DreamLake

Host Python API plan

Status: Enrollment merged; follow-up work remains. Parent: #218. Optional saving: #241. Providers: #243.

The account-authenticated DreamLakeClient now exposes hosts.plan(), hosts.enroll(), and hosts.status() in Python #23 and #24. Use the actual API guide and paired enrollment examples. Merged source is not a released package or production host-API deployment.

The Python client uses the shared main-server host API and packaged portable bootstrap without a Node dependency. It validates configuration, authorizes before target effects, enrolls without saving credentials, polls exact identity status, and supports explicit request-ID reconciliation. Calls never prompt or exit; required interactive SSH authentication fails clearly. The separate lakeshore-py runtime bridge is not the account host-management client.

Remaining delivery

  • Add tracked-run parity after the shared HTTP contract is fixed: source staging, argument vectors, durable IDs, logs/results, cancellation, and retry. --uv-run / --uvx consume the CLI tail; do not invent runnable SDK methods before implementation.
  • Verify real network SSH, Linux systemd/linger, installer availability, restart/reboot, and a real workload. Keep transport, connectivity, and execution evidence distinct.
  • Add optional credential saving through #241, with explicit consent and separate per-entry save/verification/binding results. Failure must preserve a ready host; no automatic prompts or raw secrets in errors/configuration.
  • Design additional-user linking and direct-on-target enrollment with explicit authorization.
  • Keep every implemented CLI operation paired with a tested Python example and accessible code tabs; generated references must retain both.

Evidence

The full Python suite passed 338 tests with 60 skips; focused tests, lint, packaging, and docs build passed. CLI/Python subprocesses also passed against actual main HTTP/JWT routes, persistent isolated MongoDB, control plane, and nymph binary: online status, stable replay, authorization/conflict rejection, and renewed heartbeat after restart. SSH/systemd were local adapters. This proves cross-component integration, not remote Linux or bos14/AWS workload acceptance.