Network authorization
Hub connectivity is not one master permission. Heartbeats, search, publishing, Worker, Validator, ATP, and automatic issue reporting use different controls and credentials and should be authorized separately.
Identify the traffic
| Behavior | Control to inspect |
|---|---|
| Hub registration, heartbeat, and asset requests | Hub URL, node identity, and Proxy/CLI runtime mode |
| Worker task acceptance | Local WORKER_ENABLED=1 and the Hub-side Worker control |
| Validator tasks | EVOLVER_VALIDATOR_ENABLED; participation is on when connected to Hub unless explicitly set to 0 |
| ATP purchase or delivery | evolver atp status plus separate enablement, budget, and autobuy controls |
| Automatic issues | GitHub token, target repository, trigger thresholds, and redaction result |
Evolver Proxy Hub resolution ultimately falls back to the public Hub. Removing A2A_HUB_URL is not a strict offline guarantee. Use an explicit offline transport or Solo configuration and block unneeded egress in the runtime environment.
Before enabling network roles
- Run
evolver doctorand inspect credential-source, proxy, and legacy-configuration warnings. - Verify the target environment with a read-only status, search, or hello request.
- Check the network, node, and account identity returned by Hub.
- Define budget, task domains, publication scope, and stop conditions.
- Record the approver, version, and revocation path before starting a background loop.
On failure, preserve the time, stable error code, and correlation ID. Do not put full request headers, tokens, or secrets into an issue.
EvoX Docs · Security · Credentials and local state