AI

Harnesses

A harness makes an AI coding agent build a project, or maintain a server, the way an expert in that stack would - without you writing the rules yourself.

A stack harness is a package of rules, settings, safe permissions, format hooks and slash commands. Synapse looks at a project folder (or a server), works out what it is, and offers to apply the matching harness. It writes files like AGENTS.md and .claude/settings.json into the project, merged with anything already there, and every agent that reads AGENTS.md - Claude Code, Codex, Cursor, Gemini CLI, OpenCode and others - follows the same rules.

Harnesses need the Stack harnesses service. Switch it on in Services.

Applying a harness

  1. Open the Harnesses view (or Session tools, for a connected host) for a project folder or server.
  2. Synapse detects the stack from files, dependencies and, for servers, the operating system and installed commands, and suggests the best match.
  3. Review the preview: every file it will write or merge, every permission rule it adds, every hook and any MCP server, listed exactly.
  4. Apply. Files you already have keep your content - the harness only adds its own marked block or its own files.
  5. Run the checks (a one-click button per check) to see the harness's definition of done pass or fail for the project as it stands today.

Applying again after editing the project is a no-op; applying a newer version of the same harness updates its blocks and files in place. Remove takes out only what the harness added - your own edits, and anything you added yourself, are left alone.

Previews first, always

Nothing is written until you approve the preview, and setup steps (like installing a dev dependency) only run when you click them - never automatically.

Project harnesses

Applied to a project folder. Detection looks at files and dependencies in that folder.

Laravel + MariaDB

Laravel 13 on MariaDB with any official frontend: Inertia + React, Inertia + Vue, Livewire (with Flux) or plain Blade. One harness covers all four - AGENTS.md has shared backend rules (Pest, Pint, Larastan, MariaDB-safe migrations) plus a section for whichever frontend your project actually uses. It sits alongside Laravel's own official AI package, Laravel Boost, rather than replacing it.

WordPress

For a whole WordPress install, a theme (block, classic or child) or a plugin, including block plugins. Extends with hooks instead of editing core, and treats live sites and their databases with care.

Next.js + TypeScript + Postgres

Next.js 16 (App Router, Server Components, Server Actions, Turbopack) with Postgres through Drizzle or Prisma, whichever the project already uses. Treats Server Actions as public endpoints that need their own authorisation and validation, and keeps data access in a server-only layer.

Plain PHP + MariaDB

For PHP projects without a framework: Composer with PSR-4 autoloading, a front controller and small router, PDO, plain-PHP templates. Aimed at typical shared hosting and at older codebases that need careful, well-tested changes.

Server harnesses

A server harness is for maintaining a live server, not writing application code. It's applied to an ops workspace folder on the host (~/ops by default, changeable per host), and agents run with that folder as their working directory. Detection reads the operating system and which commands and paths exist on the host itself.

cPanel & WHM

For AlmaLinux, CloudLinux or Rocky servers running cPanel & WHM, as root/WHM or as a single cPanel account (including inside CloudLinux's CageFS).

Linux server

For a live Linux server without a control panel - Ubuntu/Debian (apt, ufw, AppArmor) or the RHEL family (dnf, firewalld, SELinux) in one harness. Hosts running cPanel, Plesk, DirectAdmin, HestiaCP, VestaCP or ISPConfig are excluded, since they have their own harness or panel tools.

Docker host

For Linux hosts running containerised services with Docker Engine and Compose, including hosts fronted by Traefik, Caddy or nginx-proxy. Complements the Linux server harness (apply both on a Docker host) rather than replacing it.

How safety works

Every harness's .claude/settings.json splits commands into three lists: allow (safe, read-only or routine commands that run without asking), ask (changes that need a human in the loop), and deny (destructive commands that never run, regardless of what the agent proposes). The Harnesses preview shows you the exact rules before you apply. These rules reduce risk but are not a sandbox - they match command text, so always run agents as the least privileged user that can do the job.