readback. The bootstrap token is not retained in Runner config.
Keep the Runner active in one supported mode.
opentag start
# or, after a global install:
opentag service install
opentag service start
opentag service status
Completion: the service reports running and ready, the runtime credential
is accepted by the Runner Control Context endpoint, and the configured ACP
executor is ready.
Verify before inviting work.
opentag doctor
opentag status
opentag config show
Completion: required checks pass, the relay and Runner identities match,
the checkout maps to the intended GitHub target, and displayed secrets are
redacted.
Mention the installed OpenTag app in the bootstrapped Slack channel with one
bounded task.
Completion: the signed Slack event creates one WorkThread and Run, the
paired Runner claims one fenced Attempt, and the originating thread receives
a concise result or an explicit actionable failure.
The setup is complete only when every completion criterion above holds on the
paired route. A local process exit, queued delivery, generated pull-request URL,
or Slack acknowledgement alone is insufficient.
1---2name: opentag3description: Deploy or operate OpenTag's supported paired setup when a user needs to bootstrap the self-hosted Docker Compose Control Plane and Slack Source App, configure or pair a local ACP Runner with a GitHub Project Target, start the Runner service, verify readiness, or diagnose a Slack mention that did not complete.4---56# OpenTag78## Supported route910```text11Slack Source App12 -> self-hosted Control Plane13 -> paired local Runner14 -> ACP Agent in one local checkout15 -> GitHub Project Target/publication16 -> truthful result in the originating Slack thread17```1819Slack is the only Source App. GitHub is the Project Target and20publication/evidence provider. The Control Plane owns Slack ingress, custody,21and projection; the Runner owns local execution.2223## Load the needed reference2425- Compose deployment, Slack bootstrap, TLS, or pairing authority:26 `references/control-plane.md`27- Slack app URLs, events, scopes, channel binding, or missing mentions:28 `references/slack-setup.md`29- GitHub target, local checkout, publication, or readback:30 `references/github-setup.md`31- Codex or another supported ACP executor:32 `references/codex-runner.md`33- Any failed readiness, pairing, Run, or delivery step:34 `references/troubleshooting.md`3536Load only the references whose branch applies.3738## Guardrails3940- Pair only with the exact HTTPS Control Plane origin the user operates or41 explicitly trusts.42- Keep Slack signing and bot secrets in Control Plane secret files. Its `.env`43 contains only their host-side file paths and non-secret Slack identifiers.44- Enter the bootstrap pairing authority and GitHub token through local secret45 input. Keep them out of chat, command arguments, logs, screenshots, and git.46- The ACP Agent edits only the assigned local checkout. OpenTag performs Slack47 delivery and GitHub publication through governed provider boundaries.48- Preserve unrelated working-tree changes. Confirm the checkout and target49 before enabling write-capable work.50- Run completion, enqueue, approval, and provider acceptance are separate51 facts. Preserve `outcome_unknown` until the original provider operation is52 reconciled.5354## Paired workflow55561. Bootstrap the Control Plane and Slack installation from57 `deploy/compose/.env.example`, using file-backed Slack secrets, then start58 Compose behind TLS.59 Completion: the Compose project reports healthy, `/readyz` succeeds, and60 bootstrap logs show the intended Slack binding without secret plaintext.61622. Install the reviewed CLI and verify the local checkout and ACP login.6364 ```bash65 npm install -g @opentag/cli@0.11.066 opentag --version67 git -C /absolute/path/to/checkout status --short68 ```6970 Completion: the CLI reports `0.11.0`, the user has accepted the checkout71 state, and the chosen ACP executor is locally authenticated.72733. Configure the Runner, trusted relay, checkout, ACP executor, and GitHub74 Project Target. Omit secret flags so the CLI prompts locally.7576 ```bash77 opentag setup \78 --relay https://control.example.com \79 --project /absolute/path/to/checkout \80 --executor codex \81 --github-repository owner/repo \82 --project-target-id target_team83 ```8485 Replace `target_team` with the active Slack binding's Project Target ID from86 Compose. Do not require a duplicate Runner environment variable for it.8788 Setup performs the initial pair. For an existing configuration that is89 still unpaired, complete that same pairing with:9091 ```bash92 opentag pair \93 --relay https://control.example.com \94 --trust-relay-origin https://control.example.com95 ```9697 Completion: redacted config shows `paired_relay`, the exact trusted origin,98 a paired Runner registration, and the intended GitHub target ID; pairing has99 registered that target through the active Slack binding and verified exact100 Control Plane readback. The bootstrap token is not retained in Runner config.1011024. Keep the Runner active in one supported mode.103104 ```bash105 opentag start106 # or, after a global install:107 opentag service install108 opentag service start109 opentag service status110 ```111112 Completion: the service reports running and ready, the runtime credential113 is accepted by the Runner Control Context endpoint, and the configured ACP114 executor is ready.1151165. Verify before inviting work.117118 ```bash119 opentag doctor120 opentag status121 opentag config show122 ```123124 Completion: required checks pass, the relay and Runner identities match,125 the checkout maps to the intended GitHub target, and displayed secrets are126 redacted.1271286. Mention the installed OpenTag app in the bootstrapped Slack channel with one129 bounded task.130 Completion: the signed Slack event creates one WorkThread and Run, the131 paired Runner claims one fenced Attempt, and the originating thread receives132 a concise result or an explicit actionable failure.133134The setup is complete only when every completion criterion above holds on the135paired route. A local process exit, queued delivery, generated pull-request URL,136or Slack acknowledgement alone is insufficient.