propose a sync design, and separate the credential claim from the authority one master
A proposal, not an implementation. Nothing in it has been run. Two capabilities are missing. The global Claude Code configuration reaches the box only through a full provisioning run, via `git archive HEAD`, so the box runs the last committed state at the last delivery and drifts behind every edit since — and a dirty tree is refused outright, so an uncommitted tweak cannot be synced at all. And a project can only move one way, while an agent working on the box produces real work with no route off it. The design turns on which claim "one-way flow" names. §5.1's is about credentials: a pull model would need a bootstrap token on the box, and no credential is needed on the server to obtain its own configuration. §4.5's is about authority: the laptop holds the authoritative copy. The second is the one relaxed. Every transfer is still initiated by the laptop, which holds the only key that reaches the box; the server is given no key, no token and no address that reaches back. Credentials flow one way; code flows both ways. Both proposed scripts therefore live in `laptop/` by the layout convention's own test rather than as an exception to it — the question that directory answers is which machine must be the one to run something, and for a pull the answer is the laptop for a stronger reason than for a push. Git carries tracked files in both directions over the tailnet, rsync a deliberately narrow set of untracked ones, because a fetch moves every byte of the box's work onto the laptop without touching a working file — the only shape that is safe for a trigger which cannot stop to ask a question. Section 8 lists six questions needing an operator decision before implementation.